Privacy policy
This policy explains what personal data Neura AI collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to the Neura AI application and to this website.
Last updated: 23 September 2026
1. Who we are
Neura AI is a product of NeuraFort Group Inc., registered in Delaware, United States (“we”, “us”, “our”). We are the data controller for personal data described in this policy, except where we process data on behalf of a customer. In that case the customer is the controller and we act as their processor.
We operate with NeuraFort Group Limited, a group company registered with the Corporate Affairs Commission (CAC) of Nigeria, which provides engineering, product and customer support services. Personal data may be processed by that group company under the same contractual and security controls described in this policy.
For any privacy question, to exercise your rights, or to raise a complaint, contact hello@myneuraai.com.
2. Data we collect
We collect the following categories of data:
- Account data: name, work email address, password credentials, company name, role, and billing details for paid plans.
- Connected content: the website pages, documents, database records, calendar entries and messages you choose to connect so Neura AI can learn your business and answer questions about it. This may include personal data about your own clients and staff.
- Conversation data: messages exchanged with Neura AI, including those arriving through your website widget, WhatsApp or Telegram, and the responses and actions it produces.
- Usage and device data: pages viewed, features used, timestamps, browser and device type, IP address and the approximate location derived from it.
- Support and enquiry data: the content of messages you send us, and records of our correspondence.
We do not intentionally collect special category data (such as health, biometric or political data). If your connected content contains it, it is processed only as part of delivering the service to you and under your instructions as controller.
3. How and why we use it
We use personal data to provide and operate Neura AI, and for no incompatible purpose:
- To deliver the service: answering questions, capturing and qualifying enquiries, booking meetings, retrieving knowledge and running the workflows you configure.
- To operate accounts and billing: authentication, support, invoicing, and service communications about your account.
- To secure and improve the service: diagnosing faults, monitoring for abuse, and understanding which features are used in aggregate.
- To comply with the law: meeting accounting, tax and regulatory obligations, and responding to lawful requests.
- To send marketing: only where you have opted in or where permitted for existing customers, and always with an unsubscribe link.
We do not sell personal data. We do not use your connected content or conversations to train foundation or generalised AI models.
4. Our legal bases
We are based in the United States and serve customers internationally, so more than one privacy regime can apply to the same data. Where the EU GDPR, the UK GDPR or Nigeria's data protection law applies, we rely on the following legal bases:
- Contract: to provide the service you have signed up for, operate your account and take payment.
- Legitimate interests: to keep the service secure, prevent abuse, improve the product, and market to business customers, balanced against your rights and freedoms.
- Consent: for non-essential cookies, for optional marketing, and when you authorise a third-party connection such as a Google account. You can withdraw consent at any time.
- Legal obligation: where we must retain or disclose data to comply with the law.
Nigeria's Data Protection Regulation (NDPR) and Data Protection Act provide equivalent lawful bases of contract, consent, legal obligation and legitimate interest, and we rely on them in the same way.
United States privacy law, including the California Consumer Privacy Act as amended by the CPRA, works differently: rather than requiring a legal basis before processing, it gives consumers rights over data already collected. Those rights are set out in section 10.
5. Google user data
If you connect a Google account, Neura AI requests only the scopes needed for the features you enable, and uses that access solely to provide those features to you. You see the scopes requested on Google's own consent screen before anything is connected.
- Gmail: to read and send messages on your behalf, so Neura AI can follow up on enquiries, draft replies you approve, and file correspondence against the right client. Message content is used only to produce your results.
- Google Calendar: to read availability and create, update or cancel events, so meetings booked by Neura AI land on the right calendar without double-booking.
- Google Drive: to read the files and folders you specifically select, so Neura AI can answer questions grounded in your own material rather than guessing.
Neura AI's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained through Google APIs is not:
- used to develop, improve or train generalised or foundation AI/ML models;
- transferred or sold to third parties for advertising, resale, credit assessment or any similar purpose;
- used for serving advertisements of any kind;
- read by any human, except where you give explicit consent for specific messages, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
Google data is retained only for as long as needed to provide the feature you enabled. You can disconnect a Google account at any time from your Neura AI settings, or revoke access directly at myaccount.google.com/permissions. Revoking access stops all further syncing immediately; copies already held are deleted in line with section 8.
