Privacy Policy

Last updated: 10 August 2026

This Privacy Policy ("Policy") explains how Neurophic Limited ("Neurophic," "we," "our," or "us"), a company registered in England and Wales, collects, uses, stores, and protects your personal data when you use our website https://neurophic.ai and associated services. We process personal data in accordance with UK GDPR and the Data Protection Act 2018.

1. Who We Are

Neurophic Limited is the data controller responsible for your personal data. We are a company registered in England and Wales.

One exception: where a developer uses a project and its API keys to submit their own users' data, that developer is the data controller for that data, and we process it on their behalf under our Data Processing Terms (Schedule 1 of our Terms of Use). If you use an application built on Neurophic, please direct privacy questions and requests to that application's operator.

For any privacy-related queries, you can contact us at [email protected].

2. Data We Collect

We collect and process the following categories of personal data:

Account Data

  • Name (first name and surname)
  • Email address
  • Profile preferences (such as colour theme)
  • Invitation and access details

Billing and Payment Data

  • Billing address, subscription plan and status, and payment history when you subscribe or top up project credit
  • Payment card details are collected and held by our payment provider, Stripe; we never hold full card numbers
  • Transaction and credit history for your projects, and invoice records
  • Tax or VAT identification numbers you provide at checkout are collected and held by our payment provider, Stripe; we never hold them ourselves

Authentication and Session Data

  • Session identifiers and authentication tokens
  • Password (never stored in plain text)
  • IP addresses and browser details may be processed transiently in our infrastructure and security logs
  • Session timestamps
  • One-time passcodes for email verification (temporary, deleted after use)

Chat and Conversation Data

  • Messages you send and AI-generated responses
  • Files you upload within conversations (such as images, PDFs, and text files) and associated metadata (filename, file type, and file size)
  • Chat titles and metadata
  • Usage statistics (such as the AI model used, token counts, request counts and usage costs, used to enforce plan allowances)

Memory System Data

  • Information extracted and stored from your conversations
  • Facts, preferences, and context you share
  • Associations between related pieces of information
  • Content submitted to your memory by AI assistants you connect through your personal API key or MCP
  • Processing metadata such as timestamps and access records

Developer and API Data

  • Projects you create and their settings
  • API key records (we store only a cryptographic hash of each key, with usage timestamps)
  • End-user identifiers, optional end-user display names, and memory content submitted to your projects (processed on the developer's behalf; see Section 1)

Feedback Data

  • Feedback messages you submit (category and content)

Enquiry and Waitlist Data

  • Name and email address for users who join our waitlist or submit an enquiry
  • Company or organisation name (where provided)

Special Category Data

We do not intentionally collect special category data (such as information about health, political opinions, or religious beliefs). However, if you choose to share such information in your conversations, it may be processed by our AI and stored by the Memory System. We recommend that you avoid sharing sensitive personal data unless necessary. Where special category data is processed, we rely on your explicit consent.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Providing and maintaining the AI chat service
  • Authenticating your identity and managing your sessions
  • Personalising your experience through the Memory System
  • Processing your conversations through third-party AI providers to generate responses
  • Storing and serving files you upload as part of your conversations
  • Transmitting uploaded files to third-party AI providers for processing alongside your messages
  • Processing payments and managing subscriptions and prepaid credit
  • Sending billing and service communications (such as payment reminders)
  • Retaining records we are legally required to keep, such as tax and accounting records
  • Preventing fraud and abuse, including bot detection on public forms and handling payment disputes
  • Generating personalised suggestions from your recent chats, and understanding how our website and console are used via privacy-preserving analytics
  • Monitoring service usage and enforcing usage limits
  • Reviewing a sample of memory content to improve and assure the quality of the Memory System
  • Sending transactional emails (such as verification codes and service notifications)
  • Managing the invitation, waitlist, and enquiry system
  • Sending newsletter and marketing communications (with your consent)
  • Collecting and responding to your feedback
  • Ensuring the security of our Platform and preventing abuse
  • Complying with our legal obligations

We do not sell your personal data to third parties.

