Legal

Privacy Policy

NextWrite is committed to protecting your privacy and handling your data responsibly. This policy explains what we collect, where it is processed, how we use it, and how we safeguard it.

Last updated: 13 September 2026

1. Data Collection

We collect only the information necessary to provide the service. This includes the account details you supply when registering, the documents and files you choose to upload, and the record of conversations conducted within the application.

2. Where Your Data Is Processed

De-Cloud AI processes your content on an AI server located on your premises and owned by your organization. Every prompt your staff submit, every response the AI generates, the conversion of uploaded documents into text, and the search index built from those documents are all processed on that server. This content is not transmitted to NextWrite, to any AI model provider, or to any other third party.

NextWrite retains remote administrative access to that server for software updates, security patching, and system health monitoring. That access does not extend to the content of your prompts, the responses generated from them, or the documents you upload.

3. Data Usage

We process your data solely to provide the service: drafting, summarizing, answering questions from your own documents, and the funding and proposal features described on our Grants and Proposals page. Outputs remain under your control and are auditable within the application.

Your content is not used to train any artificial intelligence model. Because the model runs on hardware your organization owns, no model provider receives your content in the first place.

4. Security and Service Providers

The web application around your AI server is delivered through established infrastructure providers: Vercel for application hosting, Neon for the database holding accounts and chat history, Cloudflare R2 for stored files, and Resend for transactional email such as password resets. These providers maintain certifications including SOC 2 Type II, ISO 27001, and GDPR compliance.

A full description of each provider, and of exactly which data each one holds, is available on our security page. While NextWrite does not hold these certifications directly, we inherit their controls and add role-based access control, audit logging of activity within the application, and encryption of data in transit and at rest.

5. Data Sharing

We do not sell or rent your data. Data is shared only with the service providers named in section 4, each under confidentiality and data protection agreements, and only to the extent required to deliver the service. Content processed on your own AI server is not shared with anyone, including NextWrite.

6. Data Retention

Documents and records held in the web application are retained only as long as needed to provide the service. You may request deletion at any time by contacting us. Content held on your own AI server is under your organization's control and is retained or deleted at your discretion.

7. Your Rights

You may request access, correction, or deletion of your data at any time. We comply with applicable data protection laws including GDPR and CCPA.

8. Contact

If you have any questions about this Privacy Policy, please contact us at privacy@nextwrite.ai.