Privacy Policy

What personal data Neirom collects, why, and what control you have.

Last updated 1 September 2026

Neirom is risk intelligence, not legal advice. Neirom helps you spot possible marketplace policy risk before you publish. It does not guarantee compliance with any marketplace's rules or with the law.

1. Who is responsible for your data

Daniel Cirillo, a sole trader in the United Kingdom trading as Neirom, is the data controller for personal data processed through the Neirom service. That means we decide what data is collected and why.

You can reach us about privacy at privacy@neirom.com.

2. Data we collect and why

Account data — your name, email address, password credentials (stored hashed by our authentication provider), and the onboarding answers you give us such as what you sell and whether you have had a policy warning before. We use this to create and secure your account, to provide the service and to tailor your results. Legal basis: performance of our contract with you.

Listing content you submit for analysis — listing titles, descriptions, tags, categories and any images you upload. We use this to run the risk analysis you asked for, to produce results and evidence, and to keep your scan history, listings and Action Center up to date. Legal basis: performance of our contract with you.

Billing-related data — your subscription status, plan, price, billing period, renewal and cancellation state, refund requests, and the customer and subscription identifiers we receive from Paddle. Card numbers and full payment details are handled by Paddle and never reach our systems. We use this to give you the right plan, enforce your scan allowance and support billing queries. Legal basis: performance of our contract and compliance with legal obligations.

Support data — the messages, refund reasons and cancellation reasons you send us, and the notes we make when resolving your case. We use this to answer you and to improve the product. Legal basis: performance of our contract and our legitimate interest in supporting and improving the service.

Product analytics and technical data — events such as sign-up, onboarding completion, checks started and completed, pricing views and checkout starts, along with IP address, device and browser information and error logs. We use this to keep the service secure, diagnose faults and understand which features are used. We do not include your listing text or your uploaded images in analytics payloads. Legal basis: our legitimate interest in operating, securing and improving the service, and consent where the law requires it for non-essential analytics.

Free demo checks — if you run a free listing risk check on our public page without an account, we store a one-way hashed version of your IP address and the time of the check, solely to limit how many free checks can be run per visitor and per day. We cannot recover your IP address from the hash, and the listing text you submit in a demo check is not saved to any account. Legal basis: our legitimate interest in preventing abuse of a free service.

3. AI processing of your content

To generate your results, the listing content and images you submit are sent to our AI processing provider, which returns the analysis shown in your account. This happens only when you ask for a check.

We do not sell your content and we do not use your listing content or images to train external AI models. If we ever want to use your content for anything beyond providing the service to you, we will tell you first and obtain consent where required.

4. Who we share data with

  • Our hosting, database, storage and authentication providers, who process data on our instructions to run the service
  • Our AI processing provider, to generate the analysis you request
  • Paddle, our Merchant of Record, for the sale of subscriptions, subscription management, payments, invoicing and tax compliance
  • Professional advisers such as lawyers and accountants, where needed
  • Authorities or regulators, where we are legally required to disclose

We do not sell your personal data or share it with advertisers.

5. International transfers

Some of our providers operate outside the UK and the EEA, so personal data may be processed in other countries. Where personal data is transferred internationally, we work with providers that offer appropriate safeguards recognised under UK and EU data protection law.

We keep our provider arrangements under review and will update this policy if the way we transfer data materially changes.

6. How long we keep data

  • Account, listing, scan and result data: kept while your account is open, so your history stays available to you
  • Uploaded images: deleted automatically after a configurable retention window. The current technical default is 90 days, but this is not a fixed contractual commitment — we may change the retention period over time, subject to applicable privacy requirements. Images that are still attached to an open action in your account are held longer so evidence stays viewable while you work on the finding
  • Billing and refund records: kept for as long as needed to meet tax and accounting obligations
  • Support records: kept while your account is open and for a reasonable period afterwards to handle follow-up queries
  • After you delete your account: your personal data is deleted or anonymised, apart from records we must keep by law

7. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive a portable copy, and withdraw consent where processing is based on consent.

You can delete your account from Settings at any time, which removes your account data from the service. For other requests, contact privacy@neirom.com. We aim to respond within one month.

If you are in the UK or EEA and are unhappy with how we handle your data, you can complain to your local supervisory authority.

8. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, per-user access controls at the database level so one account cannot read another account's data, restricted private storage for uploaded images, and secrets held outside the application code.

No system is completely secure. We do not guarantee that unauthorised access will never happen, and we do not claim certification against any specific security standard.

9. Cookies

We use cookies and similar browser storage as described in our Cookie Policy.

9a. Marketplace-connected data (Etsy)

The term 'Etsy' is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc. Neirom is independent from Etsy, Inc.

Direct Etsy connection is not live yet and requires approval and credentials from Etsy. If you later choose to connect your Etsy shop, you authorise it through Etsy's own OAuth consent screen; we never receive or store your Etsy password. We request read-only, least-privilege scopes only — your own listings and basic shop information — and no write access. We read this data solely through the official Etsy Open API v3 and never by scraping.

Purpose: to run the risk analysis and scheduled re-checks you asked for on your own listings. Legal basis: performance of our contract with you.

Retention: listing text and metadata are cached so your results, evidence and history stay viewable; listing images follow your image retention setting (30, 90 or 365 days); OAuth tokens are stored encrypted server-side and deleted immediately when you disconnect. Disconnecting stops all further API calls, and deleting your account removes the associated data. See our Etsy Integration page for the full description.

10. Changes and contact

We will update this policy as the product changes and will note the date at the top. For anything privacy-related, contact privacy@neirom.com.