Welcome to NxtUp! This Privacy Policy explains how NxtUp ("we," "us," or "our") collects, uses, discloses, and protects your information when you use our application and related services (collectively, the "Services"). Our Services are designed to help you discover and receive personalized recommendations for shows, movies, and sports content based on your preferences and viewing history.
Please read this Privacy Policy carefully. By using our Services, you agree to the practices described here. If you do not agree, please do not use our Services.
Our core promise to you: NxtUp does not sell your personal information. We collect data to improve your experience and provide better recommendations — nothing more.
1. Information We Collect
We collect information in the following ways:
1.1 Information You Provide
- Account Information: When you register, we collect your name, email address, username, and password (stored in hashed form). We also collect your birthday, country, preferred languages, and streaming service preferences (i.e., which services you subscribe to, such as Netflix or Hulu). We may also collect an optional invite or referral code.
- Profile Preferences: Streaming service preferences, excluded genres (genres you wish to exclude from recommendations), preferred languages, sports teams, and other preference data you explicitly provide.
- Ratings: Ratings you give to shows, movies, or other content within our Services.
- Communications: Messages you send us via support channels or feedback forms.
1.2 Information Collected Automatically
- Viewing History: Records of content you have tracked, marked as watched, or added to your watchlist or favorites.
- Interaction Data: How you interact with content and recommendations, including items you add to watchlists or mark as watched, and your viewing progress.
- Device Information: Device type, operating system, unique device identifiers, and browser type.
- Usage Data: Pages or features accessed, time spent in the app, session duration, and clickstream data.
- Log Data: IP address, access times, referring URLs, and error logs.
- Session and Preference Storage: We use cookies and similar technologies (such as local storage) to maintain your session (e.g., authentication tokens), remember your preferences (e.g., display settings), and analyze usage.
1.3 Information from Third Parties
- Authentication: We currently use email and password authentication only. We may add optional sign-in with third-party providers (e.g., Google or Apple) in the future; if we do, we would collect only the identifiers and basic profile information those services provide, and we will update this policy accordingly.
- Streaming Service Preferences: We do not connect to your streaming accounts or receive viewing activity from streaming platforms. You tell us which streaming services you subscribe to so we can surface content available to you; no data is retrieved from those platforms on your behalf.
- Error and Performance Monitoring: We use third-party services such as Sentry and Vercel Speed Insights for error tracking, performance monitoring, and (in error cases) session replay. These services may collect device and usage data in accordance with their own privacy policies.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Personalized Recommendations: To power our recommendation engine, tailoring show, movie, and sports suggestions to your taste and history.
- Service Delivery: To operate, maintain, and improve our Services and your user experience.
- Account Management: To create and manage your account, authenticate your identity, and communicate with you about your account.
- Customer Support: To respond to your questions, troubleshoot issues, and fulfill your requests.
- Research and Development: To understand how our Services are used and to develop new features and improvements.
- Security and Fraud Prevention: To detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities.
- Service Communications: To send you service-related and account communications, such as password reset emails and account change notifications. We do not currently send marketing newsletters or promotional emails. If we do so in the future, we will only send them with your opt-in consent and you may opt out at any time.
- Legal Compliance: To comply with applicable laws, regulations, and legal proceedings.
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following limited circumstances:
- Service Providers: With trusted third-party vendors who perform functions on our behalf. Our current key service providers include: TMDB (content metadata), Stripe (payment processing), Sentry (error and performance monitoring), Resend (transactional email delivery), MongoDB (database hosting), and Vercel (application hosting and performance insights). These parties are bound by data processing agreements and are only permitted to use your data to provide services to us.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.
- Legal Requirements: When we believe in good faith that disclosure is required by law, to protect the rights and safety of our users or the public, or to respond to valid legal processes such as subpoenas, court orders, or government requests.
- Aggregated or Anonymized Data: We may share aggregated or de-identified information that cannot reasonably be used to identify you, for research, analytics, or business purposes.
- With Your Consent: In any other circumstances, only with your explicit consent.
4. Viewing History and Recommendation Data
Your viewing history and preferences are central to how our Services work. Here is how we handle this data specifically:
- Your history is stored securely and used exclusively to generate recommendations and improve your experience.
- You can view, manage, and delete your viewing history (tracked shows, movies, and favorites) at any time from your account settings.
- You can clear your watch history and delete your account at any time from your account settings. We do not currently offer a dedicated setting to turn off personalized recommendations; if we add one in the future, we will update this policy.
- We do not share your individual viewing history with third-party advertisers.
