Neuralith AI Studio Privacy Policy

Effective and last updated: August 22, 2026

Required before publication: The controller’s registered legal name and serviceable postal address are not present in the project sources. These details must be added to the web page before this text is published as final.

This Privacy Policy explains how the Neuralith AI Studio website and Android and iOS applications (together, the “Service”) process personal data. Neuralith AI Studio (“Neuralith,” “we,” “us”) is the data controller for the Service.

Privacy contact: [email protected]

1. Summary

  • We do not sell personal data. The website uses Google Ads conversion measurement as described in Section 11; Google may process cookie or similar-technology identifiers according to your consent choices, browser settings, and Google’s policies.
  • We do not use your content to train Neuralith’s own general-purpose AI models.
  • Prompts, reference files, and necessary conversation context may be transferred to the relevant service provider only to run the feature you request.
  • You can delete your account through Settings → Delete Account.
  • Message text is protected in the database with application-layer AES-256-GCM encryption. Uploaded files are protected through infrastructure access controls and encryption in transit.

2. Personal data we process

2.1 Account and authentication data

  • Full/display name, email address, and password hash;
  • Provider user ID, email, and display name when you sign in with Google or Apple;
  • Account verification and password-reset codes;
  • Preferred language and account settings.

We do not store your password itself; we store a one-way password hash.

2.2 User content

  • Chat prompts, AI responses, and conversation history;
  • Uploaded reference images;
  • Generated images and videos and their generation parameters;
  • Uploaded PDF/TXT documents, extracted text chunks, and semantic-search vectors;
  • Real-time audio stream and audio response when you initiate the voice feature;
  • Project/folder names and chat titles.

Do not upload special-category, sensitive, or other personal data that is unnecessary to use the Service. Upload another person’s content only when you have the required rights and permission.

2.3 Technical, security, and usage data

  • IP address, request time, limited device/browser information, and security logs;
  • Session/JWT information, Firebase Cloud Messaging (FCM) token, and notification preference;
  • Selected model, token/message counts, credit use, error, and performance records;
  • App version, platform, and language preference.
  • On the website: visited page URL, referrer, IP/device/browser data, Google Ads conversion events, and cookie or similar-technology identifiers where enabled.

2.4 Purchase and balance data

  • RevenueCat/app-store user or transaction ID, product ID, event type, and credit/balance movements.

Apple App Store or Google Play processes payment-card details; those details do not reach Neuralith’s servers.

Processing activityPurposeMain legal basis
Account creation and session managementCreate the account, authenticate the user, and provide the ServicePerformance of a contract; GDPR Art. 6(1)(b), KVKK Art. 5/2(c)
Chat, image/video generation, document search, and voiceGenerate the AI output expressly requested by the userPerformance of a contract; GDPR Art. 6(1)(b), KVKK Art. 5/2(c)
Credits, purchases, and transaction recordsCalculate entitlement, validate purchases, and account for transactionsContract and legal obligation; GDPR Art. 6(1)(b)-(c), KVKK Art. 5/2(c)-(ç)
Security logs, rate limits, and abuse preventionProtect accounts, the Service, and usersLegitimate interests and, where applicable, legal obligation; GDPR Art. 6(1)(f), KVKK Art. 5/2(f)
Service email and push notificationsDeliver verification, security, transaction, and user-enabled notificationsContract, legitimate interests, or consent where applicable law requires it
Language and product-use metricsLocalize the Service and improve capacity and product qualityLegitimate interests; GDPR Art. 6(1)(f), KVKK Art. 5/2(f)
Website security and Google Ads conversion measurementProtect forms and understand whether an advertising campaign led to a download, waitlist, or contact actionConsent where required for non-essential storage/measurement; otherwise legitimate interests where permitted

Where processing relies on consent, you may withdraw it at any time. Withdrawal does not affect processing performed before withdrawal. If required Service data is not provided, the relevant feature may not work.

4. How AI processing works

When you run a selected model or feature, the prompt, reference image, relevant chat history, or document text needed to generate a response may be sent to the relevant provider. Being able to upload an image to a model does not necessarily mean that model can edit it; the app restricts reference-file use according to model capabilities.

  • Document search: PDF/TXT content is converted into text. Text chunks may be vectorized with Google Gemini Embeddings, and relevant chunks may be sent to the selected chat provider.
  • Web search: When the feature determines it is needed, a search query may be sent to Google Gemini/Google Search.
  • Voice: Audio is transmitted in real time to the OpenAI Realtime API. Neuralith’s application server does not retain it as a permanent user audio file; the provider’s security logs and retention terms may apply separately.
  • Image/video generation: The prompt, generation settings, and—on supported models—a reference image are transferred to the selected generation provider. The result may be downloaded to Neuralith infrastructure so it can be displayed and accessed in history.

Neuralith does not use user content to train its own general-purpose models. A third-party provider’s processing is governed by the relevant agreement, API settings, and provider policy. Neuralith aims to send only data needed to provide the feature.

