Privacy Policy: How Neuri Protects Your Cognitive Data

Home / Privacy Policy: How Neuri Protects Your Cognitive Data

Privacy Policy

Effective Date: 24/04/2026 Last Updated: 24/04/2026

This Privacy Policy explains how Neuri (“Neuri“, “we“, “us“, “our“) collects, uses, shares, and protects personal data when you access or use the Neuri mobile application and any related websites or services (together, the “Service“).

For the purposes of the EU/UK General Data Protection Regulation (“GDPR“), Neuri is the controller of your personal data.

If you have any questions about this Privacy Policy or your personal data, you can reach us at:


1. Scope

This Privacy Policy applies to personal data we process when you:

  • install, open, or use the Neuri mobile application;
  • create a Neuri account or sign in with a supported identity provider;
  • purchase a subscription through the Apple App Store (or, where available, another supported store);
  • answer onboarding or in-app questionnaires, or submit feedback through the Service;
  • receive transactional emails (such as verification codes or password-reset codes); or
  • contact us for support.

It does not apply to third-party websites, apps, or services that may link to or integrate with the Service. Their privacy practices are governed by their own policies.

2. Who This Policy Applies To

The Service is intended for users 16 years of age and older. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us at support@neuri.app and we will delete it.

3. Categories of Personal Data We Collect

We collect only the data we need to operate, secure, and improve the Service. Depending on how you use it, the following categories may be collected.

3.1 Account and Profile Data

  • Account identifiers — unique account ID, auto-generated username, display name, first name, last name (optional), profile photo URL (optional).
  • Email address — collected for email/password sign-up, sign-in, email verification, password reset, and important account notices.
  • Authentication identifiers — depending on which sign-in method you choose:
    • Sign in with Apple (iOS): the stable Apple user identifier, and — only on first sign-in, and only if you allow it — your name and relay email provided by Apple.
    • Google Sign-In: the stable Google user identifier and email address.
    • Telegram authentication (where available, for the Telegram version of Neuri): your Telegram user ID, first name, last name, username, profile photo URL, and language_code.
    • Email and password: email address and a salted cryptographic hash of your password (we never store the plaintext password).
  • Verification data — one-time verification codes and password-reset codes (short-lived; expire within minutes).
  • Activity data — last-active timestamp, current authentication token, and per-request trace identifiers.

3.2 Learning and Performance Data

When you use the Service, we collect information about how you interact with the content feed:

  • Answers to interactive content items (quizzes, memory prompts, logic puzzles, reading tasks, and similar) and whether they were submitted correctly.
  • Per-session events about how you move through the feed, including which items you viewed, replayed, or skipped, and the direction of swipes.
  • Aggregated performance indicators derived from your activity — streak, total answers, per-skill and sub-skill scores (attention, executive function, memory, language, visuospatial, social cognition, processing speed, general knowledge, and their sub-skills), daily progress values, and the NeuriPower index.

Performance indicators are not medical data. These indicators are personal performance metrics for training and entertainment purposes. They are not clinical assessments and are not intended to diagnose, treat, cure, or prevent any condition.

3.3 Subscription and Purchase Data

  • In-app purchase records — store platform (Apple App Store or another supported store), product identifier, original transaction ID (Apple) or equivalent purchase token, subscription status and expiry date, environment (sandbox or production), storefront and region code, price and currency as reported by the store, the raw receipt or transaction payload from the store, and analytics metadata associated with the purchase (for example, the paywall variant shown to you).
  • We do not collect, receive, or store your payment-card details. All payment processing is handled by Apple (or the applicable store).

3.4 Referral Data (where available)

Where the referral program is available in your version of the Service, we process:

  • Your personal referral code or link and the unique token that identifies it.
  • The fact that a new account was created from a given referral code or link, and whether it met the qualifying conditions.

The referral feature relies on a short-lived referral token passed at sign-up; it is not built on cross-app tracking of individual users.

