Privacy Policy

Last updated: September 13, 2026 · Effective: September 13, 2026

Neurojourney, Inc. ("Neurojourney", "we", "us") is the controller of personal information processed through Neutropic — the web app at neutropic.io, the desktop and mobile apps, the API and the documentation (the "Service"). This Privacy Policy explains what we collect, why, how long we keep it, who we share it with, and the rights you have. It is written to meet the Personal Information Protection Act of the Republic of Korea (PIPA), the EU/UK GDPR and the California Consumer Privacy Act (CCPA).

1. Information we collect

  1. 1.1
    Account information — email address, authentication identifiers and, if you sign in with Google, the name, profile picture and Google account ID Google provides. Optional profile fields you enter (display name, role, instructions for the agent).
  2. 1.2
    Content you provide — files you upload, prompts and messages, project memory, connector imports, and the artifacts the Service generates from them (reports, tables, figures, manuscripts, code). Contact-form messages and support email you send us.
  3. 1.3
    Billing information — plan, subscription status, invoice and transaction identifiers, country and tax status received from Paddle. We never receive or store full card numbers.
  4. 1.4
    Usage and technical data — tokens and credits used per turn and per model, feature usage, artifact and storage metadata, error and audit logs, IP address, browser/OS and app version, the client kind (web, desktop, iOS, Android) and, in the mobile app, the push-notification device token you allow.
  5. 1.5
    Connector data — when you connect Google Drive or enter platform credentials, the OAuth tokens or API tokens (stored encrypted) and the files you or the agent, with your approval, retrieve.
  6. 1.6
    Consents — the time and version of the Terms and this Policy you accepted, and whether you opted in to marketing email.
  7. 1.7
    Docs assistant — questions typed into the documentation assistant are sent to a model provider together with documentation excerpts; they are not linked to an account.
  8. 1.8
    We do not intentionally collect special categories of personal data (health, biometric, genetic, sexual, political, religious or similar data). Research data you upload may contain such data about your participants; you are responsible for having the lawful basis and consents to process it, and we process it only as your service provider under Section 3.

2. Why we use it and our legal bases

  1. 2.1
    To provide the Service you asked for — authenticate you, run your requests, store your workspace, sync across devices and send notifications (performance of a contract; PIPA Art. 15(1)4).
  2. 2.2
    To bill and account for usage — enforce credits, caps and quotas, process payments through Paddle, and keep tax and accounting records (contract; legal obligation).
  3. 2.3
    To keep the Service secure and reliable — detect abuse, rate-limit, investigate incidents, audit administrator access, and debug errors (legitimate interests in security and service quality; legal obligation).
  4. 2.4
    To communicate with you — transactional emails (sign-up confirmation, billing, security), responses to your inquiries, and, only with your opt-in consent, product news and marketing email, which you can withdraw at any time via the unsubscribe link or by contacting us (consent).
  5. 2.5
    To improve the Service — aggregate, de-identified usage analytics (Vercel Analytics on the marketing site; internal usage metrics in the app). We do not use Your Content to train machine-learning models (legitimate interests).
  6. 2.6
    To comply with law — respond to lawful requests, exercise or defend legal claims, and meet record-keeping duties (legal obligation).

3. Your research data

  1. 3.1
    Web app: files you upload and the artifacts produced from them are stored in your private account workspace and processed on our servers to run the analysis. Working copies used by the analysis sandbox are cached for up to 14 days and rebuilt on demand.
  2. 3.2
    Desktop app: raw files are read on your computer only and are never uploaded to Neutropic. The desktop helper sends the model only the observations it needs (for example descriptive statistics or a figure), and artifacts created on your device stay there unless you upload them.
  3. 3.3
    Model providers: content the model must see — your prompt, relevant excerpts of uploads or artifacts, tool results — is sent to the AI model provider you selected (Google, Anthropic or OpenAI) to generate the answer. Providers process it under agreements that prohibit using it to train their models and limit retention to abuse monitoring. Projects you mark as sensitive are restricted to local models and never sent to cloud providers.
  4. 3.4
    Your Content is never sold, never used for advertising and never used to train our or anyone else's models.

4. Google user data (Google Drive connector)

  1. 4.1
    If you connect Google Drive in Customize → Connectors, Neutropic requests the following Google OAuth scopes: https://www.googleapis.com/auth/drive (see, edit, create, and delete all of your Google Drive files), openid, and email (your Google account identifier and email address). Access is granted only after you approve Google's consent screen, and you can revoke it at any time from the Service (Disconnect) or from your Google Account permissions page (https://myaccount.google.com/permissions).
  2. 4.2
    • Why we need these scopes
    • the agent uses them, only at your direction, to search and list files, read or import documents and data into your project, create or update files you ask for, copy files, share files, and move files to the trash.
    • Full Drive access is required because these actions apply to files you already own, not only to files created by Neutropic.
    • Every tool starts as "Ask each time": the agent cannot run a tool until you approve it in the chat, and you can set any tool to always allow or block.
  3. 4.3
    • How we handle Google user data
    • OAuth tokens are stored encrypted on our servers and are never sent to your browser or to third parties.
    • File contents are retrieved only when you, or the agent with your approval, request them; files you import are kept in your project space like any other upload.
    • We do not use Google user data for advertising, do not sell it, and do not use it to train AI models.
    • Google user data is shared with an AI model provider only when you choose a cloud model and the agent needs the content to complete your request.
    • Tokens are deleted when you disconnect the connector or delete your account.
  4. 4.4
    Neutropic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

