Privacy Policy
Our Position
Everything about you is yours. How we help you is ours.
This is the foundational design constraint of everything Neurow builds. Your memories, your coaching sessions, your behavioral patterns, the insights we generate about you — all of it belongs to you. You can inspect it, export it, transfer it to another service, or delete it permanently. At any time. Without asking permission.
What remains ours is how we help you: the coaching methodology, the algorithms, and the architecture that structures your information.
Our architecture is designed to meet or exceed the data protection standards set by GDPR, CCPA, the Texas Data Privacy and Security Act, and the emerging provisions of the EU AI Act — but compliance is our floor, not our ceiling. Where the law is silent, we default to the position that gives you more control, not less.
1. Design Principles
These eight commitments govern every data decision Neurow makes. They are architectural — enforced by system design, not just policy.
- Advisory, not directive. Neurow guides. You decide. We surface patterns and insights to inform your thinking. We never make decisions that produce legal, financial, or similarly significant effects on your behalf. This is not a limitation — it is the product.
- Behavioral analysis, not emotion recognition. We analyze self-reported data and behavioral patterns you share in coaching sessions. We do not perform biometric emotion detection, sentiment analysis from facial expressions, or any form of emotion recognition from physiological data.
- Explicit consent for sensitive data. Behavioral patterns, emotional states, and health information shared in coaching sessions receive their own consent — separate from general terms, specific in purpose, and withdrawable at any time.
- AI disclosure at first interaction. You know you are interacting with AI from the moment you open Neurow. This is stated in onboarding, visible in the interface, and restated here: Neurow is an AI coaching system. You are interacting with artificial intelligence, not a human coach.
- No third-party data sharing for advertising or sale. Your personal data is not sold, not shared for advertising, not provided to data brokers, and not used for cross-account analysis. The only third parties that process your data are:
- AI providers (Anthropic, OpenAI — described in Section 5)
- Integration platform providers (Composio — described in Section 5b) when you choose to connect optional integrations (Gmail, Drive, Slack, Notion, and others) in Settings → Integrations
- Our first-party product-analytics and error-monitoring providers (PostHog and Sentry — described in Sections 5d and 5e), used only to operate and improve the product
- Infrastructure providers that store your encrypted data (Supabase, Neo4j Aura, Qdrant Cloud, Mem0 — described in Sections 6 and 13)
- Deletion means deletion. When you delete your data, your content is erased from all four Brain Cloud stores — and where it lives inside tamper-evident security records that cannot themselves be deleted, your content is rendered permanently unreadable by destroying your encryption key. Not archived for our use. Not soft-deleted. Not retained for model training. The only thing that can remain is a minimized, content-free integrity record — with its link to you severed — kept where we are required or legally justified to prove our security and audit systems were not tampered with. Section 10 describes exactly what this means.
- Probabilistic, not deterministic. Coaching insights are framed as patterns and observations — never as diagnoses, certainties, or clinical assessments. "You tend to avoid financial topics when stressed" is an observation. It is not a diagnosis.
- Designed for future regulation. We build for 2028 law, not 2026 law. Being ahead of regulation is cheaper than catching up, and it is better for you.
2. What You Own and What We Keep
The line between your data and our methodology is clear, consistent, and designed to be generous toward you.
What's Yours — Full Access, Export, Delete, Transfer
| Category | Examples | Your Rights |
|---|---|---|
| Input Data | Everything you type, say, or import — coaching conversations, goals, plans, reflections, notes, calendar entries, data imported from other AI providers or files | Full access, download, delete, transfer |
| Output Data | AI-generated coaching responses, session summaries, morning briefs — content co-created between you and the coaching system | Full access, download, delete, transfer |
| Observed Data | Usage patterns and activity captured during your coaching sessions — session frequency, engagement timing, feature usage | Full access, download, delete, transfer |
| Derived Data | Behavioral patterns identified from your coaching history, coaching insights, progress tracking — generated by our processing of your Input, Output, and Observed Data | Full access, download, delete, transfer |
The first three categories follow the Data Transfer Initiative's framework for AI personal data. Input Data is what you provide. Output Data is what the AI generates in conversation with you. Observed Data is activity passively captured during your use of the service.
GDPR Article 20 requires portability of data you provided (Input Data) and data passively observed during automated processing (Observed Data). Output Data — AI-generated coaching responses — is technically controller work product under Article 20. We make it portable anyway, because it is about your life, not ours.
The fourth category — Derived Data — is where we go further still. Under GDPR Article 20, derived data is the controller's work product and is not required to be portable. We export it anyway. Behavioral patterns and coaching insights are derived from your life. We believe they belong to you, regardless of what current regulation or portability frameworks require. This is a deliberate choice, not a legal obligation.
