Privacy
In effect from 29 July 2026
This describes what Vinicios Cunha, operating as NextNode does with your information — in plain terms, and specifically enough that you could check it. Career history is personal, so the short version is: we keep as little as we can get away with.
The short version
- We don’t store what you write about yourself. Your background description is sent to the model that draws the map and then discarded. It is never written to our database.
- Your resume file never leaves your browser. It is read on your own machine and only the text inside it is sent. The file itself is never uploaded anywhere.
- We keep the finished map, not the raw input. So you can reopen it without paying again.
- There is no analytics, advertising or tracking of any kind. The only cookies we set are the ones that keep you signed in.
What we collect
Your account. Your email address, and the date you signed up. If you use a password, it is hashed by our authentication provider and we never see it. If you sign in with Google, we receive your email address and basic profile information from Google — not your Google password, and nothing else in your Google account.
Your maps. Each map you generate is saved to your account: the graph itself, a one-line summary the model writes, which model produced it, and when. You can delete any map from your library at any time.
Your credit history. Every credit granted, spent or refunded, with a timestamp and a reason. This is how a balance is calculated, and it is what lets us answer you honestly if you ever ask where a credit went. Stripe separately keeps the payment and transaction records created when you buy credits.
Signup signals. When you confirm your account by email link or sign in with Google, we record the IP address and browser user agent that did it. These exist to spot people creating many accounts to farm the free credit. They are never used to block anyone automatically, because shared offices, universities and mobile networks all put real people behind the same address.
Server logs. Like every website, our host records standard request logs including IP addresses. These are kept briefly for security and debugging. They do not contain what you typed.
What we deliberately do not collect
- The text you write about your background. It exists in server memory for the seconds it takes to generate your map, and is sent to the model provider below. It is never written to our database and never appears in a log.
- Your resume file. It is parsed in your browser. No copy is uploaded, stored or transmitted.
- Payment card details. When you buy credits, Stripe handles your card and acts as the merchant of record. Your card details never reach our servers.
- Anything for advertising. We do not sell, rent or share your information with advertisers, data brokers or anyone else for marketing. There is no third-party tracking script on this site.
Who else processes it
We use a small number of services to run NextNode. Each sees only what it needs to do its job.
| Service | What for | What it sees |
|---|---|---|
| Anthropic | Generates the map | The background text or resume text you submit, and your stated goal |
| Supabase | Accounts, database, authentication | Email address, hashed password, saved maps, credit history, signup IP |
| Vercel | Hosting and delivery | Standard server request logs, including IP address |
| Stripe | Payments and merchant of record | Payment details, billing information and independent transaction records; card details never reach NextNode |
| Brevo | Transactional account email | Your email address, name, email content and delivery status |
| ImprovMX | Forwards messages sent to our support and legal inboxes | The sender, recipients and contents of emails you send to a nextnode.app address |
Not yet in use, and this page will be updated before they are: Google.
The model provider receives your background text and your goal in order to produce the map, and retains it for a limited period under its own terms. We do not have an arrangement that eliminates that retention. Today Anthropic is the only model provider in use. A fallback provider exists in our code but is switched off; if it is ever switched on, the map itself names the provider that drew it and this page will say so first.
How long we keep it
Your account, maps and credit history are kept until you delete them. You can delete individual maps yourself from your library. Deleting your account removes your profile, every map and NextNode’s entire credit ledger along with it. Any unused credits are lost.
Account deletion does not erase the independent payment records held by Stripe. Stripe is the merchant of record for credit purchases and retains payment, transaction, tax, fraud and dispute records for as long as required to provide its services, comply with law and protect its legal interests. Those records are governed by Stripe’s own privacy terms and retention obligations.
Deleting your NextNode account is permanent and immediate. We cannot restore the account, its maps or its app credit history. Stripe’s separate payment records survive that deletion.
Your rights
Depending on where you live you may have the right to see the information we hold about you, correct it, have it deleted, or receive a copy in a portable form. We will honour all four regardless of where you live.
Delete maps yourself from your library. For anything else — a copy of your data, a correction, or full account deletion — email privacy@nextnode.app from the address on your account and we will action it.
Security
Every table is protected by row-level security, so the database itself enforces that you can only read your own rows — not just the application in front of it. Passwords are hashed by our authentication provider. The keys that can move credits exist only on the server and are never sent to a browser.
No system is perfect. If you find a security problem, email privacy@nextnode.app and we would rather hear it from you than from anyone else.
Children
NextNode is not intended for anyone under 16, and we do not knowingly collect information from children. If you believe a child has created an account, contact us and we will remove it.
Changes
If this policy changes in a way that matters, the date at the top changes and, for anything significant, we will tell account holders directly rather than quietly editing the page.
Questions about any of this go to privacy@nextnode.app. The companion document is the terms of service.