Privacy

Privacy Policy

Last updated September 20, 2026

This policy explains what Neural Garden collects when you use the service, why, and what control you have over it. The short version: your thoughts are yours, we store them so you can reach them from any device, and we do not sell or advertise on them.

What we store

Your account. When you sign in with Google, GitHub or Apple we store the name, email address and profile picture that provider gives us. When you sign in with an email link we store the address you typed. That is all an account is; there is no password. While sign-ups are by invitation, we also keep the note you write when you ask to join.

What you create. The thoughts, connections, gardens, bookmarks, regions, clusters and type definitions you make, the images you upload or paste, and the web pages you clip with the browser extension (their title, address, a text excerpt and any metadata the page publishes).

Technical data. Our server logs record the address and browser of each request for a short time, as any web server does. When something fails on our side we record which request failed, the technical error and a reference code — the same code the error page shows you, so you can quote it — but not what you were writing. If the app crashes or a tab runs out of memory, the browser or the app may send us a crash report with the page you were on, your browser, the size of the canvas and memory figures — never the content of your thoughts. A bug report you send carries the description you wrote and the device details the dialog lists in full before you send it — your browser and its user-agent string, operating system and device kind, screen and window size, language, time zone, whether you are online and on what kind of connection, processor cores, memory and storage use, your display preferences and whether you installed Neural Garden as an app, the page you were on, the app build and your sync state — again never your thoughts.

Cookies. A few sign-in cookies keep you signed in and protect the sign-in form. We use no advertising or third-party analytics cookies.

AI features and your API keys

AI features run on a key you provide for Anthropic, OpenAI, xAI or a local Ollama server. The key is stored in your own browser, encrypted where the browser supports it, and is never saved on our servers. Requests go from your browser straight to the provider you chose; for xAI, whose service does not accept browser requests, they pass through our server, which forwards them without reading or keeping them.

What you send to an AI provider — the thoughts you ask about, the text you ask it to write — is handled under that provider's terms and privacy policy, and billed to your key. We do not send your content to any AI provider on our own.

Who can see what

Only you, by default. Your gardens are private to your account until you choose otherwise.

People you invite. Sharing a garden or a node with someone lets them see and, if you make them an editor, change that canvas. They also see your name and picture, and you see theirs. The owner of a garden can also see the email addresses of its members and of the people they have invited; other members see only names and pictures.

Anyone, if you publish. A share link makes a snapshot of that canvas readable by anyone who has the link, with your display name on it; listing it in the gallery makes it discoverable. Revoking the link takes the snapshot down. Embeds you enable can be shown on other websites.

Us. An administrator can see account details (name, email, when you joined) to run the service and can remove content that breaks the terms. We do not read your gardens to build profiles, train models, or advertise.

Where your data lives

Your gardens are stored on our servers so you can open them from any device. The app also keeps a copy in your browser (its local database) so that it loads instantly and works offline. Signing out removes that copy — your gardens, the AI key you entered and cached pages — from the device, after offering to sync anything that has not reached the server yet. The Account section at the bottom of Settings can clear it without signing out. If your sign-in expires while the app is open, what you did in the meantime stays on the device and syncs once you sign in again.

Third parties

  • Google, GitHub and Apple handle sign-in and tell us your name, email and picture.
  • Resend delivers our email: sign-in links and the note that lets you in from the waitlist.
  • The AI provider you choose receives what you send it, as described above.
  • Link previews. When you paste a link, our server fetches that page's title and description; the site sees a request from our server, not from you.
  • Embedded players. A YouTube or Beatport embed on a canvas loads from that service when it is shown, under its own privacy terms.

Keeping, exporting and deleting

We keep your data for as long as your account exists. Deleted thoughts go to a trash you can empty. You can export your gardens — thoughts, connections, clusters, bookmarks and their settings — under Settings → Backup & Restore at any time; the export file does not yet include the images you uploaded.

You can delete your account yourself, without asking us: open Settings, scroll to the Account section at the bottom, choose Delete my account and type the confirmation word. It takes effect immediately: your account, every garden you own and everything in them, the images you uploaded to them and your share links are removed, you are signed out, and this device's copy is cleared. Thoughts you wrote inside someone else's garden stay in that garden without your name on them, because they are part of their work, and so do images, bookmarks and clusters you added there, which pass to that garden's owner. Daily backups of our database are kept for about two weeks and then expire, so a deleted account is gone from them within sixteen days.

If you are in the EU, UK or another place with data-protection law, you have the right to access, correct, export and delete your data, and to object to or restrict its processing; the ways above are how to exercise them, and you may also complain to your local authority.

Children

The service is not directed at children under 16, and we do not knowingly keep an account for one. If you believe a child has created an account, contact us and we will remove it.

Changes and contact

When this policy changes we update the date at the top and note it in the changelog. Continuing to use the service after a change means you accept it.

Questions or requests about this policy go to do@oui.io.

See also the Terms of Service.