The Gray Area — Made Tangible
The distinction between "yours" and "ours" is an instance vs. schema test:
- "You tend to abandon goals on Wednesdays" — this is yours. A specific observation about your behavior, derived from your data. You can see it, export it, correct it, or delete it.
- The algorithm that detected the Wednesday pattern — this is ours. Coaching intelligence that analyzes behavioral sequences across sessions to surface non-obvious patterns. It exists independently of any individual user's data.
- "Your energy drops after weeks without exercise" — yours. A behavioral pattern identified from your coaching history.
When in doubt, we apply a simple rule: if it's about you, it's yours. If it's about how we help everyone, it's ours.
3. What We Collect
Data You Provide (Input Data)
- Profile information (name, coaching preferences, focus areas)
- Coaching session conversations (your messages and AI responses)
- Goals, tasks, and priorities you set
- Notes and reflections you write
- Data you import from other AI providers or files (ChatGPT, Gemini, Claude exports; JSONL/JSON file imports)
- Google Calendar data, if you choose to connect your Google account (see Section 5c)
Legal basis: Contract performance — you signed up for a coaching service, and processing this data is necessary to deliver it (GDPR Article 6.1(b)).
Data Generated During Your Use (Output + Observed + Derived Data)
- Output Data: AI-generated coaching responses, session summaries, and morning briefs produced during your sessions
- Observed Data: Session frequency, engagement timing, and feature usage patterns captured during normal operation. We capture this using a first-party product-analytics tool (PostHog) — including which features and screens you use, in-app actions, timing, app version and device type, and, where enabled, session replays of your interactions with the app interface with your content masked. See Section 5d.
- Derived Data: Behavioral patterns identified from your coaching history, coaching insights, and progress tracking
Legal basis: Behavioral pattern processing may constitute sensitive personal data under GDPR Article 9 — particularly where coaching sessions touch on health conditions, emotional states, or behavioral patterns related to mental wellbeing. Processing of derived behavioral data requires your explicit consent, obtained separately from general terms acceptance (GDPR Article 9.2(a)). You may withdraw this consent at any time through Settings, and withdrawal does not affect the lawfulness of processing performed before withdrawal. Product-analytics processing rests on our legitimate interest in operating and improving the service (GDPR Article 6.1(f)).
Data We Do Not Collect
- Location or GPS data
- Biometric data (facial recognition, voice prints, physiological signals)
- Browsing history or device fingerprints
- Advertising cookies, ad pixels, or cross-site trackers. We use first-party product analytics only to understand and improve how the app itself is used (Section 5d); we do not use advertising networks, ad pixels, or cross-site tracking of any kind.
- Data from other users or cross-account information
- Any data for behavioral advertising purposes
- Data beyond what is necessary for coaching delivery
3b. SMS/Text Messaging Communications
If you opt in to receive SMS text messages from Neurow (for example, coaching check-ins, morning briefings, or session reminders), the following applies specifically to that channel:
- No sharing for marketing: We do not sell or share your mobile phone number, or the fact that you have opted in to receive text messages, with third parties for marketing or promotional purposes.
- Message frequency: Message frequency varies based on your coaching cadence and preferences.
- Message and data rates: Message and data rates may apply, depending on your mobile carrier and plan.
- Opt-out: You can opt out at any time by replying STOP to any text message, or reply HELP for assistance.
4. How We Use Your Data
Your data serves one purpose: to coach you.
| Processing Activity | What It Does | Legal Basis |
|---|---|---|
| Coaching delivery | Generating personalized coaching responses informed by your history and context | Contract (Art. 6.1(b)) |
| Memory extraction | Parsing your conversations and imported data into structured memories — facts, entities, categories, dates | Contract (Art. 6.1(b)) |
| Pattern recognition | Identifying behavioral patterns across your coaching sessions to surface insights | Explicit consent (Art. 9.2(a)) |
| Knowledge graph construction | Connecting your information into a structured graph that enables deeper, more contextual coaching | Contract (Art. 6.1(b)); Explicit consent (Art. 9.2(a)) for sensitive categories |
| Progress tracking | Measuring behavioral change over time to inform the coaching approach | Explicit consent (Art. 9.2(a)) |
| Product analytics & improvement | Measuring how features and screens are used, diagnosing errors and usability problems, and prioritizing what to build — via first-party analytics and, where enabled, masked session replay (Section 5d). Used in aggregate to improve the product; never to make decisions about you. | Legitimate interest (Art. 6.1(f)) |
What we do NOT use your data for:
- Training or improving AI models (Section 7)
- Targeted advertising or behavioral advertising of any kind
- Profiling for third parties
- Sale to data brokers
- Cross-account analysis or aggregation at the individual level
- Making automated decisions that produce legal or similarly significant effects concerning you
Advisory architecture: Neurow surfaces patterns and observations. It does not make consequential decisions on your behalf. If Neurow identifies that your spending increases during high-stress periods, it will raise this as a coaching observation. It will not freeze your credit card, notify your employer, or take any action beyond the coaching conversation. This is architecturally enforced, not merely a policy commitment.
