Neurall

Privacy Policy

What we collect, why we have it, who else touches it and when it is deleted. Where a number exists we have written the number down.

In effect from 27 August 2026. It replaces the version dated 18 August 2026.

The short version

  • We do not train models on your content, and nothing you make becomes a sample of ours.
  • Files you upload through the API and the outputs they produce are deleted 24 hours after they land, whether or not you ask.
  • We never sell your data. We run one advertising pixel, Meta’s. In the EEA and the UK it waits for your yes; everywhere else it runs until you say no, and saying no is one click in the footer. Page counts come from a cookieless beacon that cannot identify you.
  • You can ask for a copy of your data, a correction, or deletion, and we answer within 30 days.
  • Payments are handled by Stripe. We never receive your card number.

A summary, not the agreement. The sections below are what binds.

1. Who is responsible

Neurall, Inc., 1007 N Orange St, 4th Floor Suite #1382, Wilmington, DE 19801, United States, is the controller of the personal data described here. For privacy questions and for any request under this policy, write to support@neurall.io.

2. What we collect

Because you gave it to us

  • Account details: the email address you sign up with, and the name you choose to add. We do not ask for a real name and nothing checks that it is one.
  • Billing details: the amount, the currency, the date and a reference to the payment. Card numbers go to Stripe and never reach us.
  • What you send to a generation: prompts, and any reference files, which for several features are photographs of a person.
  • Support messages, and whatever you put in them.

Because the service produced it

  • Generation records: which feature ran, when, what it cost, whether it succeeded, and the error if it did not. This is the billing ledger as well as the operational one.
  • Technical logs: IP address, user agent, API key id and timestamps, kept to keep the service up and to catch abuse.
  • Attribution: how you reached us, and which page you bought from. If you arrived from an ad, a search result or a link on another site, we record that source once, on your first visit, and keep it in your browser so that a later purchase can be credited to it. It tells us which pages and which channels are worth paying for. This part is our own record and is shared with nobody. If you accepted advertising cookies, the same moments are also reported to Meta, which section 9 sets out in full.

What we do not do

We do not train models on your prompts, your uploads or your outputs. We do not use your work in our marketing: every asset on this site is our own. Nobody pays us for your personal data, and nothing you upload or generate is ever sent to an advertising network. The one third-party tracker on this site is the advertising pixel in section 9. It loads only if you accept it, and it never sees your files, your prompts or the work you make.

3. Why we have it, and on what basis

To run what you asked for
Generating, storing the result briefly and returning it to you. Basis: performance of the contract.
To bill you
Charging balance, refunding failures, keeping the ledger. Basis: performance of the contract, and legal obligation for tax and accounting records.
To keep the service up and safe
Logs, rate limits, fraud and abuse detection, security investigation. Basis: our legitimate interest in a service that works and is not abused.
To meet the law
Records we are required to keep, and responses to lawful requests. Basis: legal obligation.
To improve the product
Aggregate counts of what runs and what fails. Basis: legitimate interest. This uses generation metadata, never the content of your files.
To measure our advertising
Seeing which ad and which page led to a signup or a purchase, by reporting those moments to Meta. Basis: your consent, asked for by the banner and withdrawable from the footer of any page. If you decline, nothing is reported.
To email you about the service
Receipts, security notices and material changes to these documents. Basis: performance of the contract. Marketing email is separate and only with your consent.

4. How long it lives

Generated work is ephemeral by design. That is a posture rather than a limitation we have not got round to fixing: we would rather not be the long-term home for other people’s faces and voices.

Uploads through the API: 24 hours
A reference file is deleted 24 hours after it lands, whether or not a generation used it.
API outputs: 24 hours
A generation made through the API expires 24 hours after the request. the asset is deleted and the generation stops resolving.
Work made in the app: until you delete it
Your library is a place to keep things, so app work persists. Delete an item and it goes, along with its files.
Voice clones: until you delete them
A voice you create is a resource you reuse, so it is not on the 24 hour clock. Deleting it destroys the voice and cannot be undone.
Generation records: 7 years
What ran, when and what it cost is the billing ledger, and tax law requires us to keep it. It does not include your prompts or your files.
Technical logs: 90 days
Then deleted or aggregated beyond identification.
Account: until you close it
Closing the account deletes the account data, subject to the ledger above.

5. Who else touches it

We use a small number of processors, each bound by a contract that permits them to act only on our instructions. They are named because a customer is entitled to know who can touch their file, and the list is deliberately at the level of infrastructure: which company holds the data, not which recipe runs on it.

Amazon Web Services
Hosting, database and file storage, in the United States. Everything durable lives here.
Stripe
Payments and checkout. Stripe is a controller in its own right for the payment itself, and holds the card details we never see.
GPU inference providers
Generation runs on specialist compute we do not own. A prompt and any reference file are sent to whichever provider serves that feature, and are processed to produce the result. We do not permit them to train on it.
Speech and voice provider
Voiceover, avatar audio and voice cloning are produced by a specialist provider, which receives the text and, for a clone, the sample you supply.
Email delivery
Transactional email, so receipts and password resets arrive.
Cloudflare
Web analytics. It is told which page was opened, which site sent you and the ordinary technical details of the request, and it gives us back counts. It sets no cookie, issues no identifier and stores nothing on your device.
Meta Platforms
Only if you accept advertising cookies. Meta is not our processor: it receives what section 9 describes and acts as a controller in its own right, deciding for itself how that data feeds its advertising. That is exactly why this one asks your permission instead of relying on our legitimate interest.

An honest limit

Generation capacity is not tied to one provider, and we move it as availability, price and quality change. We keep the categories above accurate and we will name a specific provider on request from a business customer under a confidentiality agreement, which is also how a data processing agreement gets signed.

