Trust & your data
NeuroMyelin Privacy Policy
NeuroMyelin is built to keep your information private. Here is what we hold and the choices you have.
FluxProtection Ltd · Last updated September 2026
Who we are
NeuroMyelin is a private work memory system operated by FluxProtection Ltd. This policy explains what we hold, why we hold it, and the choices you have. If anything here is unclear, please ask us.
What we store
We store the things you choose to save, such as notes, documents, screenshots, files and procedures. We also keep your account details, which are your email address and your display name, your sign in sessions, and a history of security events on your account. If you add an AI provider key it is encrypted before it is stored and is never shown back to you.
What we do not do
We do not sell your data, use your saved content to train AI models or run advertising analytics. With your consent, Google Analytics measures navigation through generic page labels and key steps such as signup, verification, imports, first capture and first successful Recall. Analytics is optional; its cookies distinguish browsers and sessions. We do not send memory titles, saved content, filenames, search terms, AI conversations, query strings or record identifiers to Google Analytics. Workspace access depends on membership and permissions. If you create a public share, people outside the workspace can view the shared content subject to its link settings.
How AI is used
Normal saved-memory Recall does not require AI. AI-enabled features use a personal or workspace provider, depending on configuration and plan. They may send the question and relevant context to that provider. Ask AI lets you choose whether to include search results. Other AI-enabled workflows may send the context they use. Provider terms apply to that processing.
Access and protection
Access to workspace content depends on membership and permissions. Public links let others view an item under the sharing settings you choose. HTTPS encrypts information sent between your browser and NeuroMyelin. See the security page for sign-in options, password-protected memories and sharing controls.
Connected email and public sharing
If you connect an email account, we store the connection and indexed email information needed for email Recall. Connected mail is scoped to the user who connected it, not shared with other workspace members. Public shares record opens as viewing sessions, not identified people. A recipient can optionally request an emailed link; marketing updates require a separate choice and confirmation.
Desktop waiting lists
If you request a place on a Windows or Linux waiting list, we store your email address, chosen platform, request date and email verification status. You join only after confirming ownership of your email. Unverified requests expire after 48 hours and are automatically removed. A built-in request check and temporary hashed IP and email counters help limit automated requests; the check uses no external provider. We use your verified entry for updates about that release. Joining a waiting list does not subscribe you to general marketing emails. Platform administrators can view and export account emails, last login dates, waiting list membership and marketing preferences. Workspace administrators and members cannot access this directory. You can remove a waiting list entry using the link in its confirmation email.
Public traffic and service measurement
We count successful requests for approved public pages on our own server, including requests from visitors who decline Google Analytics. These counts use no analytics cookies or visitor IDs. The temporary counting logs exclude IP addresses, request headers, query strings, form values and private routes. They rotate hourly and are normally removed within about 26 hours. Only daily totals are retained for 395 days. We also count operational milestones, including verified accounts and completed imports, and keep first-use flags on accounts to prevent duplicate milestone counts. This supports our legitimate interest in checking and improving the service; these totals are not sent to Google and do not subscribe anyone to marketing. Google Analytics runs only with your consent. The Cookies page explains the information it receives and how to withdraw consent.
How long we keep it
We keep your content for as long as your account is open. Sign in sessions expire on their own, and old ended sessions are cleared automatically. Account deletion has a 30-day grace period so you can cancel a request made by mistake; after that, the account and its data are removed.
Your rights and choices
You can use the available export tools and delete individual items or request account deletion. Exports are subject to permissions and the export option. Password-protected memories and their linked content are excluded. If you are in the UK or EU you also have the right to access, correct, erase and move your personal data. The Data page explains how to do each of these.
Contact
If you have any questions about how your data is handled, or you would like to use one of your rights, please email [email protected].