Your data,
your control

We collect what we need to run NeuralFields AI, nothing else. We never train on your prompts, and we never sell your data.

Last updated: May 1, 2026

This policy explains what data NeuralFields AI ("we", "us") collects when you use our gateway, dashboard, and APIs, how we use it, and the choices you have. We've tried to write it the way we'd want to read it - plainly, and without lawyer-grade clauses where we can avoid them.

1. Information we collect

We collect only what we need to operate NeuralFields AI and bill you accurately.

Account data: name, work email, company, and authentication identifiers when you sign up or sign in with a third-party provider.

Workspace and usage data: API keys you create, project names, request metadata (timestamps, model, token counts, latency), and aggregate spend metrics.

Billing data: payment instrument details handled by our PCI-compliant payment processor - we never store full card numbers on our servers.

Prompt and response content: the prompts and completions routed through our gateway are processed in memory to deliver your response. We do not log full prompt or response bodies by default. You can opt in to request-level logging from Workspace → Settings if you want a longer-lived audit trail.

Device and log data: IP address, user agent, and minimal diagnostic logs needed to detect abuse and keep the service healthy.

2. How we use your information

Deliver the service: authenticate you, route requests, enforce rate and budget limits, and return responses.

Billing and accounts: meter token usage, generate invoices, and handle plan changes or refunds.

Service health: detect outages, fight abuse, and improve reliability with aggregate metrics.

Product communications: send transactional emails (receipts, security alerts, expiring keys) and - only if you opt in - product updates.

We do not train models on your prompts or responses. Ever.

3. How we share information

AI providers: when you route a request to Claude, GPT, Gemini, Mistral, or a self-hosted endpoint, we forward the prompt to that provider on your behalf. Each provider operates under its own policies - we honor zero-retention modes where available.

Infrastructure subprocessors: cloud hosting, payment processing, transactional email, and error tracking. A current list is available on request from privacy@neuralai.io.

Legal compliance: if compelled by a valid legal request, we will disclose the minimum information necessary and notify you unless legally prohibited.

We do not sell your data. We do not share it for advertising. We do not allow third-party tracking on the dashboard.

4. Security

Encryption in transit (TLS 1.2+) and at rest (AES-256) for all customer data we store.

Least-privilege access controls, hardware-key enforced SSO for our team, and audit logs on all production access.

Quarterly penetration tests and continuous vulnerability scanning. SOC 2 Type II report available under NDA for Enterprise customers.

No security system is perfect - if you believe you have found a vulnerability, please report it to security@neuralai.io.

5. Your rights

Access and export: download your usage history and account data from Workspace → Settings, or email us.

Correction: update your account, billing, and workspace details directly in the dashboard.

Deletion: delete a workspace at any time. Account-level data is purged within 30 days of request, except where retention is required for tax, accounting, or fraud prevention.

Objection and restriction: residents of the EU, UK, and California have additional rights under GDPR and CCPA - contact privacy@neuralai.io to exercise them.

We will not discriminate against you for exercising any of these rights.

6. Data retention

Request metadata (no prompt bodies): 90 days for usage dashboards, then aggregated.

Opt-in request logs: retained for the period you configure in your workspace, with a default ceiling of 30 days.

Billing records: kept for 7 years to meet tax and accounting obligations.

Account data: deleted within 30 days of closing your account, except where law requires longer retention.

7. International transfers

NeuralFields AI is operated from the United States, with regional processing available for Enterprise customers in the EU and APAC.

When data leaves your home region we rely on Standard Contractual Clauses or an equivalent transfer mechanism approved by the relevant authority.

8. Cookies and analytics

We use a small set of first-party cookies that are strictly necessary to keep you signed in and to remember your dashboard preferences.

We use privacy-respecting product analytics (no third-party trackers, no cross-site profiling) to understand which features are used. You can opt out from Workspace → Privacy.

9. Children

NeuralFields AI is not directed at children under 16 and we do not knowingly collect data from them. If you believe a child has provided us with personal information, contact privacy@neuralai.io and we will delete it.

10. Changes to this policy

When we make material changes we will notify account owners by email at least 30 days before the change takes effect. The "last updated" date at the top of this page always reflects the current version.

11. Contact us

Privacy and data requests: support@neuralfields.app

Security reports: support@neuralfields.app

General questions: support@neuralfields.app

Questions about your data?

Our team responds to privacy requests within two business days.

NeuralFields