Legal · Privacy
Privacy Policy.
Plain-language summary: we collect the information needed to provide the assessment, account, subscription, Foundation implementation, and support you request. We do not sell personal information or use cross-context behavioral advertising. The internal OS Assistant sends a bounded portion of your business record and recent conversation to Anthropic. A Foundation customer-facing assistant is configured only from Customer-approved materials, with its provider and data flow documented before publication. Do not put sensitive personal or regulated data into either feature.
1. Who we are and scope
Sky Hood Ventures LLC, doing business as Next Standard Systems (“NSS,” “we,” “us,” or “our”), operates nextstandardsystems.com and the related business-to-business services. This policy explains how we collect, use, disclose, retain, and protect personal information when you use the website, Business Operating Assessment, startup Business Blueprint, account, Next Standard OS, Operating Assistant, implementation intake, referral links, or support.
The Services are intended for United States business users, not children or personal, family, or household use. This policy does not govern a third party’s independent practices.
2. Information we collect
| Category | Examples | How collected |
|---|---|---|
| Account and contact | Name, business email, password hash, email-verification status, role, contact preferences | Directly from you |
| Business and assessment | Business name, industry, stage, operating answers, startup goals, team and lead ranges, notes, scores, priorities, analysis snapshots, Blueprint | Directly from you and generated from your answers |
| OS workspace | Plans, actions, KPIs, targets, check-ins, progress, reassessment history, playbook progress, profile details, recent Assistant conversation | From you and your use of the Services |
| Foundation implementation | Scope, agreement and signature evidence, Build Brief, business links, project contacts, deliverable status, approved website-assistant source material, configuration, test questions, approvals, and handoff status | Directly from you and NSS personnel |
| Billing and transaction | Plan or package, amount, currency, billing address and tax information, Stripe customer/session/subscription/payment identifiers, status, refunds | From you and Stripe; NSS does not receive full card numbers |
| Communications and consent | Support requests, transactional and marketing-email status, consent text/version/time/source, unsubscribe status, delivery/bounce/complaint events | From you and our email provider |
| Referral | Referral code, landing path, first-valid attribution, qualifying purchase and commission status | From links, cookies, and verified transactions |
| Technical, security, and usage | Session identifiers, timestamps, page or feature events, browser user agent, approximate network address, audit events, rate-limit and error information | Automatically from your browser and systems |
Acceptance-event network addresses are converted to a keyed one-way HMAC before storage; NSS does not store the raw address in the legal-acceptance record. Server and infrastructure logs may separately contain network and request information for security and reliability.
3. Information you should not submit
Do not submit passwords or API keys in assessment, Blueprint, Build Brief, check-in, or Assistant fields. Do not submit payment-card numbers, Social Security numbers, government IDs, protected health information, biometric data, consumer credit data, export-controlled data, or sensitive personal information about employees, customers, or other individuals. When sharing links or business materials, confirm that you have authority to do so and use the secure access-transfer process NSS specifies for implementation credentials.
4. How we use information
We use information to:
- create and secure accounts, authenticate sessions, and verify email addresses;
- save answers and generate assessments, analyses, Blueprints, priorities, plans, dashboards, reassessments, and operating guidance;
- provide and meter the Operating Assistant and retain conversation continuity;
- present prices, create Stripe checkout or portal sessions, confirm payments, provide entitlements, calculate applicable tax, prevent duplicate or fraudulent transactions, and handle cancellation or refunds;
- form and preserve evidence of contracts, consent, scope, and electronic signatures;
- onboard and perform Foundation implementation work, configure and acceptance-test a customer-facing information assistant from approved materials, communicate milestones, and deliver requested materials;
- send transactional messages and, only after optional affirmative consent, marketing messages;
- attribute referrals, administer commissions, measure funnel performance, and prevent abuse;
- operate, debug, secure, audit, and improve the Services; enforce agreements; comply with law; and establish or defend legal claims.
5. AI processing
5.1 Internal OS Operating Assistant and Anthropic
When you send a message to the Operating Assistant, NSS creates a bounded prompt that may contain your assessment or Blueprint, scores and priorities, profile, current plan and actions, KPIs, recent check-in, and a limited recent conversation history. NSS sends that prompt and your message to Anthropic’s commercial API to generate a response. We do not send your password or full payment-card data. The Assistant does not take actions in external systems.
NSS does not opt customer API content into model training. Under Anthropic’s published commercial API terms and privacy documentation as of this policy date, inputs and outputs are not used to train models by default and may generally be retained for up to 30 days for trust-and-safety purposes, unless a different approved configuration or legal obligation applies. Anthropic’s practices may change; its current commercial terms and privacy information govern its processing. Your Assistant conversation is also stored by NSS in your account so the feature has continuity and can be audited.
AI output may be wrong. Do not rely on it as professional advice or enter sensitive personal or regulated information. NSS may review limited records when reasonably necessary to investigate a reported problem, security event, or abuse, subject to access controls.
5.2 Foundation customer-facing information assistant
Foundation may include configuration of one customer-facing AI information assistant on a compatible Customer-controlled website. Before publication, the Build Brief or other written project record will identify the selected model, hosting or website provider, approved source materials, intended visitor-data fields (if any), retention or logging settings reasonably known to NSS, human escalation path, and responsible account owner. NSS will not enable visitor lead capture or sensitive-data collection unless the accepted scope and Customer’s own visitor notice and consent controls support it.
