NeuroPath — Privacy Policy
NeuroPath is a habit, attention and recovery tracking app. This policy explains what it collects, why, and what control you have. It is written to be read, not to be survived.
The short version. Your recovery data is never sold, never shared with advertisers, and never sent to analytics. Screen-time data never leaves your phone. Deleting your account permanently erases everything — there is no retention window.
1. Who we are
NeuroPath is operated by Talha Bin Zubair, an individual developer based in Dubai, United Arab Emirates ("we", "us"). We are the data controller for the information described here.
Contact: privacy@getneuropath.com
2. Who can use NeuroPath
NeuroPath is for adults. You must be 18 or older, or the age of majority where you live, whichever is greater. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.
3. What we collect
| Data | Why |
|---|---|
| Email address, display name, time zone, language | To create and operate your account, and to compute your day boundaries correctly |
| Password (stored only as a salted hash — never in readable form) | To sign you in |
| Habits, completions, streaks, focus sessions, challenges, activity logs | The core function of the app |
| Recovery data — the category you track (which may include pornography, social media, gaming, shopping, short-form content or phone overuse), streak dates, urge logs and trigger notes | To show your streaks, personal best and patterns. This is the most sensitive data in the app and is treated accordingly. |
| Sleep entries and bedtime settings | Sleep tracking and the optional wind-down reminder |
| Health data — steps, exercise and sleep, read from Apple Health or Health Connect with your permission | To display progress and auto-complete step/sleep verified habits |
| Push notification token | To deliver the reminders you switch on |
| Subscription status | To unlock paid features |
Screen-time data stays on your device
On Android, NeuroPath can read app usage totals to show your daily summary and warn you when you pass a limit you set. This data is processed entirely on your phone and is never transmitted to us or anyone else. Your limits are stored locally too.
On iOS, Apple never discloses your app usage to third-party apps at all. You choose which apps count using Apple's own picker, and the system enforces your limits. NeuroPath never learns which apps you selected or how long you used them.
What we do not collect
We do not collect your contacts, precise location, browsing history, or the content of anything outside NeuroPath. We do not use advertising identifiers. There are no third-party advertising or analytics SDKs in the app.
4. Health data
Health data is read-only — NeuroPath never writes to Apple Health or Health Connect. It is used solely to show you your own progress inside the app. In line with Apple and Google platform rules, health data is never used for advertising or marketing, never sold, never shared with third parties, and never used for any purpose other than the features you enabled it for. You can revoke access at any time in your device settings, and the app will keep working without it.
5. Who your data reaches
We do not sell your data. We do not share it for advertising. It reaches only the service providers needed to run the app:
- Render — application hosting
- Neon — the database where your account data is stored
- Google Firebase Cloud Messaging — delivers push notifications. Notification content is deliberately generic and never names a recovery category.
- Resend — sends account emails such as password resets
- Apple and Google — process subscription payments. We never see your card details.
Your recovery data is not sent to any of these beyond the hosting and database providers that necessarily store it. It is excluded from every analytics or third-party integration.
We may disclose data if legally compelled to do so, and will tell you unless prohibited by law.
6. Guest accounts
You can use NeuroPath without giving an email address. A guest account is a real account on our servers holding whatever you record in it, but it is not linked to any identity we can contact. If you lose access to the device, the account cannot be recovered. You can delete it from Settings at any time.
7. Security
All traffic uses HTTPS/TLS. Passwords are salted and hashed. Session refresh tokens are hashed at rest, so a database copy alone cannot be used to impersonate you. Signing out everywhere immediately invalidates every existing session. No system is perfectly secure, and we do not claim otherwise.
8. Keeping and deleting your data
We keep your data while your account exists. Deleting your account in Settings permanently and immediately erases everything — habits, logs, recovery records, health data we stored, sessions and your account row. There is no grace period and no archived copy, beyond ordinary encrypted infrastructure backups which age out on their own cycle.
9. Your rights
You can access and correct your data in the app, delete your account at any time, turn every notification type off (they are off by default), revoke health and screen-time permissions in your device settings, and email us with any privacy question.
If you are in the EEA or UK, you also have rights under the GDPR to access, rectify, erase, restrict, port, and object to processing of your personal data, and to complain to your local supervisory authority. Our legal bases are performance of a contract (running your account), consent (health data, notifications, and any special-category recovery data you choose to record), and legitimate interests (keeping the service secure).
10. International transfers
We operate from the United Arab Emirates and our providers run infrastructure in other countries, so your data may be processed outside where you live. We use providers that offer appropriate contractual safeguards for such transfers.
11. Changes
If we change this policy in a way that materially affects you — particularly anything that would send your data somewhere new — we will notify you in the app before it takes effect.
12. Contact
Privacy questions, requests, or complaints: privacy@getneuropath.com