1. Scope and our roles
This Privacy Notice applies when you visit neutronai.dev and related Neutron domains, create or administer an account, use our web or native applications, APIs, SDKs, CLI or MCP services, buy a plan, communicate with us, or otherwise interact with Neutron AI Ltd (“Neutron”, “we”, “us”, or “our”).
Neutron is the controller of personal data used to operate accounts, contracts, billing, security, product administration, support, and our public websites. When a customer submits personal data in Memory Cells, Scopes, Nuclei, entities, relationships, claims, Context Capsules, knowledge snapshots, decisions, simulations, structured Consequence artifacts, observations, outcomes, or learning records (“Customer Content”), Neutron normally acts as that customer’s processor or service provider. The customer decides why and how that data is processed; our Data Processing Addendum governs that activity.
If you interact with Neutron through a customer’s application or workspace, that customer’s privacy notice also applies. Direct requests about Customer Content should ordinarily be sent to that customer. We will assist the customer as required by contract and law.
2. Personal data we collect
Account and identity data
Name if supplied, email address, account and workspace identifiers, role, membership, authentication challenge and session records, onboarding status, account preferences, and administrator actions. Authentication secrets and one-time codes are hashed or otherwise protected where supported and are not intended to be stored in readable form.
Customer Content and configuration
Content and metadata submitted by authorised users or integrations, including Memory Cells, summaries, embeddings, Scopes, Nuclei, entities, relationships, claims, contradictions, provenance, confidence, agent and model configuration, source references, retention settings, Context Capsules, knowledge snapshots, decisions, approvals, simulations, observations, outcomes, learning records, reflections, and structured Consequence artifacts. The content may include personal data if a customer chooses to submit it.
Commercial and transaction data
Plan, subscription, credit and usage status, billing contact details, payment-provider customer and transaction identifiers, invoice and tax information, and records of purchases, renewals, cancellations, refunds, and billing support. Neutron does not intend to receive or store full payment-card numbers; those are handled by the payment provider.
Device, network, usage, and diagnostic data
IP address, approximate network location, browser and device type, operating system, referring page, request time, route, request and trace identifiers, authentication and audit events, feature and API usage, token or credit consumption, response status, latency, errors, rate-limit events, and security signals. We design operational logging to avoid raw Customer Content, credentials, cookies, private prompts, and sensitive payloads.
Communications and business information
Support requests, feedback, security reports, sales and enterprise enquiries, contract communications, and information supplied for security, compliance, data-processing, or procurement review. Calls or meetings are not recorded unless we tell participants and have a lawful basis.
Cookies and local storage
Strictly necessary authentication cookies and local storage used for native sessions or interface preferences. Our current technologies and durations are listed in the Cookie Notice.
3. Sources of personal data
We obtain personal data:
- directly from you, when you register, authenticate, configure the Service, submit content, buy a plan, or communicate with us;
- from your organisation or workspace administrator, when they invite you, assign permissions, manage a workspace, or provide business contact information;
- from your systems and customer-chosen integrations, when authorised applications, agents, repositories, model gateways, or MCP clients call the Service;
- automatically from devices and the Service, through requests, cookies, local storage, security controls, audit logs, and usage metering;
- from service providers, such as payment, infrastructure, email-delivery, fraud-prevention, or support providers; and
- from public sources, where necessary to verify an organisation, respond to security issues, or manage business relationships.
4. Why we use personal data and our lawful bases
| Purpose | Typical data | UK and EEA lawful basis |
|---|---|---|
| Provide accounts, authentication, workspaces, memory, retrieval, context, consequence, support, and requested integrations. | Account, configuration, Customer Content, device, usage, and communications data. | Performance of a contract; legitimate interests in providing the Service to business users; processor instructions for Customer Content. |
| Administer subscriptions, usage credits, invoices, payments, renewals, and tax records. | Account, commercial, transaction, and usage data. | Performance of a contract; legal obligations; legitimate interests in revenue administration. |
| Secure the Service, prevent fraud and abuse, investigate incidents, enforce terms, and protect rights. | Identity, network, audit, diagnostic, configuration, and limited content where necessary. | Legitimate interests in protecting users, systems, and rights; legal obligations; establishment, exercise, or defence of legal claims. |
| Monitor reliability, debug errors, plan capacity, measure features, and improve the Service. | Usage, diagnostic, de-identified aggregate, feedback, and support data. | Legitimate interests in maintaining and improving a safe, useful service. |
| Send transactional messages, service notices, security alerts, and respond to enquiries. | Contact, account, security, and communications data. | Performance of a contract; legitimate interests; legal obligations. |
| Comply with law, regulatory requests, sanctions, accounting duties, and court orders. | Data reasonably required for the relevant obligation. | Legal obligation; public interest where applicable; legitimate interests in legal compliance. |
| Optional activities that require a choice, such as future non-essential cookies or expressly opted-in model improvement. | Only the data described when the choice is offered. | Consent, which may be withdrawn without affecting earlier lawful processing. |
Where we rely on legitimate interests, we consider the purpose, necessity, and impact on individuals and use safeguards proportionate to the risk. You may ask for more information about that assessment. Some account, security, transaction, and service data is required to enter or perform a contract; without it, we may be unable to provide the relevant feature or account.
