This page is a placeholder structure. The final text will be published here before launch.
Privacy Policy
Last updated: [TODO: date]
This policy describes how [TODO: legal entity name] ("we", "us") handles personal data when you use Neural Studio. [TODO: opening paragraph; controller identity and address.]
1. What we collect
- Account data. Your email address and a display name. Authentication is handled by Amazon Cognito. [TODO: if federated sign-in (Google, GitHub) is enabled later, describe the identifier and email those providers share.]
- Usage analytics. Product analytics events (page views, feature usage) collected with PostHog and proxied through our own domain. [TODO: whether session recording is enabled; opt-out.]
- Billing data. Payments are processed by Stripe; we store a Stripe customer reference, purchase history and your credit ledger, never card numbers.
- Content you create. Notebooks, files, datasets, environment definitions, experiment metrics and logs stay in your workspace's storage and are processed only to run the Service for you. Workspace Secrets are stored in a managed secrets store and are never returned by the platform.
- Operational logs. Request logs and runtime lifecycle records needed to operate, secure and bill the Service. [TODO: IP addresses, retention.]
2. Why we process it
- [TODO: legal bases / purposes: providing the Service, billing, security and abuse prevention, product improvement, communications.]
3. Subprocessors
Providers that process data on our behalf. [TODO: confirm and complete this list, with locations and contractual terms.]
- [TODO: confirm] Amazon Web Services (hosting, storage, authentication)
- [TODO: confirm] Stripe (payments)
- [TODO: confirm] PostHog (product analytics)
- [TODO: confirm] the cloud providers on which runtimes launch (Amazon Web Services, Nebius, DigitalOcean, Lambda, Google Cloud), for the duration of a runtime session
- [TODO: any email or support tooling]
4. Retention
- [TODO: account data, content, logs, billing records, backups.]
- Runtime virtual machines are destroyed at the end of every session; only your workspace storage persists.
5. Your rights
- [TODO: access, correction, deletion, portability, objection; how to exercise them; supervisory authority.]
6. Cookies
- Session cookies are used to keep you signed in. [TODO: analytics cookies, consent.]
7. Children
- [TODO: minimum age.]
8. Changes to this policy
- [TODO: how changes are announced.]
9. Contact
- [TODO: privacy contact / data protection officer, if any.] See also the contact page.