This policy applies to all visitors and users of NeuropathIQ platforms. It covers our obligations under PIPEDA (Canada), GDPR (European Union), CCPA/CPRA (California, USA), and applicable US state privacy laws.
Contents
NeuropathIQ Inc. is incorporated under the laws of British Columbia, Canada. We operate the evidence intelligence platform accessible at www.neuropathiq.com, neuropathiq.com, and neuropathiq.ca (the "Platform").
For purposes of GDPR, NeuropathIQ Inc. is the data controller of personal information collected through the Platform. For purposes of CCPA/CPRA, NeuropathIQ Inc. is the business.
Data Controller / Privacy Officer
NeuropathIQ Inc.
British Columbia, Canada
Email: privacy@neuropathiq.com
This policy applies to all personal information collected through the Platform, our website, email communications, and any related services. NeuropathIQ complies with the following privacy frameworks:
| Law | Jurisdiction | Applies to |
|---|---|---|
| PIPEDA (Personal Information Protection and Electronic Documents Act) | Canada | Canadian residents |
| GDPR (General Data Protection Regulation) | European Union / EEA | EU/EEA residents |
| UK GDPR | United Kingdom | UK residents |
| CCPA/CPRA (California Consumer Privacy Act as amended by the California Privacy Rights Act) | California, USA | California residents |
| US State Privacy Laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and others) | Various US states | Applicable state residents |
Where laws differ, we apply the most protective standard available. If your jurisdiction grants rights not listed here, you retain those rights and may exercise them by contacting us.
We collect the minimum personal information necessary to operate the Platform. We do not collect health data, medical records, government IDs, biometric data, financial account details, or any sensitive personal information beyond what is listed below.
| Category | Specific data | Source |
|---|---|---|
| Contact & early access | Email address, name (optional), institutional affiliation (optional), professional role (optional) | Provided by you |
| Search queries | Text entered into the Platform search, used to query NeuropathIQ's own knowledge graph. A normalized form of successful searches (not your verbatim keystrokes) is logged with an anonymous per-browser identifier to measure Platform usage. | Provided by you |
| Usage data | Searches run, entities and relationships viewed, and similar interactions with the Platform, tied to an anonymous per-browser identifier — not your name, email address, or IP address. Used only to improve the Platform. | Automatically collected |
| Technical data | Standard web request data (such as IP address, browser type, and pages requested) is processed by our hosting and database infrastructure providers (Section 7) as part of ordinary Platform operation. NeuropathIQ's own application does not separately collect, store, or hash this data. Used for security and performance only. | Automatically collected |
| Communications | Emails you send to us, support enquiries, scientific advisory correspondence. | Provided by you |
We do not collect: Social Security numbers, financial account numbers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, health or medical information, or the personal information of children under 18.
For users in the EU, EEA, and UK, we identify a lawful basis under GDPR Article 6 for each processing activity:
| Processing activity | Lawful basis |
|---|---|
| Providing early access and Platform services | Contract — Art. 6(1)(b): necessary to provide the service you requested |
| Sending platform updates and service communications | Contract / Legitimate interests — Art. 6(1)(b)/(f): necessary to maintain service relationship |
| Security, fraud prevention, abuse detection | Legitimate interests — Art. 6(1)(f): protecting the platform and users from harm |
| Platform improvement and analytics | Legitimate interests — Art. 6(1)(f): improving service quality, balanced against your privacy rights |
| Compliance with legal obligations | Legal obligation — Art. 6(1)(c): compliance with applicable law |
We do not rely on consent as the primary lawful basis for any processing activity, meaning you do not need to withdraw consent to stop processing — you may exercise your rights to object or request deletion at any time as described in Section 11.
We do not use personal information for: advertising targeting, profiling for unrelated purposes, sale to third parties, training AI models on your data, or automated decision-making that produces legal or similarly significant effects on you.
Search: NeuropathIQ's Platform does not transmit your search queries to any third-party AI service for interpretation. Search results are returned directly from NeuropathIQ's own deterministic knowledge graph, built through structured data ingestion, normalization, and governed ontology — not AI-generated.
Research Insight (current processing): NeuropathIQ includes an AI-assisted feature called Research Insight, available only inside the Knowledge Graph view for a specific disease/pathway pattern, and generated only when you explicitly click to request it — never automatically. When you request a Research Insight, your browser sends our server only two internal identifiers (a disease ID and a pathway ID) — never a search query, free-text prompt, your account information, email address, IP address, or any other personal information. Our server independently reconstructs the relevant scientific context directly from NeuropathIQ's own public knowledge graph (the same publicly available entity names, publication metadata, and ontology relationships already shown on the Platform) and sends only that bounded, already-public scientific context to Anthropic, our third-party AI provider, to generate the explanation. This processing is strictly necessary to deliver a feature you actively requested, is never used to make automated decisions with legal or similarly significant effects on individuals (GDPR Article 22), and every Research Insight output is clearly labeled as AI-assisted, hypothesis-generating, and not a clinical decision.