4. Lawful Bases for Processing

Under UK GDPR, we rely on the following lawful bases:

  • Contract performance (Article 6(1)(b)): Processing account data, chat data, authentication data, and Memory System data is necessary to provide our services to you. This also covers processing payments, managing your subscription and prepaid credit, and sending billing and service communications. The Memory System is a core part of the service we offer and is necessary to deliver the personalised AI experience described in our service description.
  • Consent (Article 6(1)(a)): Marketing communications are based on your consent, which you may withdraw at any time.
  • Legal obligation (Article 6(1)(c)): We retain billing and transaction records to meet tax and accounting requirements.
  • Legitimate interests (Article 6(1)(f)): We process security logs to protect our platform and prevent abuse, including bot detection on public forms, payment-dispute handling, and our email suppression list. We also rely on legitimate interests to perform background processing within the Memory System to improve the relevance of the service, for privacy-preserving analytics, and to review a sample of memory content for service improvement and quality assurance. We have assessed that these interests do not override your fundamental rights.
  • Explicit consent (Article 9(2)(a)): We do not intentionally collect special category data (such as information about health, political opinions, or religious beliefs). However, if you choose to share such information in your conversations, it may be processed by our AI providers and stored by the Memory System in the same way as your other content. We recommend that you avoid sharing sensitive personal data unless necessary. Where special category data is processed because you have chosen to share it, we rely on your explicit consent, which you can withdraw at any time by deleting the relevant content (see Section 10).

Where we rely on consent, you have the right to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Providing your account data (name and email address) is necessary to enter into a contract with us and use our services. If you do not provide this data, we will not be able to create your account.

5. The Memory System

A core feature of Neurophic is our Memory System. This section explains how it processes your personal data.

What It Does

The Memory System stores information from your conversations and uses it to provide more personalised and contextually relevant responses over time. It:

  • Stores and organises information from your conversations
  • Remembers facts, preferences, and context you share across sessions
  • Uses stored information to personalise future AI responses
  • Performs periodic background processing to organise and maintain stored information

Background processing runs on a schedule and involves transmitting stored memories to our AI providers (see Section 6) without further action from you, for example to classify, connect and consolidate what you have stored. During this processing, any name attached to the memory owner (your name, or a display name a developer has supplied for their end-user) is included so that extracted facts are attributed to the correct person. Deleting Memory System data does not delete your chat transcripts, and archiving chats does not delete memories already created from them; Section 10 describes the controls for each.

Profiling

This processing constitutes profiling under UK GDPR Article 4(4), as it involves automated analysis of your personal data to build a profile of information relevant to you. The Memory System is a core part of the service we provide, and we rely on contract performance (Article 6(1)(b)) as the lawful basis for this processing.

You retain the right to request the deletion of all data held by the Memory System at any time. See Section 10 for details of your rights.

6. Third-Party Providers

We share your personal data with the following categories of third-party data processors:

AI Providers

When you send a message, your conversation content, including any files you have uploaded and relevant memories used to personalise the response, is transmitted to a third-party AI provider to generate a response, along with your name so the assistant can address you. The providers we currently use are:

  • OpenAI (United States)
  • Anthropic (United States)

Content may be processed by both providers regardless of the model you select: for example, chat titles and Memory System embeddings are generated via OpenAI even in conversations using Anthropic models. All AI traffic is routed through our AI gateway, Vercel (United States). We may add or change providers from time to time and will update this list accordingly.

Payment Provider

Stripe (United States) processes your name, email, billing address, card details and transaction history when you subscribe or top up.

Infrastructure Providers

We use third-party cloud hosting, database, and infrastructure providers to deliver our services.

Analytics

Plausible (EU), a privacy-preserving, cookieless analytics service, measures page views on our website and console.

We do not sell, rent, or share your personal data with third parties for their own marketing purposes. We only share data as described in this Policy or where required by law.

7. International Data Transfers

Our AI Providers and gateway, our payment provider, and some infrastructure providers are based in the United States. This means your personal data, including chat messages, Memory System data, project end-user data (including any display names developers supply) and billing data, is transferred outside the United Kingdom for processing.

We ensure appropriate safeguards are in place for these transfers, including:

  • The UK Extension to the EU-US Data Privacy Framework, where the receiving organisation is certified
  • UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) where the Data Privacy Framework does not apply

You may request further details about the specific safeguards applied to your data by contacting us at [email protected].

8. Automated Decision-Making and Profiling

The Memory System constitutes profiling under UK data protection law. It automatically analyses your conversation data to identify and store relevant information for personalisation.

This profiling is used to:

  • Provide more contextually relevant and personalised AI responses
  • Recall information from previous conversations
  • Identify patterns and connections in information you share

In accordance with the Data (Use and Access) Act 2025, you have the right to:

  • Be informed about significant decisions influenced by automated processing
  • Make representations about automated processing and its effects on you
  • Request human intervention in any decision significantly affected by automated processing
  • Contest any automated decision that significantly affects you

To exercise any of these rights, contact us at [email protected].

