Privacy Policy
Last updated: 29 August 2026
Short version: we store your search queries and usage so the Service can be metered, debugged and protected from abuse. We do not sell data, we do not run advertising, and there is no tracking or analytics on this site.
1. Controller
Neurobird operates the Neurobird Search API and is the data controller for the processing described here. Contact: [email protected].
2. What we collect
When you use the API
- Your API key, and the label you chose when creating it.
- Search queries and requested URLs you send to the Service.
- Usage metadata: endpoint, search depth, credits charged, result count, response time, success or failure, and a timestamp.
- IP address, recorded when a key is created and used for rate limiting and abuse prevention.
When you buy credits
- We receive from our payment provider a transaction reference, the pack purchased, the amount, and the email used at checkout.
- We never receive or store your payment credentials. Payment data is handled entirely by the payment provider.
When you visit this website
- Standard web server logs, including IP address, user agent and requested path.
- No analytics, no cookies for tracking, no advertising pixels. The demo search on the landing page runs against the same API and is rate limited per IP.
3. Why we process it, and on what basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service | Queries, key, usage | Contract, Art. 6(1)(b) |
| Metering and billing | Usage, transaction data | Contract, Art. 6(1)(b) |
| Rate limiting, fraud and abuse prevention | IP, usage patterns | Legitimate interest, Art. 6(1)(f) |
| Debugging and reliability | Queries, timings, errors | Legitimate interest, Art. 6(1)(f) |
| Tax and accounting records | Transaction data | Legal obligation, Art. 6(1)(c) |
4. Who we share it with
We use a small number of processors, and only what each one needs:
- NOWPayments is our payment provider and processes checkout, settlement and refunds. Your checkout and billing data is held by the provider under its own privacy policy.
- DeepInfra processes query text and extracted page passages to generate answers, expand queries and compute embeddings, when you request those features. Requests that do not ask for an answer do not go to a language model.
- Cloudflare fronts this domain and processes connection metadata.
- Our own server, hosted in Germany, runs the search pipeline and stores the database.
We do not sell personal data and we do not share it for advertising.
5. International transfers
Our server is in the EU. DeepInfra and Cloudflare may process data outside the EEA. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
6. How long we keep it
- Cached search responses: 15 minutes.
- Usage and query logs: 12 months, then deleted.
- API keys and credit ledger: for as long as the key exists, and after deletion only as required for accounting.
- Transaction records: as long as tax law requires, typically 7 years, held primarily by the payment provider.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest. Email [email protected] and we will respond within 30 days. You can also complain to your national supervisory authority.
To delete a key and its query history, email us the key and we will erase it.
8. Do not send us personal data you do not need to
Queries are stored. Please do not put personal data, credentials or confidential information into search queries unless you have a lawful basis for doing so. If you use the Service to process other people's personal data, you are the controller for that processing and we act as your processor for it.
9. Security
Traffic is encrypted in transit. API keys are required for all metered endpoints. Access to the server is restricted to key based administrative access. No system is perfectly secure, and we will notify affected users and the relevant authority without undue delay if a breach is likely to result in a risk to their rights.
10. Changes
Material changes will be posted here with a new date.