NeuronSearchLab

Product Privacy Policy

Last updated July 21, 2026

1. Scope

This Product Privacy Policy explains how NeuronSearchLab processes information when customers and authorized users access the NeuronSearchLab admin console, APIs, SDKs, Model Context Protocol (“MCP”) server, and related recommendation services (collectively, the “Service”). It supplements the separate privacy policy for our public marketing website.

2. Roles and customer responsibility

NeuronSearchLab processes account and service-operation data to provide the Service. For catalog, end-user, event, and recommendation data submitted by a customer, the customer determines what data is provided and why it is processed, and NeuronSearchLab processes that data on the customer's behalf.

Customers are responsible for having an appropriate legal basis and giving any notices required before submitting personal data to the Service. Customers should use stable pseudonymous user identifiers instead of names or email addresses whenever practical.

3. Information we process

Depending on how a customer configures and uses the Service, we may process:

  • account information, such as name, business email, workspace, role, and login activity;
  • catalog records, including item identifiers, names, descriptions, metadata, status, and embeddings;
  • end-user identifiers supplied by the customer, which may include an email address if the customer chooses to use one;
  • interaction events, such as views, clicks, purchases, timestamps, session identifiers, and attribution request identifiers;
  • recommendation, ranking, search, and explanation results;
  • workspace configuration, including contexts, pipelines, rules, segments, experiments, event types, training templates, and model settings;
  • analytics derived from catalog, recommendation, and event activity;
  • MCP tool names and arguments submitted by an authorized user or agent, together with the tool result needed to complete the requested console operation; and
  • technical and security data, such as IP address, browser or client type, request time, API-key prefix and hash, permission scopes, audit records, and error diagnostics.

NeuronSearchLab API keys are stored as one-way hashes. The complete key is displayed only when it is created. The hosted MCP plugin does not expose the tool that creates and returns a new API key.

4. How we use information

  • provide, secure, troubleshoot, and support the Service;
  • authenticate users and enforce workspace roles and API scopes;
  • ingest catalogs, record events, generate recommendations, rank and search items, and explain results;
  • operate customer-configured rules, experiments, analytics, and model-training workflows;
  • measure usage, enforce plan limits, prevent abuse, and maintain service reliability; and
  • comply with law and enforce our agreements.

5. MCP and AI assistants

The MCP server lets an authorized AI assistant inspect and operate the customer's NeuronSearchLab workspace. Available tools can read customer configuration and analytics or perform requested changes such as creating a rule, starting an experiment, or revoking an API key. Tool availability is limited by the authenticated workspace and key scopes.

The hosted plugin does not receive an entire ChatGPT conversation by default. It receives the tool name and arguments that the assistant sends to the MCP server. Information sent to an AI-assistant provider is also governed by the customer's agreement and settings with that provider.

6. Sharing and service providers

We do not sell personal data. We may share information with infrastructure, database, authentication, monitoring, communication, billing, and machine-learning service providers that help us operate the Service, subject to contractual confidentiality and data-protection obligations.

We may also disclose information when required by law, to protect rights or security, or as part of a corporate transaction. Connected integrations process data according to the customer's configuration and the terms of the integration provider.

7. Retention and deletion

We retain customer data for as long as needed to provide the Service and according to the workspace's configured plan, retention settings, and applicable agreement. Analytics retention periods may vary by plan. Security, billing, audit, and legal records may be kept longer where reasonably necessary.

Authorized users can update or delete many resources through the console, API, or MCP tools. Workspace administrators may contact support to request account closure, export, or deletion where those controls are not available directly.

8. Security

We use administrative and technical safeguards designed to protect information, including tenant-scoped access controls, scoped credentials, one-way API-key hashing, encryption in transit, and audit records for supported administrative actions. No system can guarantee absolute security. Customers must protect their credentials and promptly revoke any key they believe has been compromised.

9. International processing and legal rights

Information may be processed in countries where NeuronSearchLab or its service providers operate. Where required, we use appropriate safeguards for international transfers.

Depending on location, individuals may have rights to access, correct, delete, restrict, or object to processing of personal data. End users whose information was submitted by a NeuronSearchLab customer should normally direct requests to that customer. We will assist customers with verified requests as required by applicable law.

10. Children

The Service is intended for business customers and authorized adult users. It is not directed to children, and customers must not submit children's personal data unless they have all permissions and safeguards required by law and their agreement with us permits it.

11. Changes and contact

We may update this policy as the Service or legal requirements change. We will update the date above and provide additional notice where appropriate.

Questions, privacy requests, and customer-support requests can be sent to legal@neuronsearchlab.com or support@neuronsearchlab.com.