Privacy Policy
Last updated: June 20, 2026
This Privacy Policy explains how Neurixco ("Neurixco", "we", "us", "our") collects, uses, discloses, retains, and protects information when you visit our website, use our application, or interact with our dashboard (collectively, the "Service"). It applies to personal data we process as a controller, and to personal data we process on behalf of business customers as a processor in accordance with their instructions. By using the Service you acknowledge this Policy.
1. Information We Collect
Account Information. Email address, display name, organization name, role, hashed password (when not using SSO), and authentication provider identifiers (e.g., Google).
Billing Information. Plan, subscription status, invoice history, billing address, and the last four digits / brand of payment cards. Full card numbers and bank details are processed and stored by our payment processor (Stripe, Inc.), not by us.
Service Usage Data. Request and response metadata (timestamp, feature, status, credit cost, latency, error codes), aggregated activity volume, and limited request payloads retained for a limited window for debugging, abuse prevention, and quota enforcement.
Customer Content. Documents, notes, prompts, files, queries, and other content you submit to the Service. We process Customer Content only to deliver the Service, comply with law, and as instructed by you. We do not use Customer Content to train foundation models without your opt-in.
Technical Data. IP address, user-agent, browser/OS, device identifiers, referring URLs, language preference, and similar diagnostic data collected via server logs and cookies.
Communications. Records of support requests, sales inquiries, and other correspondence with us.
Cookies & Similar Technologies. Session cookies (authentication), preference cookies (UI settings), and limited first-party analytics. See Section 8.
2. How We Use Information
We use personal data to: (a) provide, secure, and operate the Service; (b) authenticate users and authorize requests; (c) meter usage, enforce quotas, and bill customers; (d) detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms; (e) provide customer support and respond to inquiries; (f) send service announcements, security alerts, and (where lawful) product updates and marketing — you may opt out of marketing at any time; (g) improve and develop the Service using aggregated and de-identified data; and (h) comply with legal obligations, enforce our agreements, and protect our rights.
3. Legal Bases (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases: (a) performance of a contract — to provide the Service you request; (b) legitimate interests — to secure the Service, prevent fraud and abuse, conduct analytics, and run our business, balanced against your rights; (c) consent — for non-essential cookies and certain marketing, which you may withdraw at any time; and (d) legal obligation — to meet tax, accounting, and other regulatory requirements.
4. How We Share Information
We do not sell personal data, and we do not "share" personal data for cross-context behavioural advertising as defined by the CPRA. We disclose personal data only as follows:
- Service providers — hosting, database, payment processing (Stripe), email delivery, customer support, error monitoring, analytics, and similar vendors, each under contractual confidentiality and data protection obligations;
- Upstream AI providers — to fulfil your requests. Provider behaviour is governed by their own privacy policies;
- Legal, safety, and compliance — to comply with law, lawful requests from public authorities, or to protect rights, property, safety, or to investigate fraud or abuse;
- Corporate transactions — in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to standard confidentiality protections;
- With your consent or at your direction.
Categories of service providers. We engage vendors in the following categories: cloud hosting and database, payment processing (Stripe, Inc., United States), transactional email delivery, error monitoring, product analytics, customer support tooling, and AI model providers used to fulfil Service requests. Questions: support@neurixco.com.
5. International Data Transfers
We and our service providers may process personal data in countries other than your own, including the United States. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary measures, or on equivalent mechanisms recognised in your jurisdiction. Copies of relevant transfer mechanisms are available on request.
6. Data Security & Breach Notification
We implement administrative, technical, and organisational measures designed to protect personal data, including encryption in transit (TLS 1.2+), encryption of sensitive fields at rest, role-based access controls, audit logging, and least-privilege engineering practices. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials and for notifying us promptly of any suspected compromise.
Breach notification. In the event of a personal data breach affecting your data, we will notify you and, where required, the relevant supervisory authority without undue delay and in any event within 72 hours of becoming aware where feasible (as required by GDPR Art. 33/34), or within the timeframe required by other applicable law.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including the duration of your account, and thereafter as required to comply with legal, tax, accounting, and audit obligations, resolve disputes, and enforce our agreements. Specifically: (a) account and billing records — for the life of the account and up to 7 years after closure where required by law; (b) usage metadata — typically up to 90 days hot retention plus aggregated long-term retention; (c) request/response payloads — short-term retention for debugging and abuse prevention; (d) security and audit logs — up to 12 months. Backups are retained for a limited rolling window and overwritten in the ordinary course.
8. Cookies & Tracking
We use strictly necessary cookies to operate authentication and session state, and limited first-party cookies for preferences and aggregate analytics. We do not use third-party advertising cookies. You can control cookies through your browser; disabling strictly necessary cookies may prevent the Service from functioning. We do not currently respond to "Do Not Track" browser signals as no consistent industry standard exists, but we do honour Global Privacy Control (GPC) signals where applicable.
9. Your Rights
Depending on your jurisdiction, you may have rights to: (a) access the personal data we hold about you; (b) request correction of inaccurate data; (c) request deletion ("right to be forgotten"); (d) object to or restrict processing, including processing based on our legitimate interests (we will cease such processing unless we can demonstrate compelling legitimate grounds that override your rights or the processing is necessary for the establishment, exercise, or defence of legal claims); (e) data portability — receive the personal data you have provided in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and transmit it to another controller; (f) withdraw consent where processing is based on consent (without affecting prior lawful processing); (g) lodge a complaint with your local data protection authority; and (h) for California residents under the CCPA/CPRA, the rights to know, delete, correct, opt-out of sale/sharing, limit use of sensitive personal information, and to non-discrimination. To exercise any of these rights, contact us at support@neurixco.com. We will verify your identity before responding and will respond within the timeframes required by applicable law (typically within 30 days under GDPR and 45 days under CCPA, extendable as permitted).
10. AI Output
The Service may relay or summarise content from third-party AI models and sources. Output may include inaccurate, outdated, or biased information and may reference personal data published by third parties. We are not the source of such third-party content and process it solely to deliver your request. If you are an individual referenced in third-party content surfaced by the Service, your rights remain primarily with the underlying publisher; you may also contact us and we will consider applicable requests in good faith.
11. Children's Privacy
The Service is intended for users aged 18 and over and is not directed to children. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such data, we will delete it promptly. Parents or guardians who believe a child has provided personal data may contact us at support@neurixco.com.
12. Automated Decision-Making
We do not use personal data to make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. Automated systems are used for fraud and abuse detection, with human review available.
13. Third-Party Links
The Service may link to third-party websites or services. We are not responsible for their privacy practices. We encourage you to review their privacy policies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice where reasonably practicable, with the revised "Last updated" date posted on this page. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Contact & Data Protection
For privacy inquiries, data subject requests, or to contact our data protection point of contact, email support@neurixco.com. EEA/UK customers may also have the right to lodge a complaint with their local supervisory authority.
