Effective: 21 September 2026
This policy explains what Next Moves Lab collects, why, and what you can do about it. It is written to be read, not to be survived.
1. Who we are
Next Moves Lab is operated by Bojan Stojanović PR Ležimir, a sole trader (preduzetnik) registered in the Republic of Serbia.
- Address: Fruškogorska 10, Ležimir, Serbia
- Tax ID (PIB): 112340770
- Contact: team@nextmoveslab.com
We are the data controller for the information described here. That means we decide what is collected and why, and we are the ones you hold responsible.
2. What we collect
Information you give us
| What | Why |
|---|---|
| Email address | To create your account, sign you in, and contact you about the service |
| Name (optional) | To address you properly |
| Everything you type into a dump | This is the core of the service. It is what the product reads to choose your task |
| Voice input, where you use it | Converted to text and treated exactly like typed input |
| Photographs of notes, where you use them | Converted to text and treated exactly like typed input |
| What you complete, swap, or park | So the product can size future picks to how you actually work |
| Messages you send us | To answer you |
About dumps specifically. You are typing freely, so a dump may contain client names, amounts owed, personal commitments, or anything else on your mind. We do not filter or restrict what you write. Section 5 explains exactly what happens to that text, and Section 6 explains what happens if it reads as a crisis.
Information collected automatically
- Account and usage data: when you sign in, which features you use, timestamps of picks and completions.
- Technical data: IP address, browser type, device type, and general location derived from IP (country/city level, not precise).
- Analytics: see Section 9.
Information we do not collect
- We do not read your email inbox.
- We do not connect to or read your calendar.
- We do not track you across other websites.
- We do not record your screen or your sessions.
- We never see or store your payment card details (see Section 8).
3. Why we are allowed to process it (legal bases)
Under GDPR we must have a lawful basis for each purpose. Ours:
| Purpose | Legal basis |
|---|---|
| Running your account and delivering the service | Performance of a contract (Art. 6(1)(b)) |
| Processing your dumps to choose and explain a task | Performance of a contract (Art. 6(1)(b)) |
| Personalising picks to your pace and history | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, service reliability | Legitimate interests (Art. 6(1)(f)) |
| Product analytics | Consent, or legitimate interests where the analytics are cookieless and aggregated |
| Marketing emails | Consent (Art. 6(1)(a)) |
| Meeting tax and accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Responding to a dump that indicates a crisis | Vital interests (Art. 6(1)(d) and Art. 9(2)(c)) |
You can withdraw consent at any time where consent is the basis. Withdrawing does not affect processing already carried out.
4. How long we keep it
- While your account is open: your dumps, picks, and history are retained so the product can keep working and stay personalised.
- When you delete your account: we delete your personal data from our live systems immediately.
- Backups: deleted data persists in encrypted database backups for up to 7 days, after which it is overwritten.
- Records we must keep by law: invoices and tax records are retained for the period Serbian law requires, regardless of account deletion.
- Support emails: kept for 12 months.
- Billing records after deletion: the subscription record keeps its Paddle subscription id and payment dates, which tax law and payment disputes require. The billing email address and the Paddle customer id on it are removed 30 days after the account is deleted. Copies of billing emails we sent you are removed after 90 days.
5. Artificial intelligence, in plain terms
This is the part most policies bury. Read it.
What happens to your dump
When you submit a dump, the text is sent to a large language model to be read and turned into a decision. We access these models through OpenRouter, which routes requests to model providers on our behalf.
This means your dump text leaves our servers and is processed by a third-party model provider. We use API access, configured so that providers do not retain your content or use it to train their models. Every request we send restricts routing to providers that do not collect user data; providers that train on inputs are excluded and never receive your text.
Personalisation is not training
We want to be precise about a distinction that matters:
- We do personalise. The product learns from your own history — what you finish, how long things actually take you, what you keep swapping away — and uses that to make your future picks better. This affects your account only.
- We do not train models on your content. Your dumps are not used to train, fine-tune, or otherwise improve any AI model, ours or anyone else's. Nothing you write becomes part of a model that serves other users.
If this ever changes, we will ask for your explicit, separate consent first. It will be opt-in, and refusing will not degrade the service.
The product can be wrong
Picks, reasoning, and first steps are generated automatically. They are suggestions. You always have the final say, and one tap replaces any pick. Nothing here is professional, financial, legal, or medical advice.
Automated decision-making
Choosing which task to show you is automated, but it produces no legal or similarly significant effect on you within the meaning of Article 22 GDPR. It is a suggestion in a productivity tool, and you can override it at any time.