5. Third-Party AI Processing
Neurow uses third-party AI models at two points in its processing pipeline. Here is exactly what happens at each.
Coaching Conversations — Anthropic (Claude)
- Provider: Anthropic, accessed via their commercial API tier
- What they receive: The content of your active coaching conversation, plus relevant context retrieved from your Brain Cloud for that specific session
- What they do NOT receive: Your full Brain Cloud memory store, your complete knowledge graph, behavioral patterns from other sessions, or data from other users
- Their retention: Anthropic's commercial API tier does not use inputs or outputs to train models. Conversation data is retained for up to 30 days for trust and safety purposes per their published data handling policies.
Memory Extraction — OpenAI
- Provider: OpenAI, accessed via their API
- What they receive: Text content from your coaching conversations and imported data, sent for structured extraction — parsing facts, entities, categories, and dates into Brain Cloud memories
- What they do NOT receive: Your full Brain Cloud memory store, knowledge graph, or data from other users. Each extraction request processes a single piece of content.
- Their retention: OpenAI's API tier does not use inputs or outputs to train models. Data is retained in abuse monitoring logs for up to 30 days per their published data handling policies.
Bring Your Own Key (BYOK)
When you configure your own API key (Settings > Model Configuration), you establish a direct relationship with your chosen provider for coaching conversation processing. Neurow remains the data controller (we determine the purpose and means of processing your Brain Cloud data), but the AI provider relationship shifts — your chosen provider processes conversation data under your API agreement with them, not ours. We support Anthropic, OpenAI, NVIDIA, and custom OpenAI-compatible endpoints. We recommend reviewing your chosen provider's data handling practices. Neurow cannot guarantee the data protection standards of providers accessed through your own API key, and your chosen provider's policies — not ours — govern their processing of your conversation data.
What Stays in Your Brain Cloud
Your memories, behavioral patterns, and session history are stored in your Brain Cloud. They are not transmitted to AI providers in bulk. Only the specific content needed for an active coaching conversation or a single extraction request is sent — and only for the duration of that operation.
5b. Third-Party Integration Platform Processing — Composio
Neurow uses Composio (composio.dev) as the integration platform layer for connecting your optional third-party accounts in Settings → Integrations. This includes Gmail, Drive, Slack, Notion, and other services you may opt to connect over time.
What Composio is
Composio is an integration platform service (SOC 2 Type II + ISO 27001:2022 certified) that handles OAuth credential management and API request proxying between Neurow and the third-party service you connect (e.g., Slack). When you click "Connect Slack" in Settings → Integrations, you authorize Composio to access your Slack account on Neurow's behalf. Neurow remains the data controller; Composio operates as a data processor for that specific integration's traffic.
What you see at OAuth grant
When you connect an optional integration via Settings → Integrations, the OAuth consent screen from the third-party service will display "Composio wants to access your [service]" rather than "Neurow wants to access your [service]." This is because Composio is the verified OAuth application handling the integration. Neurow remains the data controller — Composio's role is limited to OAuth credential management and API request proxying on Neurow's behalf, under purpose-limited terms.
What flows through Composio
When Neurow accesses your connected integration (e.g., reading a Slack message for coaching context, drafting a Gmail reply for your review), the API request and response flow through Composio's infrastructure. This means content from your connected services (Slack messages, Drive file contents, Gmail messages, Notion pages) passes through Composio's API proxy.
Composio's data handling
Composio's own privacy and data handling policies govern their processing of this content. Composio is SOC 2 Type II + ISO 27001:2022 certified. We have evaluated Composio's published data handling commitments and confirmed they align with Neurow's standards before integrating. For current Composio data handling specifics, see Composio's Trust Center.
What Composio does NOT receive
- Your Brain Cloud memories, behavioral patterns, or coaching session history
- Data from integrations you have not connected
- Data from other Neurow users
- Anything beyond the specific API request/response cycle for your active integration
Google Calendar is NOT routed through Composio
Your Google Calendar integration uses Neurow's own OAuth application directly — not Composio. Calendar tokens are stored in Neurow-managed encrypted storage. The Composio path applies only to optional Settings → Integrations connections. Section 5c describes how Neurow handles Google user data.
Your control
You can disconnect any optional integration at any time from Settings → Integrations. Disconnecting immediately terminates Composio's access to that service on Neurow's behalf. Note that disconnecting via Settings revokes the Neurow-and-Composio authorization but does not automatically delete any cached integration content already pulled into your Brain Cloud — that content follows the deletion rules described in Section 10.
