NTHSTR legal

Privacy Policy

Effective August 19, 2026 · Last updated August 19, 2026

NTHSTR is operated by Simple, LLC, an Arizona limited liability company. This policy covers data handled by the authenticated NTHSTR application and its related web, PWA, shortcut, and supported native capture surfaces. The public beta waitlist has a narrower, separate Beta waitlist privacy notice.

1. The short version

2. Data you provide

3. Data collected during operation

4. How we use data

Code-present processing, AI, scanner, outbox, sync, retrieval, and billing paths are not proof of activation. Where a path is default-off or unconfigured, NTHSTR does not describe it as processing user data unless the required activation and user action have occurred.

5. AI-assisted features

The rebuild contains local or mock behavior for ordinary testing and separately gated Anthropic adapters for some capture, structuring, and cited-answer features. A code-present adapter is not proof that an external provider is active. Anthropic receives data only when the applicable provider and product gate are enabled and you invoke the feature. No other AI provider is represented as active for rebuild user data.

6. Services and conditional processing paths

The table distinguishes core runtime infrastructure from paths that require a feature gate, configuration, permission, or deliberate user action.

Services and processing paths used by NTHSTR
Service or pathPurpose and dataWhen it applies
SupabaseAuthentication, primary database, and private source-object storage. Account identity; workspace records; and, when you upload a source, the private intake and verified source objects associated with your workspace.Core service infrastructure.
VercelApplication hosting, server execution, delivery, and scheduled routes. Request metadata such as IP address and user agent, operational logs, and content sent to a server route only as needed to provide that route.Core service infrastructure.
AnthropicOptional AI-assisted capture, structuring, and cited answers. Only the text or source context submitted for the AI action you invoke.Default-off; receives data only after the relevant provider path is separately activated and you invoke that AI action.
Browser or operating-system push service (Web Push)Optional reminder delivery to a subscribed browser or device. Push endpoint, subscription keys, user agent, and the reminder payload.Only after you grant notification permission and create a push subscription; you can remove the subscription.
PinpointOptional authenticated product feedback. The feedback note and category you submit, a same-origin page URL, bounded product metadata, a pseudonymous identity, and the trusted client IP forwarded as X-Forwarded-For for Pinpoint abuse and security controls; raw DOM selectors and your account email are not forwarded.Only when the separately configured feedback rail is enabled and you submit feedback; a local Supabase receipt is preserved first.
StripeConditional subscription checkout and billing management. If billing is activated later: billing email, workspace billing identifiers, subscription status, and Stripe object identifiers; full card details go directly to Stripe.Unconfigured and fail-closed in the current release; this notice must remain aligned before billing is activated.

7. Disclosure and sharing

We disclose data to the services above only as needed for the described function and gate. We may also disclose data when legally required, to protect users or the Service, or as part of a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate notice and applicable law. We do not sell personal data or share it for cross-context behavioral advertising.

8. Retention and deletion

Workspace records are retained while needed to provide your account and preserve the history you choose to keep. Individual deletion, source-purge, and account-level rights can be subject to authorization, provenance, recovery, legal-retention, and backup constraints. Automated processing or purge code that is default-off is not represented as an active deletion schedule. To request access, export, correction, or deletion, contact privacy@simplellc.com.

Operational logs and backups can retain residual copies for their normal security and recovery cycles. We may keep limited records required for fraud prevention, legal claims, or legal, tax, and accounting obligations. Beta waitlist entries follow the separate retention terms in the Beta waitlist privacy notice.

9. Your rights and choices

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing, and a right not to be discriminated against for exercising applicable privacy rights. We may need to verify your identity and may retain data when an applicable exception or legal duty requires it. Send requests to privacy@simplellc.com; we will respond within the period required by applicable law.

Optional notification permission, push subscriptions, feedback submission, and externally processed AI actions remain choices. Disabling a future path stops new use but does not erase records already needed for provenance, security, or a valid retention obligation.

10. Security

NTHSTR uses transport encryption, authenticated routes, workspace-scoped database controls, row-level security, private storage buckets, bounded signed URLs, hashed abuse identifiers, secret-redaction boundaries, and fail-closed activation checks where implemented. No system is perfectly secure. If an incident affects personal data, we will investigate and provide notices required by applicable law.

11. International transfers

Simple, LLC is based in the United States, and the services listed above may process data in the United States or other countries. Where applicable law requires a transfer safeguard, we will use an appropriate mechanism.

12. Children

NTHSTR is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided data, contact privacy@simplellc.com.

13. Changes to this policy

We may update this policy as the product and its activation state change. We will revise the “Last updated” date and provide additional notice for material changes when required.

14. Contact

Privacy and rights requests: privacy@simplellc.com. Legal notices: legal@simplellc.com. General questions: info@simplellc.com.

Simple, LLC, an Arizona limited liability company — 7042 E Portland St, Scottsdale, AZ 85257.