In short
- Your vault never reaches us. Your notes live as ordinary files on your own disk. We hold no copy and cannot read them.
- Telemetry is one anonymous install count, off unless you turn it on. It is not in the current release and measures nothing about what you use. When you do have it, it is off on a fresh install, off after every update, and sends four values at most once a day. Section 1 lists exactly what it does and does not contain.
- Your AI prompts depend on one choice you make. Use your own API keys and they never touch us. Use our routing and they pass through us. Section 1 explains both.
- We never see your card number. Stripe takes payment as merchant of record.
- No tracking cookies and no consent banner, because we set nothing that needs one. Signing in sets a session cookie, which is the one kind the rules exempt.
- We do not sell, rent or trade personal data. We never have.
Last updated: 29 August 2026. This website is operated by Perpetual Technologies AI Ltd, registered in England and Wales, company number 17330522, registered office 67 High Street, Shoeburyness, Southend-on-Sea, SS3 9AW. We are the data controller, we have no Data Protection Officer, and data protection questions are answered by us directly at contact@perpetualtechnologies.co.uk.
This page covers this website and the account and subscription records created when you buy NeuralVault. The desktop application has its own notice, shipped with the software as PRIVACY.md, covering what it does on your machine. The two are written to agree. The software licence is a separate document again: see the NeuralVault software licence.
What we never see
Your vault, and how the saving works
NeuralVault exists so you stop telling an AI the same thing over and over. Doing that means it has to remember, and remembering means writing things down. Here is where they get written.
Your vault is a folder of ordinary Markdown files on storage you control. When the assistant learns something worth keeping, it saves a note into that folder, on your disk, in a format you can open in any text editor. Nothing about that saving step involves us. There is no account required for it, no upload, and no copy on a server somewhere. Uninstall NeuralVault entirely and your notes are still sitting there as readable files.
We do not receive it, we cannot read it, and we hold no copy. That covers note content, note and file names, what you asked, and what a model answered. We do not measure which features you use, which notes you open, how long you use the application, or whether you use it at all. That holds whatever your settings say: the only optional signal is an anonymous install count, described below, and it carries none of those things.
Optional usage telemetry: one anonymous install count
Not in the current release. The installer available today (v1.0.0-beta) contains no telemetry code at all and sends nothing. What follows describes the signal added in the next release, written down here before you can run it rather than discovered afterwards. An earlier version of our notice said there would never be telemetry at all; the honest version is not “never”, it is never without you switching it on.
It is opt-in. Off on a fresh install, off after an update, and off until you go into Settings and turn it on yourself. No prompt that defaults to yes, no pre-ticked box, and no reminder that nags. Turning it back off takes effect immediately, deletes the random token, and will not degrade the application.
Exactly four values, at most once a day: a random token generated on your machine, the application version, your operating system, and your edition. No account, no email address, no vault path, no note count, no prompt and no model name. The token is random rather than derived from anything about your computer, so it identifies an installation and nothing about you: a token computed from a machine identifier would be stable and reversible, which is an identifier wearing a disguise. Turning the setting off deletes it, so two periods of use cannot be joined together.
What it will contain: anonymous, aggregate product usage. Which features were opened, counts and durations, the application version, the operating system family, and whether an action succeeded. It will be tied to a random identifier generated on your device, which you can reset, and which is not derived from your account, your email, your licence or your hardware.
What it will never contain: no vault content, note names, file names or folder paths. No prompts, model outputs or chat history. No agent inboxes, audit trail entries or permission settings. No account identifier, email address or licence key. Anything outside that list would be a separate opt-in with its own switch, described here before it shipped.
When it ships, this section will be rewritten in the same change that makes it available, to say what it actually sends rather than what it is intended to send. If that has not happened, the feature has not shipped.
Your AI prompts: the one thing that depends on your setup
NeuralVault talks to AI models, and those models run somewhere. There are two ways to arrange that, and they have genuinely different privacy consequences. This is the most important distinction on this page, so it is not buried in a paragraph.
You bring your own API keys
You supply keys for whichever providers you want. NeuralVault calls them directly from your machine.
Nothing passes through us. We never see your prompts, the replies, or which models you use. The traffic is between your computer and that provider, under their terms.
You use our routing
You pay for included credit and pick from a list of models we offer, instead of managing provider accounts yourself.
Your prompts and the replies pass through our provider account to reach the model. We use that to meter what you have spent. We do not use it to train anything, and we do not sell or share it.