5. Customer-controlled personal data
Customers decide what Customer Content to submit, the people and systems allowed to access each Nucleus and Scope, retention settings, model or integration choices, and the purposes for which retrieved context or Output is used. Customers must provide required notices, establish a lawful basis, respect data-subject rights, minimise content, and avoid submitting credentials, payment-card data, or personal data unnecessary for the intended memory workflow.
Neutron processes Customer Content under documented instructions, including the Agreement, API calls, product configuration, support directions, and the DPA. We may process it independently only where law requires, in which case we will inform the customer unless prohibited. We do not determine whether a customer’s particular use is lawful and do not replace the customer’s privacy, security, or impact assessment.
Special-category, criminal-offence, health, biometric, financial-account, children’s, or similarly sensitive data should be submitted only where the customer has confirmed that its plan and configuration support the workload, completed appropriate risk and impact assessments, and entered any required written terms. Customer must not use Neutron as a system for raw secrets or authentication credentials.
6. AI processing and model training
Neutron may transform text into numerical embeddings for semantic retrieval and may send authorised inputs to an AI model when a customer invokes a hosted inference feature. Other functions—including deterministic codecs, scoring, ranking, context packing, policy checks, and parts of Consequence simulation—may not use a generative model. See the AI Transparency Notice for the feature boundary.
We do not use Customer Content to train general-purpose models or Neutron models unless the customer gives separate, explicit written opt-in consent identifying that purpose. Customer-chosen model providers process data under the customer’s configuration and the provider’s applicable terms. Where Neutron supplies hosted model inference, the infrastructure providers on our Subprocessor List apply.
We may use de-identified and aggregated service statistics that exclude Customer Content and do not reasonably identify a person or customer to understand reliability, safety, and feature performance. We do not seek to reconstruct identities from de-identified data.
8. International data transfers
Neutron is established in the United Kingdom and operates a globally available service. Personal data may be processed in the United Kingdom and in other countries where our providers or customer-selected integrations operate. These countries may have different data-protection laws.
Where transfer law requires a safeguard, we use an adequacy decision where available, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or International Data Transfer Agreement, or another lawful mechanism. Our DPA incorporates the applicable contractual safeguards and addresses onward transfers. Regional preferences are operational placement choices and are not a legal data-residency guarantee unless an Order expressly says so.
You may request information about the safeguard applicable to a transfer by contacting us. We may redact commercially sensitive or security information from any copy we provide.
9. Retention, deletion, and account closure
We retain personal data only for as long as reasonably necessary for the purposes described above, including to provide the Service, honour configured retention, protect security, resolve disputes, enforce agreements, and comply with legal, tax, accounting, and regulatory obligations. We use the following periods or criteria:
- Customer Content: until deleted by an authorised instruction, the configured time-to-live expires, the account or relevant service ends, or the applicable Order requires deletion. Memory TTLs may be configured up to 10 years. Deletion creates tombstones so queued, cached, compacted, or archived data is not restored.
- Context caches: ordinarily 30 seconds to 24 hours according to customer policy; the default is five minutes where no different configuration applies.
- Consequence runs: between 1 and 365 days according to the requested retention; the default is 90 days.
- Authentication: one-time codes are usable for 10 minutes by default and sessions for 12 hours by default, subject to configured security limits. Related anti-abuse and audit records may be kept longer where necessary.
- Account and workspace data: while the account is active and afterwards for the time needed to complete deletion, maintain security and deletion integrity, resolve disputes, or meet legal obligations.
- Billing, contract, tax, and corporate records: for the period required by applicable law and relevant limitation periods.
- Security, audit, support, and diagnostic records: for periods proportionate to incident investigation, service reliability, abuse prevention, support, and legal-claim needs, with access restricted by role and purpose.
Deletion from active systems may not immediately remove encrypted backup copies. Backups are isolated, access-controlled, and overwritten or deleted on their normal cycle unless preservation is legally required. Minimal records may remain to document a request, comply with law, prevent fraud, and ensure tombstoned content is not resurrected. When retention ends, we delete, anonymise, or securely isolate the data.
