Neuralith AI Studio Privacy Policy
Effective and last updated: August 22, 2026
Required before publication: The controller’s registered legal name and serviceable postal address are not present in the project sources. These details must be added to the web page before this text is published as final.
This Privacy Policy explains how the Neuralith AI Studio website and Android and iOS applications (together, the “Service”) process personal data. Neuralith AI Studio (“Neuralith,” “we,” “us”) is the data controller for the Service.
Privacy contact: [email protected]
1. Summary
- We do not sell personal data. The website uses Google Ads conversion measurement as described in Section 11; Google may process cookie or similar-technology identifiers according to your consent choices, browser settings, and Google’s policies.
- We do not use your content to train Neuralith’s own general-purpose AI models.
- Prompts, reference files, and necessary conversation context may be transferred to the relevant service provider only to run the feature you request.
- You can delete your account through Settings → Delete Account.
- Message text is protected in the database with application-layer AES-256-GCM encryption. Uploaded files are protected through infrastructure access controls and encryption in transit.
2. Personal data we process
2.1 Account and authentication data
- Full/display name, email address, and password hash;
- Provider user ID, email, and display name when you sign in with Google or Apple;
- Account verification and password-reset codes;
- Preferred language and account settings.
We do not store your password itself; we store a one-way password hash.
2.2 User content
- Chat prompts, AI responses, and conversation history;
- Uploaded reference images;
- Generated images and videos and their generation parameters;
- Uploaded PDF/TXT documents, extracted text chunks, and semantic-search vectors;
- Real-time audio stream and audio response when you initiate the voice feature;
- Project/folder names and chat titles.
Do not upload special-category, sensitive, or other personal data that is unnecessary to use the Service. Upload another person’s content only when you have the required rights and permission.
2.3 Technical, security, and usage data
- IP address, request time, limited device/browser information, and security logs;
- Session/JWT information, Firebase Cloud Messaging (FCM) token, and notification preference;
- Selected model, token/message counts, credit use, error, and performance records;
- App version, platform, and language preference.
- On the website: visited page URL, referrer, IP/device/browser data, Google Ads conversion events, and cookie or similar-technology identifiers where enabled.
2.4 Purchase and balance data
- RevenueCat/app-store user or transaction ID, product ID, event type, and credit/balance movements.
Apple App Store or Google Play processes payment-card details; those details do not reach Neuralith’s servers.
3. Purposes and legal bases
| Processing activity | Purpose | Main legal basis |
|---|---|---|
| Account creation and session management | Create the account, authenticate the user, and provide the Service | Performance of a contract; GDPR Art. 6(1)(b), KVKK Art. 5/2(c) |
| Chat, image/video generation, document search, and voice | Generate the AI output expressly requested by the user | Performance of a contract; GDPR Art. 6(1)(b), KVKK Art. 5/2(c) |
| Credits, purchases, and transaction records | Calculate entitlement, validate purchases, and account for transactions | Contract and legal obligation; GDPR Art. 6(1)(b)-(c), KVKK Art. 5/2(c)-(ç) |
| Security logs, rate limits, and abuse prevention | Protect accounts, the Service, and users | Legitimate interests and, where applicable, legal obligation; GDPR Art. 6(1)(f), KVKK Art. 5/2(f) |
| Service email and push notifications | Deliver verification, security, transaction, and user-enabled notifications | Contract, legitimate interests, or consent where applicable law requires it |
| Language and product-use metrics | Localize the Service and improve capacity and product quality | Legitimate interests; GDPR Art. 6(1)(f), KVKK Art. 5/2(f) |
| Website security and Google Ads conversion measurement | Protect forms and understand whether an advertising campaign led to a download, waitlist, or contact action | Consent where required for non-essential storage/measurement; otherwise legitimate interests where permitted |
Where processing relies on consent, you may withdraw it at any time. Withdrawal does not affect processing performed before withdrawal. If required Service data is not provided, the relevant feature may not work.
4. How AI processing works
When you run a selected model or feature, the prompt, reference image, relevant chat history, or document text needed to generate a response may be sent to the relevant provider. Being able to upload an image to a model does not necessarily mean that model can edit it; the app restricts reference-file use according to model capabilities.
- Document search: PDF/TXT content is converted into text. Text chunks may be vectorized with Google Gemini Embeddings, and relevant chunks may be sent to the selected chat provider.
- Web search: When the feature determines it is needed, a search query may be sent to Google Gemini/Google Search.
- Voice: Audio is transmitted in real time to the OpenAI Realtime API. Neuralith’s application server does not retain it as a permanent user audio file; the provider’s security logs and retention terms may apply separately.
- Image/video generation: The prompt, generation settings, and—on supported models—a reference image are transferred to the selected generation provider. The result may be downloaded to Neuralith infrastructure so it can be displayed and accessed in history.
Neuralith does not use user content to train its own general-purpose models. A third-party provider’s processing is governed by the relevant agreement, API settings, and provider policy. Neuralith aims to send only data needed to provide the feature.
