Neuro privacy policy
Version 1 · Last updated 6 October 2026
This policy explains what Neuro keeps about you and your child, why, who else handles it, how long we keep it, and what you can ask us to do. If anything in it is unclear, write to us at privacy@neurochildren.com.
The short version
- Neuro keeps what you log about your child so that you can see it again and take it to a professional. It uses your records for nothing else.
- Your records are stored on servers located in the EU.
- We never sell your data, show you ads, track how you use the app, or use your records for research or to train AI models.
- Nobody else sees your records unless you share them yourself. Our service providers store them for us, and that is all.
- Our separate app for your child shows them only the cards you set up, and records nothing about what they do in it.
- You can delete your account, and everything in it, from the app at any time.
Who we are
Neuro is provided by Yurii Ilnytskyi, a sole proprietor registered in Ukraine (фізична особа-підприємець Ільницький Юрій Іванович). We decide how your data is used, which makes us its controller under the EU's General Data Protection Regulation (GDPR) and its «володілець» under Ukraine's law on personal data protection.
To reach us about your data: privacy@neurochildren.com.
What Neuro is for
Neuro is a diary for people who care for a child: a place to keep records and plans, look back over them and share them with the professionals who work with the child. It does not replace a professional and does not assess a child's condition.
It is for adults caring for a child: a parent, a legal guardian, or someone caring for the child with their permission. It is not meant to be used by children.
What we keep
We keep what you enter or record in Neuro: your account details, such as your email address, and everything you record about your child. Your password is stored in a form nobody can read back, us included. For each phone you are signed in on, we also keep its IP address and what kind of device it is, for as long as you stay signed in there.
You can write anything you like in Neuro, and add any picture you like to your child's cards. Keep in mind that whatever you write is kept exactly as you wrote it, with everything in it, and a photo is kept with everything it shows, such as your child, your family or your home. We only make each picture smaller and remove the hidden details a phone stores in a photo, such as where it was taken.
Using Neuro at all can suggest that your child is neurodivergent. So we treat everything you record about your child, and even the fact that you have an account, as data about health: the most protected kind of personal data.
What we do not collect
Your location or contacts, advertising identifiers, how you use the app, or crash reports. Neuro contains no analytics or advertising code. It does not ask for medical records or for any label your child has been given.
On your phone
Neuro does not store your records on your phone. They come from our server each time you open the app. Your phone keeps only what keeps you signed in, and the language you chose.
In the app for your child
If you set up cards for your child, they can use them in our separate app, on a phone or tablet you give them. That app has no account and no sign-in: you connect it to your account by scanning a code Neuro shows you, and it stays connected until you disconnect it in Neuro. It receives the cards you set up, with their pictures, and nothing else from your account. It records nothing about what your child does in it, and contains no advertising or analytics code.
On our website
neurochildren.com, where this policy is published, has no ads, analytics or cookies, and we keep no record of visits.
Why we use it, and on what legal basis
| What | Why | Legal basis |
|---|---|---|
| The records about your child | So that you can look back over them and share them | Your explicit consent, given when you sign up. GDPR Art. 9(2)(a); Arts. 7 and 11 of Ukraine's law on personal data protection |
| The cards you set up for your child | To show them to your child in our app for them | Your explicit consent, as for the records |
| Your account | To let you sign in, and to send you emails about your account | Providing the service you asked for, GDPR Art. 6(1)(b); your consent under Ukrainian law |
| IP addresses and service logs | To keep Neuro secure and to find and fix faults | Our legitimate interest in a secure service, GDPR Art. 6(1)(f) |
| Visits to our website | To deliver its pages to you | Our legitimate interest in running our website, GDPR Art. 6(1)(f) |
| What you write to us | To answer, and to be able to show that we did | Our legal obligations, GDPR Art. 6(1)(c) |
Neuro makes no automated decisions about you or your child. It puts together summaries of your records itself, without AI models, and only if you switch them on. If we add other features that process your records, they too will work only once you switch them on.
What we never do
- Sell or rent your data.
- Show you advertising, or let anyone track you.
- Use your records for research or statistics, or to train AI models.
- Send your notes to any AI model.
- Share your records with other users, schools, insurers, employers or authorities, except where the law requires it.
Who can see your records
- You, in the app, on each phone where you are signed in.
- Your child, only the cards you set up for them, in our app for them on a device you connect.
- Our service providers, only to run Neuro for us. They are listed below.
- Anyone you share them with yourself. Neuro lets you share your records with the professionals who work with your child, and you choose what to share and with whom. Once you hand a copy to someone, it is outside Neuro and we cannot take it back.
- Authorities and courts, only when the law or a court decision requires us to hand something over, and only what it names. We will tell you, unless the law forbids it.
We do not look at your records ourselves. If you ask us for help with a problem and we need to see them, we will ask your permission first.