10. Security
We use administrative, technical, and organisational safeguards designed for the nature and risk of the data, including tenant and scope validation, access controls, credential hashing, encryption in transit, provider security controls, deletion-aware workflows, rate limits, bounded processing, redacted operational logging, incident procedures, and personnel confidentiality. Further controls appear in the DPA and on our Security page.
No internet service is completely secure. Customers are responsible for secure endpoints and integrations, least-privilege credentials, workspace membership, lawful scope design, appropriate retention, and deciding what data to submit. If you believe personal data or credentials have been compromised, contact admin@neutronai.dev promptly and rotate affected credentials.
11. UK and EEA privacy rights
Depending on the law and circumstances, you may have the right to:
- receive information about our processing and obtain access to your personal data;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- restrict processing in specified circumstances;
- receive personal data you supplied in a structured, commonly used, machine-readable format and transmit it to another controller;
- object at any time to processing based on legitimate interests, including profiling on that basis, and object to direct marketing;
- withdraw consent at any time where processing relies on consent, without affecting processing already carried out; and
- not be subject to a solely automated decision with legal or similarly significant effects except where law permits it with safeguards.
To exercise a right for data Neutron controls, email admin@neutronai.dev from the account address where possible and describe the request. We may verify identity and authority, ask for clarification, or refuse or charge for a manifestly unfounded or excessive request where law permits. We will respond within the period required by applicable law.
For Customer Content, contact the customer that controls the relevant workspace or application first. If you send the request to us, we will refer it to that customer where appropriate and assist under the DPA.
You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or to the supervisory authority where you live, work, or believe an infringement occurred. We invite you to contact us first so we can try to resolve the issue.
12. United States state privacy disclosures
Residents of United States states with an applicable comprehensive privacy law may have rights under that law. Depending on the state and circumstances, these can include rights to know, access, correct, delete, obtain a portable copy, opt out of sale, targeted advertising or certain profiling, limit certain sensitive-data uses, and appeal a decision on a request.
In the preceding 12 months, we may have collected the categories described above: identifiers and account information; commercial and transaction information; internet or electronic-network activity; professional or employment-related business information; approximate geolocation derived from network information; communications; and Customer Content that may fall into another statutory category. We collect these categories from the sources and for the purposes described in sections 3 and 4, and disclose them to the recipient categories in section 7.
Neutron does not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising. We do not use or disclose sensitive personal information to infer characteristics about a person. Accordingly, we do not currently offer a “Do Not Sell or Share” link. If our practices change, we will update this Notice and honour applicable opt-out preference signals, including Global Privacy Control, as required.
Neutron processes personal information in Customer Content as a service provider or processor under the customer’s instructions and does not retain, use, or disclose it outside the business purposes specified in the Agreement except as law permits. Requests about that data should be directed to the relevant customer.
To submit a request about data Neutron controls, email admin@neutronai.dev. We will verify the request using information reasonably related to your account and may require an authorised agent to provide signed permission and verify their identity or authority. We will not discriminate against you for exercising a privacy right. If we deny an appealable request, our response will explain how to appeal.
13. Children
Neutron accounts and the Service are not directed to anyone under 18, and we do not knowingly collect personal data directly from children through account registration. If you believe a child created an account or provided personal data directly to Neutron, contact us so we can investigate and delete it where appropriate.
A customer may process data about minors through its own application only if it has a lawful basis, provides required notices, obtains any required parental authorisation, applies age-appropriate safeguards, and complies with the Agreement. Neutron is not designed for child-directed profiling, exploitation, or behavioural advertising.
14. Automated decision-making and profiling
Neutron does not use personal data for solely automated decisions about Neutron accounts that produce legal or similarly significant effects. We may use automated security, fraud, rate-limit, and abuse signals to protect the Service; materially adverse account action is subject to review or a route to contact us where appropriate.
Customers may configure memory, AI, and Consequence features as inputs to their own workflows. The customer is responsible for determining whether its use involves regulated automated decision-making or profiling, providing notices and explanations, testing accuracy and bias, completing impact assessments, and ensuring meaningful human review and contestability where required.
15. Changes to this Notice
We may update this Notice as our Service, providers, or legal obligations change. We will post the revised Notice with a new effective date. If a change materially affects how we use personal data, we will provide additional notice through the Service, account email, or another appropriate channel where required. Earlier versions may be requested from us.
Contact and company information
Questions about this document may be sent to admin@neutronai.dev.
Neutron AI LtdRegistered in England and Wales under company number 17317740
Registered office: 5 Hallett Close, Havant, United Kingdom, PO9 2BW