Privacy Policy

Privacy Policy

Protecting your personal data is important to us. This privacy policy explains what personal data we process when you visit our website, create a Neurapix account, or use our image editing service — including our plugins, the instant-processing connections (Google Drive, Frame.io, FTP) and the delivery to Adobe Lightroom — and what rights you have.

1. Who is responsible for data processing?

The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:

neurapix GmbH

Am Feuerschanzengraben 10

37083 Göttingen, Germany

Represented by the Managing Director: Nils Sauder

Registered at the District Court of Göttingen, HRB 206286

E-mail: hello@neurapix.com

2. What does this policy cover?

This policy covers:

• our website at neurapix.com,

• your Neurapix account and the Neurapix portal,

• our image editing service, regardless of the channel you use to transmit images to us (website, Neurapix plugin for Adobe Lightroom Classic, Google Drive, Frame.io, or FTP), and

• the optional connection of your Adobe Lightroom account for delivering edited images into your Lightroom catalog ("Lightroom cloud connection").

The contractual terms of the image editing service are set out in our Image Editing Contract.

3. What data do we process, for what purpose, and on what legal basis?

3.1 Website log files

When you visit our website, our web server automatically records: browser type and version, operating system, referrer URL, pages visited, date and time of access, and your IP address.

• Purpose: security, stability and improvement of our website.

• Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and stable operation of our website).

• Retention: log files are deleted within 7 days, unless a longer retention is required to investigate a specific security incident.

3.2 Cookies and consent management

We use cookies to provide functionality, security, and — with your consent — analytics and marketing. On our website we use the consent manager Cookiebot, in the Neurapix portal the consent manager Klaro. Both let you accept or decline analytics and marketing cookies and change your decision at any time; analytics and marketing tools are off by default.

Technically necessary cookies (legal basis: Art. 6(1)(f) GDPR):

• token — 2 days — keeps you logged in (portal)

• CookieConsent — 12 months — Cookiebot: records your cookie decision (website)

• klaro — 12 months — Klaro: records your cookie decision (portal)

Analytics and marketing cookies (legal basis: Art. 6(1)(a) GDPR — your consent, revocable at any time via the cookie settings; details on each service in section 6):

• _ga, _ga_* — 13 months — Google Analytics: distinguishes visitors and sessions

• _fbp — 3 months — Meta: personalized advertising and conversion measurement

• _pin_unauth — 12 months — Pinterest: conversion measurement

3.3 Account and contract data

When you register, we process the data you provide: e-mail address, name, and — where provided — company name, address, VAT ID and your chosen settings. We also process usage data required for billing (number and type of processed images, booked plans).

• Purpose: provision of your account, performance of the contract, billing, customer communication.

• Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for retention of billing records Art. 6(1)(c) GDPR (statutory retention obligations under German commercial and tax law).

• Retention: for the duration of the contractual relationship; billing-relevant records for the statutory retention periods of up to ten years.

3.4 Payment data

Payments are processed by our payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). Your payment details (e.g. credit card number, bank details) are collected directly by Stripe; we do not store full payment credentials on our systems. Stripe may transfer data to Stripe, Inc. in the USA; Stripe is certified under the EU-U.S. Data Privacy Framework and additionally uses EU standard contractual clauses.

• Purpose: payment processing, fraud prevention.

• Legal basis: Art. 6(1)(b) GDPR.

3.5 Image files you transmit for editing

Core of our service is the AI-based editing of your photos. You can transmit image files to us via the Neurapix plugin, our website, or the instant-processing sources Google Drive, Frame.io and FTP (see sections 3.7–3.9). We process these images on our servers to (a) create your individual editing profile ("SmartPreset") and (b) edit your photos in the selected style and return them to you.

• Purpose: provision of the image editing service you commissioned.

• Legal basis: Art. 6(1)(b) GDPR.

• Retention: image files transmitted for processing are deleted no later than 48 hours after processing or after delivery of the results. Preview images (JPEGs) rendered for download in your dashboard are kept for up to 7 days. Image files transmitted for the creation and continuous improvement of your individual SmartPreset are stored for as long as your contractual relationship with us exists, and are permanently deleted when no longer required for this purpose, at the latest upon termination of the contract.

Images containing personal data of third parties: Your photos may show identifiable persons (e.g. your clients). In this respect we process the image content exclusively on your behalf and on your instructions as a processor within the meaning of Art. 28 GDPR, on the basis of the data processing agreement concluded with you upon registration. You remain responsible for the lawfulness of the photographs themselves.

