Privacy policy
Operational AI records need clear data boundaries.
This policy explains how NeuralStackly handles workspace AI register records, account identity, billing state, private attachments, analytics, exports, and deletion requests. It is not legal advice or a formal compliance certification.
Last updated: July 17, 2026
1. Information we collect
- Account identity and profile data from the authentication provider, including name, email address, verification state, and session identifiers.
- Workspace records such as organization profile, members, roles, consultants, settings, billing plan mirror, and usage limits.
- AI register records such as tools, owners, vendors, categories, costs, renewal dates, data-use notes, approval state, reviews, policies, acknowledgments, reports, and audit events.
- Private evidence attachments and attachment metadata when a workspace user uploads files to support tool reviews, approvals, policies, or reports.
- Operational messages such as invitations, review reminders, billing notices, export requests, deletion requests, security reports, support requests, and delivery status.
- Product analytics events when enabled and consented to, limited to allow-listed product behavior and route IDs rather than customer content.
2. Information we deliberately avoid
- We do not monitor employee screens, prompts, keystrokes, browser history, or personal devices.
- We do not store card numbers or payment methods in the NeuralStackly application database.
- We do not intentionally send customer records, uploaded file contents, raw invitation tokens, raw download tokens, or provider payload bodies into analytics.
- We do not use NeuralStackly records to certify legal, security, privacy, procurement, or regulatory compliance.
3. How we use data
We use data to provide the AI register, enforce workspace permissions, support consultant workflows, send operational notices, process billing, generate reports, maintain audit history, prevent abuse, troubleshoot incidents, honor export and deletion requests, and improve the product using minimized analytics.
4. Processors and infrastructure providers
Clerk
authentication, account identity, and session management
Convex
application database, functions, scheduled jobs, and private file storage
Stripe
checkout, subscription billing, invoices, customer portal, tax configuration, and payment method handling
Resend
transactional email delivery for invitations, reminders, lifecycle, and billing messages
PostHog
consent-gated product analytics when configured, with autocapture and session recording disabled
Sentry
error monitoring when configured, with customer-content minimization required
Hetzner, Coolify, GitHub, and GHCR
hosting, deployment, source control, and container image delivery
5. Retention, export, and deletion
- Workspace administrators can request workspace export and workspace deletion through the product data-management flow.
- Account deletion requests are staged with a recovery window where practical, then scrub account profile data and remove memberships subject to sole-owner safety checks.
- Private attachment downloads use one-time, short-lived, hashed tokens. Attachment deletion is designed to remove stored file bodies while retaining minimal deleted metadata and audit history.
- Operational logs, audit events, billing event records, suppression records, and security records may be retained where needed for fraud prevention, accounting, dispute resolution, abuse prevention, or legal obligations.
- Backups and restored environments must replay deletion and suppression decisions before any restored data is used for production service.
6. Cookies, local storage, and analytics consent
NeuralStackly uses essential cookies and browser storage for authentication, workspace selection, security, preferences, and core application behavior. Product analytics must be consent-gated where applicable, must use allow-listed events, and must not include customer content.
7. Security and contact
We use workspace authorization, role checks, private storage, signed billing webhooks, audit events, rate limits, and operational readouts to protect the service. No internet service can guarantee perfect security. Privacy requests can be sent to privacy@neuralstackly.com. Security reports can be sent to hello@neuralstackly.com or the published security contact.