Our routing is not available yet. No version of NeuralVault you can install today offers it, and nothing is routed through us at present. It is described here in advance so the change is visible before it happens rather than after. When it ships, this section will state exactly what is retained and for how long, in the same change that makes it available. Bringing your own keys will remain a supported way to use the product, not a temporary concession.
Whichever you choose, sync and connectors stay off until you set them up, and the application asks before contacting a web address you have not approved. The application's own notice describes each of those.
If you run Business, with a team
Everything above still holds: the vault is on hardware you own and we receive none of it. What changes with a team is that more than one person can reach it, so it is worth saying plainly who can see what inside your own company.
Access is scoped per role and per folder, and it is checked on every single read. An agent can only open a folder that its own configuration lists, that your role permissions allow, and, where a plugin is involved, that the plugin was granted. Those conditions are combined with AND, not OR, so widening one of them cannot widen the others: a permissive role setting still cannot reach a folder an agent was never given. A refused read fails and is recorded; it does not quietly return nothing.
Cortex coordinates, and is bound by the same rule. It hands work to the right agent by writing the assignment into that agent's own inbox inside your vault, and agents can pass findings to each other the same way. All of that traffic is notes in your own vault, on your own hardware. It is readable by you, it is part of the record, and none of it is sent to us.
We are not a party to any of it. We do not hold your roles, your folder permissions, your inboxes or your audit trail, and we cannot inspect, override or recover them. That also means recovery is yours: if you remove someone's access or delete a vault, we have no copy to restore it from.
Back to contentsWhat this website collects
When you use the contact form
Your name and email address, which are required, plus company name, area of interest and your message, which are optional. Used solely to reply to you. A hidden anti-spam field that real visitors never see: if it is filled in, we discard the submission.
To stop the form being used to flood us we limit submissions per connection per hour. That means recognising a repeat sender, so we store a one-way scrambled fingerprint of your IP address and a count for 24 hours, then delete it. The address itself is never stored, the fingerprint cannot be reversed, and it is never linked to what you sent.
When you join a waiting list
Two separate lists, for Personal and Business. Each collects your first name and email address, plus company name on the Business list, which is optional. We record which list you joined so we only tell you about the product you asked about.
You get an email when the product is ready and when there is a significant update. Nothing else: no newsletter, no marketing sequence, no sharing or selling. Every email includes a way out, and you can ask us to delete you at any time without giving a reason.
When you subscribe to a newsletter
There are three separate lists: AI Proficiency Training, NeuralVault releases, and general updates. You choose which ones you want when you sign up, and you only ever receive the ones you chose. We keep your email address, which lists you picked, the date you signed up and which page you signed up from.
Nothing starts arriving until you confirm it. Signing up sends one email asking you to click a link, and until you do, your address sits in a separate pending record and receives nothing else. Ignore it and that record is deleted after seven days. This is deliberate: anyone can type anyone's address into a public form, so we ask the mailbox rather than trusting the form. The one exception is when you are signed in to an account and subscribe using that account's own confirmed email address, because that address has already been proved.
We hold your choices so that we can send you less. Every email has a link that opens a page where you can tick or untick individual lists, or stop all of them at once, without signing in or emailing us. That link identifies your row by a random token rather than your email address, so your address never travels in a URL. We do not sell or share any of it, and you can ask us to delete you entirely at any time without giving a reason.
The one exception, stated plainly: if something applies to everyone regardless of preference, such as a change to this policy or a security notice, we may send it to every subscriber. That is not marketing and it is the only case where your choices do not limit what arrives.
When you download the app
We count downloads. The link goes through our own server, which records only which edition and platform you asked for, the version we served, the site that sent you (the domain, never the full address), and the time. Nothing that identifies you: no IP address, no browser fingerprint, no cookie, no visitor id.
It is a count of files fetched, not of people. We cannot tell whether two downloads are two people or one person on two machines, and we are not trying to find out. If the counter fails, the download still works: it was built that way deliberately, so a broken statistic can never stop you getting the software.
When you buy a subscription
Stripe takes the payment as merchant of record, which means Stripe is the seller of record and handles VAT registration, collection and remittance. You enter your card details into Stripe's checkout, not ours. We never see or store your card number. We receive Stripe's references for the customer and subscription, and the order records UK tax law requires.
We hold your account in Supabase: your email address and a hash of your password. We never hold the password itself, and nobody here can read it or recover it, which is why a forgotten one has to be reset rather than looked up. You can create that account on this website or inside the app; either way it is the same single account. Alongside it: your subscription record, the devices that have run on your account, and a short-lived record of which are running right now.
