Legal
Privacy Policy
Last updated: July 16, 2026 | Effective: June 6, 2026
1. Information We Collect
We collect information you provide directly when you create an account, subscribe to a plan, request support, or join a team workspace. This may include your name, email address, institution, role, account settings, billing status, and support messages.
Payment details are handled by Paddle or another disclosed payment processor. BCINexus does not store raw card numbers.
When you use BCILattice locally, signal recordings, preprocessing configurations, experiments, trained models, and reports remain on your device unless you intentionally upload, sync, share, or publish them through a BCINexus cloud feature. Only content you set to "public" visibility, and only if you have not turned this off in Settings, may be analyzed to advance BCI research and to develop, train, and improve BCINexus's AI models, agents, and product features, as described in Section 2 and the Terms of Service. Team and private content is never used for this purpose.
Product analytics, operational telemetry, browser storage, and crash or error information may be collected to operate, secure, measure, and improve the Services. These signals are intended to exclude raw dataset contents and research participant identifiers.
2. How We Use Your Information
We use account information to authenticate users, manage subscriptions, provide support, send transactional emails, prevent abuse, and operate team collaboration features.
Uploaded team, project, dataset, and study data is used to provide the storage, sharing, publishing, review, and collaboration workflows you choose to use.
Separately, content you set to "public" visibility — never team or private content — may be analyzed for usage patterns, workflows, and pipeline structures to advance BCI research and to develop, train, and improve BCINexus's AI models, agents, and product features, as described in the Terms of Service. This is on by default for web-app accounts and off by default for desktop-app accounts; you can view or turn it off at any time in Settings, and doing so stops this use going forward. Local, on-device data that you never upload, sync, share, or publish is never used for this purpose, and neither is any content that could constitute PHI or other regulated patient data.
We do not sell personal information. Aggregated and de-identified operational metrics may be used to improve reliability, performance, security, abuse prevention, and product design.
3. Data Storage, Retention, and Security
BCINexus uses encryption in transit for web and API traffic and applies access controls to production systems. Passwords are stored as one-way hashes; we cannot recover your password.
Dataset and project uploads may be verified with checksums to detect corruption during upload, download, or sync. Enterprise deployments may use additional controls defined in a signed agreement.
We retain account data while your account is active and may retain limited records after deactivation, deletion, anonymization, or a privacy request where needed for reviewer activity, research papers, publications, security records, billing records, legal records, backups, disputes, abuse prevention, platform integrity, or publication integrity. Billing records may be retained for the period required by applicable tax and accounting rules.
Privacy removal, anonymization, export, objection, restriction, or erasure requests are reviewed manually through [email protected] and may be limited by legal, billing, security, research-integrity, publication-integrity, backup, or dispute requirements.
4. Data Sharing
We share data only when necessary to provide the service, comply with law, or protect users and the platform. Categories of recipients may include:
- Payment processors for billing and subscription management
- Email providers for transactional and support communications
- Cloud infrastructure providers for hosting, storage, and reliability
- Analytics, monitoring, or error-reporting providers for product measurement, security, and reliability
- Professional advisors or authorities where legally required
If we receive a valid legal request, we may disclose information as required. Where legally permitted and practical, we will notify affected users before disclosure.
5. Your Rights (GDPR and Similar Laws)
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing of your personal data.
Users in the EEA, UK, and similar jurisdictions can exercise these rights by emailing [email protected]. We may ask for information needed to verify your identity and protect your account.
Requests are handled through manual support and legal review unless a specific self-service control is available in the product. We aim to respond to verified privacy requests within 30 days unless a longer period is permitted by law.
6. Cookies, Browser Storage, and Analytics
Our website uses cookies, localStorage, and sessionStorage for authentication, security, checkout, workspace state, profile caching, preferences, and product operation.
Analytics and similar technologies are active for product reliability and usage measurement. We do not use third-party advertising cookies on authenticated application pages. See the Cookie Policy for details about known cookies and browser-storage categories.
7. Children
BCINexus is not directed to children under 16. Account creation is intended for adults and authorized institutional users. If a stricter local age threshold applies, users and institutions are responsible for meeting that requirement. If we learn that a child provided personal information without appropriate consent, we will delete it or take other required action.
8. Changes to This Policy
We may update this Privacy Policy to reflect product, operational, or legal changes. If a change is material, we will provide notice by email, in-app message, or website notice before it takes effect where required.
9. Contact
Responsible party: BCINexus. Formal legal entity name, registered address, DPO, EU representative, and UK representative details require business/legal approval before publication.
For privacy-related questions, data requests, or concerns, contact us at:
Email: [email protected]
Legal: [email protected]
Security: [email protected]