Legal
Privacy Policy
The short version: we process the URL you give us, the email address you give us if you give us one, and enough technical data to keep the thing running and unabused. Analytics is optional and off until you say otherwise. We don’t sell anything to anybody.
Last updated 25 August 2026.
Who is responsible
The data controller for Do This Next is Simon Berriman, sole trader (freelance), Karl-Rothe-Str. 4, 04105 Leipzig, Germany. Full details are in the Impressum. For anything to do with your data, email hello@dothisnext.lol — it reaches a person, and it is the right address for a request under any of the rights listed below.
Do This Next is operated from Germany and this policy is written to the GDPR and the German implementing rules, wherever in the world you are reading it from.
Where this stands today. The analysis is live: submit a URL and we fetch that page, work out what your product is, and show you what we understood. Accounts, recommendations and paid subscriptions are still being built — where this policy describes them, it describes what happens when they arrive, so that nothing here has to be rewritten later. We are not holding data from features that do not exist.
What we process, and why
Grouped by the thing you did, because that is how you will remember giving it to us.
When you run a Product Check
- The URL you submit, and the domain we derive from it. Stored so we can analyse it, show you the result, and not spend money analysing the same site twice in three days.
- The page we fetch from that URL, and what we infer from it about your product — the problem it solves, who it is for, how it is priced, what people use instead. We keep the fetched page alongside the conclusions, because a recommendation you cannot check is worth nothing.
- Anything you tell us about your product — corrections to what we got wrong, your goals, your budget, how much time you have. Corrections create a new version rather than overwriting the old one, so it stays possible to see what we believed when we gave a particular piece of advice.
- The recommendations we generate, the reasoning behind them, and anything you later record about what happened when you acted on one.
- A hashed form of your IP address. Salted with a salt that rotates every day, used only to rate-limit the free Product Check. Yesterday’s value stops matching today’s, so it cannot be used to follow you over time — and it cannot be turned back into your IP address at all.
- Basic request context — the domain that referred you (not the full page address), your browser’s user agent string, which position on our site you started from, and any campaign tags in the link you clicked.
Legal basis. Article 6(1)(b) GDPR — you asked us to analyse a product, and we cannot do that without the URL and what we find at it. The hashed IP and the rate limiting are Article 6(1)(f): our legitimate interest in not having an automated script spend our model budget, achieved with the least identifying thing that works.
When you give us your email address
- The address itself, and when you gave it. We use it to send you the result of your Product Check and, if you asked to be told when Founding Access opens, to tell you that.
Legal basis. Article 6(1)(b) for the thing you asked us to send you; Article 6(1)(a) — consent — for being told about Founding Access, which you can withdraw by replying and saying so.
When you subscribe (once billing is live)
- Your email address and subscription status, so you have access to what you paid for.
- Payment records — the amount, the plan, the status. Card details are handled entirely by Stripe and never reach us.
Legal basis. Article 6(1)(b) for the subscription itself; Article 6(1)(c) for keeping the accounting records that German tax and commercial law require us to keep.
Whenever you use the site
- Server and security logs kept by our hosting provider, which include IP addresses and request details. We do not build a profile from them; they exist so that an outage or an attack can be diagnosed.
- Our own page and event counts. First-party, cookieless and not tied to you: which page, which referring domain, which campaign tag. No identifier is set, nothing is read from your device, and the same visitor on two pages is two rows we cannot join.
- Your privacy choice, stored in your own browser. It never reaches our server — see the Cookie Policy.
- Google Analytics data, only if you consent. Covered in its own section below.
Legal basis. Article 6(1)(f) for the logs and our own cookieless counts — a legitimate interest in a site that works and that we can improve, pursued in a way that does not identify anybody. Article 6(1)(a) for Google Analytics, and for nothing that is genuinely necessary to run the product: we do not dress up required processing as a choice you have already made.
What fetching your page actually involves
One request, to the address you gave us. We do not crawl the rest of your site, follow links, or come back on a schedule — the analysis is a single page fetch, and a repeat request for the same domain within three days is served from what we already have rather than fetched again.
