Privacy Policy

Last updated: 12 August 2026

This policy explains what personal data Neyli collects, why, and what your rights are. The data controller is Soulcore Ltd, a company registered in England and Wales (No. 14143714), Flat 1, 132 Haverstock Hill, London NW3 2AY, United Kingdom. Soulcore Ltd is registered with the UK Information Commissioner's Office (ICO) under registration number ZB497063. For content your team stores in a workspace, we act as a processor on behalf of the workspace owner (see the Data Processing Addendum).

What we collect

We do not run advertising trackers. Cookies/local storage are used only to keep you signed in and remember preferences (strictly necessary), so there is no cookie banner to click through.

Google Calendar data

Connecting Google Calendar is optional. If you connect it in Settings, Neyli asks Google for permission to read your calendars (calendar.readonly) and to manage events (calendar.events). We use that access for exactly two things:

What we store: your Google connection token, encrypted (AES-256-GCM) on our API edge, and the identifiers of events Neyli created — nothing else. Google Calendar data is never shared with third parties, never used for advertising, and never used to train AI models; the Neyli assistant has no access to it. You can disconnect at any time in Settings (this removes the stored token and the future events Neyli created) or from your Google Account permissions.

Neyli's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Why we process it (legal bases)

Subprocessors

ProviderPurposeRegion
SupabaseDatabase, auth, file storageWest Europe (London)
CloudflareHosting, workers (API edge), rate limitingGlobal edge
StripePayments and subscription billingUS/EU
AnthropicAI assistant processingUS
ResendTransactional email (sign-in, password reset, invites)Ireland (eu-west-1)
SentryError monitoring — when something breaks we receive the error, the page URL and the IP address it came fromEuropean Union (Germany)
Microsoft 365 (via GoDaddy)Our own mailbox for support correspondenceEU/US

Retention

Workspace content lives for as long as the workspace exists. Deleted workspaces are removed from live systems promptly and from rolling backups within 7 days (daily database backups), and within 5 weeks from weekly offsite backups. Account data is deleted when the account is deleted. Billing records are kept as long as tax law requires.

Your rights

Depending on where you live (e.g. GDPR/UK GDPR/CCPA) you can request access, correction, export or deletion of your personal data, object to certain processing, and complain to a supervisory authority. Write to hello@neyli.app — we respond within 30 days. For content inside a customer's workspace, we will refer the request to the workspace owner, as required by our processor role.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first at hello@neyli.app so we can try to put it right. You also have the right to complain to our supervisory authority, the UK Information Commissioner's Office (ICO), at any time — you do not have to come to us first.

Our ICO registration number is ZB497063. If you are in the EEA, you may instead complain to the supervisory authority where you live or work.

Security

Data is encrypted in transit and at rest, isolated per workspace with database-level row security, and covered by weekly offsite backups. Access to production systems is limited to the operator and protected by revocable keys.

Changes

We'll announce material changes in the app or by email before they take effect.

Contact

hello@neyli.app · Flat 1, 132 Haverstock Hill, London NW3 2AY, United Kingdom