For a Customer’s website, that Customer is the website operator and is responsible for its own privacy notice, sector-specific duties, permissions for the source materials, and lawful instructions. NSS acts only within the accepted Foundation scope. The assistant must disclose that it is AI, must not request payment-card numbers, government identifiers, health information, credentials, or other sensitive or regulated information, and must not be used for decisions producing legal or similarly significant effects. Customer must provide a human contact path and keep its approved business facts current.
If NSS hosts, monitors, or maintains the Customer assistant after handoff under a separate written scope, the parties will document their respective privacy roles, approved providers, retention, security, deletion, and incident responsibilities before that processing begins. Third-party provider terms and privacy practices govern their independent processing and may change.
6. How we disclose information
We disclose information only as reasonably necessary to:
- service providers: Netlify (hosting/functions), Supabase/Postgres (database hosting), Stripe (payments, billing, tax features), Resend (email), Anthropic (internal OS AI inference), any Customer-approved website or AI provider documented for a Foundation assistant, and vendors supporting security, operations, or professional advice;
- implementation personnel and contractors: only when needed for the implementation Customer purchased and subject to confidentiality obligations;
- business transfers: in diligence or completion of a merger, financing, reorganization, or sale, with appropriate confidentiality protections;
- legal and safety needs: to comply with law or valid legal process; protect rights, safety, systems, and users; investigate fraud or abuse; or establish and defend claims; and
- at your direction: when you request or authorize a disclosure.
Google Fonts may receive ordinary browser request information when your browser loads font files from Google’s servers. We do not currently place third-party advertising or analytics cookies. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising as those terms are defined by applicable U.S. state privacy laws.
7. Cookies and similar technology
We use first-party, essential cookies:
- sid authenticates your account and is signed, HTTP-only, SameSite=Lax, and secure in production;
- dsid resumes an in-progress assessment for up to 14 days;
- referral cookies preserve a validated referral code and random visitor identifier for up to 30 days; the identifier is hashed before analytics storage.
These cookies are necessary for requested functionality and security. We do not use advertising cookies. Campaign parameters and landing paths may be stored with a session or referral to measure how users find NSS. Browser controls can block cookies, but doing so may prevent sign-in, resuming, or attribution.
8. Email and marketing choices
We send transactional messages needed for accounts and requested services, such as verification, password reset, saved-report delivery, billing, cancellation, implementation, and security notices. These are not marketing opt-ins.
Marketing email is sent only after you select an optional, unchecked consent box. We record the wording version, time, source, delivery history, and unsubscribe status. Every marketing message identifies NSS and Sky Hood Ventures LLC, includes a valid physical postal address configured before sending, and provides one-click unsubscribe. Unsubscribing does not affect your account or purchased Services. We retain a minimal suppression record so we do not email you again contrary to your request.
9. Retention
| Record | Typical retention |
|---|---|
| Incomplete assessment session | For resume, support, consent evidence, security, and funnel integrity while reasonably needed; the browser resume cookie expires after up to 14 days |
| Account, saved assessment/Blueprint, and OS workspace | While the account remains open and afterward as needed to complete a verified deletion request, preserve transaction records, resolve disputes, or meet legal obligations |
| Assistant conversation in NSS | While needed for account continuity, support, security, and audit; Anthropic’s separate temporary retention is described above |
| Contracts, acceptance evidence, payments, tax and implementation records | Generally at least seven years after the transaction or relationship ends, or longer if required for tax, accounting, dispute, or legal purposes |
| Security, audit, rate-limit, and incident records | For as long as reasonably needed to protect the Services, investigate events, and establish or defend claims |
| Email suppression record | As long as reasonably necessary to honor the opt-out |
We periodically review retention needs rather than keeping every category forever. We may keep information longer when required by law, tax or accounting rules, litigation hold, fraud prevention, backup cycles, contract enforcement, or security needs. We may retain de-identified information that cannot reasonably identify a person or business user.
10. Security
Measures include password hashing, signed HTTP-only sessions, CSRF and origin controls, encryption in transit, authenticated server-side database access, tenant-ownership checks, access logging, rate limits, webhook-signature verification, least-necessary AI context, private operational credentials, and incident-response procedures. Payment-card details are handled by Stripe. No security measure eliminates all risk; use a unique password and promptly report suspected misuse.
11. Your choices and privacy requests
You may update profile information in your account, cancel a subscription from the account, unsubscribe from marketing by one-click link, and request access, correction, deletion, or a portable copy by emailing privacy@nextstandardsystems.com. State law may provide additional rights to know, correct, delete, obtain a copy, or appeal a decision. NSS will not discriminate for exercising a legal privacy right.
We will verify requests using information reasonably related to the account and may require confirmation from the account email. An authorized agent must provide proof of authority, and we may still verify directly with you. Some records cannot be deleted immediately because they are needed for security, contracts, tax, payments, legal claims, or other lawful exceptions. If a request is denied, our response will explain why and how to appeal where applicable.
12. Children
The Services are not directed to anyone under 18, and NSS does not knowingly collect personal information from children. Contact us if you believe a child submitted information.
13. International use
The Services are currently offered to United States business users. Do not use them from another country without NSS’s prior written approval. Information is processed in the United States and may be processed where service providers operate.
14. Changes to this policy
We may update this policy prospectively. The version and effective date appear above. Material changes will be communicated through the account or email and, when required, new consent will be requested. Prior transaction evidence remains associated with the version accepted at that time.
15. Contact
Privacy questions and requests: privacy@nextstandardsystems.com. General support: support@nextstandardsystems.com. Next Standard Systems is operated by Sky Hood Ventures LLC in Phoenix, Arizona.