Sovereignty migration path
Neurow's architecture is designed to migrate optional integration connections away from the Composio third-party processor model and onto Neurow-controlled infrastructure as we scale. When migration occurs, affected users will be asked to re-authorize their integrations one time, after which their integration tokens will be stored in Neurow-controlled infrastructure rather than Composio's. If you have a current need for full data sovereignty (no third-party processing), contact us — we will work with you on early access to the sovereign migration path.
5c. Google User Data — Google Calendar
If you choose to connect your Google account, Neurow accesses your Google Calendar through Google's official APIs. This section describes exactly what we access, how we use it, and the commitments that govern it.
What Google user data we access
- Calendar events (read): upcoming and recent events on your calendars — titles, times, attendees, and event metadata — used to give your coach plan-vs-reality awareness
- Calendar events (write): with your explicit per-action approval, Neurow can create protected-work blocks, reschedule events, and decline events on your own calendar
How we use it
Google Calendar data is used exclusively to provide personalized coaching to you, the individual user who granted access — context-aware briefings, protecting time for high-leverage work, and keeping your plan aligned with reality. Events are read in real time for coaching context and stored only as event references; write actions modify only your own calendar, and you see and approve every proposed write before it is applied.
What we do NOT do with Google user data
- We do not use Google user data to train any general-purpose AI or machine-learning model
- We do not transfer Google user data to third-party AI platforms, advertising platforms, or data brokers
- We do not sell Google user data
- We do not use Google user data for advertising or credit-worthiness purposes
- We do not allow humans to read this data, except with your explicit consent, where necessary for security purposes (such as investigating abuse), to comply with applicable law, or as part of Neurow's internal operations where the data has been aggregated and anonymized
Limited Use disclosure
Neurow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage, protection, and deletion of Google user data
- OAuth tokens are stored in Neurow-managed encrypted storage; data is encrypted in transit (TLS 1.2+) and at rest (AES-256) — see Section 13
- You can revoke Neurow's access to your Google account at any time via your Google Account security settings or from within Neurow; revocation immediately terminates Neurow's calendar access
- Any calendar-derived data held in your Brain Cloud follows the same deletion rights as everything else: deletable on request through Neurow's right-to-erasure pipeline (Section 10), with account deletion completed within 30 days
5d. Product Analytics and Session Replay — PostHog
To understand how Neurow is used and to make it better, we use PostHog as a first-party product-analytics data processor.
- What it captures: which features and screens you use, in-app actions, navigation, and timing/frequency of use; app version, approximate device and browser type, and error/diagnostic events; and, where enabled, session replay — a reconstruction of your interactions with the app interface (clicks, navigation, and UI state) so we can find and fix usability problems.
- What is masked: coaching conversation content, message inputs, notes, and goals are never recorded. Session replay captures interface interactions, not the words you write or the coaching content you see.
- Identified, not anonymous: analytics events are associated with your Neurow account (which includes your email) so we can debug your specific issues and measure real usage — never to build an advertising profile.
- Where it is processed: our PostHog project is hosted in PostHog's US cloud region, so this data is processed and stored in the United States (see Section 13, International Data Transfers).
- What PostHog does NOT receive: your Brain Cloud memories, coaching conversation content, behavioral patterns, or knowledge graph; any masked content above; your data for advertising, sale, or model training.
- Retention: analytics events and session recordings are retained per PostHog's default retention configuration (session recordings are retained for a shorter period than event data) and are deleted or de-identified on that rotation. You can request deletion of your analytics data at any time via hello@neurow.io.
Legal basis: our legitimate interest in operating, securing, and improving the service (GDPR Article 6.1(f)).
5e. Error Monitoring — Sentry
To keep the service reliable, we use Sentry as a data processor for error monitoring, so we can detect, diagnose, and fix crashes and failures.
- What it captures: technical error and exception data — stack traces, error messages, timing, the operation that failed, and technical context (service, environment, and request metadata). Where relevant to a specific error, this can include your account identifier so we can trace an issue affecting you.
- What we keep out of it: we configure Sentry to avoid capturing coaching conversation content and other sensitive personal data in error reports.
- Where it is processed: the United States (Sentry US region) — see Section 13, International Data Transfers.
- What Sentry does NOT receive: your Brain Cloud memories, coaching conversation content, behavioral patterns, or knowledge graph; your data for advertising, sale, or model training.
- Retention: error events are retained per our configured Sentry retention (Sentry's standard error-event retention is 90 days) and are deleted on that rotation.
Legal basis: our legitimate interest in operating, securing, and debugging the service (GDPR Article 6.1(f)).