3.5 Surveys and Feedback

  • Your answers to onboarding questions (goals, preferences, context).
  • Any messages, screenshots, or files you send to us through support channels.

3.6 Device and Technical Data

  • Device platform (iOS / Android / web) and, where provided by the operating system, basic device model and OS version.
  • App build number and version; app bundle identifier.
  • Timezone offset (in minutes from UTC) and device language / locale.
  • IP address associated with API requests (used for security and abuse prevention).
  • Log data generated by our servers — request paths, timestamps, HTTP status, error messages, and correlation IDs (X-Request-Id).
  • Crash, exception, and performance telemetry (see Section 3.8).

3.7 Attribution and Marketing Data (via AppsFlyer)

To understand how people discover the Service and to measure marketing campaigns, we use AppsFlyer. With your consent where required, AppsFlyer collects:

  • AppsFlyer device identifier (AppsFlyer ID), Apple IDFV (Identifier for Vendor), and — only if you grant permission through Apple’s App Tracking Transparency (“ATT“) prompt — Apple IDFA (Identifier for Advertisers). On Android, AppsFlyer may use Google Advertising ID where permitted.
  • Install source, attribution signals, campaign / media-source / placement identifiers, and deep-link values.
  • In-app events you trigger, such as completing registration, completing onboarding, viewing a paywall, starting a free trial, and similar lifecycle events.

If you do not grant ATT permission, we do not receive your IDFA and we do not use tracking data to show you personalised ads across unrelated apps and websites.

3.8 Diagnostic Data (via Sentry)

To detect bugs and maintain reliability, we use Sentry to receive:

  • Error reports and stack traces when the app crashes or an exception is thrown.
  • HTTP breadcrumbs for recent requests (method, URL, status code, duration, trace ID), with sensitive values redacted where reasonably possible.
  • App release version, build number, environment (development / production), and basic OS information.
  • Minimal user context (such as account ID) so we can distinguish errors across users. You can ask us to remove your historical diagnostic data at any time.

4. How We Collect Personal Data

We collect personal data in three ways:

  • Directly from you — when you create an account, fill in a profile, answer onboarding questions, use a referral link, purchase a subscription, or contact support.
  • Automatically, from your device — through the app’s runtime and standard server logging, including technical data listed in Section 3.6.
  • From third parties — from identity providers (Apple, Google, and, where applicable, Telegram) when you sign in, from Apple (or the applicable store) when a purchase or subscription status changes, from AppsFlyer for attribution, and from Sentry for diagnostics.

5. Purposes and Legal Bases for Processing

For users protected by the GDPR or similar laws, we rely on the following legal bases:

PurposeExamplesLegal basis (GDPR)
Create and operate your accountSign-in, authentication, profilePerformance of a contract (Art. 6(1)(b))
Provide the core ServiceShow and score feed content, track progress, save preferencesPerformance of a contract
Process subscriptionsValidate receipts, restore purchases, enforce entitlementsPerformance of a contract
Keep the Service secureFraud detection, abuse prevention, rate limitingLegitimate interests (Art. 6(1)(f))
Diagnose bugs and reliability issuesSentry error reportsLegitimate interests
Attribution and product analyticsAppsFlyer install source and lifecycle eventsConsent (where required) (Art. 6(1)(a)) or legitimate interests
Send service messagesVerification codes, receipts, important account noticesPerformance of a contract
Optional marketing / promotional messagesIn-app promotions, email campaignsConsent — you can withdraw at any time
Referral program (where available)Attribute a new sign-up to a referrer and apply any eligible rewardPerformance of a contract
Product improvementAggregated analytics on how the feed is usedLegitimate interests (we use aggregated / de-identified data where feasible)
Comply with law, defend legal claimsTax, consumer-protection, disputesLegal obligation / legitimate interests

Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing that occurred before withdrawal.