Our service providers
| Provider | What they do for us |
|---|---|
| Supabase | Stores the database; handles sign-in |
| Microsoft Azure | Runs our server |
| Render | Hosts our website |
| Resend | Sends sign-up and password emails. It sees your email address and those emails, never your records |
| Google Workspace | Our email, if you write to us |
Each works under a contract that allows them to use your data only to provide their service to us.
Apple's App Store and Google Play distribute our apps, but receive nothing you record in them.
Where your data is
Your records, your child's cards and your account are stored on servers located in the EU.
Two things can be kept outside the EU, including in the United States:
- The emails Resend sends you. Resend keeps a copy of each sign-up and password email, with your email address, for up to 30 days.
- What you write to us. Our mailbox is on Google Workspace, which may keep it in any of Google's data centres.
Supabase is a company based in Singapore; Microsoft, Render, Resend and Google are based in the United States. Their staff may reach your data from outside the EU when their work needs it. For all of this, each company's agreement with us includes the European Commission's standard contractual clauses, and Microsoft, Render, Resend and Google are also certified under the EU-US Data Privacy Framework.
How long we keep it
- Your records, your child's cards and your account: until you delete your account.
- After you delete your account: it is removed from our database at once, and from our backups within 7 days. Copies of the emails we sent you stay in Resend's logs for up to 30 days. Our service logs never contain your records, and keep your IP address for 30 days at most.
- Sign-in on a phone: until you sign out there.
- A device connected to the app for your child: until you disconnect it in Neuro.
- An account nobody uses: if your account is not used for 24 months, we will email you. If it stays unused for 30 more days, we delete it.
- A sign-up never confirmed: if the email address is not confirmed within 7 days, we delete the account.
- What you write to us: 3 years after we have dealt with your request.
- Visits to our website: we keep no record of them.
Your rights
You can ask us to:
- show you your data and give you a copy. Most of it is in the app already, and Profile › Download my data gives you a copy of everything you have logged, with your account details, in a format other apps can read. For the rest of what we keep, such as the phones you are signed in on, write to us.
- correct it. You can change or delete any entry in the app yourself, or ask us.
- delete it. Profile › Delete account deletes your account and everything in it, at once.
- stop using it for a while, or stop using it for a particular reason (restriction and objection). Write to us.
- tell you how it is used: where it comes from, where it is kept, who handles it and why. This policy is our answer; ask if you need more.
Withdrawing consent. You can withdraw your consent at any time by deleting your account. Neuro cannot work without the records, so deleting the account is how consent is withdrawn. It does not change anything we did lawfully before.
How we answer. For free, within one month and never more than 30 days. We may ask you to write from the email address of your account, so that we know the request is yours.
Your child's rights. The records are about your child, and your child has rights over them too. Until your child is 14, you exercise those rights for them. From 14, your child can write to us themselves. We do not read the records, so with your child's agreement we pass the request on to you, and you decide: parents remain a child's legal representatives until 18. From 18, your child decides about the records about them. If they ask us to delete them, we check that the request really comes from them, without reading the records, tell you first so that you can download a copy, and delete them within 30 days.
Requests from anyone else. We give your records only to you. If anyone else asks for them, including your child's other parent, we do not hand them over or say whether you have an account: we answer that records are given only to the account holder or under a court decision. Nor do we delete them at the other parent's request, because we do not settle disputes between parents.
If you are a grandparent, a nanny or anyone else keeping records with a parent's permission, a parent or guardian of the child can object by writing to us. We then ask you who gave the permission. If it was the person who objects, or you do not answer within 30 days, we delete the records about the child. If the child's other parent gave it and confirms, we wait until the parents agree or a court decides.
Keeping it safe
- Everything travels encrypted between our apps and our servers, and Supabase stores it encrypted.
- Our server only ever reads the records of the account that is signed in: every request is checked against your sign-in.
- Our server and our people can reach the database only as far as their work needs.
- Please keep your phone locked. Neuro keeps you signed in so that you do not have to type your password every time, so anyone who can unlock your phone can open it. On a phone you share, sign out when you finish.
If something goes wrong and your data is exposed, we will tell the data protection authority within 72 hours where the law requires it, and tell you without delay if the risk to you or your child is high.
Children
Neuro is for adults. It holds information about a child, given by an adult who cares for them. It is not meant to be used by children, and if we learn that a child has created an account, we will delete it. The one exception is the app for your child described above: it is made for a child to use, and records nothing about what they do in it.
Changes to this policy
We will tell you in the app before a change that matters takes effect. If a change affects what we do with your child's records, we will ask for your consent again. Earlier versions are available on request.
Complaints
You can write to us first, and we will try to put it right. You can also complain to a data protection authority:
- In Ukraine: the Ukrainian Parliament Commissioner for Human Rights (Уповноважений Верховної Ради України з прав людини), ombudsman.gov.ua.
- In the EU: the data protection authority of the country where you live. The list is at edpb.europa.eu.
You can also go to court.