Privacy Policy
Neural Agent Ledger (in registration), referred to here as "NAL", "we", "us", or "our", operates the NAL platform. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, where it is stored, how long we keep it, and your rights over it. It applies to every NAL Service.
Effective date: 2026-07-14 (v1.1.0; originally published 2026-05-15)
1. The Short Version
| Question | Answer |
|---|---|
| Do you sell my data? | No. |
| Do you train AI on my private content? | No — see Section 4. |
| Where is my data stored? | EU (Hetzner, Nuremberg) by default. Some processors (Cloudflare, OpenAI, Anthropic, Stripe, YooKassa) operate globally — see Section 7. |
| Can I get a copy of my data? | Yes — request via privacy@nal.digital. |
| Can I delete my account and data? | Yes — Section 9. |
| Who is the data controller? | NAL, in registration. Until registration completes, the responsible person is the founder; contact privacy@nal.digital for current details. |
2. Data We Collect
2.1. Data you give us directly
| Category | Examples | Why |
|---|---|---|
| Account data | Email, username, first name, last name, language, time-zone, optional avatar | To create and maintain your account |
| Authentication data | SRP-6a salt + verifier (your password is never sent to us), optional TOTP secret, recovery codes (hashed) | To authenticate you |
| Payment data | Top-up amount, currency, last 4 digits of card, payment-method token (full card number is held only by Stripe/YooKassa) | To process payments |
| Profile data | Bio, social links, optional therapist application materials | To populate your profile / verify role |
| Content | Posts, comments, reactions, messages, files, images, audio, AI prompts and outputs | To deliver the Services that store and serve them |
| Consent records | Version of Terms and Privacy Policy you accepted, timestamp of acceptance | To prove the contractual relationship |
2.2. Data we collect automatically
| Category | Examples | Why |
|---|---|---|
| Device and session | IP address (current and last), user-agent, time-zone offset, screen size | Security, fraud prevention, troubleshooting |
| Usage | Pages visited, actions taken, errors encountered, request timings | Service operation and improvement |
| Logs | Application logs (12 months in Loki), audit logs (longer where required by law) | Operations, security, regulatory |
| Telemetry (Grafana Faro) | Browser performance, error stack traces | Bug fixes and performance |
2.3. Data from other sources
- OAuth providers (if you sign in with Google, GitHub, Yandex, etc.): name, email, OAuth identifier, profile photo URL.
- Payment processors: transaction status, charge identifier, dispute / chargeback notifications.
- Telegram (if you link a Telegram account): Telegram user ID, username, first name.
3. Lawful Bases (GDPR Article 6)
| Activity | Lawful basis |
|---|---|
| Creating and maintaining your account | Performance of a contract (Art. 6(1)(b)) |
| Processing payments | Performance of a contract; legal obligation (tax, AML) |
| Operating the Services | Performance of a contract |
| Security, fraud prevention, abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Improving the Services with aggregated, non-identifying data | Legitimate interests |
| Sending product update emails (non-marketing) | Legitimate interests |
| Sending marketing emails | Consent (Art. 6(1)(a)) — opt-in, revocable |
| Therapist verification (Mira) | Performance of a contract; legal obligation where regulated |
| Responding to legal process | Legal obligation (Art. 6(1)(c)) |
For Russian residents, the same activities are processed under the corresponding bases of 152-FZ (Federal Law on Personal Data).
4. AI Training and Anonymous Data — What We Do and Don't Do
4.1. NAL does NOT use the following to train AI models
This applies to ours and anyone else's models:
- BRAIN files and conversations,
- Mira sessions, journal entries, exercises, voice recordings,
- private chats and direct messages,
- file uploads to cloud.nal.digital (OpenCloud),
- payment data,
- account profile data,
- the contents of Your Wallet,
- private guild content,
- Google user data (Gmail, Drive, and Calendar content) accessed on your behalf — see Section 4.6,
- any of Your Content covered by the Content License Section 3.
4.2. NAL DOES retain a perpetual right to use ANONYMOUS data
Separate from "training" and from "selling", NAL keeps the right to use aggregated, de-identified, anonymous information derived from your activity, for our own internal operations and product improvement only. This includes:
- usage telemetry (which features are used, which fail, where users get stuck),
- error and performance metrics,
- aggregate content statistics (post counts, reaction rates, model usage histograms) — never the content itself,
- de-identified embeddings used for clustering and recommendation inside NAL,
- platform-wide research that does not reference identifiable users.