Creating an account sends you one email. It contains a link that confirms the address is yours, and the account cannot be used until you click it. That is a security step rather than marketing: it stops somebody signing up with an address that is not theirs. We do not add you to any mailing list, and there is no marketing opt-in on the form because there is nothing to opt in to.
On the device identifier. A random value generated per installation. It is not a hardware serial number or a fingerprint of your machine. Its only job is to mark a session slot so the limit on simultaneous copies can be held, and those records delete themselves once a machine stops checking in. So replacing, reinstalling or losing a device costs you nothing. A hardware fingerprint would do the same job and would also identify your machine across uninstalls and to anyone else who saw it. We chose the value that does not.
Sign-in records. Our authentication provider keeps its own audit log of sign-in events, including the IP address each came from. That is how account security incidents get investigated.
A licence check that does not exist yet. The software licence and the application's notice both describe a periodic check sending an account token, a device identifier and the application version. That is not built, and no version you can install today performs any part of it. When it exists it will send nothing from your vault. We keep no record of licence checks, because there are none.
When you book an appointment
The booking calendar is an embedded Google Calendar appointment schedule. You are entering details into Google's system, not ours. Google collects what you type, passes the booking to us, and acts as an independent controller under its own privacy policy.
When you simply browse
Our host records standard technical information needed to serve and secure the site, including your IP address, pages requested and browser type. We also run cookieless analytics: see section 4.
Back to contentsWho else sees your data
We do not sell or rent personal data, and we do not share it for anyone else's marketing. It reaches these providers only because they run parts of this business.
| Who | What they hold, and why |
|---|---|
| Vercel Inc. | Hosts this website and provides analytics and performance measurement. |
| Supabase Inc. | Accounts, authentication data, subscription records, device identifiers, live session records, issued licence records, the sign-in audit log, and (moved here from Neon on 2026-08-18) contact form, waiting list and newsletter submissions. Held in a Postgres database in Ireland (AWS eu-west-1, the EU), verified by resolving the project's own database hostname and geolocating the address, not taken from Supabase's marketing copy. |
| Resend | Delivers the emails this site sends: account emails (Supabase's confirmation, password reset and security notices, relayed through Resend's SMTP service), plus, added 2026-08-19, a receipt when you submit the contact form and a welcome message when you join the NeuralVault release list. Each of those two emails contains only what you gave us: your name (contact form) and your email address. |
| Stripe | Takes payment as merchant of record and holds the customer and payment records that go with being seller of record, including card details we never see. |
| Google LLC | The appointment booking calendar. Nothing else on this site sends data to Google. |
Each processes data under its own terms. If we change a provider, we change this page in the same commit.
Back to contentsCookies
This site does not use cookies to track you. We removed Google Analytics in August 2026 precisely because it set cookies and shared what it collected with Google for Google's own purposes, which we were not willing to ask you to accept just so we could count visits.
- Our analytics set no cookies. Vercel Analytics and Speed Insights count page views and measure load speed without storing anything that identifies you.
- The embedded Google Calendar may set cookies if you use the booking widget.
- Stripe Checkout sets cookies needed to process payment and detect fraud, on Stripe's own pages, only if you begin a purchase.
- Signing in sets cookies that keep you signed in, and only if you have an account and use it. They are strictly necessary for a service you asked for, which is the exemption the rules below describe, and they are not used to track you. They hold a short-lived session token and its refresh token, nothing else. Signing out clears them, and they expire on their own if you do not.
- No advertising, profiling or cross-site tracking. None at all.
Because we set no non-essential cookies of our own there is nothing for you to consent to and no banner asking you to. The UK rules are the Information Commissioner's guidance on cookies and similar technologies.
Back to contentsOur lawful basis, per purpose
Stated per purpose rather than in one lump, because that is what tells you which rights apply to which data.
| What | Purpose | Basis under UK GDPR |
|---|---|---|
| Enquiries and bookings | Replying to you and holding the call you asked for | Art. 6(1)(f), legitimate interests |
| Waiting list name and email | Telling you when the product ships | Art. 6(1)(a), consent |
| Account email, authentication data, subscription | Providing the account and subscription you bought, and billing it | Art. 6(1)(b), contract |
| Device identifiers, session and licence records | Issuing a licence that works, and holding the simultaneous-use limit that is a term of that contract | Art. 6(1)(b), contract |
| Sign-in audit log, including IP | Investigating account security incidents and preventing abuse | Art. 6(1)(f), legitimate interests |
| Order records | Meeting UK tax and accounting duties | Art. 6(1)(c), legal obligation |
| Analytics and performance | Knowing which pages are useful and keeping the site fast | Art. 6(1)(f), legitimate interests |
| Contact form rate limit | Keeping the site available and free of spam | Art. 6(1)(f), legitimate interests |
Where the basis is legitimate interests you have a right to object, and section 9 says how. Where it is consent, you can withdraw at any time, and withdrawing does not affect anything sent before you did.