3.6 Lightroom cloud connection (Adobe)

If you use our Lightroom cloud connection, we deliver your edited photos directly into your Adobe Lightroom catalog, so that you can access them in Lightroom (e.g. Lightroom mobile or Lightroom desktop).

To do so, you authorize Neurapix once via Adobe's sign-in (OAuth). Adobe shows you a consent screen listing the requested permissions before you grant access: your identity at Adobe (openid, AdobeID), permanent access for background delivery (offline_access), and access to the Lightroom partner APIs used to write into your catalog (lr_partner_apis). We use this access exclusively to write your edited image files and the associated albums into your Lightroom catalog; we do not read, analyze or use other content of your Adobe account for any other purpose.

In this context we process:

• your Adobe account identifier and technical identifiers of your Lightroom catalog and target albums,

• the OAuth access and refresh tokens issued by Adobe — stored on our systems encrypted (AES-256-GCM),

• the edited image files transferred to your catalog.

You can revoke the connection at any time in your Neurapix account settings or centrally in your Adobe account (account.adobe.com → connected applications). Upon revocation or deletion of your Neurapix account we delete the stored tokens.

• Purpose: delivery of edited images into your Lightroom catalog.

• Legal basis: Art. 6(1)(b) GDPR.

• Recipient: Adobe Systems Software Ireland Limited, 4–6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. Adobe may transfer data to Adobe Inc. in the USA; Adobe Inc. is certified under the EU-U.S. Data Privacy Framework. Adobe's privacy policy: https://www.adobe.com/privacy/policy.html

3.7 Google Drive connection

You can transmit image files to us by connecting your Google Drive and selecting folders to watch. New image files that arrive in a selected folder are automatically retrieved for editing.

You authorize Neurapix via Google's sign-in (OAuth) with read-only access to your Google Drive (drive.readonly). We use this access exclusively to detect and retrieve image files from the folders you selected; due to the read-only scope, we cannot modify or delete anything in your Drive. We process your Google account identifier, technical folder and file identifiers, file names and timestamps, the retrieved image files, and the OAuth tokens issued by Google — stored encrypted (AES-256-GCM). To detect new files promptly, we register push notifications with Google for the selected folders.

You can revoke the connection at any time in your Neurapix account settings or centrally in your Google account (myaccount.google.com → security → third-party access). Upon revocation or deletion of your Neurapix account we delete the stored tokens.

Neurapix's use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

• Purpose: receiving your image files for editing.

• Legal basis: Art. 6(1)(b) GDPR.

• Recipient/Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy policy: https://policies.google.com/privacy

3.8 Frame.io connection

You can transmit image files to us by uploading them to a Frame.io project or folder connected with Neurapix. You authorize Neurapix via Adobe's sign-in (OAuth; Frame.io is an Adobe service) with access to your Frame.io account (scopes: openid, email, profile, offline_access, additional_info.roles). We retrieve newly uploaded image files via the Frame.io API for editing and process the associated technical metadata (account, project and asset identifiers, file names, upload timestamps) as well as the OAuth tokens issued by Adobe — stored encrypted (AES-256-GCM). If you enable the optional "delete after import" setting, we delete the source file in your Frame.io project after successful import.

You can revoke the connection at any time in your Neurapix account settings or centrally in your Adobe account. Upon revocation or deletion of your Neurapix account we delete the stored tokens.

• Purpose: receiving your image files for editing.

• Legal basis: Art. 6(1)(b) GDPR.

• Recipient/Provider: Adobe Systems Software Ireland Limited (Frame.io), 4–6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. Privacy policy: https://www.adobe.com/privacy/policy.html

3.9 FTP upload

You can transmit image files directly from your camera or computer to our FTP server (ftp.neurapix.com), which we operate ourselves on our infrastructure in Germany. For this we issue you personal FTP credentials. The server supports encrypted transfer (explicit FTPS/AUTH TLS); because many camera bodies do not support TLS, unencrypted FTP connections are also accepted — we recommend using FTPS whenever your device supports it.

We process your FTP credentials, connection and login data (IP address, timestamps, user name, transferred file names) for the operation and security of this access (including protection against brute-force login attempts), and the uploaded image files themselves.

• Purpose: receiving your image files for editing; security of the transfer infrastructure.

• Legal basis: Art. 6(1)(b) GDPR; for security logs Art. 6(1)(f) GDPR.

• Retention: uploaded image files are deleted no later than 48 hours after successful import of the edited results into your Lightroom; files that cannot be processed (e.g. unsupported formats) are deleted after 7 days. A storage quota applies per account.

