Neurobird Search Legal

Privacy Policy

Short version: we store your search queries and usage so the Service can be metered, debugged and protected from abuse. We do not sell data, we do not run advertising, and there is no tracking or analytics on this site.

1. Controller

Neurobird operates the Neurobird Search API and is the data controller for the processing described here. Contact: [email protected].

2. What we collect

When you use the API

When you buy credits

When you visit this website

3. Why we process it, and on what basis

PurposeDataLegal basis (GDPR Art. 6)
Providing the ServiceQueries, key, usageContract, Art. 6(1)(b)
Metering and billingUsage, transaction dataContract, Art. 6(1)(b)
Rate limiting, fraud and abuse preventionIP, usage patternsLegitimate interest, Art. 6(1)(f)
Debugging and reliabilityQueries, timings, errorsLegitimate interest, Art. 6(1)(f)
Tax and accounting recordsTransaction dataLegal obligation, Art. 6(1)(c)

4. Who we share it with

We use a small number of processors, and only what each one needs:

We do not sell personal data and we do not share it for advertising.

5. International transfers

Our server is in the EU. DeepInfra and Cloudflare may process data outside the EEA. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.

6. How long we keep it

7. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest. Email [email protected] and we will respond within 30 days. You can also complain to your national supervisory authority.

To delete a key and its query history, email us the key and we will erase it.

8. Do not send us personal data you do not need to

Queries are stored. Please do not put personal data, credentials or confidential information into search queries unless you have a lawful basis for doing so. If you use the Service to process other people's personal data, you are the controller for that processing and we act as your processor for it.

9. Security

Traffic is encrypted in transit. API keys are required for all metered endpoints. Access to the server is restricted to key based administrative access. No system is perfectly secure, and we will notify affected users and the relevant authority without undue delay if a breach is likely to result in a risk to their rights.

10. Changes

Material changes will be posted here with a new date.