Privacy Notice

Effective date:

Effective date:

16 July 2026

Version:

3.0

Controller:

Controller:

Neura Labs Oy (VAT FI35508533)

Neura Labs Oy (VAT FI35508533)

Address:

Address:

Pitkäkalliontie 9, 01800 Klaukkala, Finland

Pitkäkalliontie 9, 01800 Klaukkala, Finland

Privacy Contact :

Privacy Contact :

This Privacy Notice explains how Neura Labs Oy ("Neura," "we," "us," "our") collects, uses, shares, and protects your personal data when you use the Neura Health application and related services (the "Service"), and the rights you have. It applies to the app and connected features; our separate Website Privacy Policy covers the neura.health marketing website, and our Consumer Health Data Privacy Policy provides additional disclosures for residents of certain U.S. states.

  1. Scope and Roles

We are the controller of the personal data processed through the Service. We use vetted service providers as processors who act only on our instructions under GDPR-compliant data processing agreements (see Section 6). This Notice covers all users of the Service and includes a regional addendum for the United States (Section 15). We have assessed our obligations under GDPR Article 37 and have concluded that, at our current scale of processing, we are not required to appoint a Data Protection Officer; we review this assessment as the Service grows. Privacy enquiries: support@neura.health.

2. Data we process

  • Account and profile: email, name (if provided), password hash, subscription status, settings and preferences.

  • Health and wearable data (special category, GDPR Art. 9): for example activity, heart rate, sleep, body metrics, and related device information, obtained when you connect your wearables or health sources (via the Terra integration), and any health details you choose to enter.

  • Content you capture or upload: photos and images (for example of meals, medical documents, and your profile) and files you attach.

  • Calendar data: if you connect a calendar, the event details we read to provide scheduling and week-planning (stress-forecasting) features.

  • AI chat, voice input, and generated content: the text you enter, voice input (transcribed to text to process your request), the assistant's responses, and health plans, insights, and summaries generated for you. We redact structured identifiers (such as names, emails, and phone numbers) from AI requests where technically feasible, reducing the direct identifiers included in the text sent for AI processing.

  • Telemetry and diagnostics: app events, device model and OS, crash logs, and performance data.

  • Support communications and feedback.

  • Consent records and preferences.

You are never required to enter medical diagnoses or clinical details. Only share what you are comfortable sharing.

3. Purposes and Legal Bases

Health and wearable data and the content of your AI conversations are special-category data under GDPR Article 9. All of our processing of this data — including providing the core features of the Service — takes place on the basis of your explicit consent (Art. 9(2)(a)), which we ask for when you set up the relevant features and which you can withdraw at any time (Section 13). If you do not give, or if you withdraw, this consent, we cannot provide the features that depend on that data. The table below sets out each purpose with its legal bases:

Purpose
Data used
Legal basis (GDPR)

Provide the account and non-health core features (registration, login, settings, subscription status)

Account and profile data

Performance of a contract — Art. 6(1)(b)

Provide health features: sync connected data, generate insights, plans, coaching, and AI chat responses

Connected health and wearable data, AI chat and voice content

Your explicit consent — Art. 6(1)(a) with Art. 9(2)(a); withdraw any time

Security, abuse prevention, reliability

Telemetry, logs, crash & performance diagnostics, minimal identifiers

Legitimate interests — Art. 6(1)(f)

Product analytics and improvement (where offered)

Telemetry, app events, performance data

Consent — Art. 6(1)(a) and ePrivacy rules

Marketing communications (email)

Email address, subscription status

Consent — Art. 6(1)(a), or legitimate interests (Art. 6(1)(f)) for messages about our similar services to existing customers, always with an unsubscribe option; you can object at any time (Art. 21(2))

Comply with law and respond to lawful requests

Account, transactional

Legal obligation — Art. 6(1)(c)

You can withdraw consent at any time (Section 13). Withdrawal does not affect processing carried out before withdrawal, but it means the features that depend on that consent can no longer be provided.

4. Profiling and Automated Decision-Making

To generate personalised insights, plans, and coaching, the Service analyses the data you provide and connect — this is a form of profiling under the GDPR, carried out on the basis of your explicit consent (Section 3). We do not use these processes to make decisions that produce legal effects concerning you or that similarly significantly affect you within the meaning of GDPR Art. 22. Outputs are informational and are for you to review and act on; they are not automated decisions about your rights, eligibility, or access to services.