- We identify ourselves honestly. The request arrives as
DoThisNextBot/1.0with a link back to this site, so you can recognise it in your logs. - We never send credentials, never attempt anything behind a login, and read only what an anonymous visitor to that address would get.
- The request times out after twelve seconds, stops after about 1.5MB, follows at most four redirects, and refuses private, loopback and internal addresses outright.
- We do not currently read your
robots.txtbefore that one fetch, because the fetch is of the address someone asked us to look at rather than a crawl of your site. If you would rather we did not fetch it at all, block that user agent or email us and we will stop.
AI processing
Analysing a product and writing a recommendation is done with large language models. This matters enough to be explicit about.
- The provider is OpenAI. Model calls go to the OpenAI API from our servers. If we ever add a second provider, it will be named here before it processes anything.
- What is sent. The text of the public pages we fetched from your site, the structured profile we built from them, anything you told us about your product and your goals, and the instructions that ask for a specific piece of analysis. Your email address is not sent. Your IP address is not sent. Nothing about your payment is sent.
- Training. We do not use your business’s data to train models of our own. OpenAI states that data submitted through its API is not used to train its models by default; that is their commitment under the API terms rather than ours to give, so we point at it rather than restate it as a promise.
- Judgement stays yours. The output is a recommendation. Nothing is posted, sent or published on your behalf — you decide what to do, and no decision with a legal effect on you is made by an automated process here.
Who else processes your data
A short list, and we would like to keep it short. Each of these acts as a processor on our instructions under a data processing agreement.
| Provider | What they do | Where |
|---|---|---|
| Vercel | Hosting and delivery of the site, plus the server and security logs that come with it. Our functions run in the Frankfurt region. | EU / US |
| Supabase | The database. Product Checks, email addresses, subscription records and our own event counts are stored here. | United Kingdom (London) |
| OpenAI | The model calls that analyse a product and write recommendations. | US |
| Stripe | Payments and subscription management, once billing is live. Stripe receives your payment details directly; we never see them. | EU / US |
| Google Analytics — and only if you have given analytics consent. | EU / US |
Fonts are served from our own domain rather than fetched from Google, so simply loading a page on dothisnext.lol contacts nobody but us. We do not run any third-party advertising, tag manager, session recorder or heatmap, and we do not sell or rent personal data to anyone, for any purpose, ever.
Where your data is stored, and international transfers
Our database is hosted by Supabase in Amazon Web Services’ London region, so the Product Checks, email addresses and records described above are stored in the United Kingdom. The site itself runs in Frankfurt, Germany.
The United Kingdom
The United Kingdom is not part of the European Union or the European Economic Area, so storing your data there is a transfer to a third country and needs a legal basis. Transfers of personal data from the EEA to the UK currently rely on the European Commission’s adequacy decision for the United Kingdom, which recognises UK data protection law as offering protection essentially equivalent to the GDPR. Where an adequacy decision applies, the transfer is permitted on that basis alone and no further safeguard — no Standard Contractual Clauses, no separate consent from you — is required, so we are not going to claim one.
That decision is periodically reviewed and renewed by the Commission. If it lapsed or were withdrawn, transfers to the UK would need a different basis; we would put one in place and this page would say what it is.
Everyone else
Several of the other providers above are established in the United States or may process data there. For those, the transfer relies on the mechanism set out in our agreement with that provider — the Commission’s Standard Contractual Clauses, or the provider’s certification under the EU–U.S. Data Privacy Framework where it holds one. We deliberately do not state which of those applies to which provider on this page, because we would rather say less than claim a safeguard we have not checked line by line. Ask us about a specific provider and we will tell you what our agreement with them actually says.
Google Analytics
Google Analytics is optional. It is off until you switch it on, and switching it on is the only thing that causes the Google Analytics library to be requested at all — before that, no request is made to Google and no Google cookie exists on your device.
- What it is for. Seeing in aggregate which pages people read, which ones they leave, and whether a change we made helped. It is not used to target you and we do not run ads.