6. Where it goes

We are a United States company and our infrastructure runs in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, using Neurall means your data is transferred there. Where we rely on it, that transfer is covered by the European Commission’s Standard Contractual Clauses with the receiving party, plus the UK Addendum where relevant.

7. Your rights

Wherever you live, you can ask us for a copy of your data, a correction, deletion, a restriction on how we use it, or a machine-readable export. You can object to processing we do on the basis of legitimate interest. You can withdraw consent to marketing at any time, and every marketing email carries the link.

If you are in California, you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing. We do not sell personal data for money. Running the advertising pixel in section 9 does count as sharing for cross-context behavioural advertising under California law, so there is something to opt out of, and the control is the one everyone else gets: Your privacy choices in the footer of every page, then Decline. We honour a Global Privacy Control signal from your browser as that same opt-out, without you having to click anything. We will not discriminate against you for using either.

Write to support@neurall.io from the address on the account. We answer within 30 days. If we need longer for a complicated request we will tell you inside those 30 days and why. If you think we have handled your data badly, you can complain to your data protection authority; we would rather you told us first and gave us the chance to fix it.

8. Security

  • Everything is encrypted in transit, and at rest in storage and the database.
  • Finished assets are served from a CDN on signed, expiring URLs rather than from public buckets.
  • API keys are stored hashed. A key is shown once, at creation, and cannot be recovered afterwards.
  • Access to production data is limited to the people who need it to run the service.
  • If a breach affects your personal data we will tell you and the relevant authority, without undue delay and within 72 hours of becoming aware where the law requires it.

No system is perfect, and anyone who tells you otherwise is selling something. The live health of every component is at neurall.io/status.

9. Cookies, analytics and advertising measurement

Two third parties are told that a page here was opened, and no others. One is Meta’s advertising pixel. The other is Cloudflare Web Analytics, which counts pages: it sets no cookie, reads nothing already on your device and issues no identifier, so it cannot tell a returning visitor from a new one and cannot follow you anywhere else. There is nothing in that to consent to, which is why it is not behind the banner and why opting out does not switch it off; there is no version of you in it to switch off. There is no session recording here, and no profiling beyond what is written below.

Whether we ask you first

It depends on where you are, because the law does. In the European Economic Area and the United Kingdom nothing advertising-related runs until you accept: no pixel script is fetched, no advertising cookie is set, and the site behaves identically if you decline. Everywhere else, including the United States, the standard is an opt-out rather than a permission slip, so the pixel runs from the first page and Your privacy choices, in the footer of every page, switches it off. Both are one click and neither is buried.

We work out which of those applies from your browser’s own time zone setting. It is a guess, it is made on your device, and nothing is sent anywhere to make it. Where the answer is unclear we ask, because an unnecessary question costs you a corner of the screen and a wrong assumption costs you a choice you were entitled to.

If your browser sends a Global Privacy Control signal we treat it as a no, wherever you are and without you having to click anything.

Strictly necessary
The application at app.neurall.io sets cookies that keep you signed in and protect the session. They deliver something you asked for, so the law does not require consent, and there is no way to refuse them and stay signed in.
Analytics, no cookie
Cloudflare Web Analytics records the page you opened, the site that referred you, a broad country and whether the request came from a phone or a desktop, all of it read from the request itself. Nothing is written to your browser, so no consent is required and there is no choice to make.
Advertising
Meta sets _fbp and _fbc to recognise this browser between visits and to connect an ad click to whatever happened afterwards. In the EEA and the UK they are set only once you have accepted; elsewhere they are set until you opt out, and opting out deletes them.

What gets reported

While the pixel is on for you, we tell Meta when a browser looks at one of our feature pages, starts a checkout, creates an account, or completes a purchase, and what a purchase was worth. Some of those reports are sent by your browser and some by our servers, because ad blockers stop the first kind. Both carry the same event identifier so one action is counted once rather than twice. Where you have an account with us, a report includes a one-way hash of your email address, which lets Meta recognise a profile it already holds without us handing over the address in readable form.

What is never in it: your prompts, your uploads, the work you generate, or your card details. A report says that a purchase happened and what it was worth. It does not say what it was for.

Changing your mind

Your privacy choices, in the footer of every page, reopens the bar wherever you are and whatever you answered last time. Choosing Decline deletes both Meta cookies from this browser and reloads the page without the pixel, and it stops the server-side reports too: the two halves are switched by the same answer, so there is no version of this where the browser goes quiet and our servers keep talking. Reports already sent cannot be recalled, and what Meta does with them afterwards is governed by Meta’s policy rather than ours.

10. Children

Neurall is not for children. You must be 18, or the age of digital consent where you live if that is lower and a parent or guardian agrees. We do not knowingly collect data from a child below that age, and if we learn we have, we delete it. Generating sexual content involving a minor is forbidden, reported where the law requires it, and ends the account.

11. Faces and voices

Several features process a photograph of a person or a sample of a voice. Where that person is not you, you need their permission: the Terms of Use require it, and the application asks you to confirm it when you save a person for reuse.

Biometric identifiers are not the point of any of this: we do not run face recognition, we do not build a face or voice database, and we do not use one person’s photograph to make another person’s picture. Uploads for these features are deleted on the same 24 hour clock as everything else.

12. Changes

We will post a new version with a new effective date, and tell account holders before a material change takes effect. We will not quietly start doing something with your data that this page says we do not.

13. Contact

Neurall, Inc., 1007 N Orange St, 4th Floor Suite #1382, Wilmington, DE 19801, United States.
Privacy: support@neurall.io.
Everything else: support@neurall.io, and the terms of service cover the commercial side.

Neurall, Inc., 1007 N Orange St, 4th Floor Suite #1382, Wilmington, DE 19801, United States