Privacy Policy
Last updated: 11 October 2026
This Privacy Policy explains how Simran Dhillon, trading as Nextly AI, based in Kuala Lumpur, Malaysia (“Nextly AI”, “we”, “us”), handles personal information when you use the Nextly AI app for macOS (the “App”), Nextly Camera and our website at nextly-ai.app (together, the “Service”). Capitalised terms have the meanings in our Terms Of Service.
We designed the App to keep your meeting content on your Mac. This policy is specific about what stays there, what goes to the Third-Party Providers you choose, and the small amount of account information we handle.
1. Who We Are
Nextly AI is operated by Simran Dhillon, trading as Nextly AI, a sole proprietor based in Kuala Lumpur, Malaysia. We are the controller (data user, under Malaysia’s Personal Data Protection Act 2010) of the personal information described in this policy. You can reach us at [email protected].
This policy does not cover Third-Party Providers you connect to the App, or your meeting apps. They handle data under their own privacy policies.
2. What Stays On Your Mac
In short: Your meeting content lives on your Mac, not on our servers.
The App runs a local backend on your Mac that accepts connections only from your Mac itself. The following are stored locally, in ~/Library/Application Support/Nextly AI and the macOS Keychain, and are not sent to our servers:
- Saved meetings (see Section 3): titles, transcripts, AI answers and related details.
- Your prompts, notes, résumé and files you add for context, plus the local search index built from them.
- Settings and preferences, and your local Account sign-in state.
- API keys for Third-Party Providers, stored in the macOS Keychain.
- Nextly Camera video. Eye Contact and Beauty run on your Mac. Camera frames and face landmarks are not sent to us.
Audio is processed in short segments for transcription and is not saved by the App. Meeting text is encrypted in the local database (see Security).
3. Meeting History
In short: Meetings are saved on your Mac by default. Switch to Until I Save or Don’t Keep, or delete them at any time.
Default behaviour. Unless you change it, Keep Meetings is set to Forever (shown as Memory on in Settings › General). When a meeting ends, the App saves it automatically to the local database on your Mac, and it stays there until you delete it.
What a saved meeting contains: the session title, mode, start and end times; the transcript, with the text of each turn, its source and its timing within the meeting; the AI answers shown to you, with the model used and which of your files were referenced; and the session context used to generate answers. It does not contain audio.
How to change it (Settings › Storage › Keep Meetings):
- Forever: meetings save automatically when they end (default).
- Until I Save: a meeting is kept only if you choose Save This Session before it ends; otherwise it is discarded.
- Don’t Keep: the whole meeting is discarded as soon as it ends.
You can also turn on Do Not Save Meetings (Settings › General) to block saving entirely.
How to clear it:
- delete a single meeting from History;
- use Settings › Storage › Delete Local Data to remove saved sessions and the avatar for the signed-in Account on this Mac;
- use Settings › Privacy › Delete All Local Data to remove saved sessions, uploaded files and search indexes. Provider API keys stay until you remove them in Settings › Providers.
4. Information We Collect About You
We handle a limited amount of information to provide sign-in, activation and support:
- Account information: email address, first and last name, email-verification status, and an identifier from your sign-in method (email, Google, GitHub, Apple or Microsoft). If you sign in with an email password, it is sent over HTTPS through our licensing service to WorkOS for verification and is not stored on our servers.
- Licence and device information: plan and licence status, and a device label for each Mac you activate (“Nextly Mac” followed by a short code). To recognise the same Mac across reinstalls, the App derives a device identifier by hashing your Mac’s hardware identifier with a random value kept on that Mac. The raw hardware identifier is not sent to us.
- Purchase information (only if Paid Plans launch and you buy one): order and subscription details from our payment processor. Card details are handled by the processor, not by us.
- Issue reports you choose to send: your comment, any screenshots or files you attach, and a fixed set of diagnostics (App version and build, macOS version, Mac architecture, meeting mode, permission status, a few feature flags and error codes). You review each report before it is sent. Reports do not automatically include meeting content.
- Messages you send us and our replies.
- Technical request data: when the App contacts our services (to sign in, check your licence, check for updates or send a report), or you visit our website, Cloudflare receives standard request data such as IP address, time and user agent.
The App does not include third-party analytics, advertising or crash-reporting software, and we do not collect usage analytics from it.
5. Data Sent To AI And Speech Providers
In short: Content only goes to the providers you pick, straight from your Mac.
