NeuroCognica
Privacy Policy
Version: 2.0 · Effective: 2026-08-04 Data controller: Michael Holt, trading as NeuroCognica
Read this first: two different things
NeuroCognica runs two things with genuinely different privacy properties, and blurring them would be dishonest in one direction or the other.
| What it is | Where your data lives | |
|---|---|---|
| ChronoSophia | The desktop application you install | Your machine. Nothing is transmitted to us |
| neurocognica.org | This website | Our infrastructure, like any website |
The desktop application is local-first and stays that way. The website is a website. When we say "nothing leaves your machine", that is a statement about ChronoSophia, and this document keeps the two apart so it cannot be read as covering both.
Part A — ChronoSophia, the desktop application
A1. What runs locally
Everything on the creative path:
| Data | Where it lives |
|---|---|
| Your prompts | Local — processed by a language model on your machine |
Renders, .blend files, textures, manifests |
Local — your renders and data directory |
| Scene plans and validation decisions | Local |
| Safety-gate decisions (allow, refuse, hold) | Local — sealed into your own ledger |
| The provenance ledger (BLAKE3 hash-chained) | Local, on your disk |
| AI models | Local — downloaded from their publishers to your machine |
No cloud API keys are required. No inference happens off your machine. We could not read your prompts if we wanted to, because they are never sent anywhere.
That includes the content-safety gate. It evaluates your request on your own hardware and records the decision to your own ledger. A refusal is not reported to us, and we cannot see that it happened.
A2. Telemetry — what is actually true today
The application has a telemetry framework with three consent levels, visible in Diagnostics ▸ System ▸ Telemetry & Privacy: Operational (marked required), Performance (off by default), and Content / training data (off by default).
The honest state of this feature: the collector is a local sink only. It writes JSONL to a file in your own application data directory. There is no upload endpoint, no network transport, and no code path that sends any of it to us. "Operational telemetry required" means a local log is written, not that anything is reported to anyone.
If that ever changes it will be disclosed in the release notes and require your consent before transmission — not enabled quietly in an update.
You can read your own telemetry log; its path is shown in Diagnostics ▸ System. You may delete it at any time.
A3. Network activity the application does make
Local-first does not mean airgapped, so here is every case:
- Dependency and model setup — downloads third-party tools and AI models from their own publishers, with your item-by-item consent, during setup.
- Update checks — if the in-app updater is used, it requests a feed file from the configured URL. Like any HTTP request, that reveals your IP address and the fact a check occurred to whoever hosts the feed. It carries no prompts, no renders, and no identity.
Neither path carries your creative work.
Part B — neurocognica.org, this website
B1. What the website collects today
Today: nothing. As of this version the site is static pages served from Cloudflare. It sets no cookies, runs no analytics, has no accounts, and embeds no third-party trackers, fonts, or scripts. There is nothing for you to opt out of because nothing is running.
The one unavoidable exception is the same for every website in existence: our host, Cloudflare, processes connection data — your IP address, the page requested, your browser's user-agent — in order to physically deliver the page and to block attacks. That is infrastructure, it is not analytics, and we do not receive a report of it.
B2. What we receive when you contact or buy
Only what you deliberately send:
- Purchase data — your email address and order details, handled by the payment platform. Where a platform acts as merchant of record it is the controller for payment data and holds your card details; we never see your card number. The platform in use is identified at checkout.
- Support correspondence — whatever you write to us, plus any logs or support bundle you choose to attach.
B3. Support bundles — read before sending
A support bundle may contain log files, configuration, version details, and file paths — which can include folder names and, depending on what you were doing, prompt text.
You choose whether to send one. Nothing is transmitted automatically. Review it first if it might contain something sensitive; we will work without one, it is just slower. Support material is used only to solve your problem, is never used for training, is not shared with third parties, and is deleted when the issue is closed or on your request.
Part C — Accounts and Mirrorborn
Status: not yet active. Sign-in, accounts, analytics and the Mirrorborn assessment are in development and not running on this website today. This section is published in advance so the terms are visible before anything collects anything — not after.
Nothing described here starts silently. When it launches, this document gets a new version and effective date, and analytics will not run at all until you have actively consented.
C1. What accounts will collect
- Identity from Google sign-in — your Google account identifier, email address, name and profile picture. We never receive your Google password.
- Purchase and download records — so you can re-download what you bought and we can support you.
- Consent records — what you agreed to and when, including whether you opted into analytics.
C2. Mirrorborn assessment data — the sensitive part
Mirrorborn is a reflection tool. Its whole purpose is that you write about yourself, so its data is more sensitive than anything else we hold, and it gets stated bluntly rather than buried:
- We will store your written answers, the resulting five-station profile, and your history of past assessments — the history is the point of the product, because it is what lets you see change over time.
- Answers are processed by a third-party AI model provider to tag them against a fixed taxonomy. That is a real disclosure: unlike ChronoSophia, this processing happens off your machine.
- Legal basis: your consent. Not contract, not legitimate interest. You can withdraw it, and withdrawing means deletion.
- Mirrorborn is not a clinical or diagnostic tool and its output is not
medical or psychological advice. See
MIRRORBORN_TERMS.md. - You will be able to export everything, delete a single assessment, or delete your account and all of its data.
C3. Analytics, when it exists
First-party only — no Google Analytics, no advertising networks, no cross-site tracking, and your data is never sold or shared with advertisers.
- Gated behind an explicit consent banner. Nothing fires before you opt in.
- IP addresses and user-agents stored hashed, never in the clear.
- Retained 90 days, then deleted automatically.
C4. Administrative access
For support and refunds, the operator can view an individual account's purchases, downloads and assessment status. That means a human at NeuroCognica can, in principle, read what you wrote in an assessment. Every administrative action is written to an append-only audit log. We would rather tell you this than have you assume otherwise.
Part D — Applies to everything
D1. Legal basis and retention
| Data | Basis | Retained |
|---|---|---|
| Purchase records | Contract, and legal obligation for tax | As required by tax law, typically 6–7 years |
| Support correspondence | Contract / legitimate interest | Until resolved, then routinely deleted |
| Support bundles | Your consent | Deleted when the issue closes, or on request |
| Account identity (when live) | Contract | Until you delete your account |
| Assessment data (when live) | Consent | Until you delete it or withdraw consent |
| Analytics events (when live) | Consent | 90 days |
| Anything on your machine | — | Entirely yours; we hold no copy |
D2. Your rights
You may request access to, correction of, or deletion of the personal data we hold. You may object to processing, request portability, withdraw any consent you gave, and complain to your data protection authority (in the UK, the ICO).
Ask via SUPPORT.md and you will get a straight answer about exactly what exists.
D3. Children
Neither ChronoSophia nor Mirrorborn is directed at children under 16, and we do not knowingly collect their data.
D4. Changes
Material changes are published with a new version and effective date at the top. The copy shipped with your installed version records the terms in force for it. A change that starts new collection requires fresh consent; it does not take effect by publication alone.
D5. Contact
Privacy questions or requests: see SUPPORT.md.