Legal Document

Privacy Policy

Neuriko — Learning your way

Last Updated: June 18, 2026

This Privacy Policy sets out the rules for processing and protecting personal data collected by the Neuriko platform (hereinafter: "Platform", "Service", "we", "us") available at neuriko.pl and in the mobile app (if applicable).

The personal data controller is Jakub Tomczyk, running an unregistered business within the meaning of Art. 14 of the Act of March 6, 2018 — Entrepreneurs' Law (hereinafter: "Controller"). In matters related to the processing of personal data, you can contact the Controller at the e-mail address: kontakt@neuriko.pl.

1. Personal Data Controller

The controller of your personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR") is:

  • Jakub Tomczyk
  • Unregistered business (Art. 14 of the Entrepreneurs' Law)
  • Correspondence address: kontakt@neuriko.pl
  • E-mail: kontakt@neuriko.pl

The Neuriko Platform is created by the team: Jakub Tomczyk (design, UX/UI, frontend), Patryk Malczyk (logic, backend, AI).The personal data controller within the meaning of the GDPR is Jakub Tomczyk as a natural person running an unregistered business.

Pursuant to Art. 37 sec. 7 of the GDPR, the Controller — as an entity employing fewer than 250 people and not carrying out data processing which, due to its nature, scope, or purpose, could cause a risk of violating the rights and freedoms of individuals — has not appointed a Data Protection Officer (DPO). All requests regarding data protection should be directed directly to the Controller at: kontakt@neuriko.pl.

2. Scope of collected personal data

In connection with the use of the Platform, the following categories of personal data may be processed:

2.1. Data provided voluntarily by the User (Parent/Guardian)

  • E-mail address — necessary for registration, login, and communication
  • Password — stored in a secure form (hash)
  • First and last name (optional) — for personalized communication
  • Configuration preferences regarding the child's profile: number range, visual theme, sensory sensitivity level
  • Data necessary to process subscriptions (plan, billing period)

2.2. Data concerning the Child

The Platform is intended for use by children under the supervision of a parent or legal guardian. We only collect the following data concerning the child:

  • First name (pseudonym) — provided voluntarily by the parent solely for interface personalization
  • Educational level and sensory preferences — configured by the parent during the onboarding process
  • Learning outcomes and interaction metrics (see section 2.3) — linked to the parent's account, not directly to the child's identity

We do not request or process the child's full name, national ID number (PESEL), date of birth, or any other data allowing direct identification of the child. The child's profile is linked to the parent's account and identified solely by a pseudonym.

2.3. Behavioral data and learning metrics (Micro-metrics)

The platform automatically collects and analyzes the following data regarding the child's interaction with educational material:

  • Time required to make the first decision (reaction time)
  • Time to return to interaction after an incorrect answer (emotional resilience indicator)
  • Number of correction attempts before obtaining a correct result
  • Overall learning progress (completed lessons, achieved levels)
  • Preferences regarding visual and audio modes (selected themes, muted sounds)

The collected micro-metrics are used solely to generate progress reports for the parent/guardian and to dynamically adjust the difficulty level and presentation of educational material. This data is not shared with third parties for advertising or commercial profiling purposes.

2.4. Technical data and logs

  • IP address (in shortened/anonymized form)
  • Browser type and version
  • Operating system
  • Date and time of HTTP requests, URLs of visited subpages
  • Session identifiers

3. Legal basis for data processing

The processing of your personal data takes place on the following legal bases, in accordance with Art. 6 sec. 1 of the GDPR:

  • Art. 6 sec. 1 lit. b) — performance of a contract (registration and provision of educational platform services);
  • Art. 6 sec. 1 lit. f) — legitimate interest of the Controller (ensuring security, improving service quality, analytics, handling requests);
  • Art. 6 sec. 1 lit. a) — explicit consent of the User (newsletter, push notifications, essential optional features);
  • Art. 6 sec. 1 lit. c) — legal obligation (e.g., tax regulations, pursuing claims).

4. Protection of children's data (Art. 8 GDPR)

In accordance with Art. 8 sec. 1 of the GDPR, in relation to the direct provision of information society services to a child under 16 years of age, the processing of data is lawful only if and to the extent that consent is given or authorized by the holder of parental responsibility over the child.

Registration on the Platform and its use is possible only for individuals over 18 years of age. The child uses the Platform exclusively under the supervision and with the consent of a parent or legal guardian who is a registered User of the Platform.

By registering on the Platform and creating a child's profile, the parent or legal guardian consents to the processing of data regarding the child's use of the Platform to the extent necessary to provide educational services.

5. Special categories of data (Art. 9 GDPR)

The Platform is designed for children on the autism spectrum (ASD) and with ADHD. Information about the sensory profile and educational preferences provided by the parent during onboarding do not constitute special categories of data within the meaning of Art. 9 of the GDPR — these are interface and educational preferences, not health data.

Nevertheless, we treat this data with special care, applying strict security measures analogous to those provided for special categories of data. AI-generated diagnostic reports containing educational progress assessments are available exclusively to the logged-in parent/guardian and are not shared with third parties without explicit, separate consent.

