Website & early-access privacy
Understand what
you share with NPS.
This notice covers the public website and early-access requests. It does not describe every future NPS product or client.
Updated September 21, 2026 · Notice status: draft
The retention and request rules below have been approved. The privacy-request email channel is not yet operational or available. It must be set up and tested before broader enrollment. Share only the information needed to describe your interest.
Website operation
Cloudflare hosts and helps protect this website. It may process IP addresses, browser information, request timing, and security signals to deliver the service.
Early-access requests
The request form is provided through Google Forms. Information you submit is used to review your request, understand relevant operational needs, contact you about access, and administer early-access opportunities.
The form asks for contact information and context about your work or organization. Your preference for development and release updates is separate from your interest in access.
Information to leave out
Do not submit passwords, MFA codes, financial-account credentials, tax identifiers, precise route history, confidential employer records, or private customer information.
Sign-in and service providers
Clerk provides authentication for Account and My NPS. Signing in does not automatically grant product access. Cloudflare, Google, and Clerk process information for their respective services under their applicable terms and privacy practices.
Analytics and cookies
The public site is not intentionally configured with advertising trackers or behavioral analytics. Authentication and external services may use cookies or similar technologies to operate their services.
Use and sharing
Request information is intended for early-access administration and the update preferences you select. It is not intended to be sold for advertising. Service providers may process information to host, authenticate, secure, or operate the request process.
Early Access application retention
We retain an application while you remain interested in NPS Early Access and the information is reasonably useful for evaluating or contacting you about access. After 24 months without meaningful interaction, we delete the application unless you have separately opted in to ongoing NPS updates. This is the normal expiration rule; we do not keep Early Access information indefinitely just in case.
Optional development and release updates
We retain your email address and subscription preference until you unsubscribe or request deletion. Unsubscribing from updates does not withdraw an active Early Access application unless you also ask to withdraw or delete it.
Withdrawal, deletion, access, and correction
You may withdraw from Early Access or request deletion at any time through the privacy contact once it is operational and published. You may also request a copy of the Early Access information associated with your email address or ask us to correct inaccurate information.
For a valid deletion request, our operational target is to remove your application data and optional update subscription from active systems within 30 days, subject to the limited exceptions below. If you withdraw only from Early Access and want to keep receiving updates, we retain only the information needed for that subscription. If you unsubscribe only from updates, we retain your application if it is still active unless you also ask to withdraw or delete it.
The NPS owner/operator is responsible for responding to privacy requests. The email channel is not yet available; contact details and request instructions will be published after inbound delivery has been tested. Do not send passwords, financial information, identification documents, or other sensitive information for a privacy request.
Limited retention exceptions
Information may be retained longer only when reasonably necessary for:
- Legal or regulatory obligations.
- Security, fraud, abuse, or incident investigation.
- Resolving an active dispute.
- Minimal suppression records needed to honor an unsubscribe or do-not-contact request.
- Backup or recovery copies that cannot reasonably be removed individually, provided they are not used for ordinary processing and are removed through the normal backup-retention cycle.
If backup systems are implemented later, deletion from active systems comes first. Any restored backup must have deletion requests re-applied before the restored data returns to normal use. This rule does not claim that a backup system or a particular backup-retention cycle currently exists.
Product data
This notice is limited to the website and early-access process. Released clients and modules need disclosures covering their actual data collection, permissions, storage, synchronization, and recovery behavior.
For the current product approach, read Security & trust.