Privacy Policy
Last updated: August 2026
This policy explains how Blackbird Marketing (“Next Level”, “we”), based in the Republic of Kosovo, collects, uses, and protects personal data when you use the Next Level platform (the “Service”).
Controller vs. processor. For your own account data we act as a data controller. For the content inside a workspace (tasks, comments, files, and similar), the organisation that owns the workspace is the controller and we act as its processor, handling that content on its instructions to run the Service.
1. What we collect
- Account data, your email address, name, and optional avatar; the workspaces and roles you hold; and your preferences.
- Workspace content, the tasks, comments, files, goals, and other material you or your team create in the Service.
- Usage & technical data, log and device data such as IP address, browser type, and actions taken, used to operate, secure, and improve the Service.
- Integrations, if your workspace connects Slack, the identifiers needed to deliver notifications to the right people.
- Payment data, handled by our merchant of record, Paddle. We receive subscription and billing status, not your full card details.
2. How we use it
- to provide, maintain, and secure the Service and your account;
- to power features you use, including search and the AI assistant;
- to process subscriptions and prevent fraud and abuse;
- to provide support and send service-related messages;
- to improve the Service and understand how it is used, in aggregate;
- to comply with legal obligations and enforce our terms.
3. Legal bases (EEA/UK)
Where the GDPR applies, we rely on: performance of a contract (to give you the Service you signed up for); legitimate interests (to secure, support, and improve the Service, balanced against your rights); consent (for optional things like connecting Slack, which you can withdraw); and legal obligation (for example, tax and accounting records).
4. The AI assistant
When you or a teammate use the AI assistant, the relevant workspace content is sent to our AI provider (Anthropic) to generate a response, and text you index is sent to Voyage AI to build search embeddings. These providers process that content only to deliver the feature to you and do not use it to train their general-purpose models. If you do not use AI features, your content is not sent to these providers for that purpose.
5. Sub-processors
We share data only with vendors that help us run the Service, under contracts that require them to protect it:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Authentication, database, and file storage | EU |
| Vercel | Application hosting and delivery | EU (Frankfurt) |
| DigitalOcean Spaces | Object storage for uploaded files | EU (Frankfurt) |
| Paddle | Payments and subscriptions (merchant of record) | EU / UK |
| Anthropic (Claude) | Powers the AI assistant on the content you send it | US / EU |
| Voyage AI | Creates search embeddings so you can search by meaning | US |
| Slack | Optional notifications, if your workspace connects it | US / EU |
| Email delivery provider | Sends sign-in links and notification emails | EU / US |
We do not sell your personal data or share it for advertising.
6. Where your data is stored
Your account data and workspace content are hosted in the European Union. Some sub-processors (such as our AI providers) may process data outside the EU; where they do, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. How long we keep it
- Workspace content is kept while your workspace is active.
- Deleted tasks go to a Trash that is recoverable for 30 days and then permanently removed. A deleted workspace is retained briefly for recovery, then purged.
- After account closure, we delete or anonymise personal data within a reasonable period, except where we must keep records (for example, billing) to meet legal obligations. Backups are overwritten on a rolling cycle.
8. Security
We protect data with encryption in transit, access controls, and workspace isolation enforced at the database level, so one workspace cannot read another’s data. No system is perfectly secure, but we take reasonable measures to protect your information and review them as the Service grows.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the use of your personal data, and to object to certain processing. You can update much of your account data in the app directly. For other requests, contact us at privacy@usenextlevel.app. If a workspace holds content about you as a member or guest, that organisation is the controller; we will refer your request to them or help them fulfil it. You may also complain to your local data-protection authority.
10. Cookies
We use only the cookies and local storage needed to keep you signed in and remember your preferences (such as theme). We do not use advertising or cross-site tracking cookies.
11. Children
The Service is for organisations and is not directed to children under 16. We do not knowingly collect their data.
12. Changes
We may update this policy as the Service evolves. If a change is material, we will take reasonable steps to notify you. The “last updated” date above shows the current version.
13. Contact
For any privacy question or request, contact privacy@usenextlevel.app. See also our Terms of Service.