Privacy policy.
What we process, why, where it runs and for how long. In plain words, and including the parts that are inconvenient for us.
Last updated 19 September 2026
The short version
- We do not train models on what you send. Not ours and not anyone else's, on every plan including the free one.
- No tracking, no advertising, no third-party analytics. The only cookie keeps you signed in.
- The company is Swiss; the standard servers are not. They run in the United States and the European Union, and we say so below.
- You can delete any conversation, the profile the assistant built, a connected account or the whole account yourself, in the settings.
Who is responsible
Neurolism, Zurich, Switzerland (VAT number CHE-231.469.196), is responsible for the processing described here. For anything about your data, write to info@neurolism.com. Company details are on the imprint page.
What we process, and why
- Your account: name, email address and password, stored hashed with Argon2id and never in plain text. If you sign in with Microsoft or Google, we receive your name, email address and an account identifier from them instead of a password. Needed to give you an account.
- Conversations: what you write and what the assistant answers, so the conversation is there when you come back. Incognito conversations are not stored. Needed to provide the service.
- Files you attach: kept until you delete them or the account. Spreadsheets you analyse with Python are processed in your browser; their content still goes to the model as part of the conversation.
- What the assistant learned about you: if you switch on “Let it get to know you” in the settings, a short list of traits is drawn from your conversations (your work, tools, language and style) so you do not have to explain them each time. Off means nothing is kept, and you can delete the list at any time.
- Connected Microsoft 365 or Google accounts: if you connect one, we store the access keys it gives us, encrypted. The assistant then searches and reads your files or mail when you ask it to, and only reads: it never changes, sends or deletes anything. What it reads goes to the model like anything you type, and ends up in the conversation. Disconnecting in the settings deletes the keys at once.
- Student confirmation: if you confirm that you study, the university email address, the name of the university and, if you give it, your programme. Kept for twelve months, to apply the student price. We send one code to that address and nothing else.
- Price alerts: the symbol and the level you set, until you remove the alert. When the price crosses the level, you get one email.
- Shared conversations: if you create a link, the conversation as it was at that moment can be read by anyone who has the link, without attachments, until you delete the link.
- Payment: Stripe handles it. We store a customer reference and the plan, never a card number.
- Usage counters: how much of your allowance is used per window and per week. Numbers, not content.
- Where you came from: once, when you sign up, the campaign tags of the link you arrived through, the site that linked to us and an invitation code if you had one.
- Server logs: IP address, time, address requested and status code, kept for 14 days to find faults and abuse.
- Emails we send: sign-in and confirmation codes, receipts, price alerts and notices about your subscription. No newsletters unless you ask for them.
The legal basis is the contract with you (providing the service you signed up for), our legitimate interest in running it securely (logs, abuse prevention), your consent where you give it (connected accounts, the learned profile) and legal duties (keeping accounting records).
What we do not do
No training. Your conversations, files, mail and documents are not used to train a model, ours or anyone else's. No analysis. They are not evaluated for statistics, product research, advertising or profiling. No sale. We do not sell or rent data to anyone. The two people who administer the servers could technically see stored data; they look only when you ask for help with a specific problem.
Who processes data for us
These companies process data on our instructions and for no purpose of their own. None of them may use it to train models.
Business accounts can have a deployment in Switzerland, with the model, conversations and files kept inside the country, under a separate contract. The standard plans (Free, Plus, Pro, Pro Max) do not run there.
Data outside Switzerland
Because the standard servers are in the United States and the European Union, your data leaves Switzerland. The EU offers a level of protection Switzerland recognises as adequate. For the United States we rely on the provider’s certification under the Swiss-U.S. Data Privacy Framework where it has one, and otherwise on the standard contractual clauses recognised by the Federal Data Protection and Information Commissioner (FDPIC).
Google and Microsoft data
Neurolism’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The same rules apply to data from Microsoft: it is used only to answer what you ask, is not used for advertising or training, is not sold, and is not read by people unless you ask us to look into a problem or the law requires it.
How long we keep things
Conversations and files: until you delete them or the account. Connected-account keys: until you disconnect. Student confirmation: twelve months. Usage counters: rolling, gone once the window has passed. Server logs: 14 days. Payment and accounting records: ten years, because Swiss law requires it. When you delete your account, everything else goes with it.
Cookies and storage in your browser
One cookie keeps you signed in. The app also remembers settings such as the language and the sidebar in your browser’s own storage, which never leaves your device. No advertising or analytics cookies, which is why there is no cookie banner.
Your rights
Under the Swiss Data Protection Act and, where it applies, the GDPR, you may ask what we hold about you, have it corrected or deleted, receive it in a portable form, object to processing and withdraw a consent at any time. Most of this you can do yourself in the settings; for the rest, write to info@neurolism.com. You may also complain to the FDPIC in Bern or to the supervisory authority where you live.
Security
Everything travels encrypted over TLS. Passwords are hashed with Argon2id, connected-account keys are encrypted, API keys are stored only as hashes. Sessions use a short-lived access token and a rotating refresh token, so a stolen token has a short life and its reuse is detected.
Changes
When something here changes, the date at the top changes with it. For changes that matter to you, such as a new place where data is processed, we tell account holders by email before it applies.
See also the terms of service and the imprint.