3.10 E-mail communication

For transactional e-mails (e.g. registration confirmation, invoices, processing notifications) and — with your consent — product news, we use the dispatch service Brevo (Sendinblue GmbH / Brevo, Köpenicker Str. 126, 10179 Berlin, Germany) as a processor.

• Legal basis: Art. 6(1)(b) GDPR for transactional e-mails; Art. 6(1)(a) GDPR for marketing e-mails (unsubscribe at any time via the link in each e-mail).

3.11 Support

If you contact our support, we process your contact details, the content of your enquiry and, where relevant, account and job data needed to resolve your request. We use the ticketing service Help Scout (Help Scout PBC, Boston, MA, USA) as a processor. Help Scout is self-certified under the EU-U.S. Data Privacy Framework (including the UK Extension); in addition, transfers to the USA are safeguarded by EU standard contractual clauses.

• Legal basis: Art. 6(1)(b) GDPR (support as part of the contract), otherwise Art. 6(1)(f) GDPR.

4. Recipients and processors

We use carefully selected service providers as processors under Art. 28 GDPR, in particular:

• Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — hosting of our website, portal, API and FTP server (data centers in Germany). AI image processing itself runs on our own hardware at our site in Göttingen, Germany.

• Stripe (payments, section 3.4)

• Adobe (Lightroom cloud connection, section 3.6; Frame.io, section 3.8)

• Google (Google Drive connection, section 3.7; analytics, section 6)

• Brevo (e-mail dispatch, section 3.10)

• Help Scout (support, section 3.11)

• Meta, Pinterest (marketing, section 6)

We only disclose personal data to third parties where this is necessary for the performance of the contract, where you have consented, or where we are legally obliged to do so.

5. Transfers to third countries

Where the services named above transfer personal data to countries outside the EU/EEA (in particular the USA), this is done on the basis of an adequacy decision of the EU Commission (EU-U.S. Data Privacy Framework) or EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

6. Analytics and marketing

We use the following analytics and advertising services on our website and in the Neurapix portal. All of them run only with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the cookie settings (Cookiebot on the website, Klaro in the portal). In addition to the browser-side tags, we transmit selected service events (e.g. registration, first payment) to some of these providers server-side to measure the performance of our advertising; in doing so your e-mail address is only ever transmitted in hashed form (SHA-256), together with a pseudonymous ID and, where present, the advertising click ID of the respective platform.

6.1 Google Analytics

We use Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to analyze the use of our website and portal (including IP address, approximate location, time and frequency of visits). IP addresses are anonymized before any transfer outside the EU/EEA. Selected service events are additionally transmitted server-side via the Google Analytics Measurement Protocol using a pseudonymous identifier. Google may transfer data to Google LLC in the USA on the basis of the EU-U.S. Data Privacy Framework. Opt-out add-on: https://tools.google.com/dlpage/gaoptout

6.2 Meta pixel and Conversions API

We use the Meta pixel and the Meta Conversions API, provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland, to measure conversions from our ads and to enable interest-based advertising on Facebook and Instagram. Data may be transferred to Meta Platforms, Inc. in the USA on the basis of the EU-U.S. Data Privacy Framework and EU standard contractual clauses. You can manage your ad preferences at https://www.facebook.com/ads/preferences

6.3 Pinterest tag and conversions API

We use the Pinterest tag and the Pinterest conversions API, provided by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland, to measure conversions from our Pinterest ads. Data may be transferred to Pinterest, Inc. in the USA on the basis of EU standard contractual clauses. Privacy policy: https://policy.pinterest.com/privacy-policy

7. How do we keep your data secure?

Communication with our website, portal and APIs is encrypted (TLS/SSL); the FTP server additionally offers encrypted transfer via FTPS (see section 3.9). OAuth tokens for connected services are stored encrypted (AES-256-GCM). Access to our servers is restricted to authorized staff bound by confidentiality obligations. We regularly review our technical and organizational measures.

8. Your rights

You have the right to:

• access to your personal data (Art. 15 GDPR),

• rectification (Art. 16 GDPR),

• erasure (Art. 17 GDPR),

• restriction of processing (Art. 18 GDPR),

• data portability (Art. 20 GDPR),

• object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21 GDPR),

• withdraw any consent at any time with effect for the future (Art. 7(3) GDPR).

To exercise your rights, contact us at hello@neurapix.com.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.

9. Changes to this privacy policy

We will update this privacy policy when our services or the legal requirements change. The current version is always available on this page.

Last updated: 12 August 2026

Start with 1,000 free AI edits.

Automate your
editing process.

Automate your
editing process.

Automate your
editing process.

Copyright © 2026 Neurapix GmbH. All rights reserved.