Research Insight output is derived analysis, not source evidence; it does not establish causation; and it is never written back into NeuropathIQ's knowledge graph as source fact. We have not independently verified, and this policy does not represent, Anthropic's own data retention or model-training practices for API requests; if you require details of Anthropic's provider-level data handling for compliance purposes, contact legal@neuropathiq.com.
Other AI-assisted features: If additional AI-assisted interpretation features beyond Research Insight are introduced or enabled on the Platform in the future, we will update this section before those features go live to describe: which third-party AI provider (if any) is used, what data is transmitted and why, the lawful basis for that processing, and applicable international-transfer safeguards.
We share personal information only with service providers necessary to operate the Platform. We select providers whose standard commercial terms include data-processing commitments requiring them to process personal information only for the purposes we specify and to maintain appropriate security.
| Provider | Purpose | Location | Data shared |
|---|---|---|---|
| Supabase Inc. | Database hosting | Canada / USA (AWS) | Anonymous usage telemetry (session identifier, search/interaction events) — no email, name, or account data |
| Vercel Inc. | Website hosting and edge delivery | USA / Global CDN | Technical logs, IP addresses |
| Brevo SAS | Early-access email sign-up | France / EU | Email address, professional role (if provided) — only when you register for early access |
| Anthropic PBC | AI processing for the Research Insight feature (Section 6) | USA | Bounded public scientific graph/evidence context only — no personal information |
We do not share personal information with: research institutions, pharmaceutical companies, advertisers, data brokers, analytics companies, or any third party for their own commercial purposes.
NeuropathIQ uses Anthropic as a third-party AI provider solely to power the Research Insight feature described in Section 6, and uses Brevo SAS solely to manage early-access email sign-ups. Any additional third-party provider introduced in the future will be added to this table before that processing begins.
NeuropathIQ does not sell, rent, share for advertising purposes, or otherwise transfer your personal information to any third party for monetary or other valuable consideration.
This applies to all users globally. For California residents specifically: we do not "sell" or "share" personal information as defined under CCPA/CPRA. We do not engage in cross-context behavioral advertising. The "Do Not Sell or Share My Personal Information" right under CCPA applies but there is nothing to opt out of — we have no such practices.
We do not use your data to train AI models, license data sets, or create derived commercial products from your personal information.
We retain personal information only for as long as necessary for the purposes described in this policy, or as required by law.
| Data category | Retention period | Reason |
|---|---|---|
| Early-access email address | While on our early-access list + 90 days after a deletion request | Early-access communications |
| Anonymous usage telemetry (search activity, feature usage) | Retained in a form tied to a per-browser identifier, not your name, email, or IP address; no automatic deletion schedule currently applies | Platform-usage measurement and improvement |
| Technical / server logs | Per our hosting and database providers' own infrastructure log retention, not separately set by NeuropathIQ | Security and performance |
| Communications (emails, support) | 3 years from last contact | Legitimate interests / legal records |
When retention periods expire, data is either permanently deleted or irreversibly anonymized. Anonymized aggregate data is not personal information and is not subject to retention limits.
NeuropathIQ's current Platform does not charge subscription fees or process payments and does not currently collect financial or billing information. If paid services are introduced in the future, this section will be updated to describe applicable retention periods before those services launch.
NeuropathIQ is operated from Canada. When you use the Platform, your data may be transferred to and processed in Canada and the United States. The United States does not have an EU adequacy decision under GDPR.
Safeguards for EU/EEA/UK users: Where required, transfers to US-based service providers (Supabase, Vercel, Anthropic) rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, consistent with each provider's standard data-transfer terms, to protect international transfers under GDPR Article 46.
Canada is recognized by the European Commission as providing an adequate level of protection for personal data under GDPR, meaning transfers to Canada do not require additional safeguards.
By using the Platform, you acknowledge that your data will be processed in Canada and the United States under the safeguards described above.
Regardless of where you are located, you have the following rights over your personal information. We respond to all requests within 30 days (extendable to 45 days where legally permitted with notice).
To exercise any right, email privacy@neuropathiq.com with a description of your request. We may ask for information to verify your identity before processing the request. We will not charge a fee for reasonable requests.
This section applies to residents of California and supplements the rest of this policy. References to "personal information" have the meaning given under the CCPA.
In operating the Platform, NeuropathIQ collects the following categories of personal information from California residents:
We do not collect: Social Security numbers, financial information, health information, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic data, biometric data, or any other sensitive personal information as defined under CPRA.
Directly from you (registration, search queries, communications) and automatically from your use of the Platform (technical and usage data).
Providing, maintaining, and improving the Platform; security and fraud prevention; communications about the service; legal compliance.
Identifiers and internet activity are shared with Supabase (database) and Vercel (hosting) as described in Section 7. Each provider receives only the data necessary for their specific function.
NeuropathIQ does not sell personal information and does not share personal information for cross-context behavioral advertising. You have the right to opt out of the sale or sharing of your personal information — but we have no such practices to opt out of. Exercising this right will have no effect on your access to the Platform.
We do not collect sensitive personal information as defined under CPRA. The "Limit the Use of My Sensitive Personal Information" right is acknowledged but inapplicable to our current data practices.