5. Cookies and Similar Technologies
We use cookies and similar technologies (such as local storage) to support the operation of our Services and enhance your experience. The technologies we use include:
- Essential Session Storage: We store your authentication token (JWT) in local storage to keep you signed in. This is required for the Services to function and cannot be disabled.
- Preference Storage: We use local storage to remember your settings and preferences across sessions (e.g., dark mode and display preferences).
- Error and Performance Monitoring: We use Sentry and Vercel Speed Insights for error tracking and performance monitoring. These services may use their own cookies or similar tracking technologies. We do not currently use first-party analytics cookies or marketing cookies.
You can control cookies through your browser settings, though disabling certain storage may affect the functionality of our Services. We currently do not respond to browser Do Not Track signals. You may manage available preference settings within your account.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our Services. If you delete your account, we will delete or anonymize your personal information promptly upon your request — including your profile, tracked content, favorites, watch history, and related data — except where we are required to retain it for legal, regulatory, or fraud prevention purposes.
Aggregated, anonymized data derived from your activity may be retained indefinitely for analytics and product improvement purposes.
7. Data Security
We take the security of your personal information seriously. We implement reasonable technical, administrative, and organizational safeguards to protect your information against unauthorized access, loss, misuse, or alteration. These measures include:
- Encryption of data in transit using TLS/HTTPS.
- Storage of your data with infrastructure providers (MongoDB Atlas, Vercel) that implement encryption at rest at the infrastructure level.
- Passwords stored exclusively in hashed form — we never store plaintext passwords.
- Access controls limiting who within our organization can access personal data.
- Error and performance monitoring via Sentry to detect and respond to issues promptly.
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security and encourage you to use strong, unique passwords and to protect your account credentials.
8. Children's Privacy
Our Services are not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such information, we will take prompt steps to delete it. If you believe a child has provided us with personal information, please contact us at support@solvaralabs.com.
9. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct inaccurate or incomplete information.
- Deletion: Request that we delete your personal information, subject to certain exceptions.
- Portability: Request a machine-readable copy of the data you have provided to us.
- Opt-Out of Service Communications: You may opt out of non-essential service communications by contacting us. Some account-related communications (e.g., password resets) are necessary for the operation of your account and cannot be opted out of.
- Watch History: You may clear your watch history at any time from your account settings. We do not currently offer an in-app opt-out of personalized recommendations; if we add this option, we will update this policy.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to our processing of your data where we rely on legitimate interests.
To exercise any of these rights, please contact us at support@solvaralabs.com. We will respond to your request within 30 days. We may need to verify your identity before processing your request.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), including:
- The right to know what personal information we collect, use, disclose, and sell.
- The right to delete personal information we have collected from you.
- The right to opt out of the sale or sharing of your personal information. We do not sell your personal information.
- The right to non-discrimination for exercising your privacy rights.
- The right to correct inaccurate personal information.
- The right to limit use and disclosure of sensitive personal information.
To submit a California-specific privacy request, please contact us at support@solvaralabs.com.
11. International Users
Our Services are operated in the United States. If you access our Services from outside the United States, please be aware that your information may be transferred to and processed in the United States, which may have different data protection laws than your country.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR). Our lawful bases for processing include your consent, performance of a contract with you, compliance with legal obligations, and our legitimate interests (such as improving our Services and preventing fraud).
12. Third-Party Services
Our Services integrate with and rely on third-party providers to function. Below is a summary of our key service providers and their roles:
- TMDB (The Movie Database): Provides content metadata — titles, descriptions, artwork, and related information — for shows, movies, and other content.
- Stripe: Processes payments securely. We do not store full payment card details; Stripe handles payment data in accordance with PCI-DSS standards.
- Sentry: Provides error tracking, performance monitoring, and (in error scenarios) session replay to help us identify and resolve issues.
- Resend: Delivers transactional emails (e.g., password resets, account notifications) on our behalf.
- MongoDB: Hosts our database infrastructure. Data stored in MongoDB Atlas benefits from infrastructure-level encryption at rest.
- Vercel: Hosts our application and provides Speed Insights for performance monitoring.
This Privacy Policy does not apply to third-party services and we are not responsible for their privacy practices. We encourage you to review the privacy policies of these services. We do not connect to your streaming platform accounts (e.g., Netflix, Hulu) and we do not currently use third-party social login providers to collect data about you.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Post the updated Privacy Policy on this page with a new effective date.
- Notify you via email or an in-app notification if the changes are significant.
Your continued use of our Services after any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this page periodically.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
NxtUp
Email: support@solvaralabs.com
Website: nxt-up.app
We take privacy concerns seriously and will respond promptly to your inquiries.
© 2026 NxtUp. All rights reserved.