Privacy Policy
Last updated: October 1, 2026
Who we are
NeuroTerm is developed by Ecro ("we"), an individual developer in the Republic of Korea. Supporter and Commercial purchases are sold through LemonSqueezy, our merchant of record. We are the controller for the personal data described under "Data we receive", and we also act as its privacy officer. Contact: support@neuroterm.dev or neuroterm.dev/support.
The short version
- NeuroTerm runs on your computer. Terminal sessions, logs, documents and local AI models stay there unless you use one of the features listed under "Data that leaves your computer".
- The app has no telemetry and no analytics. Crash reports are written to a local file only.
- Some features send data directly from your computer to other companies: OpenRouter (and the model provider it routes to), GitHub and Hugging Face. We do not receive what you send to them. From version 1.11 the app never checks a license and sends nothing to us or to LemonSqueezy; older versions with a key entered still do (see below).
- Text sent to OpenRouter has values that look like secrets removed first. This lowers the risk; it does not remove all personal data.
- The app shows each of these flows, and whether it is on, in Settings → Data & Privacy.
Data we receive
We receive personal data only when you make a Supporter or Commercial purchase or write to us:
- Name, email address, country, order and subscription details — from LemonSqueezy, our merchant of record. Purpose: providing the purchase or the Commercial seats, support, refunds, and legal and tax records. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) and, for tax records, a legal obligation (Art. 6(1)(c)). Kept while the purchase or subscription is active, then as long as tax law requires (in Korea, 5 years), then deleted.
- Messages you send us — from you. Purpose: answering you. Legal basis: our legitimate interest in answering (Art. 6(1)(f)). Kept up to 3 years after the conversation ends, then deleted.
We do not sell this data, share it for advertising, or use it for automated decisions.
Data that leaves your computer
These flows run directly between NeuroTerm on your computer and the named company, under that company's own terms and privacy policy. Any request also carries your IP address.
NeuroFlash log search (Jev) — on, sends only when you press Enter
- Recipient: OpenRouter (openrouter.ai), which passes the request to TypeSafe, the provider of the Jev model.
- What is sent: the symptom you type and the log lines being searched (your selection, otherwise the newest 2,000 lines of the terminal, or a log file you choose), with secrets redacted, only when you press Enter.
- It runs under your own OpenRouter account and terms. OpenRouter and TypeSafe decide routing and retention; NeuroTerm does not control them.
Cloud AI (OpenRouter) — off unless you turn it on
- Recipient: OpenRouter (openrouter.ai) and the model provider it routes to, depending on the model you pick.
- What is sent: prompts, terminal text, connection names (host or serial port) and imported documents, with secrets redacted. While Cloud AI is on, idle summaries, the session journal and error explanations send automatically, without asking each time.
- It runs under your own OpenRouter API key, account and terms (OpenRouter privacy policy). Requests carry headers that name NeuroTerm as the calling app.
- By default NeuroTerm asks OpenRouter to use only providers that do not collect data (
data_collection: deny). If you turn on "allow providers that collect data", it may route to providers that store or train on prompts. Providers may keep data under their own retention policies.
License checks in versions 1.10 and earlier (LemonSqueezy) — only with a key entered
- Recipient: LemonSqueezy (api.lemonsqueezy.com), our merchant of record (LemonSqueezy privacy policy).
- What is sent: your license key, an activation id and the installation name, with your IP address, at startup and once a day.
- From version 1.11 the app never contacts LemonSqueezy. Update NeuroTerm, or remove the key in the older version, to stop it.
Update checks (GitHub) — on unless you turn them off
- Recipient: GitHub (github.com).
- What is sent: your IP address and app version when checking for updates, and the download when you install one.
- Can be turned off in Settings.
Model downloads (Hugging Face)
- Recipient: Hugging Face (huggingface.co).
- What is sent: model searches and downloads, with your IP address. The embedding model used for document search downloads automatically when Settings opens with a local model ready.
Agent serial access (MCP) for Claude Code and Codex — only if you set it up
- Recipient: the agent CLI on your own computer, over a local connection only your user account can open. NeuroTerm itself sends nothing further.
- What is sent: the output of your serial tabs, which the agent can read; NeuroTerm does not redact it. Sending input or borrowing a port needs your approval in NeuroTerm.
- The agent may send what it reads to its own AI provider, under that provider's terms and privacy policy, not ours.
SSH, SFTP, WSL and serial sessions connect only to the hosts and devices you choose. Setting up agent integration writes configuration files on those hosts only after you confirm.
Secret redaction
Before any text goes to OpenRouter (Cloud AI or Jev), NeuroTerm replaces values that match built-in patterns — private keys, access keys and API tokens, passwords in URLs, and values assigned to names such as password, token or secret — with a marker. It is always on. IP addresses, host names and serial port names are not redacted, because the analysis often needs them. Redaction cannot recognise every secret or every piece of personal data; do not send text you would not share with the recipient.
International transfers
OpenRouter, LemonSqueezy, GitHub and Hugging Face are based in the United States. Transfers you start by using a feature happen under each recipient's own terms and safeguards; see their privacy policies. Messages you send us are forwarded to a Gmail mailbox, so Google stores them, possibly in the United States, under Google's terms and safeguards. Order records stay with LemonSqueezy in the United States. Personal data that reaches us from the European Economic Area comes to the Republic of Korea, which the European Commission recognises as providing adequate protection.
Your rights
You can ask us to access, correct, delete or export the personal data we hold, to restrict or object to its processing, and to withdraw consent where processing relies on it. Write to support@neuroterm.dev; we answer within 10 days. You also have the right to complain to a data protection supervisory authority, such as the one where you live, and in Korea to the Personal Information Protection Commission (www.pipc.go.kr). For data held by OpenRouter, TypeSafe, LemonSqueezy, GitHub or Hugging Face, contact them directly.
This website
neuroterm.dev uses no analytics and sets no advertising or tracking cookies. The site is hosted on Vercel, which processes your IP address and request details in its server logs to deliver and protect the site. The Supporter and Commercial checkouts open in LemonSqueezy's window and run under LemonSqueezy's privacy policy.
Changes
We update this page when NeuroTerm's data flows change and show the date at the top.