California residents have the following additional rights under CCPA/CPRA:
To submit a CCPA rights request, email privacy@neuropathiq.com. We will verify your identity and respond within 45 days (extendable by a further 45 days with notice). You may authorize an agent to submit a request on your behalf.
NeuropathIQ does not sell or share personal information, so there is no sale or sharing for a Global Privacy Control (GPC) signal to opt you out of. The Platform does not currently include automated technical detection of GPC signals; if you want to submit a formal Do Not Sell/Share request regardless, email privacy@neuropathiq.com.
NeuropathIQ does not use automated decision-making technology (ADMT) to make decisions with legal or similarly significant effects on California residents. Where AI-assisted interpretation features are offered, any such output is a hypothesis-generating tool for qualified researchers, not a decision.
California residents may request information about personal information disclosed to third parties for their direct marketing purposes during the past calendar year. NeuropathIQ does not disclose personal information to third parties for direct marketing purposes. There is nothing to report under this provision.
This section supplements the rest of this policy for residents of the European Union, European Economic Area, and United Kingdom.
In addition to the rights in Section 11, EU/EEA/UK residents have the right to:
We assess privacy risk for processing activities that may present higher risk to individual rights. Our assessment of Research Insight, our current AI-assisted feature described in Section 6, concluded that risk to individuals is low because: (a) Research Insight processes only two internal identifiers (a disease ID and a pathway ID) — never a free-text query, your account information, email address, or IP address; (b) the scientific context sent to our AI provider is already-public information reconstructed from NeuropathIQ's own knowledge graph; (c) we do not build individual profiles from Research Insight requests or use them to make automated decisions. If future AI-assisted features process personal information in a way that increases this risk, we will assess that processing before launch and update this section.
NeuropathIQ does not currently have a formal EU Representative under GDPR Article 27, as our processing of EU resident data is not systematic, large-scale, or likely to result in high risk to EU residents. If this changes, we will appoint a representative and update this policy.
NeuropathIQ is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial privacy legislation.
Under PIPEDA you have the right to access personal information we hold about you and to challenge its accuracy. Contact our Privacy Officer at privacy@neuropathiq.com.
In the event of a breach of security safeguards that creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as soon as feasible after we determine the breach creates that risk, as required under PIPEDA's Breach of Security Safeguards Regulations. Unlike GDPR, PIPEDA does not set a fixed notification deadline.
To contact the Office of the Privacy Commissioner of Canada: priv.gc.ca · 1-800-282-1376
NeuropathIQ does not set any cookies. The Platform uses a minimal set of browser local-storage and session-storage mechanisms — not cookies — for the strictly functional purposes below. We do not use advertising cookies, cross-site tracking, third-party marketing pixels, Google Analytics, or any behavioral tracking technology.
| Storage mechanism | Purpose | Duration | Required |
|---|---|---|---|
| Guest search count (localStorage) | Tracks your remaining free searches before early-access registration — only active when that mode is enabled | Until you clear browser storage or register | Functional — only used in registration-gated mode |
| View preference (sessionStorage) | Remembers your selected Knowledge Graph / Literature view for the current browser tab | Cleared when you close the tab | No — functional only |
| Anonymous usage identifier (localStorage) | Random ID, not derived from your identity, used to measure anonymous Platform usage (Section 5) | Until you clear browser storage | No — functional/analytics only |
NeuropathIQ does not sell or share personal information and has no non-essential cookies requiring consent. The Platform does not currently include automated technical detection of Global Privacy Control (GPC) signals. Because the Platform uses only strictly necessary and functional browser storage (no cookies), a cookie consent banner is not required under ePrivacy Directive standards — you may clear your browser's local storage at any time.
We implement appropriate technical and organizational security measures to protect personal information against unauthorized access, loss, destruction, or alteration:
No transmission over the internet is 100% secure. In the event of a breach posing real risk of significant harm, we will notify affected individuals and applicable regulators as soon as feasible (PIPEDA) or within 72 hours (GDPR Article 33) of becoming aware, as applicable.
NeuropathIQ is designed for scientific and biomedical research use and is not directed to children under 18. We do not knowingly collect personal information from anyone under 18.
If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@neuropathiq.com and we will delete it promptly.
We will notify you of material changes to this policy by email (where we hold your email address) and by posting a prominent notice on the Platform, at least 30 days before changes take effect. The "Last updated" date at the top of this page reflects the date of the most recent revision.
For non-material changes (such as clarifications or corrections that do not affect your rights), we will update the policy without notice but will update the "Last updated" date.
Your continued use of the Platform after the effective date of any revised policy constitutes acceptance of the updated terms.
Privacy Officer
NeuropathIQ Inc.
British Columbia, Canada
Email: privacy@neuropathiq.com
We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you have the right to escalate your complaint to the relevant supervisory authority:
Legal note: This privacy policy is provided for informational purposes and reflects NeuropathIQ's good-faith compliance efforts as of the date noted above. It is not a substitute for legal advice. Privacy laws evolve rapidly — we review and update this policy at least annually. If you have compliance questions specific to your organization's use of the Platform, we recommend consulting qualified legal counsel.