Contents
- Scope and Controller
- Personal Data We Collect
- How We Use Personal Data
- Legal Bases for Processing (GDPR)
- How We Share Personal Data
- International Data Transfers
- Data Retention
- Security
- Your Privacy Rights
- Additional GDPR / UK GDPR Rights
- Additional California Rights (CCPA / CPRA)
- Do Not Sell or Share My Personal Information
- Children
- Cookies and Similar Technologies
- Automated Decision-Making
- Changes to This Policy
- Contact
1. Scope and Controller
This Privacy Policy applies to personal data processed by Neural Flow Dynamics LLC as an Illinois limited liability company doing business as [DBA NAME]. For the purposes of the GDPR and UK GDPR, Neural Flow Dynamics LLC is the data controller for personal data collected through the Service.
This Policy does not apply to third-party websites, applications, or services that may be linked from the Service. Those services are governed by their own privacy policies.
2. Personal Data We Collect
2.1 Data you provide
- Account data. Email address, password (stored as a cryptographic hash, never in plain text), display name, subscription plan selection.
- Payment data. We do not store full payment-card numbers. Payments are processed by Stripe, Inc. We receive a tokenized reference, the last four digits of the card, card brand, billing country, and postal code.
- Communications. Messages you send to support, feedback, or survey responses.
- User content. Queries you run, saved views, notes, preferences, and other content you create in the Service.
2.2 Data collected automatically
- Device and connection data. IP address, user-agent, device type, operating system, browser, screen size, general location inferred from IP (country / region, not precise geolocation).
- Usage data. Pages and features viewed, queries run, timestamps, referrer, session identifiers, feature interactions, and error diagnostics.
- Cookies and similar technologies. See the Cookie Policy for categories, retention, and how to manage them.
2.3 Data from third parties
- Payment processor. Stripe provides charge outcomes, fraud signals, and subscription status.
- Sports data providers. We ingest team, player, and game statistics. These are not personal data about you.
- Authentication providers. If you sign in using a third-party identity provider, we receive the identifiers and profile fields you authorize that provider to share.
3. How We Use Personal Data
We use personal data to:
- Create and maintain your account, authenticate you, and secure the Service.
- Process payments, manage subscriptions, and send billing communications.
- Operate the Service, including producing Model Output, dashboards, and other features.
- Respond to support requests and communicate with you.
- Measure and improve the Service, diagnose issues, and develop new features.
- Detect, investigate, and prevent fraud, abuse, and violations of our Terms and Acceptable Use Policy.
- Comply with legal obligations, establish or defend legal claims, and enforce our rights.
4. Legal Bases for Processing (GDPR)
For individuals in the European Economic Area, United Kingdom, or Switzerland, we rely on the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Account creation, authentication, delivery of the Service | Contract (GDPR Art. 6(1)(b)) |
| Billing, subscription management, tax and accounting records | Contract and legal obligation (Art. 6(1)(b), 6(1)(c)) |
| Service security, fraud prevention, abuse monitoring | Legitimate interests (Art. 6(1)(f)) |
| Product analytics, usage measurement, error tracking | Consent where required; otherwise legitimate interests (Art. 6(1)(a) or (f)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Responding to legal process, establishing or defending claims | Legal obligation / legitimate interests (Art. 6(1)(c), 6(1)(f)) |
Where we rely on legitimate interests, you have the right to object as described in Section 10.
5. How We Share Personal Data
We share personal data only as described in this Policy. Categories of recipients include:
- Service providers (processors) who act on our instructions under written data-processing agreements, including our payment processor (Stripe), our hosting and database providers, email delivery, error tracking, and customer support tooling.
- Professional advisers such as auditors, accountants, and lawyers, under duties of confidentiality.
- Legal and regulatory authorities where we are required to disclose by law, legal process, or a good-faith belief that disclosure is reasonably necessary to comply with legal obligations, protect rights, or prevent harm.
- Corporate transactions. In connection with a merger, acquisition, reorganization, financing, or sale of assets, subject to customary confidentiality protections and continued application of this Policy.
We do not sell personal data for money, and we do not currently engage in cross-context behavioral advertising. See Section 12 for California-specific disclosures.
6. International Data Transfers
We are based in the United States. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States and in other countries where our service providers operate. Those jurisdictions may have data-protection laws different from those in your country.
For transfers of personal data out of the European Economic Area, United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (2021 SCCs) and the UK International Data Transfer Addendum where applicable, together with supplementary technical and organizational measures.
7. Data Retention
We retain personal data for as long as necessary to provide the Service, comply with legal obligations (including tax and accounting retention periods), resolve disputes, and enforce our agreements. Typical retention periods include:
- Account data — for the life of your account and up to 24 months after deletion, unless a longer period is required by law.
- Billing records — up to 7 years, as required by U.S. tax and accounting rules.
- Operational logs — generally 30 to 365 days, depending on log type.
- Support communications — up to 3 years from last contact.
When no retention purpose applies, we delete or de-identify the data.
8. Security
We implement administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit (TLS), encryption at rest for sensitive stores, access controls and least-privilege provisioning, password hashing, logging and anomaly monitoring, vulnerability management, and employee confidentiality obligations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please choose a strong, unique password and notify us immediately at [SUPPORT EMAIL] if you suspect unauthorized access to your account.
9. Your Privacy Rights
Subject to applicable law, you may have the following rights with respect to your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — ask us to delete personal data we hold about you, subject to legal retention obligations.
- Portability — request a copy of your data in a structured, commonly used, machine-readable format.
- Restriction or objection — ask us to limit how we process personal data, or object to processing based on our legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw that consent at any time (this does not affect the lawfulness of processing carried out before withdrawal).
- Lodge a complaint — with your local supervisory authority.
To exercise any of these rights, email [SUPPORT EMAIL] with the subject line “Privacy Request”. We may need to verify your identity before fulfilling the request. We will respond within the timeframes required by applicable law (generally 30 days under GDPR, 45 days under CCPA/CPRA, extendable once with notice).
10. Additional GDPR / UK GDPR Rights
If you are in the European Economic Area, United Kingdom, or Switzerland, you may contact your data-protection authority if you believe we have not adequately addressed a concern. A list of EU data-protection authorities is maintained by the European Data Protection Board. In the United Kingdom the authority is the Information Commissioner’s Office (ICO).
Representative. We do not currently appoint an EU or UK representative under Article 27, as we do not meet the criteria that would require one. If that changes we will update this Policy.
11. Additional California Rights (CCPA / CPRA)
California residents have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information. We do not discriminate against consumers for exercising these rights.
Categories collected in the last 12 months. Identifiers, customer records, commercial information (subscription activity), internet and network activity, inferences drawn from the above, and geolocation inferred from IP. We do not intentionally collect any special categories of sensitive personal information other than account credentials.
Sources. You, your device, our service providers, and authentication providers you use.
Business purposes. Providing the Service, billing, security, fraud prevention, product improvement, and legal compliance.
Disclosures for a business purpose. To the service providers described in Section 5, under written contracts that restrict use to the specified business purpose.
12. Do Not Sell or Share My Personal Information
We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. If that changes, we will update this Policy, provide a visible “Do Not Sell or Share” mechanism, and honor Global Privacy Control (GPC) signals as required by California law.
To submit any California privacy request, email [SUPPORT EMAIL] with the subject line “California Privacy Request”.
13. Children
The Service is intended for adults aged eighteen (18) or older. We do not knowingly collect personal data from children under eighteen. If you believe a child has provided us with personal data, please contact [SUPPORT EMAIL] and we will delete it promptly.
14. Cookies and Similar Technologies
We use strictly necessary cookies to operate the Service, and — only with your consent where required — additional cookies for functionality and analytics. For the full list of categories, specific cookies, and how to manage them, see our Cookie Policy. You can change your cookie choices at any time from the Cookie Preferences link in the footer.
15. Automated Decision-Making
The Service produces statistical Model Output using automated methods. These outputs are research and informational products and are not used to make decisions that produce legal or similarly significant effects about you. If that changes we will update this Policy and provide the information required under GDPR Article 22.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will provide notice, such as by email or by posting a prominent notice on the Service, before the changes take effect. The “Effective date” at the top of this Policy indicates when it was last revised.
17. Contact
[MAILING ADDRESS]
Email: [SUPPORT EMAIL] (subject line “Privacy Request”)
This Privacy Policy is provided for review and reflects enterprise-grade defaults. Before relying on it for customer-facing use, it should be reviewed and finalized by qualified legal counsel licensed in your jurisdiction.