- What it receives. Page addresses, referrer, approximate location derived from IP, device and browser characteristics, and a few product events such as “someone started a Product Check”. Google sets cookies to recognise a returning browser. Property
G-QYB0Z2WDTZ. - What it never receives. Your email address, the URL you submitted, anything you told us about your business, anything a model wrote for you, or the link to a private Product Check — that page address is redacted before it is sent. Advertising features, Google Signals and ad personalisation are switched off, and advertising consent is refused at all times whatever else you choose.
- Provider. Google Ireland Limited, with Google LLC in the United States as a sub-processor. Google’s own explanation of what it does with the data is at policies.google.com/privacy.
- Changing your mind. Use Cookie settings in the footer of any page. Turning analytics off stops further collection, clears the Google cookies that were set, and reloads the page so nothing of Google’s is still running on it.
Legal basis. Your consent — Article 6(1)(a) GDPR, and § 25(1) TDDDG for the storage on your device. Withdrawing it is as easy as giving it and has no effect on anything else you can do here.
How long we keep things
An anonymous Product Check is deleted 90 days after it was created. That is enforced by a job that runs every day, not a policy we intend to get round to: the expiry is set on the record when it is created, and the purge deletes the check together with the pages we fetched from your site, the profile we inferred and the verdict we wrote. Nothing is left behind except counts — how many checks ran, what they cost us — which carry no information about you or your business.
The exception is a Product Check that belongs to an account. Once you are a customer, your checks are your records: they stay until you delete them or close the account, rather than disappearing off a timer while you are still using them. Accounts do not exist yet, so today the 90-day rule applies to everything.
- Account and subscription data will be kept while the account exists, and deleted afterwards apart from what tax and commercial law require us to retain — which for invoices and accounting records in Germany is a matter of years, not our discretion.
- Your email address goes when the Product Check it is attached to goes. If you separately asked to be told when Founding Access opens, that record is kept until you tell us to stop, because it is the thing you asked for.
- Hashed IP addresses stop being linkable to anything within 24 hours, because the salt rotates daily. Rate-limit counters are keyed to a time window and are meaningless once it has passed.
- Server and security logs are kept as long as they are useful for diagnosing a problem, under our hosting provider’s retention, and are not used for anything else.
- Our own cookieless event counts are aggregate from the moment they are written and are not linked to a person, so there is nothing in them to delete on request.
- Your privacy choice lives in your browser, not with us, and lasts until you clear your browser storage or change it. Clearing it simply means we ask again.
You do not have to wait 90 days. Ask us to delete a check and we delete it.
Your rights
Under the GDPR you have the right to ask us for a copy of the personal data we hold about you (Article 15), to have inaccurate data corrected (Article 16), to have it deleted (Article 17), to have our processing restricted (Article 18), to receive it in a portable form (Article 20), and to object to processing we base on legitimate interests (Article 21). Where we rely on your consent you can withdraw it at any time, without giving a reason and without it affecting anything that happened before.
Email hello@dothisnext.lol. There is no form and no portal. We will respond within a month, and if what you are asking for is deletion, deletion means the Product Check, the fetched pages and the analysis actually go.
You also have the right to complain to a data protection supervisory authority. For this operator that is the Saxon Data Protection and Transparency Officer (Sächsischer Datenschutzbeauftragter, datenschutz.sachsen.de), and you may also complain to the authority where you live or work.
A few things we don’t do
- We don’t sell or rent your data. To anyone. Ever.
- We don’t use your business’s data to train models of our own. If we ever learn across customers, it will be from aggregated, de-identified patterns that could not point back to you.
- We don’t post, send or publish anything anywhere on your behalf. We draft; you decide.
- We don’t run advertising, ad tracking or cross-site tracking of any kind, and there is no advertising consent to give because we are not asking for one.
- We don’t make your Product Check public. It has an unguessable link, it is not indexed and it is not listed anywhere. If we later add a way to publish one, it will be off unless you turn it on.
Children
Do This Next is a business tool and is not intended for anyone under 16. We don’t knowingly process children’s data; if you think we have, tell us and we will delete it.
Changes to this policy
If we add a processor, a purpose or a category of data, this page changes first and the date at the top changes with it. A change that affects what you have consented to means the consent banner asks again rather than quietly inheriting your last answer.