NeuroHub Compass

AI policy

Version 1.0Updated 8 October 2026Applies in the UK and the European Union

This policy explains how NeuroHub Compass uses artificial intelligence (the Phoenix companion), what happens to the things you tell it, and the rights you have under the UK GDPR, the Data Protection Act 2018 and the EU GDPR. It is written in plain words. Our privacy page covers the rest of the service. How NeuroHub uses AI in everything else it does is in the NeuroHub AI Policy.

At a glance

1. About this policy

Who we are. NeuroHub Compass is made and run by NeuroHub Community Ltd (“NeuroHub”, “we”, “us”). For the personal data described below, NeuroHub is the data controller, and NeuroHub Community Ltd is registered with the Information Commissioner’s Office (ICO), registration reference ZC088866.

What it covers. The web app at the NeuroHub Compass address and the installed app, including the Phoenix companion that floats beside the app, Phoenix’s chat, voice, memory notes, document drafting and the daily ideas.

Laws it follows. The UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) and, for people in the European Economic Area, the EU GDPR. We also follow the transparency duties of the EU AI Act (Regulation 2024/1689) as they apply to a service like this.

2. What the AI is and is not

Phoenix helps you think things through, talk about your check-ins, use tools such as breathing and grounding, and draft documents. It is a companion for reflection and learning, built on knowledge written by NeuroHub and by authors who have given permission, credited by name when used.

Phoenix is not

If you are in danger, call your local emergency number (999 in the UK, 112 in the EU). In the app, the red Help button shows helplines for your country.

3. How the AI works

Phoenix has two ways of answering you, and you can switch at any time in Settings.

Built-in helper

Answers come from rules and writing stored in the app. It runs entirely on your device and works offline. Nothing you type leaves your device.

Phoenix AI

  1. You send a message. The app adds Phoenix’s instructions and, where relevant, short reference extracts, the memory notes you have chosen to keep and, only if you have allowed it, a short numbers-and-notes summary of your recent check-ins.
  2. That bundle goes to NeuroHub’s server, which checks that you are signed in, that your licence allows it and that it is a genuine Phoenix request, and then forwards it to Anthropic’s Claude model.
  3. The reply streams straight back to you. NeuroHub does not store or log your messages or the replies. We keep only anonymous counters and a hashed record of how many replies your account has used, to apply the limits.
  4. Only the most recent part of the conversation is sent, up to a fixed length.

What the AI is not allowed to do

Automated safeguards

Some checks run on your device before and after the AI: spotting words that suggest a crisis, handling questions about medicines with a careful built-in answer, and checking that helpline numbers in a reply are the verified ones. These protect you. They do not produce any decision about you that has legal or similarly significant effects, so Article 22 of the GDPR (automated decision-making) does not apply.

4. Limits on Phoenix AI

Every reply costs NeuroHub money, so there are limits, and they follow your licence: a fair daily allowance while you are making your six payments; 10 replies each calendar month after you own the app; and the daily allowance again for as long as you keep the optional AI add-on. If you have no active licence, Phoenix AI is off and the built-in helper answers. There are also daily and monthly limits for everyone together as a last line of defence. We may pause Phoenix AI at any time. The built-in helper, the Toolkit and the safety tools are never limited.

5. Data we handle and why

PurposeDataLawful basis (UK and EU GDPR)Who sees it
Phoenix AI repliesThe messages you send, Phoenix’s instructions, reference extracts, any memory notes you have kept, and (if you allow it) a short check-in summaryArticle 6(1)(b), providing the service you bought. For any health details you choose to type, or allow Phoenix to read, Article 9(2)(a), your explicit consentAnthropic as our processor, for the moment it writes the reply. NeuroHub does not keep the content
Check-ins, notes, documents, settingsEverything you create in the appOn your device. If you keep sync on, Article 6(1)(b) and Article 9(2)(a), explicit consent given by turning sync onYou. NeuroHub staff do not read synced data, which is encrypted with a key only the server holds
AccountA one-way fingerprint of your email addressArticle 6(1)(b)NeuroHub systems only. Brevo sends the sign-in code
Licence and paymentsThe account fingerprint, payments made, plan status, Stripe reference numbers, amounts, and the version of the terms agreed. Your email address and card are held by Stripe, not NeuroHubArticle 6(1)(b), and Article 6(1)(c) for accounting recordsStripe as a payment processor. NeuroHub sees status and amounts
Usage numbers on your accountDays the app was used, check-ins done per day, streak, ideas opened. Numbers only, never contentArticle 6(1)(f), our legitimate interest in running and improving the serviceAuthorised NeuroHub admins, as totals on a dashboard
Memory notesShort notes Phoenix keeps about you, which you can view, edit, switch off and deleteArticle 6(1)(a), your consent, which you give by leaving notes switched onYou. The notes go to Anthropic with a message so Phoenix can use them
Optional sharing of check-in scoresThe date, seven numbers from 1 to 5 and a random ID made on your deviceArticles 6(1)(a) and 9(2)(a), explicit consent. Off until you turn it on. 16 and over onlyAuthorised NeuroHub admins, as group results only (never for fewer than five people)
Limits and abuse preventionA hashed account reference and a counterArticle 6(1)(f), our legitimate interest in stopping abuse and keeping the service affordableNeuroHub systems only
Anonymous usage countsDaily totals, coarse device type, country code, referring site. No cookies, no identifierArticle 6(1)(f). You can switch it off. We honour Do Not Track and Global Privacy ControlAuthorised NeuroHub admins
Security and legal dutiesTechnical logs held by our host, and information needed to respond to a legal requestArticle 6(1)(f) and Article 6(1)(c)Our host. Authorities where the law requires

What we never do. We do not sell personal data, use it for advertising, or build marketing profiles.

