# Privacy Policy

> Last updated: March 22, 2026

## What This Policy Covers

This policy describes how Neither ("we", "us", "our") collects, uses, and protects your information when you use our application at neither.online. Neither is a management intelligence platform that imports documents, emails, and messages from connected services to help teams make better decisions.

## Information We Collect

**Account information.** When you sign up, we collect your email address and name via Supabase Auth. If you sign in with Google, we receive your name, email, and profile picture from your Google account.

**Connected service data.** When you connect third-party services (Google Drive, Gmail, Microsoft OneDrive, Outlook, Slack, Teams, or messaging platforms), we access data from those services based on the permissions you grant. This includes file metadata and contents from selected folders, email threads and metadata from selected labels, and message content from connected channels or conversations.

**Usage data.** We collect basic usage information such as pages visited and features used, to improve the product.

## How We Use Your Information

- To provide the core service: importing, analyzing, and organizing your documents and communications into actionable project intelligence
- To generate AI-powered briefs, suggestions, and decision support using the content you import
- To maintain and improve the platform
- To communicate with you about your account or service updates

We do not sell your data. We do not use your data for advertising. We do not use your content to train AI models.

## Google User Data

Neither's use and transfer to any other app of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

We only use Google user data to provide the features you explicitly request. We do not use Google data for advertising, and we do not transfer it to third parties except as necessary to provide the service.

## Third-Party Services

We use Supabase (database and authentication), Railway (application hosting), Nango (OAuth connection management), and OpenAI (AI processing under a DPA; your data is not used to train their models). These services process your data solely to provide Neither's functionality.

## Data Security

All data is encrypted with TLS 1.3 in transit and AES-256 at rest. Every workspace is isolated with row-level security (RLS) policies. See our [Data & Security](https://www.neither.online/security) page for more detail.

## Data Retention

Your data is retained as long as your account is active. Raw uploaded files are processed and not retained after extraction — we keep only the structured data. When you delete your account or data, it is removed within 30 days (backup retention window).

## Your Rights

You can access, export, delete items or your entire workspace, disconnect integrations, or delete your account. Use in-app settings or contact privacy@neither.online.

## Changes to This Policy

If we make material changes, we will notify you via the email associated with your account. Continued use of Neither after changes constitutes acceptance.

## Contact

privacy@neither.online