6. App Tracking Transparency (iOS)

On iOS devices, before we — or our partners — use Apple’s IDFA or use your data to track you across apps and websites owned by other companies, we will ask for your permission through Apple’s App Tracking Transparency prompt. You can change your choice at any time in:

iOS Settings → Privacy & Security → Tracking → Neuri

Declining the ATT prompt does not disable core functionality of the Service.

7. Third Parties and Sub-Processors

We share personal data with the following categories of third parties only as needed to operate the Service. They act as our processors or as independent controllers for their respective services.

7.1 Identity Providers

  • Apple Inc. — “Sign in with Apple” on iOS.
  • Google LLC — “Sign in with Google”.
  • Telegram FZ-LLC — Telegram sign-in for the Telegram version of Neuri, where available.

When you sign in, the provider shares a stable identifier and, depending on the provider and the permissions you grant, basic profile data (name, email, avatar, language). Their use of your data is also governed by their own privacy policies.

7.2 Payments and Subscription Validation

  • Apple Inc. — App Store billing, receipt validation, and subscription status changes via server-to-server notifications.
  • Where the Service is made available on other stores (for example, Google Play or Telegram Stars), those stores will likewise process your purchase under their own terms.

7.3 Analytics and Attribution

  • AppsFlyer Ltd. — mobile attribution, campaign measurement, and in-app event analytics.

7.4 Diagnostics and Performance

  • Functional Software, Inc. (d/b/a Sentry) — error tracking and reliability monitoring.

7.5 Email Delivery

  • An SMTP email-delivery provider is used to send transactional email such as verification and password-reset codes. These emails are sent from noreply@neuri.app.

7.6 Hosting and Infrastructure

We host the Service on third-party cloud infrastructure. Data is stored in managed PostgreSQL databases and related systems operated by our hosting providers. We rely on industry-standard encryption in transit (HTTPS / TLS) and at rest.

7.7 Business Transfers

If Neuri is acquired, merged, or transfers substantially all of its assets, personal data may be transferred as part of that transaction. We will provide notice and an opportunity to object where required by law.

7.8 Law Enforcement and Legal Requirements

We may disclose personal data when we reasonably believe it is necessary to comply with a law, legal process, or enforceable governmental request, to protect the rights, property, or safety of Neuri, our users, or the public, or to enforce our Terms.

We do not sell your personal data, and we do not share your personal data for cross-context behavioural advertising as those terms are defined under U.S. state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA).

8. Data Retention

We retain personal data only for as long as is necessary for the purposes set out in this Privacy Policy.

Data categoryTypical retention
Account profile dataUntil you delete your account
Learning and performance historyUntil you delete your account
Subscription and purchase recordsFor the life of the subscription plus up to 7 years, to satisfy tax, accounting, and consumer-protection obligations
Referral tokens and referral attribution recordsUntil you delete your account or until the token expires, whichever is earlier
Verification and password-reset codesUp to 10 minutes (short-lived; invalidated after use)
Server logsUp to 90 days for operational logs; up to 12 months for security-relevant logs
Sentry diagnostic eventsUp to 90 days
AppsFlyer attribution dataUp to 24 months, or as set by AppsFlyer’s product configuration
Support correspondenceUp to 3 years after last contact

When you delete your account, we delete or irreversibly anonymise your personal data, except where we must retain it to comply with a legal obligation, resolve a dispute, or enforce our agreements.

9. Your Rights

Subject to your location, you may have the following rights in relation to your personal data:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your personal data (you can also do this directly via Profile → Settings → Delete Data).
  • Restriction — ask us to limit how we use your data.
  • Portability — receive certain data in a structured, commonly used, machine-readable format.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent — where processing is based on consent (for example, optional marketing or ATT-based tracking).
  • Complaint — lodge a complaint with a data-protection authority, including your local supervisory authority in the EU/EEA or the UK ICO.