6. Health and other sensitive information

Check-ins and conversations can touch on health, neurotype and other special category data, so we treat all of it with extra care. You choose what to write, and the app never needs you to type health details to work. By default, your check-ins are not sent to the AI. After a crisis conversation Phoenix does not write memory notes. Because this is a wellbeing tool that handles health information, we are completing a Data Protection Impact Assessment (DPIA) for it, and we will review it at least every six months and whenever these features change.

7. Who receives data

ProviderRoleWhat it receives
AnthropicProcessor. Runs the Claude model that writes Phoenix AI repliesThe content of a Phoenix AI request, at the moment you send it
NetlifyProcessor. Hosts the website, the app, the server functions and the encrypted account storeOrdinary server data such as IP addresses in short-lived logs, and encrypted account data
BrevoProcessor. Sends the one-time sign-in code by emailYour email address, at sign-in, so the code can be delivered
StripeProcessor (and independent controller for its own legal duties). Takes the payments and tells NeuroHub Compass whether your plan is activeYour email address and payment details, entered on Stripe’s own page, and your account’s anonymous fingerprint
Your browser vendor (Google or Microsoft)Independent. Turns speech into text if you use voice in Chrome or EdgeAudio from your microphone while listening. This happens in your browser, not through NeuroHub

We do not give personal data to anyone else, except where the law requires it. Results we may publish about wellbeing are combined and anonymous, and are never shown for fewer than five people.

8. Transfers outside the UK and the EEA

Anthropic, Netlify, Brevo and Stripe may process data outside the UK and the European Economic Area, including in the United States. Where they do, we rely on an adequacy decision or the UK–US and EU–US data bridge arrangements where the provider is certified, or the standard contractual clauses approved by the European Commission together with the UK International Data Transfer Addendum. You can ask us for a copy of the safeguards in use.

9. Keeping and deleting data

DataHow long
Phoenix AI messages and repliesNot kept by NeuroHub. They pass through and are discarded
Data on your deviceUntil you delete it in Settings or clear your browser data
Account dataUntil you delete your account. Deleting is permanent, removes all synced data and ends your licence
Saved data after payments stop earlyKept read-only for 30 days so you can download, delete or carry on, then permanently deleted. A daily job removes it even if you never return
Payment records and amountsAs long as the law requires for accounting, usually six years. Stripe keeps payment records for as long as the law requires
Usage numbers on your accountWhile the account exists
Reported repliesUntil reviewed, and no longer than one year. Only the reply, the reason and your note are kept, with nothing that identifies you
Shared check-in scoresUntil you withdraw and delete them, and no longer than two years
Limit countersDays to one month
Anonymous usage totalsAs totals, for as long as they are useful. They contain nothing about you

10. Your rights

Under the UK GDPR and the EU GDPR you have these rights. Most you can use yourself in Settings. For the rest, contact us. We reply within one month and do not charge, unless a request is clearly unfounded or excessive.

Be informedThis policy and our privacy page.
AccessDownload everything held about you in Settings.
CorrectEdit your notes, documents and settings.
EraseDelete your data or account in Settings.
Restrict or objectSwitch off the AI, notes or counting.
Take it with youExport in a common format.
Withdraw consentAt any time, as easily as you gave it.
Human involvementNo solely automated decisions are made about you.

Because your email address is not stored, we may ask you to sign in to show that an account is yours before we act on a request about it.

11. Safety and limits

12. Fairness, accuracy and transparency

13. How we govern it

14. Age

NeuroHub Compass is designed for adults. An account and the licence are for people aged 18 and over. If we learn that we hold data from someone below that age, we will delete it.

15. Contact and complaints

NeuroHub Community Ltd. For questions, to use a right, or to report an AI reply that went wrong, write to enquiries@neurohubcommunity.org or use the form at neurohubcommunity.org/contact-us. Please include “NeuroHub Compass” in the subject line. If you are unhappy, please tell us first and we will try to put it right. You can also complain to a data protection authority at any time.

Quick questions

Does NeuroHub read my check-ins or chats?

No. They are on your device. With Phoenix AI, a chat message passes through our server to Anthropic and is not stored or logged by us. If you keep sync on, your data is encrypted and staff cannot read it. The dashboard shows numbers only.

Is my data used to train AI?

No. NeuroHub does not train models, and Anthropic’s commercial terms do not allow it to train on API content by default.

Can I use it with no AI at all?

Yes. Choose the built-in helper in Settings. It works offline and sends nothing anywhere. The check-in, the daily ideas, your trends and the Toolkit never need the AI.

What happens if the AI says something harmful?

Tell us, or press Report under the reply. We review it, fix the cause and, if needed, pause Phoenix AI. Safety checks also run on your device independently of the AI.

Changes to this policy

Version 1.0, 8 October 2026, was the first version. When we make a material change we will update the date and version, show a notice in the app, and keep earlier versions available on request.