Privacy Policy
Last updated: July 15, 2026
NeuroLog is a program of the NeuroLog.life 501(c)(3) nonprofit. It helps autistic and minimally-verbal children communicate, and helps their parents and therapists work together. Because our users include young children, we hold ourselves to a strict standard: we collect the minimum data the product needs, we never sell or advertise with it, and your child's name is never stored in readable form on our servers. This page explains exactly what we collect and why.
What we collect about your child
- Name — encrypted. You give us your child's name so the app can greet you with it. It is encrypted (AES-256-GCM) before it is stored; our database, backups, logs, emails, and AI systems only ever see the encrypted form or a random code like
#A7B3. - Age and communication level (e.g. non-verbal, minimally verbal).
- Communication-board activity: which picture-words your child taps, the phrases they build, emotion check-ins, calming-tool use, and when this happens. This is the product — it is how the app shows you what your child is asking for.
- Structured home and therapy entries: fixed-choice logs from you (sleep, meals, moods — chips and scores, no free-text) and from the linked therapist (activities, prompt levels, scores, checkbox observations — no free-text notes).
We deliberately do not collect: your child's date of birth, diagnosis records, medication names, photos or videos of your child, precise location, or any prose anyone writes about your child. The forms simply have no place to put them.
What we collect about you (parent or therapist)
- Account details: name, email, phone number, and (for therapists) clinic name.
- Your access request answers when you ask to join the pilot.
- Product-usage signals (which screens are used, which features are pressed) — these are validated so they can never contain your child's data, and they exist so we can tell our funders the product is used and improve it.
- Feedback and support messages you choose to send us.
What we will never do
- No selling data. Ever.
- No advertising, no ad trackers, no third-party analytics scripts. The app contains none.
- No sharing with data brokers, insurers, or schools.
- No AI training on your child's data without separate, optional consent. The optional research consent at signup is unbundled — you can use NeuroLog fully without checking it, and you can withdraw it at any time.
Children's Privacy Notice
Children under 13 use the NeuroLog communication board directly. We collect their board activity (described above) only after a parent or legal guardian creates the account, consents, and hands the child the device. Parents can review everything collected about their child in the parent dashboard, and can delete it all at any time (see Deletion). We maintain a written children's data security program, we do not condition the service on consenting to research, and we never use children's data for advertising or profiling. If you believe a child's data reached us without guardian consent, email founders@neurolog.life and we will delete it.
How your data is protected
- Encrypted in transit (TLS) and at rest (AES-256); the child's name is additionally encrypted at the application layer.
- Strict access rules: a therapist can only ever see children explicitly linked to them by the parent's code; families can never see each other's data.
- Every server request is identity-verified; admin access uses cryptographically-signed claims; sessions expire after 20 minutes of inactivity in clinical views.
- Infrastructure runs on Google Cloud with least-privilege service accounts, no shared keys, and independent security review (our latest audit findings and fixes are tracked internally).
Who processes your data
- Google Cloud (Firestore database, Cloud Run hosting, Cloud Storage) — where the app runs and data lives (US region).
- Google Vertex AI (Gemini) — generates the plain-language activity summaries. It receives only de-identified pattern data: never your child's name, never free-text about them.
- Stripe — processes donations only. Stripe never sees any child data.
- ARASAAC — the child's device loads its open-source pictogram images from ARASAAC's servers (like loading any image on the web). No account data is sent.
Retention and deletion
Your data is kept while your account is active. When you delete your account (Profile → Delete account), we permanently delete your children's profiles, all board activity, home and therapy entries, uploaded photos, and your usage records — immediately and irreversibly. We retain only: a de-identified deletion record (hashed identifiers, no names) for accountability, and consent records we are legally required to keep. Feedback you sent us is kept but stripped of your identity.
If something goes wrong
If a breach of unsecured data ever affects your family, we will notify you directly and promptly, and notify the U.S. Federal Trade Commission as required by the FTC Health Breach Notification Rule. We are a Texas organization and honor the Texas Medical Records Privacy Act's protections for Texas residents.
Your rights
- See everything we hold about your child (it is all in your dashboard).
- Correct your account information (Profile page).
- Delete everything (Profile → Delete account, effective immediately).
- Withdraw research consent without losing the service — email us.
- Unlink a therapist at any time — their access ends immediately.
Changes and contact
If we materially change this policy, we will email account holders and require renewed consent before the change applies to children's data. Questions, requests, or concerns: founders@neurolog.life.