6. When a dump indicates distress
If the text you write appears to indicate that you may be in crisis, the product stops planning and shows a message pointing you to real help, including a link to a helpline directory.
We do not store that determination. No flag is written to your account, no record is kept that a crisis response was shown, and no human at Next Moves Lab is notified. The check happens, the response appears, and nothing about it is retained.
We handle it this way deliberately. Inferring that someone may be in distress touches on health information, which deserves the highest protection. The safest version of this feature is one that helps in the moment and remembers nothing.
Where such processing is unavoidable in delivering that response, we rely on vital interests (Art. 6(1)(d), Art. 9(2)(c)).
Next Moves Lab is not a mental health service and is not a substitute for professional care or emergency services.
7. Information about other people
Your dumps will sometimes contain other people's information — a client's name, someone you owe a reply to, a person you are meeting.
We process that information solely to deliver the service to you, on the basis of legitimate interests. We do not build profiles of those people, do not contact them, and do not use their information for any purpose beyond producing your picks.
You are responsible for what you put in. Please do not enter other people's sensitive information — health details, financial account numbers, government identifiers — where you can avoid it. If someone contacts us about information you entered, we may need to act on their rights under data protection law.
8. Who else touches your data
We keep this list short on purpose. Every processor listed here is bound by a data processing agreement.
| Processor | What they do | Where |
|---|---|---|
| Supabase | Database and authentication | Ireland (EU) |
| Vercel | Application hosting and delivery | Ireland (EU) |
| OpenRouter and the model providers it routes to | AI processing of dump text | Varies by provider; see Section 5 |
| Resend | Sending transactional email | Ireland (EU) |
| Paddle | Payments, as merchant of record | EU / global |
| Vercel Analytics | Cookieless product analytics | EU |
| Vemetric | Page-view counts on our public pages | EU |
| Meta | Advertising pixel on our public pages | US |
Payments. Paddle is the merchant of record for purchases, meaning Paddle sells the subscription to you and handles payment and tax. We never see, receive, or store your card details. Paddle's own privacy policy governs that transaction.
International transfers. Some processors operate outside the EEA. Where that happens, transfers are covered by Standard Contractual Clauses or an adequacy decision. Serbia is currently recognised as providing adequate protection by the European Commission.
We do not sell your data. We have never sold your data. There is no version of this business where we sell your data.
9. Cookies and analytics
We use cookies that are strictly necessary to run the service — keeping you signed in, and security. These do not require consent.
Analytics: two tools count visits to our public pages, and neither identifies you.
- Vercel Web Analytics measures page views and general usage in aggregate. No cookies are set, no cross-site tracking occurs, and no individual is identified.
- Vemetric counts page views on our public marketing pages only. It runs through our own address, sets no cookies, identifies nobody, and is never loaded on signed-in pages.
Where a page address could itself be sensitive — a share link, for example, where the address is the credential — the identifying part is removed in your browser before anything is reported.
Advertising: we use one advertising pixel, from Meta, on our public marketing pages and on the page you land on after paying. It tells Meta that a page was viewed and that a purchase happened, so we can tell whether an advert worked. It never runs inside the application: signed-in pages carry a security policy that blocks Meta's servers outright, so nothing you type into a dump can reach an advertising network. That is enforced in our code, not promised in this policy. Meta's own privacy policy governs what Meta does with the signal, and a browser setting or ad blocker that blocks Meta stops it entirely.
10. Your rights
If you are in the EU/EEA, the UK, or Serbia, you have the right to:
- Access a copy of your data
- Correct anything inaccurate
- Delete your account and data
- Export your data in a portable format
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Withdraw consent at any time where consent applies
How to use them: email team@nextmoveslab.com. We answer within 30 days, usually much sooner. Export and deletion are also available directly in the app, without asking us.
Complaints: you may complain to the Serbian Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs), or to your local supervisory authority if you are in the EU/EEA.
If you are in California: you have rights of access, deletion, correction, and to know what is collected. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. Exercising these rights will never result in worse service or a different price.
11. Security
Data is encrypted in transit and at rest. Access to production systems is limited to those who need it. We use reputable infrastructure providers rather than running our own servers.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data and poses a risk to you, we will notify you and the relevant authority within 72 hours as required.
12. Age
Next Moves Lab is for adults. You must be 18 or older to create an account. We do not knowingly collect data from anyone under 18. If we learn that we have, we delete it.
13. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. Minor clarifications will be posted here with an updated date.
14. Contact
team@nextmoveslab.com
A human answers. Usually the founder, usually the same day.