5. Recipients and service providers
Depending on your selected model and feature, data may be transferred to these recipient categories:
| Provider/category | Data that may be transferred | Purpose |
|---|---|---|
| OpenAI | Prompt, chat context, reference media, audio stream | Text, image, video, and real-time voice generation |
| Google Gemini, Google Search, and Firebase | Prompt, context, reference media, document text, search query, FCM token | AI output, embeddings, web search, and push notifications |
| Anthropic | Prompt, chat context, and images on supported models | Claude responses |
| DeepSeek | Prompt and chat context | DeepSeek responses |
| Mistral AI | Prompt, chat context, and images on supported models | Mistral responses |
| xAI | Prompt, chat context, and reference media | Grok text, image, and video generation |
| Moonshot AI | Prompt, chat context, and images on supported models | Kimi responses |
| Alibaba Cloud DashScope | Prompt, chat context, and reference media on supported models | Qwen/Wan/HappyHorse/GLM outputs |
| RevenueCat, Apple App Store, and Google Play | User/transaction/product identifiers and purchase status | Purchase validation and credit allocation |
| Apple and Google Sign-In | Email, display name, and provider identifier | Authentication |
| Cloudflare | IP, traffic, and security metadata | CDN, bot/DDoS protection, and Turnstile |
| Google Ads / Google tag | Page URL, referrer, IP/device/browser data, conversion events, and cookie/similar-technology identifiers where enabled | Advertising campaign and conversion measurement |
| Hosting, email, and operational vendors | Account, log, and communication data needed for their function | Hosting, backups, and service email |
We may disclose data when a competent authority or court makes a valid legal request or when necessary to protect rights and security in accordance with law. We do not sell personal data.
6. International transfers
AI, authentication, payment, email, notification, and infrastructure providers may process data in different countries. Personal data may therefore be transferred outside Türkiye and the European Economic Area.
To the extent required by applicable law, a transfer uses an adequacy decision, a KVKK standard contract, GDPR Standard Contractual Clauses, binding corporate rules, or another legally permitted safeguard or derogation. Contact [email protected] to request information about applicable safeguards.
7. Retention and deletion
| Data | Retention approach |
|---|---|
| Account profile and preferences | While the account is open and until account deletion is completed |
| Chats, messages, media, and documents | Until the user deletes the relevant chat/file or account |
| Real-time audio | Not retained by Neuralith as a permanent user file; provider retention may apply separately |
| Verification/password-reset code | Generally 15 minutes; cleared after use or replacement |
| Temporary chat cache | Generally up to 1 hour |
| FCM notification token | Until replaced, account deletion, or no longer operationally required |
| Security and technical logs | For the limited period needed for security, error investigation, and legal-claim risks |
| Backups | Up to 90 days after active-system deletion, within the backup lifecycle |
| Abuse-prevention archive | After account deletion: a one-way email hash, final balance, and archive time instead of the plain email; retained only as needed to prevent repeat promotional-credit abuse and manage legal claims |
Deleting a chat permanently removes its messages, document records, and semantic-search chunks from the active database and removes related files from storage. Deleting an account initiates permanent deletion of active chats, messages, files, projects, and transaction records associated with it. Data previously transferred to a provider may remain subject to that provider’s legal or contractual retention period.
8. Security
We apply technical and organizational measures proportionate to risk to protect confidentiality, integrity, and availability. They include:
- HTTPS/TLS encryption in transit;
- Application-layer AES-256-GCM database encryption for message text;
- Strong one-way hashing for passwords;
- Authentication, authorization, rate limiting, and access controls;
- Infrastructure and file-access controls for uploaded media/documents;
- Security logging, incident review, and backup controls.
No system can guarantee absolute security. If a security incident creates a legally reportable risk to your rights and freedoms, we will fulfill applicable notification duties.
9. Your rights
Depending on applicable law, you may have the right to:
- Learn whether and how your personal data is processed;
- Access the data and, where available, obtain a portable copy;
- Correct inaccurate or incomplete data;
- Request deletion, destruction, or anonymization where legal conditions apply;
- Restrict processing or object to processing based on legitimate interests;
- Withdraw consent;
- Object to a result against you arising exclusively from automated processing;
- Seek compensation for unlawful processing where applicable;
- Complain to the Turkish Personal Data Protection Authority under KVKK or the competent supervisory authority under GDPR.
Send a request to [email protected]. We may request reasonable information to verify your identity and account ownership. We respond within the period required by applicable law.
10. Children’s privacy
The Service is not directed to children under 13. Where local law sets a higher age of digital consent, a user must meet that age or have valid authorization from a parent or guardian. Contact us if you believe we process a child’s data unlawfully.
11. Cookies and tracking
The website and applications may use the following storage or similar technologies:
- Essential/security: session and security technologies and Cloudflare Turnstile used to protect forms from abuse;
- Preferences: browser local storage used to remember light/dark theme;
- Administration: local storage used for the administrator session on the restricted admin interface;
- Advertising measurement: the Google tag (
AW-18348958928) and Google Ads conversion events used to measure whether website activity leads to actions such as an app-store visit, waitlist submission, or contact submission. Depending on configuration, consent, browser settings, and Google settings, Google may read or set cookies or similar identifiers and receive the page URL, referrer, IP/device/browser data, and conversion event.
Non-essential advertising or analytics storage must be subject to any consent choice required by applicable law. You can also delete or block cookies and local storage through browser controls and manage Google’s advertising settings through Google’s privacy tools. Blocking essential/security storage may prevent parts of the website or administrator interface from working. The mobile app may store authentication tokens and preferences on the device.
12. Automated decision-making
The Service uses automated systems for content generation, security controls, and credit calculations. Neuralith does not intend to make decisions about a user that create legal or similarly significant effects based solely on automated processing.
13. Policy changes
We may update this Policy as the Service or applicable law changes. For material changes, we will provide reasonable advance notice through the app, email, or the website. The date at the top identifies the latest version.
14. Contact
For privacy questions and data-subject requests:
- Email: [email protected]
- Web: https://neuralithaistudio.com
- Controller: Neuralith AI Studio — the registered legal name and serviceable postal address must be completed before publication.