Privacy Policy
Last updated: 12 August 2026
This policy explains what personal data Neyli collects, why, and what your rights are. The data controller is Soulcore Ltd, a company registered in England and Wales (No. 14143714), Flat 1, 132 Haverstock Hill, London NW3 2AY, United Kingdom. Soulcore Ltd is registered with the UK Information Commissioner's Office (ICO) under registration number ZB497063. For content your team stores in a workspace, we act as a processor on behalf of the workspace owner (see the Data Processing Addendum).
What we collect
- Account data — email address, display name, hashed password (we never see the plain password), workspace membership and role.
- Workspace content — the projects, tasks, boards, notes, messages and files your team creates. This is your data; we host it.
- Billing data — plan, seat count and subscription status. Card details go directly to Stripe; we never store them.
- Assistant usage — prompts and needed workspace context are processed by our AI provider to generate responses; we meter token usage per workspace. We do not use your content to train models.
- Technical logs — IP address, error reports and coarse usage events needed to run, secure and rate-limit the Service.
We do not run advertising trackers. Cookies/local storage are used only to keep you signed in and remember preferences (strictly necessary), so there is no cookie banner to click through.
Google Calendar data
Connecting Google Calendar is optional. If you connect it in Settings, Neyli
asks Google for permission to read your calendars
(calendar.readonly) and to manage events
(calendar.events). We use that access for exactly two things:
- Showing your Google events on your Neyli calendar. Events are fetched from Google when you open the calendar and are displayed to you only — they are not stored on our servers and are never visible to your teammates.
- Adding your Neyli schedule to Google — Neyli creates calendar events for your dated tasks and meetings, and updates or removes only the events it created itself. It never modifies or deletes events you or anyone else created.
What we store: your Google connection token, encrypted (AES-256-GCM) on our API edge, and the identifiers of events Neyli created — nothing else. Google Calendar data is never shared with third parties, never used for advertising, and never used to train AI models; the Neyli assistant has no access to it. You can disconnect at any time in Settings (this removes the stored token and the future events Neyli created) or from your Google Account permissions.
Neyli's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Why we process it (legal bases)
- To provide the Service you asked for (contract).
- To secure the Service, prevent abuse and debug faults (legitimate interest).
- To bill subscriptions and keep required records (contract, legal obligation).
- To send product/service emails such as invites and receipts (contract); marketing only with consent.
Subprocessors
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, auth, file storage | West Europe (London) |
| Cloudflare | Hosting, workers (API edge), rate limiting | Global edge |
| Stripe | Payments and subscription billing | US/EU |
| Anthropic | AI assistant processing | US |
| Resend | Transactional email (sign-in, password reset, invites) | Ireland (eu-west-1) |
| Sentry | Error monitoring — when something breaks we receive the error, the page URL and the IP address it came from | European Union (Germany) |
| Microsoft 365 (via GoDaddy) | Our own mailbox for support correspondence | EU/US |
Retention
Workspace content lives for as long as the workspace exists. Deleted workspaces are removed from live systems promptly and from rolling backups within 7 days (daily database backups), and within 5 weeks from weekly offsite backups. Account data is deleted when the account is deleted. Billing records are kept as long as tax law requires.
Your rights
Depending on where you live (e.g. GDPR/UK GDPR/CCPA) you can request access, correction, export or deletion of your personal data, object to certain processing, and complain to a supervisory authority. Write to hello@neyli.app — we respond within 30 days. For content inside a customer's workspace, we will refer the request to the workspace owner, as required by our processor role.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first at hello@neyli.app so we can try to put it right. You also have the right to complain to our supervisory authority, the UK Information Commissioner's Office (ICO), at any time — you do not have to come to us first.
- Online: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Our ICO registration number is ZB497063. If you are in the EEA, you may instead complain to the supervisory authority where you live or work.
Security
Data is encrypted in transit and at rest, isolated per workspace with database-level row security, and covered by weekly offsite backups. Access to production systems is limited to the operator and protected by revocable keys.
Changes
We'll announce material changes in the app or by email before they take effect.
Contact
hello@neyli.app · Flat 1, 132 Haverstock Hill, London NW3 2AY, United Kingdom