Trust
Privacy and data handling
This page describes what Next Standard Health actually does today with data on this website, in its private editing area, and in the accounts it is connected to. It does not describe plans or promises we have not built.
Reading the site
You can read every public page without an account and without signing in. We do not run advertising networks, tracking pixels, or an analytics product on the public pages, and we do not sell or share reader information with anyone.
Our hosting provider handles ordinary web-server request logs, as any web host does. We do not build reader profiles from them.
The private editing area
Staff sign in with an email address and password to reach the review and publishing pages. Those accounts, and the sign-in process, are handled by our hosted backend provider. We store the account's email address and which staff role it has, plus the record of which account approved each story.
Article drafts, source links, review notes and social post drafts are stored in our own database. Nothing in this area is public until a staff member approves it.
Email notifications
The site can email the publisher when stories are ready for review. Those notices contain a link to the review queue and no article text. We send them from the newsroom's own Gmail account through Google's mail API, using a connection that was authorised only to read and send mail from that mailbox.
The connected YouTube channel
An administrator can connect the newsroom's own YouTube channel by signing in with the Google account that owns it. What that connection covers:
- Which account. Only the single Google account an administrator deliberately signs in with. We do not ask readers to connect Google accounts, and there is no Google sign-in for readers.
- Permissions requested. Two:
youtube.upload(upload a video to that channel) andyoutube.readonly(read the channel's own name, handle and id so we can show which channel is connected). We do not request access to a personal Google profile, contacts, Drive, or any other Google service through this connection. - What we store. The channel's id, name and handle, the list of permissions granted, and the Google access and refresh credentials for that channel. The credentials are stored server-side in our database and are never sent to the browser or shown on any page.
- What we do with it. Nothing is uploaded automatically. A video is only sent to YouTube after a staff member opens that specific package in the private area and approves it. We do not read channel analytics, comments, subscribers, viewer data, or anyone else's videos.
Data obtained through the YouTube API is used only for the purposes above. Our use of it follows the YouTube Terms of Service and the Google Privacy Policy.
Disconnecting and removing data
An administrator can disconnect the channel at any time from the private social page. Disconnecting asks Google to revoke the stored credential and deletes our stored record of the connection, including the credentials and the channel details.
You can also revoke this site's access directly from the Google account that granted it, at myaccount.google.com/permissions. YouTube's own privacy and data controls are at myaccount.google.com/yourdata/youtube. Revoking there stops any further use immediately; the stored record on our side is removed when the connection is disconnected here.
To ask us to delete data we hold about you or about a connected account, write to nextstandardhealth@gmail.com. We will tell you what we hold and what we removed.
Other connected services
Where the site prepares posts for Facebook, Instagram or TikTok, the same rule applies: drafts are prepared in the private area and nothing leaves the site until a staff member approves that specific package. Where a service is not connected with an authorised account, the site says so rather than pretending it can post.
Contact
Questions about this page, about a story, or about data we hold: nextstandardhealth@gmail.com.