5. AI Memory and Personalisation

To give you a more continuous experience, the Service may store limited parts of your previous conversations ("memory") to help the assistant recall relevant context such as your preferences or goals and improve the relevance of responses. Memory data is stored within our environment, encrypted in transit and at rest, and is not used to train AI models. You can request a copy or deletion at any time (Section 13), and memory is deleted when your account is removed.

6. Recipients and Subprocessors

We share personal data only with vetted processors under GDPR data processing agreements, to provide the Service, to comply with law, or at your direction. We do not sell your personal data, and we do not use health data for advertising or marketing. Our current processors and recipients are:

  • Microsoft Azure (Microsoft Ireland Operations Ltd / Microsoft Corp.) — cloud hosting, databases, file storage, logging and monitoring (Azure Log Analytics), and all AI processing. AI features run on Azure OpenAI Service and on model deployments in Azure AI Foundry operated within our own Azure environment; prompts and outputs are processed by Microsoft as our processor, are not shared with the underlying model vendors, and are not used to train models. Microsoft may retain limited interaction data briefly for abuse monitoring as described in its documentation. Production deployments are configured to EU regions

  • AlphaAI Technologies Inc. d/b/a Tavily (United States) — web search and public-content retrieval used to ground research answers in current sources. When the assistant runs a research step, we send a de-identified topic query only — for example “hs-CRP reference ranges in adults”. We do not send your name, email, account identifier, device identifier, or your personal measurements or history. Queries are processed in the United States under Standard Contractual Clauses. Tavily does not use our queries to train models.

  • Terra (Terra Enabling Developers Ltd) — unified wearable and health-data integrations with secure (HMAC-signed) webhook delivery.

  • Google Firebase (Google Ireland Ltd / Google LLC) — push-notification delivery (Firebase Cloud Messaging). Some processing may take place in the United States.

  • Google Cloud Storage — file storage for certain Service content.

  • RevenueCat, Inc. (United States) — subscription management and entitlement processing (no health data).

  • Apple / Google — if you purchase through the App Store or Google Play, the store processes your payment as an independent controller under its own terms.

  • Mailgun (Sinch Email), EU sending region — transactional and (where you have opted in) marketing email delivery.

  • Sentry (Functional Software, Inc.) — crash- and error-diagnostics processing, configured to the EU data region, with personal and health data scrubbed from diagnostic events.

  • Grafana Loki — operational log management and monitoring (in addition to Azure Log Analytics, listed above).

We disclose data to public authorities only where legally required and, where health data is involved, only in response to a valid, legally binding request.

7. International Transfers

We prefer EU/EEA data residency where available (for example EU regions for AI and monitoring). Where a processor is outside the EEA, we rely on appropriate safeguards under Chapter V of the GDPR, and in particular on both, as applicable:

            •          Standard Contractual Clauses (Commission Decision (EU) 2021/914) together with a transfer impact assessment and supplementary measures; and/or

            •          the EU–U.S. Data Privacy Framework where the U.S. processor is certified.

We rely on Standard Contractual Clauses as our standing safeguard so that transfers remain lawful even if an adequacy mechanism such as the Data Privacy Framework changes or is invalidated. You can request a copy of the relevant safeguards using the contact details above.

8. Retention

We keep personal data only as long as necessary for the purposes described, then delete or anonymise it:

            •          Account and subscription: while your account is active, then deleted within 90 days of account deletion (billing and security records may be kept longer where required by law, for example under Finnish bookkeeping rules).

            •          Health and wearable data: until you withdraw consent or delete your account; routine cleanup thereafter (typically within 30 days).

            •          AI chat content and memory: kept in your account history until you delete it or your account; Microsoft may keep short-term service logs as described in Section 6.

            •          Telemetry and diagnostics: up to 13 months, then aggregated.

            •          Support tickets: up to 24 months.

9. Security

We apply encryption in transit and at rest, role-based and least-privilege access controls, key management, audit logging, redaction of structured identifiers from AI requests, and signed (HMAC) webhooks for health-data integrations. No method of transmission or storage is completely secure, but we maintain measures appropriate to the sensitivity of the data.

