Privacy Policy
Last updated: 2026-05-21
1. Overview
Noospera is a service that processes your AI conversation history into an interactive map of the topics you have explored. This Privacy Policy explains what information we collect, how we use it, who else sees it, how long we keep it, and the rights you have over it. It is published by Noospera LLC, a Wyoming limited liability company.
Our default posture is to collect as little as the Service requires to function, to keep what we collect under your control where the law gives you that control, and to never expose your User Content or any data derived from it to additional third parties without your explicit, action-by-action opt-in.
2. Information we collect
We collect three categories of information:
(a) What you give us.
- Email address — collected by our identity vendor (currently Privy) when you sign in, and used as your account identifier.
- AI conversation exports — the file(s) you upload, such as a ChatGPT export or an export from another large-language-model provider.
- Payment information — handled by our payment processor (currently Stripe). We receive a transaction ID, amount, and status. We never receive or store your full card number, CVV, or bank credentials.
- Settings and preferences — including any optional notification email you provide.
(b) What we generate from what you give us.
- Analytical artifacts derived from your uploads — including embeddings, topic clusters, cluster summaries, summary cards, topic essays, graphs, statistical aggregations, classifications, and other comparative or positional analyses we may compute (see Section 5 of the Terms of Service for the license you grant us to do this).
(c) What we collect automatically.
- Standard operational logs — including IP address (used for rate-limiting and security investigation), user-agent, request method, response code, and timestamp.
- Browser-side storage we set on your device — see our Cookie Notice.
3. How we use it
- To authenticate you and operate the Service.
- To run the processing pipeline you have paid for and deliver its outputs to you.
- To compute analytical artifacts as described in Section 2(b) and Section 5 of the Terms.
- To process payments and prevent fraud.
- To detect, investigate, and respond to abuse, spam, security incidents, and violations of our Acceptable Use Policy.
- To maintain, secure, evaluate, and improve the Service, including by developing new analyses and product features.
- To comply with legal obligations and respond to lawful requests.
- To support any future opt-in capability you actively choose to enable (see Section 10).
4. Service providers and other recipients
We share information with the following categories of recipients, and only for the purposes listed:
Service providers (sub-processors). These vendors process information on our behalf, under contractual data-protection obligations, only to enable us to operate the Service.
- OpenAI — receives your User Content for the embedding and summarization stages of the processing pipeline. We use API endpoints (not consumer products) and do not authorize use of your content for OpenAI model training.
- Privy — provides email-based authentication and identity. Receives the email address you sign in with.
- Stripe — processes payments. Receives card or other payment details directly from you; passes us a transaction ID, amount, and status.
- Railway — provides our hosting infrastructure. Stores the encrypted underlying volumes that hold your account, uploads, and derived artifacts; routes network traffic.
Legal disclosures. We may also share information, including your User Content and metadata, where we believe in good faith that doing so is required by, or appropriate under, applicable law. This includes disclosure in response to valid legal process (such as a court order, subpoena, warrant, or regulator's lawful request), to defend or assert legal claims, to enforce our agreements, or to protect the rights, property, or safety of Noospera, our users, or others. Where the law permits, we will attempt to notify the affected user of such a request before complying; some legal processes prohibit notification.
Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, information may be transferred to the counterparty or successor as part of that transaction, subject to confidentiality obligations and to this Policy continuing to apply to that information.
5. Security
We take commercially reasonable technical and organisational measures to protect User Content and personal information from unauthorized access, disclosure, alteration, and destruction. These include encryption in transit (TLS) for communication between your browser and the Service, encryption at rest provided by our hosting infrastructure (Railway, which stores data on underlying cloud volumes encrypted by the cloud provider), authentication and access controls scoped to the minimum set of personnel needing access, and contractual data-protection obligations on each sub-processor.
No system is one hundred percent secure. We do not warrant that the Service, your User Content, or your personal information will be free from unauthorized access, loss, or alteration. By using the Service you acknowledge this inherent risk. The Service's broader risk allocation, including limitations on our liability, is set out in our Terms of Service (Sections 10–12).
If a security incident affects your personal information, we will notify affected users to the extent and within the timeframe required by applicable law. We do not commit to a notification timeline shorter than the law requires.
