Privacy Policy

What we hold, and why

Neuctra Authix stores account data for developers and user data on their behalf. This page says exactly what that means — including the parts we cannot do for you.

Last updated 13 August 2026

1.Two kinds of people are described here

Neuctra Authix is developer infrastructure. That means personal data reaches us two different ways, and the rules are not the same for both. Almost every confusing question about a service like ours comes from mixing these up, so we separate them first.

Account holdersEnd users
WhoDevelopers who sign up at authix.neuctra.com and build on our APIThe people who sign in to an application built by an account holder
Our roleController — we decide what to collect and whyProcessor — we store and process on the account holder's instructions
Relationship with youDirect. This policy is our agreement with youIndirect. We have no relationship with you; the app you signed into does
Who to contactUs, at the address in the last sectionThe operator of the app you used — they control your data, not us
If you signed in to someone else's app

We hold your email and password hash because a developer chose Neuctra Authix to run their sign-in. We cannot identify which app you mean, verify who you are, or delete your account on request — doing so on a stranger's say-so would itself be a security failure. Contact whoever runs that application. When they act, their changes reach us immediately.

2.What we collect from account holders

Everything below is either required to run the service or supplied by you deliberately. There is no tracking pixel in the product, no profiling, and no data broker anywhere in this list.

DataWhy we hold itNotes
Name and emailIdentifies your account, sends verification and password resetsEmail must be verified before the API will serve your apps
PasswordSigning you inStored only as a bcrypt hash. We cannot read or recover it
One-time codesEmail verification and password resetAlso stored hashed, and expire shortly after being issued
Phone, address, avatarOptional profile fields you can fill in or leave blankNever required, never used for anything but display
API keysAuthenticating your requestsOnly a SHA-256 hash is stored. The key itself is shown once at creation and never again — not even to us
Usage countersEnforcing the request limits on your planA monthly request count, not a log of what you requested
Billing stateKnowing which plan you are onA customer id, a subscription id and a status. Card details never reach our servers

3.What we store on behalf of account holders

When a developer builds on Neuctra Authix, their users' records live in our database. We hold this data; we do not decide what goes into it.

  • End user accounts — name, email, a bcrypt password hash, verification status, and optional phone, address, avatar and role.
  • Records the application writes — arbitrary JSON stored per user or per app. Orders, notes, preferences, whatever the developer chose to put there.
  • A searchable copy of that JSON as plain text, so search queries can use a database index instead of scanning every record.
We cannot police what developers store

The data API accepts any JSON. If an application writes health records, government identifiers or children's data into it, we have no way to detect that and no way to apply the extra protections such data legally requires.

Neuctra Authix is not built or certified for HIPAA, PCI-DSS or comparable regimes. Developers are responsible for what they put in — see the Terms of Service.

4.Cookies and analytics

Session cookies are how sign-in works; there is no version of the product without them. The analytics cookie is separate and is only on the marketing site.

CookiePurposeLifetime
authix_admin_sessionKeeps you signed in to the Neuctra Authix dashboard24 hours
authix_user_sessionKeeps an end user signed in to an application built on Neuctra Authix24 hours
_ga / _ga_*Google Analytics — page views on this marketing site only. Not set inside the dashboard or by the APIUp to 2 years, set by Google

Both session cookies are HttpOnly, so JavaScript cannot read them, and are marked Secure in production so they are only ever sent over HTTPS. They hold a signed token, not your details, and there is no session table behind them — which is also why signing out everywhere works by invalidating every token at once rather than by deleting rows.

Google Analytics is the only third-party script on this site. To opt out, use your browser's tracking protection or Google's opt-out add-on. Nothing about your use of the product depends on it.

5.Who else processes your data

We run on other companies' infrastructure. These are all of them. We do not sell personal data, and we do not share it for advertising.

ProviderWhat it doesWhere
NeonHosts the PostgreSQL database — every record described aboveAWS, US East
VercelHosts this website and the dashboardGlobal edge network
PaddleTakes payments as merchant of record. Card details go to Paddle, never to usSee Paddle's own policy
Email providerDelivers verification and password-reset messages[your SMTP provider]
Google AnalyticsPage-view statistics for the marketing site onlyGoogle infrastructure

Data is stored in the United States. If you are in the UK, EU or another region with transfer rules, using Neuctra Authix means data about you — and about your end users — leaves that region.

6.How long we keep it

  • While your account is open — account details, apps, end users and their records are kept until you delete them or close the account.
  • Deletion is immediate and permanent. Deleting an app deletes its users and their records. Deleting a user deletes everything belonging to that user. There is no recycle bin and no undo — export first if the data matters.
  • Backups are retained by our database provider for a limited window, so deleted data may persist in a backup for a short time before ageing out.
  • Billing records are kept as long as tax and accounting law requires, which is longer than the account itself.

7.How we protect it

Stated plainly, including the limits — a security section that only lists strengths is not much use to someone deciding whether to trust us.

  • Passwords and one-time codes are hashed with bcrypt. API keys are hashed with SHA-256. A database leak would not expose usable credentials.
  • All traffic is over HTTPS. The database is encrypted at rest by our provider.
  • API keys are scoped: an API key is locked to the signed-in user's own data, so exposing one in a mobile app or browser does not expose everyone else's records.
  • Sessions are signed tokens with a 24-hour life, and can be invalidated everywhere at once — which happens automatically on password change and reset.
  • Rate limiting and security headers are applied to every request.
What we do not claim

We do not offer end-to-end encryption. Data stored through the API is encrypted in transit and at rest, but it is readable by our systems — that is what makes searching and indexing it possible.

We hold no SOC 2, ISO 27001 or comparable certification, and we have not been independently audited. If your project requires a certified processor, Neuctra Authix is not it yet.

8.Your rights

If you hold an Neuctra Authix account, you can exercise all of these from the dashboard or by writing to us:

  • Access — see what we hold about you and export your applications' data.
  • Correction — edit your profile at any time.
  • Deletion — delete individual records, whole apps, or your entire account.
  • Objection and restriction — tell us to stop processing, understanding that this generally means closing the account, since the processing is the service.
  • Complaint — raise it with your local data protection authority. We would rather you raised it with us first.

We respond within 30 days. We do not charge for these requests unless they are repetitive or excessive.

9.Children

Neuctra Authix is a developer tool and is not directed at children. You must be at least 16, or the age of digital consent where you live, to hold an account. If a developer builds an application for children on Neuctra Authix, complying with COPPA, the UK Children's Code and equivalent rules is their responsibility — we have no way to know the age of an end user and do not attempt to infer it.

10.Changes and contact

We will update this policy when the service changes. Material changes are announced by email to account holders before they take effect; the date at the top always reflects the current version.

Privacy questions: [email protected]. Anything else: get in touch.

Neuctra Authix is operated by [registered company name], [registered address]. Data controller for account holder data: [controller entity].