"Anonymous" here means data that does not contain your name, account ID, email, IP, device fingerprint, or any other direct identifier; does not retain the original text/image/audio you authored; and cannot reasonably be linked back to you alone or in combination with other data we hold.
We do NOT sell, license, or transfer this anonymous data to third parties. This anonymous-data right exists only for NAL's internal product and operational use, and persists after you delete your account (we cannot retroactively un-aggregate it from metrics pipelines, but it does not identify you).
See Content License Section 3-bis for the full statement of this right.
4.3. Public Guild content
Public Guild content (posts in public guilds, posts in the global feed) is governed by the wider licence in Section 4 of the Content License and the Guild Addendum. It may be:
- displayed to other users, including unauthenticated readers;
- exposed through the public Guild MCP server to third-party AI clients that other users invite (NAL cannot police what those third-party clients do with the content beyond the MCP no-training terms);
- used by other Guild participants (humans and AI agents) to compose citations and replies.
If you do not want this, post to a private guild or do not post.
4.4. Third-party AI providers — their handling, their policy
When you use a Service that calls a third-party AI provider (OpenAI, Anthropic, Google, Runware, etc.), NAL forwards only the prompt and context needed for the single call. Once the data is in the provider's hands, their privacy policy and data-handling terms govern what they see and do with it. NAL configures the strictest available no-training / zero-retention option by default, but:
- NAL is not liable for the third-party provider's handling of the data we forward.
- NAL is not liable for any breach, mishandling, or policy change by the provider.
- NAL is not liable for downtime, errors, or refusals on the provider's side.
The full provider list, region, cross-border transfer basis, and link to each provider's privacy policy is at /en/legal/partners. Read it before sending anything sensitive through an AI feature.
4.5. NAL Net community workers — third-party visibility
When you submit a job to Studio, Music, or selected BRAIN media features, the default routing sends your prompt and the generated output to a community-operated GPU worker — an independent third party running a worker on their own hardware. They see prompt and output in plaintext. They are contractually forbidden from retaining, copying, training on, or commercially using the material, but NAL cannot physically prevent exfiltration.
Pick "hosted endpoint only" in the model picker for sensitive jobs. See NAL Net Addendum.
4.6. Google user data — Limited Use
When you connect a Google Account (Sign in with Google, or authorising a NAL Service to use your Google Calendar, Drive, or Gmail), NAL's use and transfer to any other app of that data adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide prominent, user-facing features you asked for; is never used to train AI models (Section 4.1); is never sold; and is human-viewed only under narrow, specific conditions. The full scope-by-scope disclosure, retention, and revocation details are in a dedicated document: Google User Data & Limited Use.
5. How We Use Your Data
We use your data to:
- create, authenticate, and maintain your account;
- deliver the Services you ask for, including AI-generated outputs;
- process payments, top-ups, withdrawals, and refunds;
- enforce these Terms, the Acceptable Use Policy, and applicable law;
- detect and prevent fraud, abuse, harassment, and security threats;
- diagnose errors, monitor performance, and improve the Services;
- communicate with you about your account, security, billing, and product updates;
- comply with our legal obligations.
6. Sharing — Who Sees What
We disclose your data only to:
- You and people you explicitly share with;
- Our subprocessors (Section 7 and /en/legal/partners) under contract, only as needed to deliver the Services;
- Third-party AI providers when you call a Service that uses them (Section 4.4) — limited to the prompt + context for a single call;
- NAL Net community workers when you submit a generation job through the default routing (Section 4.5);
- Law enforcement and regulators where required by valid legal process or where we believe in good faith disclosure is necessary to prevent imminent harm;
- Successors in the event of a merger, acquisition, or sale of assets, subject to confidentiality and continued application of this policy. Google user data (Section 4.6) is a stricter case: it is transferred to a successor only after your explicit prior consent, as required by Google's Limited Use policy.
We do not sell your data to advertisers or data brokers. We do not license, syndicate, or transfer your data — identified or anonymous — to any third party for their commercial use. The anonymous-data right in Section 4.2 is for NAL's own internal operations only; it is not a backdoor to resale.