Back to contentsWhere your data goes
Supabase holds the database in Ireland. Vercel, Stripe, Resend and Google process data in the United States. Sending your data to any of them is a transfer out of the UK, the Irish one included, because the rule is about data leaving the UK rather than leaving Europe.
UK law allows a transfer like that on one of three routes: it is approved by regulations, it is covered by appropriate safeguards, or a specific exception applies. Ireland is on the first route, because the regulations approving transfers to the European Economic Area remain in force, so no extra contract is needed for it. For the United States we rely on the second: the safeguards each provider commits to in its own data processing terms, which are standard contractual clauses with the UK Addendum, or the UK Extension to the EU-US Data Privacy Framework where that provider is certified under it.
Back to contentsHow long we keep it
- Enquiries: while we deal with your enquiry and for as long as we have an active business relationship, then deleted.
- Waiting lists: until the product ships and we have told you, or until you ask to be removed.
- Newsletters: until you unsubscribe. After that we keep the record of your address and the date you opted out, so that we can prove we honoured it and so nothing later adds you back by accident. Ask us to erase you and it goes entirely.
- Unconfirmed signups: seven days, then deleted automatically. If somebody enters an address and never confirms it, nothing is ever sent to it again and the record removes itself.
- Accounts and subscriptions: while your account exists. Close it and we delete the account and its device and session records, keeping only what tax law requires.
- Live session records: they delete themselves once a machine stops checking in.
- Order records: six years, which UK tax law requires. We cannot delete these on request within that period.
- Analytics: Vercel Analytics' default retention. Aggregate counts, not a record of you.
- Download counts: kept indefinitely as a running total. There is nothing in them to delete: no row identifies a person, so none can be traced back to you even by us.
- Server logs: kept short-term by our host for security and diagnostics.
How we protect it
The site is served over HTTPS. Access to enquiry data is limited to the people who need it to answer you. Card details never reach our systems at all. We ask for the minimum we need rather than everything we could get, which is the single most effective protection there is: data never collected cannot be lost.
Your account records are locked to your account at the database. Every table holding customer data has row-level security switched on, so a request carrying your sign-in can only ever return your own rows, and one carrying no sign-in returns nothing. The key published in this website's code grants no access on its own: it is designed to be public, and it is the database rules rather than the secrecy of that key that decide what anyone can read. The administrative key that would bypass those rules is not in this website, not in the app, and not in the code we publish.
Sign-in and sign-up are rate limited by our authentication provider, per address and per account, so repeated guessing is slowed rather than unlimited. Passwords are stored only as a hash. We deliberately give the same answer whether an email address has an account or not, on sign-in, sign-up and password reset alike, so that these pages cannot be used to find out who has an account with us.
Back to contentsYour rights
Under UK GDPR you have the right to be told what we hold and receive a copy, to have inaccurate data corrected, to have data deleted, to restrict how we use it, to receive it in a portable format, and to object to processing based on legitimate interest. You will never be charged for exercising these rights and we will not treat you differently for it.
To exercise any of them, email contact@perpetualtechnologies.co.uk. We aim to respond well within the one month the law allows.
If you are unhappy with how we handled your data you can complain to the Information Commissioner's Office at ico.org.uk. We would ask you to raise it with us first so we have the chance to put it right.
Back to contentsChildren, automated decisions and changes
Children
This site is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
Automated decision-making
Nobody is scored, ranked or profiled by a machine on this website, and we make no automated decision producing a legal or similarly significant effect about you.
When the licence check described in section 2 is built, whether it succeeds will be decided automatically from your subscription status and how many copies are already running. A refusal means the application drops to the Free edition. It does not lock, delete anything, or touch your vault. If you think a refusal is wrong, email us and a person will look at it.
Changes to this policy
If what we collect or who processes it changes, we update this page and the date at the top, in the same change that alters the behaviour. We do not make quiet changes.
Back to contentsContact
Questions about this policy, or about anything we hold: contact@perpetualtechnologies.co.uk, or through our contact page.
Perpetual Technologies AI Ltd, company number 17330522, registered in England and Wales. Registered office: 67 High Street, Shoeburyness, Southend-on-Sea, SS3 9AW.
Back to contents