Who operates the service
Neural Notes is provided by PearaByte LLC. Questions and privacy requests can be sent to support@pearabyte.com.
Local use
You can use Neural Notes offline and signed out. Notes and settings are stored locally in the app’s workspace database. Account workspaces are separate from the signed-out workspace. Files you explicitly save or export may remain elsewhere on your device.
Account and cloud information
When you create or use an account, the service processes your email, display name, password hash where applicable, linked-provider identifiers, sessions, device information, and account capabilities. These support authentication, recovery, sync, sharing, and security. Passwords are hashed; Secure private keys are kept on clients rather than sent to the backend.
Standard cloud Neurons contain notes, files, and related metadata that the server can process. Secure Neuron content is encrypted on clients; the server stores ciphertext, encrypted key envelopes, public keysets, and the metadata needed for sync, file transfer, and access control. Secure does not mean that all account or sharing metadata is hidden.
Sharing and messages
When you invite someone, we process their email and invitation details and may send them an invitation before they have an account. Shared content is available to the authorized recipients. People may retain copies they have already downloaded. Transactional email supports verification, password recovery, invitations, and account deletion.
Service providers and technical records
Hosting infrastructure is provided through OVHcloud. Transactional email uses Resend. Google or Apple processes its own sign-in flow when that option is enabled and used. These providers may process data in countries different from yours under their own terms and privacy practices.
Technical and security records can include request times, network addresses, app/device versions, error codes, and delivery status. Manual account and sync diagnostics remain on your device unless you choose Send report in Settings. Sending requires sign-in. The optional What gets sent? section explains the report, which includes: a random report ID, time, app version, platform/OS, release channel, action, recognized error category, and whether the action was marked as involving Secure features. Reports omit raw error messages and stacks. The server filters reports again before storage in the administrative report queue; account identity, note content, filenames, passwords, access tokens, and Secure secrets are not included in the stored report.
The app keeps up to 120 recent diagnostic entries in memory for the current session. Clearing diagnostics clears that local list, not records already sent. Submitted reports expire after 30 days and are removed by scheduled, bounded cleanup. Reports do not contain your account ID, so account deletion cannot identify individual reports. Diagnostic email forwarding is disabled when this queue is enabled. Network/security logs are separate from report contents. Do not put sensitive content into support messages unless it is necessary to resolve your request.
Administration and access records
Authorized administrators can look up accounts, devices, entitlements and cloud Neuron metadata, review submitted reports, and inspect Standard note content for support and moderation. Secure note content remains encrypted and is not available in the admin console. Administrative actions and content access are recorded for 90 days before scheduled cleanup. Account changes, manual Pro access and pack grants may be managed by administrators.
This website
These pages do not include advertising trackers or analytics scripts. The account page keeps authentication tokens in page memory, not cookies or browser local storage. Closing or reloading it clears that browser state. The server may retain the resulting session until sign-out, revocation, or expiry.
Retention and deletion
Active account and cloud data is kept to provide the features you use. Account deletion removes the account database records and owned cloud content when confirmed. A hash of the deletion proof and hashed sign-in identifiers used to block delayed sign-ins expire after 24 hours and is removed by scheduled cleanup. Normal terminal account-mail and action history is pruned after seven days; account deletion removes the account-linked records sooner.
PearaByte does not currently operate a separate customer backup archive for this private-test deployment. Operational logs are rotated according to infrastructure limits, not kept as an account backup; the retention interval varies with activity. Records already held by infrastructure, identity, or email providers follow their applicable retention practices. Contact us with a privacy request concerning these records.
Content contributed to Neurons owned by others, independent signed-out workspaces, exported files, and copies already held by recipients are not remotely erased by deleting your account. See the deletion page for the complete process and limits.
Your choices and requests
Use Profile to manage account settings and remove this device’s account data. Use the app’s available export tools to save your work. You may ask us about access, correction, deletion, or other rights available under the laws that apply to you. We verify ownership before disclosing or deleting account information.
Changes
We will update this notice as private testing and the service evolve. Material changes will be identified here or communicated through an appropriate account channel.