5. Who we share it with (processors and transfers)

  1. 5.1
    We do not sell personal information and do not share it for cross-context behavioural advertising. We share it only with processors that act on our instructions under data-processing agreements, each receiving only what its function requires: Supabase, Inc. (USA — authentication, database and file storage), Railway Corp. (USA — API hosting and the analysis sandbox), Vercel, Inc. (USA — website hosting, edge network and privacy-preserving analytics), Paddle.com Market Ltd. (UK — payments, invoicing, tax; Paddle is an independent controller for its own purchases records), Resend, Inc. (USA — transactional and, with consent, marketing email), Google LLC, Anthropic PBC and OpenAI, L.L.C. (USA — AI model inference for the model you select; the docs assistant uses Google), Google LLC (OAuth and Google Drive, only when you connect them), and Apple / Google push services (mobile notifications).
  2. 5.2
    Cross-border transfers: we operate from the Republic of Korea and the processors above are located mainly in the United States and the United Kingdom, so your personal information is transferred and stored outside Korea, and for EEA/UK users outside the EEA/UK. We rely on data-processing agreements with standard contractual clauses (and the UK Addendum) and on the processors' security certifications, and we transfer only what the function requires. Items transferred: account, content, billing, usage and connector data as described in Section 1; time and method: continuously over encrypted connections while you use the Service; retention: as in Section 6. You can object to a transfer by not using the relevant feature or by contacting us, understanding that the Service cannot be provided without its core processors.
  3. 5.3
    We may also disclose information to comply with law, to enforce our Terms, to protect the rights and safety of users or the public, or in a merger, acquisition or asset sale (with notice to you). We do not disclose personal information to third parties for their own purposes without your consent.

6. How long we keep it

  1. 6.1
    Account and profile: until you delete your account, then removed from live systems within 30 days and from backups within 90 days.
  2. 6.2
    Your Content (uploads, artifacts, memory): until you delete the item or your account (same schedule); sandbox working copies up to 14 days.
  3. 6.3
    Billing and tax records: 5 years after the transaction (Korean Act on Consumer Protection in Electronic Commerce and tax law); consumer-complaint records 3 years.
  4. 6.4
    Usage, security and audit logs: 12 months; access logs (IP, time) at least 3 months as required by Korean law. Contact-form and support messages: 3 years.
  5. 6.5
    • Connector tokens: until you disconnect or delete your account.
    • Consent records: 5 years after withdrawal or account deletion.
    • Docs-assistant questions: not stored by us beyond the request; provider retention applies.
  6. 6.6
    When retention ends we permanently delete or irreversibly anonymize the data: electronic files are erased so they cannot be restored, and any paper records are shredded.

7. Your rights

  1. 7.1
    You may access, correct, export (portability), delete or restrict your personal information, object to processing based on legitimate interests, withdraw consent (for example to marketing email) at any time without affecting prior processing, and — for account deletion — do it yourself under Customize → General. Requests can be sent to contact@neurojourney.ai; we verify your identity, respond within 10 days (PIPA) or one month (GDPR), and do not charge a fee unless requests are manifestly unfounded or excessive. An authorized representative may act for you with written authority.
  2. 7.2
    If you are in the EEA or UK, you may also lodge a complaint with your supervisory authority (for example the Irish Data Protection Commission or the UK ICO). California residents have the rights to know, delete, correct, and to opt out of sale or sharing (we do not sell or share), and will not be discriminated against for exercising them. Residents of the Republic of Korea may contact the Personal Information Dispute Mediation Committee (privacy.kisa.or.kr, 1833-6972), the KISA Privacy Call Centre (privacy.kisa.or.kr, 118) or the police cybercrime unit (ecrm.police.go.kr, 182).
  3. 7.3
    Research participants: if your data was uploaded by a Neutropic user (for example a researcher), that user is the controller of it and we process it as their service provider. Please direct requests to them; we will assist them in responding.

8. Cookies, local storage and analytics

  1. 8.1
    We use strictly necessary cookies and browser local storage to keep you signed in (Supabase auth tokens), remember your language, theme and composer settings, and protect against cross-site request forgery. The marketing site uses Vercel Analytics, which counts page views without cookies and without identifying individuals. We do not use advertising cookies or third-party tracking pixels. You can block or delete cookies in your browser; the Service may not work correctly without the necessary ones.

9. Security

  1. 9.1
    We protect personal information with encryption in transit (TLS) and at rest, encrypted storage of connector tokens, row-level access controls, least-privilege and audited administrator access, isolated code-execution sandboxes, secret management, monitoring and regular dependency updates. Access to production data is limited to staff who need it. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you and the competent authorities as required by law (in Korea within 72 hours of becoming aware).

10. Children

  1. 10.1
    The Service is intended for adult researchers and students. We do not knowingly collect personal information from children under 14 (Republic of Korea), under 16 (EEA/UK) or under 13 (USA). If you believe a child has provided us information, contact us and we will delete it.

11. Changes to this policy

  1. 11.1
    We may update this Policy as the Service or the law changes. We will post the updated version on this page with a new effective date and, for material changes, notify you by email or in the Service at least 7 days in advance (30 days where the change reduces your rights). Previous versions are available on request.

12. Privacy officer and contact

  1. 12.1
    • Controller: Neurojourney, Inc., 6064, 6F, Nuri Dream Square, 396 World Cup buk-ro, Mapo-gu, Seoul, Republic of Korea. Privacy officer (개인정보 보호책임자): Hyunwoo Lee, Chief Executive Officer
    • contact@neurojourney.ai.
    • For EEA/UK users, the same contact acts as our point of contact for data-protection matters.
    • We answer privacy inquiries, complaints and requests for remedy at this address.