6. Your Brain Cloud
Brain Cloud is the structured memory system that powers your coaching experience. It stores your data across four specialized systems, each serving a distinct cognitive function:
- Structured storage (Supabase) — your profile, session records, goals, factual data, and structured metadata
- Knowledge graph (Neo4j) — relationships between your information: how goals connect to behaviors, how patterns relate to outcomes, how different domains of your life intersect
- Semantic memory (Mem0) — natural-language memories and contextual understanding for coaching conversations
- Associative memory (Qdrant) — similarity-based connections that surface relevant past experiences when you're working through new challenges
You can inspect the data about you at any time through the Knowledge Graph view in the app. The information Neurow has stored about you — your memories, your behavioral patterns, your coaching history, the connections between different areas of your life — is visible, transparent, and under your control. You can correct any information you believe is inaccurate, or request deletion of any data point.
All personal data stored in your Brain Cloud belongs to you. This includes data you entered directly AND insights generated from your data. The Brain Cloud architecture itself — how we structure, organize, and connect your data across the four stores — is our engineering, not user data. You own what's about you. We built how it's organized. This is designed to address the transparency requirements of GDPR Article 15 (right of access) and Minnesota's "right to question" profiling logic.
7. AI Training
Neurow does not use your personal data to train or improve AI models — by default, by opt-in, or at all.
- We do not train on your data by default.
- We do not offer an opt-in to training on your data.
- We do not share your data with third parties for training purposes.
- The third-party AI providers we use (Section 5) operate under commercial API tiers that contractually exclude using inputs or outputs for model training.
- The third-party integration platform we use (Section 5b) does not use the content flowing through their API proxy to train any general-purpose AI model.
Personalization is not training
Neurow's coaching system uses your data to provide personalized coaching to you — the individual user who shared it. This personalization happens within the active coaching context for your specific account; it does not contribute to training, fine-tuning, or improving any AI model that would affect other users or persist beyond your coaching relationship. We make this distinction explicit because the line between "personalization for the individual user" (which IS what Neurow does) and "training a general AI model on user data" (which Neurow does NOT do) is not always obvious from the outside.
If we ever revisited this position, any change would require direct notification to you and your affirmative opt-in before any new processing begins — not a quiet policy update, not a pre-checked box, and not retroactive application to data already collected under this policy. Per FTC guidance: "Quietly updating privacy notices to adopt more permissive data practices could be an unfair or deceptive practice."
Your coaching data is too personal for any other approach.
8. Data Portability
You have the right to take your data with you. We didn't bolt portability onto the product — we built the product around it. Export is not a compliance checkbox. It is a confidence signal: a user who can leave but stays is a user who values the service.
Export — Download Your Data
You can export your personal data at any time (Settings > Your Data > Export). The export is delivered as a structured, machine-readable JSON file directly to your device. Per GDPR Article 20, you have the right to receive your personal data "in a structured, commonly used and machine-readable format" and to "transmit that data to another controller without hindrance."
What you receive:
- All memories, notes, and reflections — the content about you stored in your Brain Cloud
- Complete coaching session history — your messages, AI responses, and goal cascades
- Behavioral patterns, coaching insights, and observations that have been surfaced to you
- Your full profile and preferences
- Category metadata across all your memories
What is NOT included in exports:
- The Brain Cloud graph architecture — node types, relationship types, traversal patterns, and the ontology that structures your knowledge graph. This is our engineering (Section 2).
- Neurow's coaching prompt templates and methodology (loaded at runtime, never in export)
- Signal detection algorithms and scoring models
- Vector embeddings and similarity indexes
- Our coaching framework and behavioral science approach
The export delivers your data as flat, structured content — your memories, your coaching history, your behavioral insights, readable and portable. You get everything about you. We keep how we organized it.
Interoperability — MCP (Open Protocol)
Export gives you a file. Interoperability gives you a choice of AI.
Brain Cloud is built on MCP (Model Context Protocol) — an open agent-to-agent interoperability standard. Any MCP-compatible AI service can connect directly to your Brain Cloud and access your data where it lives. This is how Neurow itself connects — through the same open protocol any other AI can use.
This means you do not have to export and re-import to switch AI providers. Your Brain Cloud stays intact. You connect a different AI to it. Your data doesn't move — your AI does.
Brain Cloud also accepts DTP-formatted imports (Data Transfer Project — the open data format standard powering Google Takeout and other major portability tools), giving you a path to bring data in from other services.
Exceeds the Standard
GDPR Article 20 requires portability of data you provided (Input Data) and data passively observed during automated processing (Observed Data). It does not require portability of Derived Data — behavioral patterns, coaching insights, and inferences generated through our processing. We export Derived Data anyway.
Response time: GDPR Article 12 requires response within 30 days. In practice, our export is instant and self-service.