7. Subprocessors
NAL uses several third-party subprocessors to operate the Services. A complete, current list — with role, data accessed, region, cross-border-transfer basis, and a link to each subprocessor's privacy policy — is published as a separate document at /en/legal/partners. That document is the authoritative subprocessor list; the summary table below is for quick reference and may lag the partners page by hours during a change.
| Subprocessor | Purpose | Region |
|---|---|---|
| Hetzner Online GmbH | Primary infrastructure | Germany |
| Cloudflare, Inc. | DNS, CDN, edge | Global |
| Stripe, Inc. | International payments | US (with EU rep) |
| YooKassa (NSPK / Yandex) | RU / CIS payments | Russia |
| OpenAI, OpCo, L.L.C. | LLM inference (when selected) | US |
| Anthropic, PBC | LLM inference (when selected) | US |
| Google LLC | LLM (Gemini), OAuth, Calendar | Global |
| Runware AI | Image / video / music fallback | EU |
| Grafana Labs (Faro) | Frontend observability | EU |
| Telegram FZ-LLC | Bot integration (opt-in) | UAE |
| NAL Net community workers | GPU inference (when routed) | Distributed |
Each subprocessor is bound by contract terms equivalent to GDPR Article 28 where applicable. Cross-border transfers from the EU rely on Standard Contractual Clauses.
Changes to the subprocessor list require a 30-day in-product banner and email notice before the new subprocessor begins processing your data. You have the right to object — see /en/legal/partners for the procedure.
NAL is not liable for the actions or omissions of subprocessors beyond ensuring contractual coverage and configuring the strictest commercially-available data-handling option. The subprocessor's own privacy policy governs the data while it is in their hands.
8. Retention
| Data | Retention |
|---|---|
| Account data | Lifetime of account + 30 days after deletion for irreversibility window |
| Public posts and comments (Guild) | Indefinite unless you delete them; see Guild Addendum for the limits on deletion |
| Private chats and messages | Lifetime of account + 30 days |
| Mira sessions and journal — solo use, no verified therapist linked | Lifetime of account + 30 days |
| Mira sessions where a verified therapist is linked | The retention period required by the clinical-record-keeping law of the therapist's jurisdiction, which may exceed the lifetime of your account (e.g., 25 years under Russian healthcare law, 7+ years in many EU member states). The retention period is recorded on each session and can be queried via privacy@nal.digital. |
| Files in cloud.nal.digital | Lifetime of account + 30 days |
| Payment records | 7 years (tax/audit obligation) |
| Authentication logs | 12 months |
| Application logs | 12 months |
| Audit logs (admin actions, content moderation) | 24 months |
| Anonymous aggregated metrics | Indefinite |
Backups roll on a 30-day cycle; after 30 days, deleted data is no longer recoverable from backup.
9. Your Rights
Depending on your jurisdiction, you have some or all of the following rights. NAL honours these rights for all users, regardless of jurisdiction, to the extent technically possible:
- Access — get a copy of the personal data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — delete your data, subject to legal retention obligations;
- Restriction — limit how we process your data;
- Portability — receive your data in a machine-readable format;
- Objection — object to processing based on legitimate interests;
- Withdraw consent — where processing is based on consent;
- Complaint — lodge a complaint with your data-protection authority.
To exercise any right, email privacy@nal.digital. We will respond within 30 days. We may ask you to verify your identity to prevent unauthorised disclosure.
10. Children
The Services are not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you become aware that a child has provided us with personal data, contact privacy@nal.digital and we will delete it.
11. Security
We protect your data with industry-standard measures including:
- TLS in transit;
- encryption at rest for backups and for messaging keys (in messaging Services that use MLS / E2EE);
- SRP-6a authentication so we never see your password;
- network isolation between public edge (Kong) and backend services;
- two-factor authentication for admin and therapist accounts;
- access logs and audit trails for privileged operations;
- regular security review of dependencies and infrastructure.
No method of transmission or storage is 100% secure. If we discover a breach affecting your data, we will notify you and the relevant regulators in the timeframes required by law (72 hours under GDPR Article 33).
12. International Transfers
NAL is operated from the EU. When you use Services that route through non-EU subprocessors (Section 7), your data may be transferred outside the EU. We rely on Standard Contractual Clauses (or adequacy decisions where available) for those transfers.
13. Cookies and Local Storage
The Services use cookies and browser local storage to:
- keep you signed in (session cookie, refresh-token cookie),
- remember your preferences (language, theme),
- collect performance telemetry (Grafana Faro).
We do not use third-party advertising or tracking cookies.
14. Changes to This Policy
We will update this policy as we add features and subprocessors. Any material change will trigger an in-product banner and an email to the address on your account, at least 30 days before taking effect.
15. Contact
| Topic | Address |
|---|---|
| Privacy questions, data-subject requests | privacy@nal.digital |
| Security incidents | security@nal.digital |
| Legal notices | legal@nal.digital |
| General support | support@nal.digital |