We do not operate our own cloud AI. Transcription and answers come from Third-Party Providers you choose. When you use one:
- the audio, transcript text, prompts, notes or file excerpts and, if you use a screenshot feature, screenshots needed for the request are sent directly from your Mac to that provider, using your own API key or account. They do not pass through our servers;
- this content is not anonymised and may include names and anything said in the meeting;
- the provider handles it under its own terms and privacy policy, including its own retention and training settings. Review them before sending sensitive information.
If you use a local option, such as macOS’s built-in speech recognition where available, or a local model through a tool like Ollama, processing happens on your Mac as determined by that tool. The App does not ship its own speech model. Links to common providers’ policies are in Section 8.
6. How We Use Information
- to create and secure your Account, sign you in and verify your email;
- to activate the App on your Mac, check your licence and enforce device limits;
- to deliver App updates;
- to process purchases, if Paid Plans launch;
- to respond to support requests and investigate issue reports;
- to send service messages, such as security notices and changes to our terms;
- to prevent abuse and fraud and keep the Service secure;
- to comply with legal obligations and enforce our Terms.
We send marketing emails only where the law permits, and every one includes a way to opt out.
7. Legal Bases For Processing
Where the GDPR, UK GDPR or similar laws apply, we rely on:
- contract: to provide the Account, licence and features you ask for;
- legitimate interests: to secure the Service, prevent abuse and support users, balanced against your rights;
- consent: where we ask for it, such as optional marketing; you can withdraw it at any time;
- legal obligation: where the law requires us to keep or disclose information.
Under Malaysia’s PDPA, we process your personal data for the purposes in Section 6, which are directly related to providing the Service.
8. Service Providers And Third Parties
Our service providers (processors). We share information with these providers only as needed to run the Service:
| Provider | What they do for us | Data involved | Privacy policy |
|---|---|---|---|
| WorkOS | Sign-in and email verification | Email, name, sign-in provider identifier, password (email sign-in only) | WorkOS policy |
| Dodo Payments | Customer and licence records; payment processing if Paid Plans launch. A customer record is created when you verify your Account. | Name, email, licence status, device label; payment details if you buy | Dodo policy |
| Cloudflare | Hosts our website, licensing service, App update feed and issue-report storage | IP address and request data; issue reports you send | Cloudflare policy |
Third-Party Providers you choose. These receive content because you send it to them from the App. They are independent of us, not our processors, and their own policies apply. Common options include:
| Third-Party Provider | Used for | Privacy policy |
|---|---|---|
| xAI (Grok) | Transcription, answers | x.ai |
| Deepgram | Transcription | deepgram.com |
| Groq | Transcription, answers | groq.com |
| OpenAI (incl. ChatGPT) | Transcription, answers | openai.com |
| Google (Gemini, Google Cloud Speech) | Transcription, answers | policies.google.com, Gemini API terms |
| Microsoft (Azure Speech) | Transcription | microsoft.com |
| Anthropic (Claude) | Answers | anthropic.com |
| ElevenLabs | Transcription | elevenlabs.io |
| IBM Watson | Transcription | ibm.com |
| NVIDIA | Transcription, answers | nvidia.com |
| OpenRouter | Answers | openrouter.ai |
| DeepSeek | Answers | deepseek.com |
| Kimi (Moonshot AI) | Answers | kimi.com |
Other providers listed in the App work the same way. Check each provider’s policy before connecting it.
Other disclosures. We may disclose information to professional advisers, to authorities where the law requires it, or to a successor if Nextly AI is transferred to a company or sold, in which case this policy will continue to protect your information.
We do not sell personal information and do not share it for cross-context behavioural advertising.
9. macOS Permissions
The App asks macOS for permissions only for features you use. You can change them at any time in System Settings › Privacy & Security; the related feature will then stop working.
- Microphone and Screen Recording / system audio: to capture meeting audio.
- Speech Recognition: if you use macOS’s built-in transcription.
- Accessibility: for global shortcuts and Clipboard To Type.
- Camera and the Nextly Camera system extension: for Nextly Camera.
10. Data Retention
In short: We keep account data only while you have an Account, plus up to 30 days.
| Data | Where | How long |
|---|---|---|
| Saved meetings, files, settings | Your Mac | Until you delete them (see Section 3) |
| API keys | Your Mac (Keychain) | Until you remove them |
| Account and licence records | WorkOS, Dodo Payments, our licensing service | While your Account exists, then deleted within 30 days of your deletion request |
| Purchase records (if Paid Plans launch) | Dodo Payments | As long as tax and accounting law requires |
| Issue reports | Cloudflare storage | 12 months from receipt, then deleted |
| Support emails | Our mailbox | Up to 12 months after the conversation ends |
| Licensing service request logs | Cloudflare | Up to 7 days (Cloudflare’s default Workers log retention) |
11. Security
- Encrypted local history. Meeting titles, transcripts, answers, session context and settings are encrypted in the local database with AES-256-GCM. The encryption key is stored in the macOS Keychain.