6. Recipients of personal data

Personal data may be transferred to the following categories of recipients:

  • Clerk Inc. — authentication service provider (registration, login, account management). Data processed in the USA subject to Standard Contractual Clauses (SCCs). Clerk Privacy Policy
  • Mistral AI / OpenRouter — provider of artificial intelligence services for generating diagnostic reports and educational recommendations. Data transmitted to the EU/EEA. Mistral AI Privacy Policy
  • Google (Analytics) — analytics service provider. Data is collected in aggregated form, with IP addresses anonymized. Google Privacy Policy
  • Stripe, Inc. — payment service provider. We share necessary data (e.g., email address, account ID) to handle subscription payments. Full payment card details are processed directly by Stripe and are not stored on our servers. Stripe Privacy Policy
  • Hosting providers — provider of the server infrastructure hosting the PostgreSQL database.
  • Entities authorized by law — state and local government authorities as provided by law.

7. Data transfer outside the EEA

Some personal data may be transferred to entities located outside the European Economic Area (EEA), in particular to the United States (Clerk Inc.). Data transfer takes place only on the basis of:

  • An adequacy decision,
  • Standard Contractual Clauses (SCCs) approved by the European Commission,
  • Exceptions set out in Art. 49 sec. 1 of the GDPR (explicit consent, performance of a contract).

The Controller has taken appropriate steps to ensure an adequate level of data protection, including entering into data processing agreements with entities processing data outside the EEA containing Standard Contractual Clauses.

8. User Rights (GDPR)

In accordance with the GDPR, you have the following rights:

  • Right of access (Art. 15) — the right to obtain information about processed data, their categories, recipients, and retention period;
  • Right to rectification (Art. 16) — the right to correct inaccurate personal data;
  • Right to erasure ("right to be forgotten", Art. 17) — the right to request the deletion of personal data, unless processing is necessary to comply with a legal obligation;
  • Right to restriction of processing (Art. 18) — the right to request the restriction of data processing for the time needed to verify the legitimacy of processing;
  • Right to data portability (Art. 20) — the right to receive data in a structured, commonly used, and machine-readable format (e.g., JSON, CSV);
  • Right to object (Art. 21) — the right to object to processing based on a legitimate interest;
  • Right to withdraw consent (Art. 7 sec. 3) — where processing is based on consent, the consent may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal;
  • Right to lodge a complaint (Art. 77) — the right to lodge a complaint with a supervisory authority.

To exercise the above rights, please contact us at: kontakt@neuriko.pl. We will respond to every request promptly, no later than 30 days from its receipt.

9. Cookies and tracking technologies

The Platform uses the following categories of cookies:

9.1. Essential (technical) cookies

Required for the proper functioning of the Platform. These include, among others, session strings, authentication tokens, and interface preferences. They do not require User consent.

9.2. Analytical cookies

Used by Google Analytics to understand how Users use the Platform. Data is collected in an aggregated form, with IP addresses anonymized. They require User consent.

9.3. Cookie management

The User can manage cookie settings in their browser at any time, including blocking or deleting cookies. However, please note that disabling certain categories of cookies may affect the functionality of the Platform.

10. Artificial Intelligence and profiling

The Platform uses an artificial intelligence system (LLM — Mistral AI) to:

  • Generate personalized reports on the child's educational progress;
  • Create recommendations for parents and therapists regarding working with the child at home;
  • Dynamically adjust the difficulty level and presentation of educational material.

The AI system does not make automated decisions that produce legal effects or significantly affect the User (Art. 22 GDPR). All AI recommendations are for informational and auxiliary purposes and do not substitute for a clinical diagnosis or advice from a professional therapist.

Data sent to Mistral AI is limited solely to educational metrics and does not contain data allowing for the direct identification of the child. Transmitted data is encrypted in transit (TLS 1.3).

11. Data security

The Controller applies appropriate technical and organizational measures to ensure the security of personal data, in particular:

  • Encryption of data transmission (HTTPS / TLS 1.3) between the browser and the server;
  • Password encryption using one-way hashing algorithms (bcrypt);
  • Regular data backups with at-rest encryption;
  • Restricting access to data exclusively to the Controller;
  • Locking the Parent Zone with a PIN code (4 digits) preventing unauthorized access to the management panel by the child.

12. Data retention period

Personal data is stored for the period necessary to achieve the purposes of processing, in particular:

  • Account and profile data — until the account is deleted by the User or the agreement is terminated;
  • Educational metrics and AI reports — for the duration of the subscription and 12 months after its end;
  • Technical logs — 6 months from collection;
  • Data necessary for pursuing claims — until the statute of limitations for claims expires (according to the Civil Code).

After the retention period expires, the data is deleted or anonymized in a way that prevents the User from being identified.

13. Changes to the Privacy Policy

The Controller reserves the right to amend this Privacy Policy. Users will be notified of any significant changes via:

  • E-mail notification sent to the address associated with the account;
  • An initial message after logging into the Platform;
  • Update of the "Last Updated" date in this document.

In the event of fundamental changes to data processing rules, the Controller will require re-acceptance of the updated Policy before continuing to use the Platform.

14. Unregistered business activity

The Platform is operated as part of an unregistered business activity in accordance with Art. 14 of the Act of March 6, 2018 — Entrepreneurs' Law. Unregistered business allows providing services without registering in CEIDG, provided that the revenue limit specified in the regulations is not exceeded.

For any complaints and the exercise of consumer rights, Users can contact the Controller directly at: kontakt@neuriko.pl.

15. Contact

For matters regarding the protection of personal data and the exercise of rights under the GDPR, please contact the Controller:

  • Data Controller (unregistered business activity): Jakub Tomczyk
  • E-mail: kontakt@neuriko.pl
We care about privacy and data security — especially children's data.
If you have any questions or concerns, we encourage you to contact us.
HomeTerms of Service