Legal
NeuroDash privacy policy
Effective 26 July 2026
NeuroDash is a personal wellbeing tracker. This policy explains what personal data we use, why we use it, who may process it for us, how long it is kept, and the choices available to you.
Data we collect
We collect data you provide, data created when you use the service, and limited technical data needed to keep your account secure.
- Account data: name, email address, profile image, verification status, sign-in provider, role, and authentication records.
- Wellbeing data: daily scores, symptoms, routines, notes, comments, medication or supplement text, environmental context, and any other information you choose to enter.
- Derived data: trend calculations, correlations, summaries, recommendations, and exports generated from your entries.
- Location and weather data: browser or device coordinates used for a weather request, a saved location held locally on iPhone, location labels, and weather attached to an entry.
- Watch data: linked-account details, today’s snapshot, enabled metrics, queued drafts, and sync acknowledgements stored locally on the paired devices.
- Community data: resource submissions and, for authorised authors, public profile information.
- Technical data: session token records, IP address, user agent, request time, and limited operational or security logs.
How and why we use data
We use account and technical data to create and secure your account, provide sign-in, prevent abuse, communicate essential service messages, and operate NeuroDash. We use wellbeing data to save the entries, analysis, exports, and device sync you request.
For ordinary account processing, our legal bases may include providing the service you request, complying with legal obligations, and legitimate interests in security and reliable operation. Health and wellbeing information may be special-category data; where applicable, we rely on your explicit consent and you may withdraw that consent by stopping the relevant feature or deleting your data.
NeuroDash does not make solely automated decisions that produce legal or similarly significant effects.
Location, AI, and device storage
Location is optional. Coordinates are used to obtain weather and are not stored in your account as raw coordinates, although a place label and weather may be saved with an entry. The iPhone app can retain a chosen weather location locally until you replace it or delete the account.
AI summaries are optional and remain blocked until you explicitly consent. Immediately before the first request, NeuroDash names Google Gemini, explains the purpose and fields, and asks you to affirmatively agree. Gemini receives the four core scores, up to three optional wellbeing scores furthest from the neutral midpoint, up to three symptoms marked yes, and up to 500 characters of entry comments.
For AI summaries, NeuroDash does not send your name, email, account ID, entry date, location, weather, moon data, wake-up time, food tags, medications, supplements, general notes, pain location, or pain description. The returned summary is stored only if you save the entry.
Your consent decision is stored with its time, disclosure version, provider, purpose, and disclosed data categories. You can withdraw consent in Settings at any time. Withdrawal prevents future transfers to Gemini without affecting the rest of NeuroDash; summaries already saved remain part of their entries until you edit or delete them.
Signing out clears phone entry and analysis caches. A queued Watch draft and the last Watch snapshot remain protected on the Watch so the same account can finish syncing later, but saving and syncing are blocked while the phone is signed out. Account deletion permanently purges those local Watch records.
International transfers and security
Some providers may process data outside your country. Where required, we use contractual or other recognised safeguards for international transfers.
We use access controls, encrypted transport, private object storage for health exports, protected local files, and Keychain storage for the iPhone session token. No system is completely secure, so please use a unique password and keep your devices protected.
Children
NeuroDash is intended for people aged 16 or over. Do not create an account or submit personal data if you are below the minimum age that applies where you live.
Service providers and data sharing
We do not sell personal data or use health entries for advertising. The following providers process only the data needed to supply their part of the service:
| Provider | Purpose | Data involved |
|---|---|---|
| Production hosting and PostgreSQL providers | Run the web/API service and database | Account, entry, session, and technical data |
| Cloudflare R2 | Store private analysis exports and managed avatars | Export files, avatars, object metadata, and account-scoped object paths |
| Resend | Deliver verification and account-deletion email | Email address, display name, and short-lived verification link |
| Apple, Google, and GitHub | Optional social sign-in selected by the user | Provider account identifier, email, name, avatar where provided, and authentication tokens |
| Google Gemini | Optional AI-generated entry summaries | Four core wellbeing scores; up to three optional scores; up to three affirmative symptoms; and up to 500 characters of comments. No account identity, date, location, weather, medication, food, or general notes. |
| Open-Meteo | Optional weather lookup | Coordinates, requested date, and network metadata |
Retention and deletion
- Account details and wellbeing entries are kept while your account is active, unless you delete an entry sooner.
- Saved analysis exports and uploaded avatars are kept until you remove them or delete the account.
- Sessions remain until they expire or are revoked. Email verification and deletion tokens are short-lived; deletion links expire after one hour.
- Operational and security logs are kept for no longer than 30 days unless a longer period is required to investigate abuse, protect the service, or comply with law.
- Where encrypted infrastructure backups are enabled, residual copies may remain isolated from normal use for up to 35 days before rotation.
After you confirm account deletion, NeuroDash removes the active database account and associated entries, sessions, connected sign-in records, avatar objects, and saved analysis exports. The iPhone app clears its token, entry cache, analysis cache, saved weather location, Watch inbox, and account preferences. A deletion notice is sent to the paired Watch; if it is offline, local Watch data is removed when it next reconnects.
Your rights and choices
- Access and export your entries using NeuroDash’s export tools.
- Correct profile information and update or delete individual entries.
- Withdraw optional location or AI choices without deleting your account.
- Request restriction, object where applicable, or ask for a portable copy of your data.
- Delete your account from Settings on the web or iPhone app.
- Complain to your local data-protection authority. In the UK, this is the Information Commissioner’s Office.
Contact
NeuroDash is the controller responsible for NeuroDash. For a privacy request or question, email privacy@northflare.studio.
We may update this policy when the service or legal requirements change. Material changes will be presented in the service before they take effect.