9. Your Rights
| Right | What It Means | How to Exercise |
|---|---|---|
| Access (GDPR Art. 15) | View the personal data Neurow holds about you — your memories, patterns, connections, and coaching history | Knowledge Graph view in the app; data export via Settings |
| Correction (GDPR Art. 16) | Fix any information you believe is inaccurate | Edit through coaching sessions, Knowledge Graph view, or contact us |
| Deletion (GDPR Art. 17) | Request complete data removal across all four stores | Settings > Your Data > Delete; or contact us. See Section 10. |
| Portability (GDPR Art. 20) | Receive your data in machine-readable format; connect another service to your data | Instant self-service JSON export; MCP interoperability with other AI providers |
| Object (GDPR Art. 21) | Opt out of specific processing activities | Opt out of behavioral pattern detection via Settings |
| Restrict processing (GDPR Art. 18) | Limit how we process your data while a dispute is resolved | Contact us at hello@neurow.io |
| Withdraw consent (GDPR Art. 7.3) | Revoke consent for sensitive data processing at any time | Settings > Privacy; withdrawal does not affect prior lawful processing |
| Transparency (GDPR Arts. 13-14) | Understand what data we hold, how we process it, and why | This policy; Knowledge Graph view; contact us |
| Question profiling logic (Minnesota CDPA) | Understand and question how automated pattern detection works | Knowledge Graph view shows all detected patterns; coaching conversation can explore any pattern's basis |
| Lodge complaint (GDPR Art. 77) | File a complaint with your local data protection authority | Contact your national supervisory authority or contact us first at hello@neurow.io |
To exercise any right, use the in-app controls (Settings, Knowledge Graph view) or contact hello@neurow.io. We respond within 30 days as required by GDPR Article 12, though most rights can be exercised instantly through the app.
Request process: Upon receiving a privacy request via email, we will verify your identity before processing it. We will acknowledge receipt within 5 business days and fulfill the request within 30 days. If we are unable to fulfill a request, we will explain our reasons and inform you of your right to lodge a complaint with a supervisory authority.
California residents (CCPA/CPRA): Neurow does not sell your personal information and does not share it for cross-context behavioral advertising. You have the right to know what personal information we collect and how it is used (described in Sections 3 and 4), to delete your data (Section 10), and to not be discriminated against for exercising any privacy right. We treat all users equally regardless of whether they exercise their privacy rights.
Texas residents (TDPSA): You have the right to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of the processing of personal data for targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects. Neurow does not engage in targeted advertising, data sales, or such profiling.
10. Deletion and Aggregate Data
Individual Deletion — Hard Delete
When you request data deletion, your data is removed from all four Brain Cloud stores:
| Store | What's Deleted | Mechanism |
|---|---|---|
| Supabase (structured) | Profile, sessions, goals, memories, factual records | Row deletion with cascade; scoped to your user ID |
| Neo4j (knowledge graph) | All nodes and relationships belonging to your user account | Node + relationship deletion by user scope |
| Qdrant (associative) | All vector embeddings associated with your data | Point deletion by user filter |
| Mem0 (semantic) | All natural-language memories for your user ID | Memory deletion by user scope |
Deletion is completed within 30 days of request. For your operational data this is hard deletion across the live stores — not archival, not soft-delete, not "marked inactive." Residual copies in automated infrastructure backups are handled through beyond-use controls and overwritten through standard provider rotation cycles, and are not used for any processing in the interim.
Security & Integrity Records
Neurow keeps a small set of tamper-evident records that exist to protect everyone's data integrity: a log of inputs our system quarantined or rejected as suspicious (fraud/abuse protection), and a cryptographically chained audit ledger that proves our records were not secretly altered. These records are intentionally immutable — they cannot be edited or deleted, because that is what makes them trustworthy to a security reviewer or auditor.
When you delete your account, we do not exempt these records from your deletion. We erase your content inside them by destroying your personal encryption key — so any content you contributed becomes permanently unreadable — and we sever the record's link to your account. What remains is a minimized, content-free integrity marker (for example, "an integrity event occurred at this time," plus the cryptographic proofs that the ledger was not tampered with). This minimized evidence is retained only where required or justified for security, integrity verification, and legal-defense purposes; it is treated as pseudonymized — not anonymous — unless separately cleared, is access-controlled, and is never used for coaching, profiling, advertising, or any secondary purpose.
Aggregate Data
After your individual data is deleted, Neurow retains anonymized, population-level patterns — statistical observations like "70% of users abandon morning routines by week 3." These are business intelligence, not individual data. There is no re-identification path from an aggregate statistic back to you.
A doctor who has treated 10,000 patients has clinical judgment informed by all of them. When one patient leaves, the doctor doesn't forget what they learned about medicine. But they do delete the patient's medical records.