5. Recipients and service providers

Depending on your selected model and feature, data may be transferred to these recipient categories:

Provider/categoryData that may be transferredPurpose
OpenAIPrompt, chat context, reference media, audio streamText, image, video, and real-time voice generation
Google Gemini, Google Search, and FirebasePrompt, context, reference media, document text, search query, FCM tokenAI output, embeddings, web search, and push notifications
AnthropicPrompt, chat context, and images on supported modelsClaude responses
DeepSeekPrompt and chat contextDeepSeek responses
Mistral AIPrompt, chat context, and images on supported modelsMistral responses
xAIPrompt, chat context, and reference mediaGrok text, image, and video generation
Moonshot AIPrompt, chat context, and images on supported modelsKimi responses
Alibaba Cloud DashScopePrompt, chat context, and reference media on supported modelsQwen/Wan/HappyHorse/GLM outputs
RevenueCat, Apple App Store, and Google PlayUser/transaction/product identifiers and purchase statusPurchase validation and credit allocation
Apple and Google Sign-InEmail, display name, and provider identifierAuthentication
CloudflareIP, traffic, and security metadataCDN, bot/DDoS protection, and Turnstile
Google Ads / Google tagPage URL, referrer, IP/device/browser data, conversion events, and cookie/similar-technology identifiers where enabledAdvertising campaign and conversion measurement
Hosting, email, and operational vendorsAccount, log, and communication data needed for their functionHosting, backups, and service email

We may disclose data when a competent authority or court makes a valid legal request or when necessary to protect rights and security in accordance with law. We do not sell personal data.

6. International transfers

AI, authentication, payment, email, notification, and infrastructure providers may process data in different countries. Personal data may therefore be transferred outside Türkiye and the European Economic Area.

To the extent required by applicable law, a transfer uses an adequacy decision, a KVKK standard contract, GDPR Standard Contractual Clauses, binding corporate rules, or another legally permitted safeguard or derogation. Contact [email protected] to request information about applicable safeguards.

7. Retention and deletion

DataRetention approach
Account profile and preferencesWhile the account is open and until account deletion is completed
Chats, messages, media, and documentsUntil the user deletes the relevant chat/file or account
Real-time audioNot retained by Neuralith as a permanent user file; provider retention may apply separately
Verification/password-reset codeGenerally 15 minutes; cleared after use or replacement
Temporary chat cacheGenerally up to 1 hour
FCM notification tokenUntil replaced, account deletion, or no longer operationally required
Security and technical logsFor the limited period needed for security, error investigation, and legal-claim risks
BackupsUp to 90 days after active-system deletion, within the backup lifecycle
Abuse-prevention archiveAfter account deletion: a one-way email hash, final balance, and archive time instead of the plain email; retained only as needed to prevent repeat promotional-credit abuse and manage legal claims

Deleting a chat permanently removes its messages, document records, and semantic-search chunks from the active database and removes related files from storage. Deleting an account initiates permanent deletion of active chats, messages, files, projects, and transaction records associated with it. Data previously transferred to a provider may remain subject to that provider’s legal or contractual retention period.

8. Security

We apply technical and organizational measures proportionate to risk to protect confidentiality, integrity, and availability. They include:

  • HTTPS/TLS encryption in transit;
  • Application-layer AES-256-GCM database encryption for message text;
  • Strong one-way hashing for passwords;
  • Authentication, authorization, rate limiting, and access controls;
  • Infrastructure and file-access controls for uploaded media/documents;
  • Security logging, incident review, and backup controls.

No system can guarantee absolute security. If a security incident creates a legally reportable risk to your rights and freedoms, we will fulfill applicable notification duties.

9. Your rights

Depending on applicable law, you may have the right to:

  • Learn whether and how your personal data is processed;
  • Access the data and, where available, obtain a portable copy;
  • Correct inaccurate or incomplete data;
  • Request deletion, destruction, or anonymization where legal conditions apply;
  • Restrict processing or object to processing based on legitimate interests;
  • Withdraw consent;
  • Object to a result against you arising exclusively from automated processing;
  • Seek compensation for unlawful processing where applicable;
  • Complain to the Turkish Personal Data Protection Authority under KVKK or the competent supervisory authority under GDPR.

Send a request to [email protected]. We may request reasonable information to verify your identity and account ownership. We respond within the period required by applicable law.

10. Children’s privacy

The Service is not directed to children under 13. Where local law sets a higher age of digital consent, a user must meet that age or have valid authorization from a parent or guardian. Contact us if you believe we process a child’s data unlawfully.

11. Cookies and tracking

The website and applications may use the following storage or similar technologies:

  • Essential/security: session and security technologies and Cloudflare Turnstile used to protect forms from abuse;
  • Preferences: browser local storage used to remember light/dark theme;
  • Administration: local storage used for the administrator session on the restricted admin interface;
  • Advertising measurement: the Google tag (AW-18348958928) and Google Ads conversion events used to measure whether website activity leads to actions such as an app-store visit, waitlist submission, or contact submission. Depending on configuration, consent, browser settings, and Google settings, Google may read or set cookies or similar identifiers and receive the page URL, referrer, IP/device/browser data, and conversion event.

Non-essential advertising or analytics storage must be subject to any consent choice required by applicable law. You can also delete or block cookies and local storage through browser controls and manage Google’s advertising settings through Google’s privacy tools. Blocking essential/security storage may prevent parts of the website or administrator interface from working. The mobile app may store authentication tokens and preferences on the device.

12. Automated decision-making

The Service uses automated systems for content generation, security controls, and credit calculations. Neuralith does not intend to make decisions about a user that create legal or similarly significant effects based solely on automated processing.

13. Policy changes

We may update this Policy as the Service or applicable law changes. For material changes, we will provide reasonable advance notice through the app, email, or the website. The date at the top identifies the latest version.

14. Contact

For privacy questions and data-subject requests: