Privacy Policy
Last updated July 20, 2026
NeuralCore is operated by Muhammed Semri ("NeuralCore," "we," "us," or "our"), located at Judeidah-Maker, Israel. This Privacy Policy explains how NeuralCore handles information when you use the NeuralCore mobile application and contact us about the app.
NeuralCore is designed to work without an account. Its free features can be used with data stored only on your device. If you choose to create an account and use eligible Premium features, limited account, tinnitus-related, progress, masking-preference, and subscription information is processed as described below.
1. At a glance
- We do not sell personal information.
- We do not use advertising, analytics, cross-app tracking, or crash-reporting SDKs.
- We do not use personal information for targeted advertising.
- The microphone is used only to estimate ambient room loudness in real time. Audio is not recorded, saved, or transmitted.
- An account is optional. Without one, app preferences and progress remain on your device.
- For signed-in Premium users, selected progress, questionnaire answers, and masking settings are synced through Firebase so they can be used across devices.
- Apple or Google processes payments. We do not receive your full payment-card or bank-account details.
- You can delete your NeuralCore account and synced data in the app. Account deletion does not cancel an App Store or Google Play subscription.
2. Information we handle
A. Information stored only on your device
Depending on how you use NeuralCore, the app may store the following locally using your device's app storage:
- onboarding completion and your optional answers to the tinnitus questionnaire;
- your nightly goal, session progress, current streak, best streak, and last session date;
- masking preferences, including noise type, volume setting, and notch-filter setting and frequency;
- subscription-entitlement status cached for offline use;
- app appearance or theme preference; and
- internal development settings in non-production builds.
This information does not leave your device unless you are both signed in and eligible for cloud sync as described below. Local information generally remains until you clear the app's data or uninstall the app. Using the in-app account deletion feature clears the locally stored account, onboarding, progress, masking, and entitlement information, but keeps the device's theme preference. You can remove that preference by clearing the app's data or uninstalling the app.
B. Account and sign-in information
Creating an account is optional. If you create or use an account, Firebase Authentication processes:
- a unique account identifier;
- your email address;
- authentication credentials or tokens;
- your sign-in provider (email/password, Apple, or Google); and
- limited security and technical information used by Firebase Authentication, such as IP address, user agent, and sign-in activity.
If you sign in with Apple or Google, that provider may supply profile information such as your email address, name, or profile image, depending on your provider settings and what you authorize. NeuralCore's app interface uses only your account identifier and email address, but Firebase Authentication may retain profile fields returned by your sign-in provider. We do not receive your Apple ID or Google Account password. For email/password accounts, Firebase Authentication handles the password; we do not store a readable copy.
C. Information synced for signed-in Premium users
When a Premium user signs in, NeuralCore uses Cloud Firestore to sync two account-specific records:
- Profile and progress: optional questionnaire answers about what bothers you most, the type of tinnitus sound you experience, and how tinnitus disrupts you; your nightly goal; streak counts; best streak; last session date; and record-update time.
- Masking preferences: noise type, volume offset, whether the notch filter is enabled, notch frequency, and record-update time.
Questionnaire answers and masking preferences may reveal information about your health or tinnitus symptoms. The questionnaire is optional and may be skipped. Where applicable law treats this information as sensitive or health data, we process it with your consent or another basis permitted by law. You can withdraw consent by deleting the synced data and your account, but this does not affect processing that occurred before withdrawal.
Firestore records are keyed to your Firebase account identifier. The app's database rules restrict each signed-in user to their own records. They are not public or visible to other users.
D. Microphone and ambient loudness
The Premium adaptive-volume feature can use your device's microphone while masking audio is playing. NeuralCore analyzes the microphone input on your device in real time to calculate a temporary ambient-loudness estimate. The estimate is used to adjust the masker volume within the app's safety limit.
NeuralCore does not record microphone audio, route it into the masking output, save it, upload it, or send it to us or any third party. The temporary loudness estimate is not saved or associated with your account. If you deny or revoke microphone permission, NeuralCore uses fixed-volume masking instead. You can change microphone permission in your device settings.
E. Subscription and purchase information
Purchases are processed by Apple through the App Store or by Google through Google Play. The relevant store handles your billing details under its own terms and privacy policy. We do not receive your full payment-card or bank-account information.
NeuralCore uses RevenueCat to provide subscription offerings, validate purchase receipts, restore purchases, and determine whether Premium access is active. RevenueCat receives:
- a random RevenueCat identifier when you are signed out, or your Firebase account identifier when you are signed in;
- purchase receipt, product, transaction, subscription-status, entitlement, expiration, and renewal information; and
- limited app, device, platform, and technical information needed to operate and secure the purchase service.
NeuralCore does not intentionally send your name or email address to RevenueCat. A signed-in Firebase identifier is nevertheless linked to your NeuralCore account in our systems.
F. Communications with us
If you contact us, we receive the information you choose to provide, such as your email address, message, and any troubleshooting details you include. Please do not send medical records or other sensitive information that is not needed to answer your request.
3. How and why we use information
We use the information described above to:
- provide, personalize, and maintain NeuralCore's features;
- create and authenticate optional accounts;
- sync settings and progress across devices for eligible signed-in users;
- adapt masking volume on-device when you enable microphone access;
- process, validate, restore, and manage Premium entitlements;
- protect the app, prevent fraud or misuse, and troubleshoot problems;
- respond to support, privacy, and legal requests;
- comply with law and enforce our Terms of Service; and
- improve reliability based on direct feedback, without analytics or tracking SDKs.