Residents of California and certain other U.S. states may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA“), and similar U.S. state privacy laws. These rights may include:

  • Right to know / access — request the categories and specific pieces of personal data we have collected about you, the categories of sources, the purposes of collection, and the categories of third parties to whom we disclose personal data.
  • Right to delete — request deletion of personal data we collected from you, subject to legal exceptions.
  • Right to correct — request correction of inaccurate personal data.
  • Right to opt out of sale or sharing — opt out of the sale of personal data or sharing of personal data for cross-context behavioural advertising. Neuri does not sell personal data and does not share personal data for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
  • Right to limit use of sensitive personal information — where applicable, request that sensitive personal information be used only for limited permitted purposes.
  • Right to non-discrimination — you will not be discriminated against for exercising your privacy rights.

To exercise your rights, email support@neuri.app from the email address associated with your Neuri account. We may ask you to verify your identity before acting on your request. We will respond within the timeframes required by applicable law (generally within one month under GDPR and within the period required by applicable U.S. state privacy laws).

If we deny or limit your privacy request and applicable law gives you a right to appeal, you may appeal our decision by emailing support@neuri.app within 60 days of receiving our response. Please include your original request, the date of our response, and a short explanation of why you believe our decision was incorrect.

10. Account Deletion

You can delete your Neuri account at any time from within the app:

Profile → Settings → Delete Data

Deleting your account removes your profile, learning history, performance analytics, and other associated personal data from our systems. Deletion does not automatically cancel a subscription billed through the Apple App Store or another store — you must cancel the subscription separately through the respective store to stop future renewals.

11. Sensitive Personal Data and Biometric Data

Neuri does not intentionally collect biometric identifiers, biometric templates, precise geolocation, government identification numbers, genetic data, or other sensitive personal data unless this is clearly disclosed and, where required by law, you have given prior consent.

The learning and performance indicators generated by the Service are used for personal training, entertainment, product functionality, and product improvement. They are not medical data, biometric data, clinical assessments, or health diagnoses.

If we ever introduce a feature that requires processing sensitive personal data, we will explain the purpose, request consent where required, and allow you to withdraw that consent in accordance with applicable law.

12. Direct Marketing and Communications

We may send you direct marketing or promotional communications only where permitted by law and, where required, only after you have given consent. These communications may include email, push notifications, or in-app messages about Neuri features, offers, updates, or relevant content.

You can opt out of marketing communications at any time by using the unsubscribe instructions in the message, changing your in-app notification settings where available, disabling push notifications in your device settings, or contacting support@neuri.app.

Opting out of marketing does not stop essential service messages, such as verification codes, password-reset emails, subscription notices, security alerts, or important account-related communications.

13. Security

We use technical and organisational measures designed to protect your personal data, including:

  • HTTPS / TLS encryption for all traffic between the app and our servers.
  • At-rest encryption for database storage where provided by the hosting platform.
  • Hashed passwords (salted, with a strong key-derivation function).
  • Short-lived authentication tokens.
  • Access controls and the principle of least privilege for operational access.
  • Application-level logging and monitoring to detect abuse.

No method of transmission or storage is 100% secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant authorities where required by law.

14. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If we learn we have collected such data, we will delete it. Parents or guardians who believe their child has used the Service without authorisation should contact support@neuri.app.

15. Automated Decision-Making

The Service uses automated logic to personalise the feed content you see (for example, to recommend items appropriate to your demonstrated level). These decisions do not produce legal effects concerning you or similarly significantly affect you. You can opt out of personalised content recommendations by contacting us.

16. Cookies and Similar Technologies

The Neuri mobile application does not use browser cookies. We use local storage on your device to keep you signed in (authentication tokens and minimal UI preferences). We also use mobile advertising and analytics identifiers as described in Section 3.7, subject to your ATT choice on iOS.

17. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or for legal, operational, or regulatory reasons. The updated Policy will be posted at https://neuri.app/privacy-policy/ with a revised “Last Updated” date. When changes are material, we will notify you in-app or by email where appropriate.

18. How to Contact Us

For any privacy-related question or to exercise any of the rights described above:


© 2026 Neuri. All rights reserved.