- Keys in the Keychain. Provider API keys are stored in the macOS Keychain, not in plain files.
- Local-only backend. The App’s backend listens only on your Mac’s loopback address (127.0.0.1) and cannot be reached from the network.
- Encrypted connections. The App refuses to contact our licensing service or update feed over plain HTTP; all traffic to them uses HTTPS (TLS). Connections to Third-Party Providers use their HTTPS endpoints.
- Minimal server data. We store no meeting content on our servers, and device identifiers are hashed before they leave your Mac.
- Reviewed reports. Issue reports contain a fixed list of diagnostics, and you see the report before it is sent.
No system is completely secure. Protect your Mac with a strong login password and FileVault, and keep the App up to date. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as the law requires. To report a security issue, email [email protected] rather than posting it publicly.
12. Your Rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you and get a copy;
- correct inaccurate information;
- delete your Account and personal information;
- receive your information in a portable format;
- object to or restrict certain processing, and withdraw consent;
- complain to a data-protection authority.
These rights come from laws including Malaysia’s Personal Data Protection Act 2010, the GDPR and UK GDPR, and California’s CCPA/CPRA. California residents may also opt out of the sale or sharing of personal information; we do not sell or share it as those laws define it. We will not treat you differently for exercising your rights.
How to make a request:
- Email [email protected] from the email address on your Account, saying what you would like (for example, “access”, “correction” or “deletion”).
- We acknowledge your request within 7 days. If we cannot confirm it came from you, we may ask you to verify your identity.
- We complete your request within 21 days of verifying it, or tell you within that time if we need longer (up to the period the law allows) and why.
- If we cannot fulfil a request, we will explain why. You can then complain to your data-protection authority, such as Malaysia’s Personal Data Protection Commissioner or your local EU/UK supervisory authority.
Data stored only on your Mac is under your control; you can view and delete it directly in the App.
13. Deleting Your Account And Data
In short: Email [email protected] to delete your Account (done within 30 days), and remove the local folder to clear your Mac.
To delete your Account:
- Email [email protected] from your Account email with the subject “Delete my account”.
- Within 30 days we delete your Account record, your WorkOS user and your Dodo Payments customer record, and email you to confirm. Records we must keep by law, such as purchase records if you bought a Paid Plan, are kept only for as long as required.
To delete data on your Mac (we cannot do this for you):
- Optional: in the App, go to Settings › Providers and remove your API keys.
- Quit Nextly AI completely.
- In Finder, choose Go › Go to Folder, enter
~/Library/Application Support/Nextly AI, and move that folder to the Trash. - To remove remaining Keychain items, open Keychain Access, search for
nextly.ai, and delete the entries. - Drag Nextly AI from Applications to the Trash, approve removing the Nextly Camera extension if macOS asks, then empty the Trash.
Deleting local data does not delete your Account, and deleting your Account does not remove data from your Mac, so do both if you want everything gone. Content you sent to Third-Party Providers must be deleted with those providers.
14. International Transfers
We are based in Malaysia. Our service providers and the Third-Party Providers you choose may process information in other countries, including the United States, where data-protection laws may differ from yours. Where the law requires it, we rely on appropriate safeguards for transfers we make, such as the providers’ standard contractual clauses or other lawful transfer mechanisms.
15. Cookies And Analytics
Our website does not use cookies, analytics or tracking pixels, and does not store anything in your browser. Cloudflare processes technical data, such as IP addresses, to deliver and protect the site. The App does not use cookies or analytics. Because we do not track you, we treat all visitors the same whether or not their browser sends a Do Not Track or Global Privacy Control signal.
16. Children
The Service is for adults aged 18 or over. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has given us personal information, email [email protected] and we will delete it.
17. Changes To This Policy
We may update this policy as the Service changes. We will update the “Last updated” date and, for material changes, give notice on the website, in the App or by email before the change takes effect. We will not use personal information in a materially different way without telling you first and, where required, asking for your consent.
18. Contact
Simran Dhillon, trading as Nextly AI
Kuala Lumpur, Malaysia
Privacy requests: [email protected]
General support: [email protected]
Website: nextly-ai.app
If we are required by law to appoint a representative in the EU or UK, we will publish their details here.
Related: Terms Of Service · Privacy Policy · Refund Policy · Questions: [email protected]