6. Retention
We retain your information for the period reasonably required to operate, secure, audit, and improve the Service, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Operational logs (such as IP addresses captured for rate-limiting and security purposes) are retained for the period set by our hosting infrastructure (currently provided by Railway), plus any additional period required for active security investigation, legal hold, or fraud prevention.
On account deletion, we remove your account record and your uploaded User Content from active systems within a reasonable period. Residual copies may remain in backups, in audit and security logs, and in records we are required by law to retain; these residual copies roll off in the ordinary course.
7. International transfers
Service infrastructure may be located in the United States and in other countries depending on our hosting provider's regional configuration. If you access the Service from outside the United States, you consent to the transfer of your information to, and its processing in, the jurisdictions where our infrastructure and sub-processors operate. Where required, we rely on standard contractual clauses or other recognised transfer mechanisms for cross-border data transfers.
8. Your rights
Depending on where you live, you may have one or more of the following rights with respect to the personal information we hold about you:
- EU and UK (GDPR / UK GDPR). Access, rectification, erasure, restriction of processing, portability, objection, and the right to lodge a complaint with a supervisory authority in your country of residence.
- California (CCPA / CPRA). The right to know what personal information we collect about you, the right to request deletion or correction of it, and the right to opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising.
- Other U.S. states. Similar rights are available to residents of Colorado, Connecticut, Virginia, Utah, and an increasing list of other states with consumer privacy statutes.
To exercise any of these rights, contact us at [email protected] or via the contact form. We will respond within the period required by applicable law. We may need to verify your identity before we can act on a request. Some rights have lawful limits — for example, a deletion request may not extend to information we are required to retain for tax, accounting, or fraud-prevention purposes.
9. Other persons referenced in your uploads
AI conversations may reference identifiable other persons — colleagues, clients, friends, family members, employers, professionals, public figures. The user, not Noospera, is solely responsible for ensuring they have the legal right to upload and process such references. By uploading User Content, the user represents and warrants on each upload that they have that right under applicable law, contractual obligations, professional ethics, and any other applicable framework.
Where a credible request reaches us from a third party identified in a user's User Content, we may, at our sole discretion and without any admission of fault, take action that includes removing the affected material from the Service, restricting access to it, contacting the user to resolve the matter, or declining to act if the request is not credible or not legally required. Nothing in this Section creates an obligation to act on any particular request.
We may also disclose user information (including User Content, derived artifacts, account metadata, and operational logs) to third parties — including courts, regulators, law enforcement agencies, and other government bodies — where we believe in good faith that doing so is required by, or appropriate under, applicable law, lawful process, or to defend our legal interests. This is in addition to the legal-disclosures clause in Section 4.
10. Future opt-in capabilities
Any future capability that would expose your User Content or any derived analytical artifacts to parties beyond the service providers listed in Section 4 will require your active, opt-in choice for that specific exposure. No such capability will be enabled silently or by default. This includes, without limitation:
- Licensing — making part or all of your User Content (or analytical artifacts derived from it) available to organisations under an agreed licence. Governed by the framework described on our Future Directions page.
- User-initiated sharing — for example, choosing to post a summary card or topic essay to a social platform (Facebook, X, LinkedIn, etc.). Before any such share executes, you will see what you are about to expose, to whom, and on what platform, and you will confirm.
- API access or third-party integrations — connecting your data to other tools or services you choose to authorise.
In every case, the exposure is your choice. Once material has been shared with a third party through such a feature, we cannot recall it from that third party. Your current use of the Service is not consent to any of these capabilities; consent is captured at the time of each specific action.
11. Children
The Service is not directed to children under 18. We do not knowingly collect or process personal information from minors. If you believe a minor has provided information to us, contact us at [email protected] and we will take appropriate action.
12. Cookies and browser storage
We use a minimal amount of browser-side storage to keep you signed in and to record your consent choices. Details, including any analytics we enable with your consent, are described in our Cookie Notice.
13. Changes to this Policy
We may modify this Policy from time to time. Material changes will be announced on the site and, where required, communicated to users with an account via the email address on file. Continued use of the Service after a change constitutes acceptance.
14. Contact and data controller
The data controller for the personal information described in this Policy is:
Noospera LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States
Email: [email protected]
Privacy questions and rights requests can be sent to the email above or via the contact form.