NeuralCore does not make decisions that produce legal or similarly significant effects based solely on automated processing.
4. Legal bases for processing
Where the law requires us to identify a legal basis, we rely on one or more of the following:
- Performance of a contract: to provide the app, accounts, cloud sync, and subscription features you request.
- Consent: for optional microphone access and, where required, optional health-related questionnaire information or other sensitive information. You may withdraw consent at any time through app or device controls or by contacting us.
- Legitimate interests: to secure the service, prevent fraud, provide support, and maintain the app, where those interests are not overridden by your rights.
- Legal obligation: to comply with applicable law, valid legal requests, tax, accounting, or consumer-protection requirements.
5. When information is disclosed
We disclose information only as needed for the purposes described in this Policy:
- Google Firebase: Firebase Authentication provides account sign-in and Cloud Firestore provides optional cloud sync. Google generally acts as our service provider or processor for this data. See Firebase Privacy and Security and the Google Privacy Policy.
- RevenueCat: RevenueCat manages subscription status and purchase validation. See the RevenueCat Privacy Policy.
- Apple and Google: Apple or Google provides sign-in when selected and processes app-store purchases. See Apple's Privacy Policy and the Google Privacy Policy.
- Professional advisers and authorities: We may disclose information to advisers, courts, regulators, law enforcement, or other authorities when reasonably necessary to comply with law, protect rights or safety, investigate fraud, or establish, exercise, or defend legal claims.
- Business changes: If the app or its operator is involved in a merger, financing, reorganization, sale, or transfer, information may be disclosed subject to appropriate confidentiality and privacy safeguards.
We do not permit service providers to use NeuralCore account or health-related information for their own advertising.
6. International data transfers
Firebase, RevenueCat, Apple, and Google may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we and our service providers use recognized safeguards for international transfers, such as adequacy decisions, contractual protections, or other lawful transfer mechanisms.
7. How long information is kept
- On-device information remains until you change or clear it, use the in-app account deletion feature, clear the app's data, or uninstall the app. As noted above, account deletion keeps the device theme preference.
- Firebase account and synced data is generally kept while your account is active. The in-app deletion flow attempts to delete the two synced Firestore records and then your Firebase Authentication account immediately. If a network or authentication error interrupts deletion, retry in the app or contact us.
- Purchase and subscription records may be retained by RevenueCat, Apple, or Google for subscription administration, fraud prevention, accounting, dispute resolution, and legal compliance under their own retention rules. Signing out of RevenueCat or deleting your NeuralCore account does not itself cancel a subscription or erase store transaction records.
- Support communications are kept only as long as reasonably necessary to answer the request, maintain appropriate records, resolve disputes, or comply with law.
Service providers may retain securely protected backups or logs for limited periods under their own documented retention processes. We may also retain information where law requires it, while limiting use to that purpose.
8. Your choices and privacy rights
Depending on where you live, you may have rights to:
- access or receive a copy of personal information;
- correct inaccurate personal information;
- delete personal information;
- restrict or object to certain processing;
- withdraw consent;
- receive certain information in a portable format; and
- appeal a refusal or complain to your local data-protection authority.
You may also have the right not to receive discriminatory treatment for exercising a privacy right. NeuralCore does not sell personal information or share it for cross-context behavioral advertising.
To exercise a right, email privacy@neuralcore.io. We may need to verify your identity before completing a request. Authorized agents may submit requests where permitted by law, subject to verification of their authority.
Delete your account and data
You can permanently delete your NeuralCore account from Settings → Delete account. The app deletes your synced profile and masking records, deletes the Firebase Authentication account, and clears locally stored account data except the device theme preference. Deletion is immediate and cannot be undone once completed.
If you no longer have access to the app, email privacy@neuralcore.io with the subject "NeuralCore account deletion request." Do not send your password. We will provide a way to verify the request.
Deleting your NeuralCore account:
- does not cancel an App Store or Google Play subscription;
- does not delete your Apple ID or Google Account; and
- does not automatically erase transaction records that Apple, Google, or RevenueCat must or is permitted to retain.
Cancel an active subscription separately through your Apple subscriptions or Google Play subscriptions settings.
9. Security
We use reasonable technical and organizational safeguards appropriate to the information we handle. These include encrypted network transport provided by our service providers and Firestore access rules designed to limit account records to the authenticated account owner. No system is completely secure, and we cannot guarantee absolute security.
10. Children
NeuralCore is intended for adults and is not directed to children under 16. We do not knowingly collect personal information from anyone below that age. If you believe a child has provided personal information, contact privacy@neuralcore.io so we can investigate and delete it where appropriate.
11. Health information and emergency use
NeuralCore is a self-management and wellness tool. It is not a medical device and does not diagnose, treat, cure, or prevent any medical condition. Information entered in the app is not monitored by healthcare professionals. Do not use NeuralCore to communicate an emergency. Seek help from a qualified healthcare professional for medical advice, diagnosis, or treatment, and contact local emergency services when appropriate.
12. Changes to this Policy
We may update this Policy to reflect changes to NeuralCore, our service providers, or the law. We will update the "Last updated" date and provide additional notice in the app or by other appropriate means if a change is material or consent is required.
13. Contact us
Questions, complaints, and privacy requests may be sent to:
Muhammed Semri
Judeidah-Maker, Israel
privacy@neuralcore.io