Last updated: January 2025
Next Thing Security is a blog about digital privacy and account security for ordinary adults. It would be strange to write about protecting your personal information while quietly collecting more of it than we need. This policy explains, in plain language, what nextthingsecurity.com collects, why, who else can see it, and what you can do about it.
We have written this document the way we try to write everything on this site: without jargon where jargon can be avoided, and without pretending that a privacy policy is a substitute for good practices. If something here is unclear, we would rather you ask than guess.
1. Who We Are
Next Thing Security operates the website located at nextthingsecurity.com. We publish articles, guides, and commentary about personal account security and privacy decisions. We are the "data controller" for information collected through this site, meaning we decide what is collected and how it is used.
We are a publisher, not a security service provider. We do not host your accounts, manage your passwords, scan your devices, or monitor your credentials. That limits how much information we need from you, and we try to keep it that way.
2. Information We Collect
2.1 Information You Give Us Directly
Most visitors to nextthingsecurity.com never hand us anything at all. You can read every article without creating an account, filling in a form, or identifying yourself. When you do choose to interact with us, we may collect:
Email address — if you subscribe to a newsletter or update list, so we can send you what you asked for.
Name or display name — if you provide one when contacting us or leaving a comment. A first name or handle is fine; we do not verify identities.
Message content — the text of any email, contact form submission, correction, or question you send us, along with anything you choose to include in it.
Comment content — if commenting is enabled on an article, the comment text and any name or email you attach to it.
Please do not send us passwords, recovery codes, account numbers, government identifiers, or screenshots containing credentials. We do not need them, we cannot help with them, and we do not want to be holding them. If you send sensitive material by accident, tell us and we will delete it.
2.2 Information Collected Automatically
Like nearly every website, nextthingsecurity.com automatically receives certain technical information when your browser requests a page. This may include:
IP address, which may be truncated or anonymized before storage
Browser type and version, operating system, and device category
Screen or viewport size, used to check that pages render correctly
Referring URL, meaning the page or search engine that sent you here
Pages viewed on this site, time spent, and general navigation patterns
Approximate location at the country or region level, derived from IP address
Date and time of your visit
Some of this information is recorded in standard server logs, which exist primarily for security, abuse prevention, and troubleshooting. Server logs are a normal part of running a website and are not used to build profiles of individual readers.
2.3 Cookies and Similar Technologies
Cookies are small files a website asks your browser to store. Next Thing Security uses as few of them as we reasonably can. The categories that may apply are:
Strictly necessary cookies — required for the site to function, such as remembering your cookie preferences, maintaining security protections, or keeping a session stable. These cannot be switched off without breaking the site.
Preference cookies — remember choices you make, such as light or dark reading mode, or dismissing a banner you have already read.
Analytics cookies or identifiers — help us understand which articles are read, how people arrive, and where pages fail. Where available, we prefer analytics configured to avoid cross-site tracking and to anonymize IP addresses.
You can control cookies through your browser settings. Every major browser lets you block cookies, delete existing ones, or refuse third-party cookies specifically. Blocking strictly necessary cookies may affect how parts of nextthingsecurity.com behave, but reading articles should still work.
2.4 Analytics
We use website analytics to see what readers actually find useful. The questions we are trying to answer are editorial, not commercial: which guides get finished, which headlines mislead, which pages people leave immediately. We look at aggregate patterns, not individual browsing histories.
Where our analytics provider supports privacy-protective settings — IP anonymization, shortened data retention, disabled advertising features, and no cross-site identifiers — we enable them. If we ever change analytics providers in a way that materially affects your privacy, we will update this policy.
2.5 What We Do Not Collect
To be explicit, Next Thing Security does not knowingly collect biometric data, precise GPS location, contact lists, browsing history from other websites, financial account information, health information, or the contents of your device. We do not sell reader data, and we do not participate in data brokerage.
3. How We Use Information
We use the information described above for a limited set of purposes:
To deliver the site — serving pages, loading images, and making the site work on your device.
To improve our writing — understanding which topics and formats help readers make better decisions, and which do not.
To respond to you — answering questions, processing corrections, and handling requests about your data.
To send what you subscribed to — newsletters or update notices, if and only if you asked for them.
To protect the site — detecting abuse, spam, scraping, and attempts to compromise the site or its readers.
To meet legal obligations — responding to valid legal process and maintaining required records.
We do not use your information to build advertising profiles, to infer sensitive characteristics about you, or to make automated decisions that produce legal or similarly significant effects.
4. Legal Bases for Processing
For readers in jurisdictions where a legal basis must be identified, we rely on:
Legitimate interests — operating, securing, and improving a publication that readers voluntarily visit, balanced against your privacy expectations.
Consent — for non-essential cookies, analytics where consent is required, and email subscriptions. Consent can be withdrawn at any time.
Legal obligation — where retention or disclosure is required by applicable law.
5. Third-Party Sharing and Service Providers
We do not sell, rent, or trade your personal information. We share limited information with service providers who help us operate nextthingsecurity.com, and only as needed to perform their function. These may include:
Web hosting and content delivery providers, which necessarily process IP addresses and request data to serve pages to you.
Analytics providers, which process usage data as described above.
Email delivery platforms, if you subscribe to a mailing list, which store your email address and delivery statistics such as whether a message was opened.
Security and anti-spam services, which may evaluate traffic patterns to block malicious activity.
These providers are bound by their own agreements to process data on our instructions. We also disclose information where legally compelled — in response to a valid subpoena, court order, or similar process — or where disclosure is necessary to protect the rights, safety, or property of readers, the public, or Next Thing Security.
5.1 Affiliate Links and Sponsored Content
Some articles discuss paid products, and some links may be affiliate links that earn a commission if you make a purchase. Where this applies, we disclose it. Clicking such a link takes you to a third-party site with its own privacy practices, and that third party may set its own cookies. Our recommendations reflect our editorial judgment about whether a paid product is genuinely worth considering; commission arrangements do not determine what we recommend.
5.2 External Links
We link to outside sources frequently, because verifying claims matters. Once you leave nextthingsecurity.com, this policy no longer applies. We encourage you to review the privacy policy of any site you visit, especially one asking you to create an account.
6. Data Retention
We keep personal information only as long as there is a reason to keep it:
Server logs — typically retained for a short period (generally up to 90 days) for security and troubleshooting, then deleted or aggregated.
Analytics data — retained in aggregate form; individual-level records are kept for the shortest period our provider allows, typically 14 months or less.
Email subscriptions — retained until you unsubscribe, after which your address is removed or suppressed. Suppression lists exist only to ensure we do not email you again.
Correspondence — retained as long as needed to handle your inquiry and maintain a reasonable record, then deleted.
Comments — retained while published, unless you request removal.
7. Your Rights and Choices
Depending on where you live, you may have some or all of the following rights. We extend the core of these choices to all readers regardless of location, because we think that is the right default.
Access — ask what personal information we hold about you.
Correction — ask us to fix information that is inaccurate.
Deletion — ask us to delete your personal information, subject to legal retention requirements.
Portability — request a copy in a portable format, where applicable.
Objection and restriction — object to certain processing based on legitimate interests.
Withdraw consent — unsubscribe from emails at any time using the link in every message, or change cookie preferences in your browser.
Opt out of sale or sharing — we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. If that ever changes, we will say so plainly and provide a mechanism.
Non-discrimination — exercising any of these rights will not affect your ability to read anything on this site.
To exercise a right, contact us using the details in Section 12. We will respond within the timeframe required by applicable law, generally within 30 to 45 days. We may ask for limited information to confirm your request relates to you — but we will not demand identity documents for a request that can be verified more simply.
7.1 Do Not Track and Global Privacy Control
Browsers differ in how they signal tracking preferences. Where we can detect a recognized opt-out signal such as Global Privacy Control, we honor it as a valid request to limit non-essential data processing.
8. Children's Privacy
Next Thing Security is written for adults making their own account and privacy decisions. The site is not directed to children, and we do not knowingly collect personal information from anyone under 13 years of age (or under 16 where a higher age applies by local law).
If you believe a child has provided personal information to nextthingsecurity.com, please contact us and we will delete it promptly. We deliberately do not cover family device setup or parental control configuration, so there is no reason for a minor's information to reach us in the ordinary course.
9. International Data Transfers
Next Thing Security is operated from the United States, and our service providers may process data in the United States or other countries. If you access the site from outside the United States, your information will be transferred to and processed in a jurisdiction whose data protection laws may differ from those where you live.
Where transfers involve personal data originating in the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or a recognized adequacy mechanism used by our providers. By using the site, you understand that information may be processed in the United States.
10. Security Measures
We take reasonable technical and organizational measures to protect the limited information we hold. These include HTTPS encryption for all traffic to nextthingsecurity.com, restricted administrative access, multi-factor authentication on the accounts used to operate the site, keeping software and dependencies current, and minimizing collection so there is less to protect in the first place.
Data minimization is our primary security control. The safest record is the one that was never created. Still, no website or transmission method is perfectly secure, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify affected individuals and regulators as required by applicable law, and we will describe what happened without spin.
11. Changes to This Policy
We may update this Privacy Policy as the site evolves, as we change service providers, or as legal requirements shift. When we do, we will revise the "Last updated" date at the top of this page. For material changes — such as new categories of data collection or new sharing arrangements — we will provide more prominent notice on the site and, where you have subscribed to email updates, by email.
Continuing to use nextthingsecurity.com after an update means you accept the revised policy. We encourage you to review this page occasionally, and we keep the language stable so changes are easy to spot.
12. Contact Information
Questions, corrections, or requests about your personal information can be sent to the Next Thing Security team at privacy@nextthingsecurity.com. For general editorial feedback or story suggestions, use the contact form on this site.
Please include enough detail for us to understand what you are asking, and let us know which right you are exercising if your message concerns your data. We read everything, and we answer real questions from real readers.
If you are located in the European Economic Area or the United Kingdom and believe we have not handled your request adequately, you have the right to lodge a complaint with your local data protection authority. We would prefer you raise it with us first so we have the chance to fix it.