Privacy policy
Last updated 9 August 2026
The short version: what you write in the lab is yours. We don't share it with anyone, we don't advertise against it, and we never send it to an outside AI model. Your reflections and your budget aren't visible to us at all, and anything you do share with us, like letting us into your account to fix something, is a switch you control and can turn off. We run the database, so we can reach what is in it; this page says exactly what that means in practice rather than leaving you to assume.
Who we are
next[you]labs is operated by Jignesh Parbhu, a sole trader in New South Wales, Australia. If you have a question about your data, email archie@nextyoulabs.io. A person reads it.
You need to be 18 or over to hold an account. The lab deals with money, careers and personal decisions, and we'd rather be honest about who it's built for.
What we collect
When you create an account: your name and email address, and a password we never see. It's hashed by our authentication provider before it reaches storage. If you sign up with Google we also receive the name and profile picture on your Google account. We read your device's timezone so dates and streaks land on your day rather than ours.
When you fill in your profile: your country, city, date of birth, and which of a short list of topics brought you here: budgeting, career, habits and so on, with “prefer not to say” among the choices. All of it is optional, and you can change or clear any of it from Settings.
As you use the lab: everything you type: goals, tasks, mentoring requests and support messages, along with any experiment records and reflections from the earlier lab. We also record one row per day that you open the portal, which is what draws your streak. That's a date, not a log of what you did.
If you use the budget module: the income, bills and commitments you enter. If you import a bank statement, that includes the transactions in it: dates, amounts, merchant names and the bank's own description text. The statement file itself is never stored. It's read in memory, turned into transactions, and discarded; we keep only a fingerprint so importing the same file twice doesn't duplicate everything.
We don't ask for anything about your health, beliefs, background or identity, and there is nowhere in the lab designed to collect it. But the writing surfaces are open text, and people reflecting honestly sometimes write personal things. That's your call to make. Nothing here requires it, and reflections are the one place nobody but you can read.
What we do with it
We use it to run your account and show you your own work back: your lab, your streaks, your progress. We use aggregate counts, like how many people added a task, how many opened the portal this week, to decide what to build next. That's the whole list.
Nothing you write is sent to an AI model. No part of this platform passes your text to an outside AI service. If that ever changes, it changes here first, and we'll tell you before it does.
We don't share your data
Not with other members, not with advertisers, not with anyone else. There is no sharing feature, no public profile and no team view. There is no other member can see anything of yours, because there is no way for them to. We don't sell it, rent it or trade it, and we don't hand it to anyone for their own purposes.
What you share is your decision
If you want help with something, you can open a support session: it lets us work inside your account to fix whatever is wrong. It is off by default. You turn it on, it lasts 30 days, and you can switch it off instantly from Settings → Privacy & access once you're signed in.
While one is running, a banner stays on your screen the whole time, you can see a record of every session that has ever happened on your account, and we cannot delete anything while we're in there. Your budget is a second, separate switch. Turning on support access does not open it, and switching support off closes both.
Your reflections and your budget are yours alone. Your notes, your financial model, your weeks and your imported transactions carry no staff access in the app at all. There is no screen anywhere that will show them to us. That is enforced by the database, not by us choosing not to look.
The part we should be straight about
We run the database. That means, in the plainest terms, that the person operating this service can reach what is stored in it. This is true of every online service you use, because someone has to be able to fix the thing when it breaks, and we'd rather say it than let you assume otherwise.
In practice, that means some of your information is visible to us in our own admin view so we can run the lab and help you: your account details, including your date of birth and the topics you picked, your goals and tasks (and any experiment history from the earlier lab), which days you were active, and your mentoring and support history. We look when there's a reason to: answering your ticket, chasing a bug, seeing whether a feature works. It is one person, not a team, and none of it goes anywhere else.
One thing that runs the other way: when a mentor writes notes on a session, you see them once they're published rather than as they're drafted. They are still your information, and you can ask for them at any time.
The services we rely on
Running this needs a small number of other companies. They process data on our instructions and for no purpose of their own. There are four:
- Supabase, the database, sign-in and file storage. Your data lives here, in Sydney.
- Vercel, hosting, in Sydney. Vercel also gives us page-view analytics: which pages get visited and roughly where from. It sets no cookies and never sees what you write.
- Resend, email. When you open a support ticket or request a mentoring session, that message is emailed to us so we actually notice it, including your name, email address and what you wrote.
- Google, only if you choose to sign in with Google, and only to confirm it's you.
We don't use advertising networks, trackers or data brokers. There is no third-party analytics beyond the page views above, and we set no advertising or tracking cookies. The only cookies here keep you signed in and remember whether your sidebar is open.
Your data is stored in Australia. Email and page-view analytics are handled by providers who may process outside it.
How long we keep it
While your account is open. There's no clock running in the background. Nothing expires, and nothing is quietly archived. When you delete your account, it goes.
Deleting your account
You can do it yourself from Settings → Privacy & access once you're signed in. It's immediate and it can't be undone: your profile and everything in your lab goes with it: goals, tasks, budgets, transactions, any experiment history and reflections from the earlier lab, mentoring records and support access history. We keep no backup you could ask us to restore from.
Two exceptions, so that promise is exact. Feedback and feature requests you sent us stay on our build list, and support messages you sent stay on their ticket, in both cases with your name, email and account removed, so nothing left behind points at you. We keep them because deleting them would erase the reasoning behind what we build. If you'd rather they went too, email archie@nextyoulabs.io and we'll remove them by hand.
Separately: notification emails already sent to us about your tickets or mentoring requests sit in an ordinary inbox, and deleting your account doesn't reach into it. Ask and we'll clear those too.
Your rights
You can see and change most of your information yourself, from Settings. Beyond that you can ask us to give you a copy of what we hold, correct something that's wrong, delete your account and data, or export your data in a portable form. Email archie@nextyoulabs.io. We'll respond within 30 days, and we won't charge you for it.
If you're in the UK or EU, you have these rights under the GDPR. We handle your data because we need it to provide the service you asked for, and because we have a legitimate interest in keeping the platform working and secure, never to build a profile of you or to sell anything on.
Security, and what happens if we get it wrong
Your data is separated at the database level, not just in the interface: the rules that decide who can read a row live in the database itself, so a bug in a page can't hand your budget to someone else. Connections are encrypted. Passwords are stored only as hashes and are never visible to us.
We're not going to tell you that's unbreakable, because nobody can. If something goes wrong that puts your data at serious risk, we'll tell you and the relevant regulator, promptly and in plain terms.
Complaints
Come to us first. Email archie@nextyoulabs.io and we'll take it seriously. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. In the UK or EU, you can complain to your local data protection authority.
Changes
When this page changes we'll update the date at the top. If a change actually affects what happens to your data, rather than just how it's worded, we'll tell you rather than leave you to notice.