Privacy
NeuroHub Compass is a place to check in with yourself, so we have built it to know as little about you as possible. This page says what we hold, what we do not, and why. How the AI part works, and your rights in full, are in the AI policy.
The short version
- We do not store your email address. We use it once to send you a sign-in code, and keep only an unreadable fingerprint of it.
- What you write and how you rate things is stored on your device, and in your account if you keep it in sync, where it is scrambled with a key only our server holds. NeuroHub staff do not read it.
- The dashboard NeuroHub sees is numbers only: how many people have accounts, how many are paying, on which days the app was used, and how many check-ins were done. It never shows what you wrote or how you rated anything, unless you choose to share your scores anonymously in Settings (off until you turn it on).
- We do not sell data, show adverts, or build marketing profiles. There are no advertising or tracking cookies.
What we hold, and why
| What | Why we hold it | Legal basis |
|---|---|---|
| A fingerprint of your email address | To find your account when you sign in, without keeping your address | Contract (providing the service you bought) |
| Your licence: how many of the six payments have been made, whether the plan is active or has ended, Stripe’s reference numbers, the version of the terms you agreed to, and amounts for our accounts | To know what you may use, to keep accounting records, and to deal with refunds | Contract, and legal obligation (keeping accounting records, usually for six years) |
| Your synced data: check-ins, notes you write, documents, settings, chats and what Phoenix remembers (only if you keep sync on) | So that your history follows you between devices. It is encrypted before it is stored | Contract. Where it contains health information, your explicit consent, which you give by turning sync on |
| Usage numbers on your account: the days the app was used, how many check-ins you did each day, your streak, and how many daily ideas you opened | So that we can count how many people use NeuroHub Compass and see whether it helps people stay with it. Numbers and dates only, never what you wrote or how you rated anything | Our legitimate interest in running and improving the service |
| Anonymous counts: page views, clicks on the start button, app opens, which parts of the app are used. Daily totals with no identifier | To see how people find and use the app | Our legitimate interest. You can switch it off in Settings. We honour Do Not Track and Global Privacy Control |
| Phoenix AI messages | Passed through our server to Anthropic’s Claude to write a reply. We do not store or log them. See the AI policy | Contract, and consent for any health detail you choose to type |
| If you choose: your check-in scores shared anonymously | Off until you turn it on. Seven numbers and a date, with a random ID, for 16 and over. Shown only as group results of five or more | Explicit consent, which you can withdraw and delete at any time |
Payments
Payments are handled by Stripe. You enter your card on Stripe’s own page and we never see or store it. Stripe holds your email address and payment details as a processor, under its own privacy notice. The link to pay carries your account’s anonymous fingerprint, not your email address. Stripe tells us only that a payment was made, failed, was refunded or that your plan ended, with Stripe’s reference numbers and the amounts.
Who else receives data
- Stripe, to take payments (see above).
- Brevo, to email your sign-in code. It receives your email address at that moment.
- Netlify, which hosts the website, the app and the encrypted account store. Like any host it may keep ordinary server logs (such as IP addresses) for a short time for security and operation.
- Anthropic, whose Claude model writes Phoenix AI replies. It receives the content of a request at the moment you send it.
- Your browser vendor (Google or Microsoft), if you use voice in Chrome or Edge: your browser sends what the microphone hears to them to turn it into text. Phoenix does not record or keep audio.
Some of these providers process data outside the UK. We use safeguards such as the UK–US data bridge or the standard contractual clauses. Details are in the AI policy.
How long we keep things
- Your account and synced data: until you delete your account. Deleting is permanent.
- If payments stop before the sixth: your saved data is kept read-only for 30 days, so you can download it, delete it or carry on, and then it is permanently deleted.
- Payment records and amounts: as long as the law requires for accounting, usually six years. They contain no health information.
- Shared check-in scores: until you delete them, and no longer than two years.
Your rights
You can see, download, correct and delete your data in Settings, withdraw consent at any time, and ask us about anything on this page. If you want to use a right we cannot do for you in the app, write to enquiries@neurohubcommunity.org. Because we do not store your email address, we may ask you to sign in to prove the account is yours. You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. The AI policy lists all your rights.
Age
NeuroHub Compass is for adults. An account and the licence are for people aged 18 and over. Sharing check-in scores is for people aged 16 and over, which only applies where the account holder is old enough to hold one.
Cookies
We set no advertising or tracking cookies. The app keeps your settings and data in your own browser storage because the service you asked for needs it, which is allowed without consent. The private dashboard uses one strictly necessary sign-in cookie, for the people who run it.
Contact
NeuroHub Community Ltd, enquiries@neurohubcommunity.org, neurohubcommunity.org/contact-us. NeuroHub Community Ltd is registered with the Information Commissioner’s Office, reference ZC088866.