6. Sharing and sub-processors
We do not sell personal data or share it for independent use. We share it with service providers who process it on our behalf, under written contracts that limit them to our instructions and require appropriate security:
- Cloudflare: Application hosting, content delivery, DNS and DDoS protection. Processing location: Global edge network.
- Google Cloud: Application infrastructure, databases and encrypted backups. Processing location: United States and European Union.
- AI model providers: Generating responses, summaries and classifications from the content you connect. Processing location: United States and European Union.
- HubSpot: Customer relationship management and marketing communications. Processing location: United States and European Union.
- NeuraFort Group Limited: Group company providing engineering, product and customer support services. Processing location: Nigeria.
We may also disclose personal data where required by law or valid legal process, to establish or defend legal claims, or to a successor entity in connection with a merger, acquisition or sale of assets, in which case we will tell affected customers.
7. International transfers
We are established in the United States and operate with a group company in Nigeria, so personal data is transferred internationally as a normal part of running the service.
Where data is transferred out of the European Economic Area or the United Kingdom, we rely on an approved transfer mechanism, either an adequacy decision where one applies, or Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment and technical measures including encryption in transit and at rest. Transfers to NeuraFort Group Limited are covered by intra-group agreements on the same terms.
8. Retention and deletion
We keep personal data only as long as we need it for the purposes in this policy:
- Connected content and conversations: for the retention window you configure. You can delete individual items, or all of your data, at any time from within the application.
- Account data: for as long as your account is open, then deleted or irreversibly anonymised within 30 days of closure.
- Billing records: for as long as tax and accounting law requires, typically six years.
- Encrypted backups: purged on their normal rotation cycle after deletion from live systems.
9. Security
We protect personal data with measures appropriate to the risk, including encryption in transit and at rest, role-based access scoped to what each user and integration needs, least-privilege access for our own staff, audit logging of actions taken in the application, tenant isolation between customers, and regular patching and dependency review.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.
10. Your rights
Subject to the conditions in the applicable law, you have the right to access your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to processing, including objecting to direct marketing at any time; to receive your data in a portable format; and to withdraw consent where we rely on it. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
These rights are available under the EU GDPR and the UK GDPR, and for individuals in Nigeria under the Nigeria Data Protection Regulation and the Nigeria Data Protection Act, which provide equivalent rights of access, rectification, erasure, objection and portability.
United States residents. Depending on your state, you may have the right to know what personal information we collect and the purposes we use it for; to request a copy of it; to request deletion; to request correction; to opt out of the sale or sharing of personal information and of targeted advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these rights. California residents have these rights under the CCPA as amended by the CPRA, and residents of states including Virginia, Colorado, Connecticut, Utah and Texas have comparable rights under their own statutes.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. You may use an authorised agent to submit a request on your behalf, and we will verify the request before acting on it. If we decline a request we will tell you why, and you may appeal by replying to our response.
To exercise any right, email hello@myneuraai.com. We will respond within one month, and will tell you if we need longer because the request is complex. We do not charge a fee unless a request is manifestly unfounded or excessive.
If we process your data on behalf of a customer of ours, we will refer your request to that customer and support them in answering it.
11. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at hello@myneuraai.com so we can put it right. You also have the right to complain to the regulator for your region:
- Nigeria: the Nigeria Data Protection Commission (NDPC).
- United Kingdom: the UK Information Commissioner's Office (ICO).
- European Economic Area: your national data protection authority in the EEA.
- United States: your state Attorney General.
12. Cookies and similar technologies
We use strictly necessary cookies to run the site and keep you signed in. These do not require consent. We use analytics cookies to understand how the site is used, and marketing cookies where you have agreed to them; both are set only with your consent and can be withdrawn at any time through your browser settings.
This website uses Vercel Web Analytics and Vercel Speed Insights to measure page views and loading performance. Both are cookieless and neither identifies individual visitors, so they run without a consent prompt. They record aggregate information such as the page visited, the referring site, and the country and device type derived from your request.
13. Children
Neura AI is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact hello@myneuraai.com and we will delete it.
14. Changes to this policy
We may update this policy as the product and the law change. We will update the date at the top of this page, and where a change materially affects your rights we will tell you directly before it takes effect. See also our terms of service.