NextAct

Your privacy

NextAct is built to need very little about you, and to delete what it does not need.

Most of a check never leaves this service

Reading the wording, examining a link’s structure, decoding a QR code, extracting text from a PDF or an email, comparing claims with evidence and producing the assessment all happen inside NextAct. No page is fetched, no link is followed and no attachment is opened.

What leaves, and only when you ask

The additional checks on a link contact outside services, and send the minimum each protocol needs:

  • the hostname, to a DNS resolver;
  • the registrable domain (example.com, never a full address), to that domain’s registry;
  • a connection to the site’s server to read its certificate — no page is requested.

Never sent: the message text, email bodies, uploaded files, the path or query of a link, your identity, your session or the check’s identifier. Checking a link does tell that domain’s infrastructure that someone asked about it; it does not tell them who you are or what you were asked to do.

AI

What NextAct does with AI

Nothing you submit is sent to an AI company. NextAct does not use one.

The assessment is never decided by a model. It is produced by NextAct’s own checks, and a model can only affect the wording of the explanation.

Removed and replaced with a placeholder first

  • account numbers, IBANs and other payment destinations
  • card numbers
  • cryptocurrency addresses
  • long digit strings that could be an account or reference
  • message and thread identifiers
  • national identity numbers
  • one-time passcodes and verification codes
  • passwords, API keys and anything that looks like a credential
  • phone numbers
  • sort codes and bank identifiers
  • the names people are addressed by
  • the personal part of email addresses

Never sent

  • the original file — a screenshot, PDF or email is never uploaded anywhere
  • your account, your session, or anything identifying you
  • other cases you have checked
  • the assessment itself, which is decided here and not by a model

What you get with no AI at all

  • the risk band and everything the assessment rests on
  • the link, domain and character checks
  • the comparison between who the message claims to be and where it points
  • the unknowns, and the safe way to check each of them
  • the explanation — NextAct writes its own when no model is involved

Nothing is sent, so there is nothing held by anyone else. What NextAct keeps is only what you chose when you submitted it.

What is kept

You choose at submission. Keep it in my history stores the check for 90 days so you can return to it. Delete the original once checked keeps the result and the evidence summary and removes what you submitted as soon as the analysis is stored — including the spans of it quoted into summaries, the path and query of any link, and any value an automated reading proposed.

Deleting is real

Deleting a check removes the case and everything derived from it: the material, extracted values, entities, claims, evidence, signals, assessments, policy records and any AI records. The confirmation page counts exactly what will go. There is no hidden copy and no “deleted” flag on a row that stays.

Your checks

What NextAct never does

  • It does not link your checks to anyone else’s, and no relationship crosses a case.
  • It does not sell or share what you submit, and no analytics vendor receives it.
  • It does not need an account, an email address or a phone number.
  • It does not store card numbers in full, and one-time codes are never stored at all.