1Introduction
Infrastacks, LLC, doing business as NeuronEdge.AI ("NeuronEdge," "we," "us," or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our PII protection services ("Services").
By accessing or using our Services, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Services.
2Company Information
3Information We Collect
Account Information
When you create an account, we collect:
- Email address and name
- Organization name and details
- Billing information (processed by Stripe)
- Authentication credentials (managed by Clerk)
Usage Data
We automatically collect certain information when you use our Services:
- API request metadata (timestamps, endpoints, response codes)
- Request volume and rate limiting information
- Detection statistics (entity types detected, counts—never the actual PII values)
- Performance metrics (latency, error rates)
Customer Data Processing
Critical: We do not store your PII data.
Our Services are designed specifically to protect your sensitive data.
- PII is detected and redacted in-memory only
- Original values are restored on response and never persisted
- We maintain zero-knowledge of the actual PII content
- Only metadata (entity types, counts) is logged for analytics
4How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain our Services
- Process your transactions and manage your account
- Send administrative information (service updates, security alerts)
- Respond to your comments, questions, and support requests
- Monitor and analyze usage patterns to improve our Services
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
5Third-Party Services
We use the following third-party services to operate NeuronEdge:
Infrastructure & Hosting
- Cloudflare: Edge computing, CDN, and security (SOC 2, ISO 27001, GDPR compliant)
- Neon: PostgreSQL database hosting (SOC 2, HIPAA BAA available)
Authentication & Payments
- Clerk: User authentication and session management (SOC 2 compliant)
- Stripe: Payment processing (PCI DSS Level 1 compliant)
Analytics & Monitoring
- Cloudflare Analytics Engine: API usage analytics (no PII logged)
- Sentry: Error tracking and monitoring
6Data Security
We implement appropriate technical and organizational measures to protect your data:
- All data is encrypted in transit using TLS 1.3
- Database encryption at rest
- API keys are hashed using bcrypt (not stored in plaintext)
- Role-based access controls for all internal systems
- Regular security assessments and penetration testing
- Infrastructure on SOC 2 and ISO 27001 certified platforms
7Data Retention
We retain different types of data for different periods:
- Account data: Retained while your account is active, deleted within 30 days of account closure
- Usage analytics: Aggregated data retained for up to 2 years
- Audit logs: 7-90 days depending on your subscription tier
- Customer PII: Never stored—processed in-memory only
8Your Rights
GDPR Rights (EU/EEA Residents)
If you are located in the European Economic Area, you have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Request erasure of your personal data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
CCPA Rights (California Residents)
California residents have the right to:
- Know what personal information is collected
- Know whether personal information is sold or disclosed and to whom
- Say no to the sale of personal information (we do not sell your data)
- Access your personal information
- Request deletion of your personal information
- Not be discriminated against for exercising your rights
9International Data Transfers
Your information may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Data Processing Agreements with all subprocessors
- Use of providers certified under recognized frameworks
10Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us.
11Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For material changes, we will provide notice via email or through the Services.
12Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us: