Legal

Privacy policy

Last updated: 17 May 2026 (initial policy)

1. Who we are

What's Next? is operated by Joe Houghton (joe.houghton@gmail.com, houghtonphoto.com). The service gives you AI-powered recommendations for books, TV, films, and podcasts.

Data controller and processor: Joe Houghton (sole operator). For any questions about how your data is handled, contact joe.houghton@gmail.com.

2. What data we collect and why

Account

Email address. Used to identify you across visits and to send the 6-digit verification code that proves you control the email. We don't store passwords — sign-in is by one-time code only. Legal basis: performance of a contract (we can't deliver personalised recommendations without an account).

Taste data

Titles you've liked, disliked, or want to avoid; genres and platforms you prefer. This is the core data that makes recommendations useful. It's stored on your account and sent to Anthropic's Claude API to generate new suggestions. You can delete it at any time.

Queue and history

Items you've added to your queue, marked as completed, or rated. Used to personalise future recommendations and (on paid plans) to produce your weekly digest.

Feedback you submit

When you use the Send Feedback button, we store your message, the URL you were on, up to four optional screenshots, and an optional contact email if you want to be notified when your suggestion lands.

3. How long we keep your data

Account data is kept for as long as you have an account. Inactive accounts (no sign-in for 24 months) are automatically deleted; you'll receive a warning email 30 days before deletion. You can delete your account at any time by emailing joe.houghton@gmail.com.

Feedback messages are kept until the suggestion is shipped or dropped from the roadmap. Screenshots attached to feedback are deleted after 12 months.

GDPR erasure logs are retained after deletion but contain only hashed identifiers — no readable email addresses or names.

4. Sub-processors

We use the following third-party services. All process data within the EU or under appropriate safeguards.

  • Vercel

    Hosts the web application and serverless API routes. EU regions used.

  • Neon (PostgreSQL)

    Stores all structured data (accounts, taste profiles, queue, history). Frankfurt region.

  • Brevo

    Sends transactional emails (verification codes, weekly digest, deletion warnings). Paris-headquartered, EU-hosted.

  • Anthropic

    Powers the AI recommendations engine. Your taste data and queue are sent to Anthropic's Claude API to generate suggestions. No data is used to train Anthropic's models under their API terms.

  • TMDB (The Movie Database)

    Provides cover art, metadata, and cast information for films and TV. No personal data is sent to TMDB.

5. Your rights

Under GDPR you have the following rights. To exercise any of them, email joe.houghton@gmail.com.

  • Right of access (Art. 15)Request a copy of all data we hold about you — delivered as JSON within 30 days.
  • Right to rectification (Art. 16)Ask us to correct inaccurate data.
  • Right to erasure (Art. 17)Delete your account and all associated data. Permanent and irreversible.
  • Right to restriction (Art. 18)Pause processing while a dispute is resolved.
  • Right to portability (Art. 20)Receive your data in machine-readable JSON format.
  • Right to object (Art. 21)Object to processing based on legitimate interest.

If you're unhappy with how your data is handled, you may also lodge a complaint with the Data Protection Commission (Ireland) at dataprotection.ie or the supervisory authority in your country of residence.

6. Cookies

What's Next? uses one strictly necessary session cookie to keep you signed in. We don't set advertising or tracking cookies. The feedback form uses your browser's localStorage to remember your contact email so you don't have to retype it — this stays on your device and is never sent except in the feedback submission itself.

7. Security

All data is transmitted over HTTPS. We don't use passwords — sign-in is by a one-time 6-digit code valid for 10 minutes, stored as a SHA-256 hash. The plaintext only ever exists in the email. All API keys are stored in encrypted Vercel environment variables.

8. Minimum age

What's Next? is intended for users aged 16 and over. By registering you confirm you meet this age requirement.

9. Changes to this policy

We'll update this page when material changes happen. Significant changes are announced on the roadmap and by email to all account holders.

10. Contact

For any privacy-related questions or to exercise your rights: joe.houghton@gmail.com