The fine print

Privacy, in plain language.

The short version: your work stays in your browser. This page tells you exactly what that means, the few narrow things that reach our servers, and the rights you have over any of it.

The short versionRead this if you read nothing else

Your role, your answers, and the work you build here live in your browser's local storage — not in an account on our servers. There is no login, no profile we hold, and no database of your career on our side. You can see, export, or erase all of it from the Your data page whenever you want.

This is how the site is built, not just a policy we could quietly change. That said, we want to be honest and specific rather than sweeping: a few narrow features do send limited information to a server to work. Those are listed plainly below, with exactly what leaves your browser and what does not.

What stays in your browserThe default

Everything you enter into the tools stays local by default. That includes your cohort and role from onboarding, your Signal report and its cached narrative, your Pivot tool results (skills, values, energy, stories), your Upgrade progress, your Search campaigns and contacts, your Lab drafts, and your preferences like theme choice. It is stored under keys that begin with byn2. in this browser, on this device.

Because it is local, clearing your browser data, switching devices, or using private browsing will lose it — there is no cloud copy. If you want a backup, export it yourself from the Your data page.

What reaches our serversFour narrow exceptions, disclosed plainly

A handful of features need a server to function. Here is every one of them, and precisely what each sends.

  • 1 · AI narration and coaching (/api/ai) When a surface uses AI — narrating your Signal report, resolving a role we can't match, or coaching you through a tool or Lab draft — we send only the minimal fields that surface needs to do its job (for example, the tasks in your report, or the free text you asked us to interpret), to Anthropic's Claude API through our function. We send the least we can, never your whole profile. Exactly which surfaces use AI, and what they send, is documented in the AI disclosure on the Methodology page. AI output is a draft, labeled as AI-generated, and never presented as invented data.
  • 2 · Anonymous analytics (/api/track) We count anonymous pageviews and events (like "started the Signal") so we know which parts of the site help and which don't. This carries no personal information and no account — no names, no emails, nothing that identifies you. For basic abuse protection we rate-limit by a one-way hash of your IP address; we do not store your raw IP, and the hash can't be reversed back to it. You are a number in an aggregate count, not a profile.
  • 2b · Product analytics, only if you accept (PostHog) On your first visit you'll see a consent banner. If you accept, we additionally use PostHog to collect richer usage data — pages, clicks, device and browser, approximate location from IP, and session replays with every form input masked — and it sets first-party cookies to do so. If you decline, PostHog loads nothing, collects nothing, and sets no cookies; the anonymous counting above is all there is. Your choice is remembered in this browser, and you can change it anytime by clearing this site's data. Either way, we use no advertising trackers — no ad pixels, no ad networks, no cross-site tracking.
  • 3 · Company research for the Search desk (/api/ai dossier prefill) When you ask the Search desk to prefill a company dossier, we research the company name you entered on the server and cache the result so it can be reused across everyone who researches that same company. What is sent and cached is the public company name and the public research about it — never your notes, your edits, your fit reasoning, or anything else you type into that campaign. Your dossier edits stay in your browser.
  • 4 · When you choose to create an account If — and only if — you make an account to keep your work across devices, the work you already created in your browser is copied to our database so it can sync. This is optional and never required to use anything here. We store what you already had locally (your report, tools, campaigns, and preferences) tied to your email, nothing more. You can export it or delete it — permanently, server and all — from the Your data page, and deleting your account erases it from our servers entirely.

When you paste a job description (for the Signal or to start a Search campaign), that text is processed on the server to build your report or extract the role — and then it is discarded. Job-description text is never stored server-side.

If you subscribe to the weekly Briefing, the newsletter form sends the email address you type to our newsletter provider so we can send you the Briefing and nothing else. That is the one place you deliberately hand over a personal detail, and it is one click to leave, with no selling and no sharing, ever.

Hosting and logsWho serves the pages

This site is hosted on Netlify. Like any web host, Netlify's infrastructure automatically processes the standard request information needed to serve a page — such as your IP address and browser user-agent — and may keep short-lived operational logs for security and reliability. That is ordinary hosting, not profiling by us, and it is governed by Netlify's privacy policy. The AI features route through Anthropic's Claude API as described above, governed by Anthropic's privacy policy.

We do not set advertising cookies and we do not sell or share your data. The only third-party analytics is PostHog, and only after you accept the consent banner, as described above. Fonts are self-hosted — no font request leaves this domain.

Your rightsIncluding under GDPR

Because your work lives in your browser, most data rights are yours to exercise directly and immediately: you can access everything (it is on your device), export it as a file, and erase it — all from the Your data page, without asking us.

If you are in the European Economic Area, the United Kingdom, or a jurisdiction with comparable law, you have the rights afforded by the General Data Protection Regulation and similar regimes over any personal data we do process — which, in practice, is essentially your newsletter email address if you subscribe, and the operational and anonymous data described above. Those rights include the right to access, rectify, erase, restrict, or object to processing, and the right to data portability. To exercise any of them, or to ask us anything about your data, email buildingwhatsnext@gmail.com and we will respond. You also have the right to lodge a complaint with your local data protection authority.

Children and changesTwo last notes

Build Your Next is intended for working adults and is not directed to children under 16. We do not knowingly collect data from them.

If we change how any of this works, we will update this page and its effective date. Because we hold so little, changes here will usually be about clarity rather than new collection — and if that ever changes, we will say so plainly.

Questions about privacy go to buildingwhatsnext@gmail.com. See also the Terms and the Methodology page.