Individual content: erased from the live stores and rendered permanently unreadable inside tamper-evident records (see Security & Integrity Records above). What may remain is minimized, content-free, link-severed integrity evidence — treated as pseudonymized unless separately cleared — and anonymized, population-level aggregate patterns.
Aggregate patterns: anonymized population learning. Designed to fall outside the Regulation's scope when truly anonymized (GDPR Recital 26).
11. Data Retention
| Data Category | Retention Period | Justification |
|---|---|---|
| Profile information | Duration of your account | Required for coaching service delivery |
| Coaching sessions | Until you delete them | Core coaching record; user controls lifecycle |
| Memories and behavioral patterns | As long as underlying session data exists | Derived from sessions; deleted when source data is deleted |
| Imported data | Until you delete it | User-initiated import; user controls lifecycle |
| Product analytics — events and session-replay recordings (PostHog) | Per PostHog's default retention (recordings retained for a shorter period than events); deletable on request | Product improvement and usability diagnosis (Section 5d); provider-governed |
| Error events (Sentry) | Per our configured Sentry retention (Sentry standard is 90 days), then deleted | Reliability and debugging (Section 5e); provider-governed |
| Google Calendar data | Event references only, while your Google account is connected; access ends immediately on revocation | Real-time coaching context; see Section 5c |
| Export files | Generated on-demand; not stored server-side | Produced at time of request; no server retention |
| Third-party AI processing (Anthropic) | Up to 30 days for trust and safety | Provider-governed; not Neurow retention |
| Third-party AI processing (OpenAI) | Up to 30 days for abuse monitoring | Provider-governed; not Neurow retention |
| Integration platform proxy (Composio) | Per Composio's published retention policy (see Composio's Trust Center); Neurow does not store integration content beyond what is cached in your Brain Cloud per the source-data rules above | Provider-governed; not Neurow retention. Composio's role is purpose-limited API proxying. |
| Security & integrity records (quarantine/rejection logs; audit ledger) | Your content is crypto-shredded at account deletion; a minimized, content-free integrity marker is retained under a named security/legal-defense basis | GDPR Art. 17(3)(b)/(e); US-state security-integrity + legal-obligation exemptions. Minimized + pseudonymized; access-controlled; no secondary use. |
Principle: We do not retain data beyond its stated purpose. When you delete the source, we delete the derivatives. When you close your account, we delete everything within 30 days.
Account inactivity: If your account has no activity for 24 consecutive months, we will notify you at your registered email before taking any action. If no response is received within 30 days of notification, the account and all associated data will be scheduled for deletion.
12. Sensitive Data
Coaching conversations may include sensitive personal information — health conditions, financial situations, emotional states, relationship dynamics, behavioral patterns related to mental wellbeing. Under GDPR Article 9 and multiple US state laws, behavioral and mood data may constitute special category data requiring heightened protection.
Our approach:
- Explicit consent: Processing of sensitive data requires your explicit consent, obtained separately from general terms acceptance during onboarding. This consent is specific (names the processing activities), informed (explains what will happen), freely given (you may decline or withdraw sensitive data consent without losing access to core coaching functionality), and withdrawable (at any time via Settings).
- Purpose limitation: Sensitive data is used exclusively for coaching delivery and behavioral pattern recognition within your personal Brain Cloud. No secondary use.
- No cross-purpose use: Sensitive data is never used for advertising, profiling for third parties, or any purpose beyond your personal coaching.
- Kept out of analytics: Session replay is expressly configured so that coaching content is never recorded (Section 5d), keeping special-category data out of the product-analytics pipeline.
- Behavioral analysis, not emotion recognition: We analyze patterns in self-reported data — what you tell us about how you feel, what you're working on, what's difficult. We do not perform emotion recognition from biometric data. This distinction matters under the EU AI Act, where emotion recognition from biometric data triggers prohibited or high-risk classification. Self-reported behavioral data does not.
13. Security Architecture
Encryption
- In transit: TLS 1.2+ for all data transmission between your device, Brain Cloud stores, and third-party AI providers
- At rest: AES-256 encryption across all four Brain Cloud stores — Supabase (PostgreSQL-level encryption managed by AWS), Neo4j Aura, Qdrant Cloud, and Mem0 (each encrypted at rest by infrastructure provider)
- Key management: Your written words in our main store are encrypted with a key unique to you. Deleting your account destroys that key.
User Data Isolation
- Per-user scoping across all stores: Every query across all four Brain Cloud stores is scoped to the requesting user's ID. No code path exists to return data belonging to a different user.
- Defense in depth: Application-level user scoping as the primary isolation boundary, with database-level Row-Level Security (RLS) in PostgreSQL providing an additional enforcement layer independent of application logic.