10. Personal Data Breaches

If a personal data breach occurs, we will assess it without undue delay and, where required, notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33), and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34).

U.S. residents: we also comply with the U.S. FTC Health Breach Notification Rule (16 C.F.R. Part 318). If a breach of security involves your unsecured identifiable health information, we will notify you without unreasonable delay and no later than 60 calendar days after discovery (by email together with a clear and conspicuous in-app message), and we will notify the Federal Trade Commission — at the same time as affected individuals where 500 or more people are affected — and, where required, prominent media outlets.

If you believe your account has been compromised, contact us immediately at support@neura.health.

11. Children

The Service is intended for adults aged 18 and over, consistent with our Terms of Service. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from someone under 18 without a proper legal basis, we will delete it promptly.

12. Your Rights (GDPR)

You have the rights to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing (including profiling based on legitimate interests, and an absolute right to object to direct marketing); data portability; and to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, www.tietosuoja.fi) — or with the authority in your country of residence. We extend the controls described in this Notice to all users, wherever they live.

13. How to Exercise Your Rights

Use the in-app Privacy & Data controls or the "Delete my account" option, or email support@neura.health. We verify identity before acting on a request and respond within the timeframes required by law (generally within one month under the GDPR, extendable where permitted). If we decline a request, we will explain why and tell you how to complain or appeal.

14. In-App SDKs and Consent

The app includes a crash- and performance-diagnostics tool (Sentry, configured to the EU data region) that helps us detect and fix errors and keep the Service reliable. It processes diagnostic data (for example crash reports, error events, device model and OS, and performance metrics) on the basis of our legitimate interest in the security and reliability of the Service (Art. 6(1)(f)); we configure it to scrub personal identifiers and health data from diagnostic events, and it is not used for advertising or behavioural profiling. Push notifications are delivered via Firebase Cloud Messaging. The app does not include third-party behavioural-advertising or product-analytics SDKs. If we introduce optional product analytics, they will run only with your consent, which you can give or withdraw at any time in Settings. Our Website Privacy Policy describes cookies used on neura.health.

15. Regional Addendum — United States

Availability note: the Service is currently not offered to, or directed at, residents of the United Kingdom.

If you are a U.S. resident, we honour the privacy laws applicable in your state, including comprehensive state privacy laws and state consumer-health-data laws. Depending on your state, you may have rights to know/access, delete, correct, and port your data, to opt out of "sale," "sharing"/targeted advertising, and profiling, and to appeal a denied request.

            •          No sale or sharing. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

            •          Sensitive information. We limit use of sensitive information: health-related data is used only to provide the Service you request, not for advertising or marketing.

            •          Consumer health data. If you live in Washington, Nevada, or another state with a consumer-health-data law, our separate Consumer Health Data Privacy Policy (https://neura.health/legal/chd-policy) describes the consumer health data we collect, why, with whom it is shared, and your rights (including withdrawal of consent, deletion, and appeal).

            •          Global Privacy Control (GPC). Where required by law, we treat a valid GPC opt-out signal from your browser as a request to opt out of "sale"/"sharing."

            •          Reproductive and other sensitive health data. We do not use it for advertising, and we disclose it only as strictly necessary to provide the Service under confidentiality obligations, or where legally compelled by valid legal process.

            •          Breach notification. See Section 10 for our obligations under the FTC Health Breach Notification Rule and state breach-notification laws.

To exercise these rights, email support@neura.health or use the in-app Privacy & Data settings. You may use an authorised agent, and we may verify your identity and the agent's authority. We respond within the timeframe required by the applicable state law (for example within 45 days in several states, extendable as permitted). If we deny your request, you may appeal by replying to our decision; if the appeal is denied, we will tell you how to contact your state attorney general.

16. Changes to this Notice

We will update this Notice as needed (for example new processors, purposes, or retention). We will communicate material changes in-app or by email, and, where the change requires it, ask for your consent. We keep prior versions available on request.

14. Contact

Neura Labs Oy
Pitkäkalliontie 9, 01800 Klaukkala, Finland
support@neura.health