Last updated 20 August 2026
This policy explains what Neurobound collects, why, and what you can do about it. It covers this website and the Neurobound application.
Neurobound operates this website and the Neurobound sales platform. For anything about this policy or about your data, write to alex@neurobound.tech.
For visitors to this website and for the people who hold accounts, we decide what is collected and why. In data-protection terms we are the controller.
For the content customers put into the product — prospect details, campaign material, call transcripts — the customer's organisation decides what goes in and why, and we act only on their instructions, as a processor. If your employer gave you your account, ask them first about that content.
Account data: your email address, name, company name, role in the workspace, language preference, and anything you write in your profile.
Product content: research you request and its results, emails the product generates for you, campaign and lead data you import, transcripts of simulated calls, and the coaching reports built from them.
Usage data: which features were used and how often, model and token counts, and timestamps.
Technical data: your IP address, your browser's user agent, and the requests your browser makes, recorded in server logs.
Support data: problem reports you submit, including a screenshot if you attach one.
The call simulator sends your microphone audio to a speech-to-text provider so the conversation can continue, and plays synthesised speech back. We do not store the audio. What is kept is the text transcript and, when one was produced, the coaching report.
We use PostHog, running on European infrastructure, to see how the product is used.
Until you accept, PostHog runs in cookieless mode: the visit is counted, but nothing is written to your device and no identifier follows you from one visit to the next.
If you accept, an identifier is stored on your device so separate visits can be recognised as the same person, and — once you sign in — connected to your account.
You can change your mind at any time, in the section at the end of this page.
Signing in sets a session cookie. Without it the application cannot tell who you are, so it is not optional and does not ask for consent.
Your theme and language choices are stored in your browser so the app looks the same next time. They never leave your device.
Analytics storage is the only thing here that asks for your consent.
To provide the service you or your employer signed up for, we process account and product data on the basis of that contract.
To keep the service running and secure — server logs, abuse prevention — we rely on our legitimate interest in operating it safely.
To store analytics data on your device, we rely on your consent, and on nothing else.
Our servers and our analytics are in the EU. Several of the AI providers listed above are in the United States, so running a generation, a research task or a simulated call sends the relevant text there. Those transfers rely on the European Commission's Standard Contractual Clauses.
Account data, transcripts and reports are kept for as long as the workspace exists. Deleting a workspace deletes its users and everything attached to them, call history included.
A practice call you did not finish is kept for 24 hours, so you can still ask for a coaching report on it, and is then deleted automatically. Reports you saved stay for as long as the workspace does.
Server logs are kept only as long as they are useful for diagnosing problems, and are rotated.
If you want your data removed sooner, write to us and we will remove it.
You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to limit what we do with it, ask for it in a portable form, or object to processing we base on legitimate interest. Withdrawing consent to analytics is one click and costs you nothing else.
Write to alex@neurobound.tech. If our answer does not satisfy you, you can complain to your national data protection authority.
Traffic is encrypted in transit. The database is not reachable from the internet — only the application server can talk to it. Provider credentials are encrypted at rest. Each workspace's data is separated, and every query is scoped to the workspace that asked.
If this policy changes we update the date at the top, and material changes are announced in the product.
These providers run parts of the service. Each receives only what its part needs.
| Provider | What it does | Where |
|---|---|---|
| OpenAI | Text generation, transcription, speech, live call simulation | United States |
| Deepgram | Live speech-to-text | United States |
| Cartesia | Speech synthesis | United States |
| Apollo.io | Prospect enrichment, only where a workspace enables it | United States |
| Resend | Invitation and password-reset email | United States |
| PostHog | Product analytics | European Union |
| Hetzner | Hosting and databases | Finland, EU |
Analytics is not running in this environment.