- No cross-account access: There is no mechanism — by design — for one user's session to access another user's Brain Cloud data.
Third-Party Sub-Processors
All third-party processors used by Neurow are evaluated for security posture before integration. Composio (integration platform — Section 5b) is SOC 2 Type II + ISO 27001:2022 certified. PostHog (product analytics — Section 5d) and Sentry (error monitoring — Section 5e) each maintain SOC 2 Type II certification and GDPR-aligned data processing terms. Anthropic and OpenAI (AI providers — Section 5) maintain SOC 2 Type II certification and other industry standards. Our infrastructure providers (Supabase, Neo4j Aura, Qdrant Cloud, Mem0) maintain SOC 2 + GDPR-aligned data processing terms.
Architecture
- Four independent stores with separate access controls, separate authentication, and separate failure domains. A compromise of one store does not automatically grant access to the others.
- No bulk data exposure: Brain Cloud data is retrieved per-query based on the active coaching context. No endpoint exposes a user's complete data store in a single request (the export tool is the deliberate exception, authenticated and user-initiated).
International Data Transfers
Brain Cloud infrastructure is hosted on cloud services based in the United States. If you access Neurow from outside the US, your data will be transferred to and processed in the US. For EEA users, these transfers are governed by Standard Contractual Clauses (SCCs) as implemented by our infrastructure providers.
Breach Notification
In the event of a security breach involving your personal data, we will notify you within 60 days as required by the FTC Health Breach Notification Rule and applicable state breach notification laws. Notification will include: the nature of the breach, the categories of data affected, and the steps we are taking in response. Where required by law, we will also notify the relevant regulatory authorities.
Export Security
- Export is user-initiated only (no automated bulk export)
- Authenticated to the requesting user's session
- Scoped to the requesting user's data
- Export files are generated on-demand and delivered directly to the user's device — not stored server-side
14. Automated Decision-Making and Profiling
GDPR Article 22 governs automated decision-making that produces legal or similarly significant effects. Neurow does not engage in such processing — our advisory architecture (Design Principle #1) means coaching insights inform your thinking without making decisions on your behalf. We disclose our approach to automated profiling below for transparency, and because multiple US states (including Texas, Colorado, and California) require plain-language explanation of profiling activities.
How pattern detection works (plain language): Neurow uses AI to identify patterns in your coaching data. For example, it might recognize that you tend to avoid financial conversations when stressed, that your most productive periods follow consistent morning routines, or that discretionary spending increases in the week after high-stress calendar periods. These patterns are surfaced as coaching observations to help you understand yourself better.
No consequential automated decisions: Neurow advises. You decide. There is no automated approval, denial, scoring, ranking, or determination that affects your rights, opportunities, or access to services. This is not merely a policy — it is an architectural constraint.
Your control:
- View all detected patterns and inferences in the Knowledge Graph view
- Question the basis of any pattern through coaching conversation
- Request correction or deletion of any pattern you believe is inaccurate
- Opt out of behavioral pattern detection entirely via Settings
15. Data Protection Impact Assessment
Given the sensitive nature of coaching data and behavioral pattern processing, a formal Data Protection Impact Assessment will be completed prior to production launch, as contemplated by GDPR Article 35 for high-risk processing. Our preliminary assessment identifies the following areas of focus: the necessity and proportionality of behavioral pattern processing for coaching delivery; risks to data subjects from inference generation; safeguards (user transparency via the Knowledge Graph view, hard deletion across all stores, granular consent mechanisms, advisory architecture); and third-party AI processing data flows, retention policies, and scope limitations.
Neurow maintains records of its data processing activities as contemplated by GDPR Article 30, including the purposes of processing, categories of data subjects, categories of personal data, and retention timelines.
16. Children
Neurow is designed for adults. You must be 18 years or older to use Neurow. We do not knowingly collect data from anyone under 18. Age verification is self-reported during onboarding, consistent with industry practice for non-child-directed services. If we learn that we have collected data from a minor, we will delete it promptly.
17. Changes to This Policy
We will notify you directly of any material changes to this policy before they take effect. We do not quietly adopt more permissive data practices. If we ever change our position on AI training, data sharing, retention, or the scope of data portability, you will be informed explicitly and asked for fresh consent before any change takes effect.
This policy is reviewed quarterly and updated as necessary.
18. Contact
Neurow, Inc., a Delaware corporation
Austin, TX, United States
For privacy questions, data access requests, deletion requests, or to exercise any right described in this policy, contact our Privacy Lead: hello@neurow.io
Governing law: This policy is governed by the laws of the State of Texas, United States, without regard to conflict of law principles. For EEA residents, nothing in this policy limits your rights under applicable EU data protection law.