Neuctra Authix stores account data for developers and user data on their behalf. This page says exactly what that means — including the parts we cannot do for you.
Neuctra Authix is developer infrastructure. That means personal data reaches us two different ways, and the rules are not the same for both. Almost every confusing question about a service like ours comes from mixing these up, so we separate them first.
| Account holders | End users | |
|---|---|---|
| Who | Developers who sign up at authix.neuctra.com and build on our API | The people who sign in to an application built by an account holder |
| Our role | Controller — we decide what to collect and why | Processor — we store and process on the account holder's instructions |
| Relationship with you | Direct. This policy is our agreement with you | Indirect. We have no relationship with you; the app you signed into does |
| Who to contact | Us, at the address in the last section | The operator of the app you used — they control your data, not us |
We hold your email and password hash because a developer chose Neuctra Authix to run their sign-in. We cannot identify which app you mean, verify who you are, or delete your account on request — doing so on a stranger's say-so would itself be a security failure. Contact whoever runs that application. When they act, their changes reach us immediately.
Everything below is either required to run the service or supplied by you deliberately. There is no tracking pixel in the product, no profiling, and no data broker anywhere in this list.
| Data | Why we hold it | Notes |
|---|---|---|
| Name and email | Identifies your account, sends verification and password resets | Email must be verified before the API will serve your apps |
| Password | Signing you in | Stored only as a bcrypt hash. We cannot read or recover it |
| One-time codes | Email verification and password reset | Also stored hashed, and expire shortly after being issued |
| Phone, address, avatar | Optional profile fields you can fill in or leave blank | Never required, never used for anything but display |
| API keys | Authenticating your requests | Only a SHA-256 hash is stored. The key itself is shown once at creation and never again — not even to us |
| Usage counters | Enforcing the request limits on your plan | A monthly request count, not a log of what you requested |
| Billing state | Knowing which plan you are on | A customer id, a subscription id and a status. Card details never reach our servers |
When a developer builds on Neuctra Authix, their users' records live in our database. We hold this data; we do not decide what goes into it.
The data API accepts any JSON. If an application writes health records, government identifiers or children's data into it, we have no way to detect that and no way to apply the extra protections such data legally requires.
Neuctra Authix is not built or certified for HIPAA, PCI-DSS or comparable regimes. Developers are responsible for what they put in — see the Terms of Service.
We run on other companies' infrastructure. These are all of them. We do not sell personal data, and we do not share it for advertising.
| Provider | What it does | Where |
|---|---|---|
| Neon | Hosts the PostgreSQL database — every record described above | AWS, US East |
| Vercel | Hosts this website and the dashboard | Global edge network |
| Paddle | Takes payments as merchant of record. Card details go to Paddle, never to us | See Paddle's own policy |
| Email provider | Delivers verification and password-reset messages | [your SMTP provider] |
| Google Analytics | Page-view statistics for the marketing site only | Google infrastructure |
Data is stored in the United States. If you are in the UK, EU or another region with transfer rules, using Neuctra Authix means data about you — and about your end users — leaves that region.
Stated plainly, including the limits — a security section that only lists strengths is not much use to someone deciding whether to trust us.
We do not offer end-to-end encryption. Data stored through the API is encrypted in transit and at rest, but it is readable by our systems — that is what makes searching and indexing it possible.
We hold no SOC 2, ISO 27001 or comparable certification, and we have not been independently audited. If your project requires a certified processor, Neuctra Authix is not it yet.
If you hold an Neuctra Authix account, you can exercise all of these from the dashboard or by writing to us:
We respond within 30 days. We do not charge for these requests unless they are repetitive or excessive.
Neuctra Authix is a developer tool and is not directed at children. You must be at least 16, or the age of digital consent where you live, to hold an account. If a developer builds an application for children on Neuctra Authix, complying with COPPA, the UK Children's Code and equivalent rules is their responsibility — we have no way to know the age of an end user and do not attempt to infer it.
We will update this policy when the service changes. Material changes are announced by email to account holders before they take effect; the date at the top always reflects the current version.
Privacy questions: [email protected]. Anything else: get in touch.
Neuctra Authix is operated by [registered company name], [registered address]. Data controller for account holder data: [controller entity].
Related: Terms of Service · Disclaimer · Refund Policy