9. Data Retention

We retain your data for the following periods:

  • Account data: deleted promptly when your account deletion completes (an automated process, typically the same day). Accounts with no active subscription for 6 months or more may be deleted after we give notice by email.
  • Chat, conversation and file data: retained while your account is active. Conversations can be archived; chat history and uploaded files are deleted when you delete your account.
  • Memory System data: until you delete it, individually, via Reset memory, or by deleting your account.
  • Billing and transaction records: retained for up to 6 years after the relevant financial year, as required by UK tax law, including at our payment provider after account deletion.
  • Usage and session records: for the life of your account or project.
  • Email suppression list: if an email to you bounces or you report our email as spam, we keep that email address after account deletion so we never contact it again (legitimate interests).
  • Erasure receipts: a pseudonymised record of each deletion (a hashed reference, counts and timestamps, no readable personal data) is kept indefinitely as proof of deletion.
  • Project end-user data: retained until the developer deletes it or the project is deleted. Suspended projects' data is retained; projects suspended for 90 days or more may be deleted after notice. A display name attached to an identifier is retained until the developer overwrites it, resets the identifier (which clears it) or deletes the identifier; because names can appear inside derived memory content, complete removal of a name requires an identifier reset or deletion.
  • Waitlist and enquiry data: until you ask us to delete it at [email protected].
  • Verification codes: expire within minutes of being issued.
  • Residual copies: may persist in encrypted backups, transient processing queues and operational logs for a limited period before expiring automatically.

When you delete your account, we delete your personal data except the specific records described above (suppression list, erasure receipt, legally required billing records, and expiring backups) and records we reasonably need to establish, exercise or defend legal claims or to investigate fraud or abuse.

10. Your Data Protection Rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you, including Memory System data.
  • Right to rectification: Request that we correct any inaccurate personal data.
  • Right to erasure: Request deletion of your personal data, including all Memory System data.
  • Right to restrict processing: Request that we limit how we process your data.
  • Right to data portability: Request your data in a structured, commonly used, and machine-readable format.
  • Right to object: Object to processing of your data, including profiling by the Memory System. You have an absolute right to object to direct marketing.
  • Right to withdraw consent: Where processing is based on consent (such as marketing emails), you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

You can exercise deletion yourself at any time: individual memories and entities can be deleted in the app, Settings offers Reset memory (erases all Memory System data immediately) and Delete account (full erasure), and project owners can delete or reset identifiers (reset also clears any stored display name), delete memories or whole projects in the console. For access and portability, email [email protected] and we will provide your data in a machine-readable format within one month.

If your data reached us through an application built on Neurophic, that application's operator is the controller: please direct requests to them, and we will assist them in fulfilling your request.

To exercise any of these rights, email us at [email protected]. We will respond within one month. In complex cases, we may extend this by a further two months, and we will inform you if this is necessary.

Requests are free of charge unless they are manifestly unfounded or excessive.

If you are unhappy with how we handle your personal data, you have the right to complain to us: contact [email protected] and we will acknowledge your complaint within 30 days and investigate.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection. You can contact the ICO at ico.org.uk or by telephone on 0303 123 1113.

11. Cookies

We use only strictly necessary storage in your browser: to keep you signed in and to remember interface preferences. This is essential for the platform to function and does not require your consent.

Our website and console analytics (Plausible) are cookieless and do not identify you, and public forms are protected against bots by Cloudflare Turnstile. We do not use cookies or any other tracking for advertising, and no cross-site tracking of any kind.

12. Children

Our services are not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete that data promptly.

13. Marketing and Communications

We only send marketing communications (such as newsletters and product updates) with your explicit consent. We will not send marketing emails unless you have actively opted in.

Transactional emails, such as verification codes and important service notifications, are sent as part of providing our services and do not require marketing consent.

You can unsubscribe from marketing communications at any time by using the unsubscribe link in any marketing email, or by contacting us at [email protected].

14. Data Security

We take appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, or misuse. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

15. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by email or through a notice on the Platform before the changes take effect.

The latest version of this Policy will always be available on this page.

16. Contact Us

If you have any questions about this Policy or how we handle your personal data, please contact us at:

Email: [email protected]
Website: https://neurophic.ai