📋 Legal Document — Privacy Policy
NeuroSecure Logo

Your Privacy is Our
Core Architecture

We built NeuroSecure so your biometric data never leaves your device. Here's exactly how we protect you.

🛡️ GDPR Compliant
🔐 AES-256 Encrypted
📱 On-Device Only
Privacy by Design
Last Updated: 03 May 2026
Effective: 03 May 2026
Version: 1.0
✓ GDPR Compliant Architecture
📑
Table of Contents
🏛️
Section 01

Introduction

NeuroSecure is an AI-powered browser privacy protection extension developed by Faiez Tariq at FAST-NUCES, Pakistan. We use facial recognition technology to protect your screen from unauthorized viewing.

This Privacy Policy explains what data we collect, how we use it, where it is stored, and your rights. We are committed to full compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

🔑 Our Core Privacy Promise
  • Your face data is encrypted and stored only on your device
  • We cannot access your biometric data — even if we wanted to
  • We never sell your data to anyone, ever
  • You have full control to delete everything at any time
🗃️
Section 02

Data We Collect

🧬
Biometric Embeddings
128-dimensional mathematical face vector. Never the raw image. Encrypted on your device only.
📧
Account Data
Email address, encrypted password (via Supabase Auth), creation date, subscription plan.
🚨
Alert Data (Pro)
Timestamp, intruder photo, hashed tab URL. Stored on secure servers. Auto-deleted after 30 days.
📷
Camera Access
Used only when detection is active. No video transmitted. Stops when extension is paused.
🚫 Data We Do NOT Collect
  • Browsing history or raw URLs
  • Personal files or documents
  • Keystrokes or screen content
  • Location data of any kind
⚙️
Section 03

How We Use Your Data

Data TypePurposeLegal Basis (GDPR)
Face EmbeddingIdentify authorized user, protect screenExplicit Consent — Art. 9(2)(a)
Account DataAccount management, subscriptionContract — Art. 6(1)(b)
Alert DataNotify you of unauthorized accessLegitimate Interest — Art. 6(1)(f)
Email AddressSecurity alerts, account managementContract + Consent

We will NEVER send marketing emails without your explicit opt-in consent.

🔐
Section 04

Storage & Security

📱
On-Device (Biometrics)
chrome.storage.local — AES-256-GCM encrypted. Key: PBKDF2(PIN, salt, 100,000 iterations). Only you can decrypt.
☁️
Server (Account Data)
Supabase — SOC2 Type II certified. TLS 1.3 in transit. AES-256 at rest. Role-based access controls.
🎫
Auth Tokens
Stored in chrome.storage.session only. Automatically cleared when browser closes. Never persisted.
🤝
Section 05

Data Sharing

⚡ We Do NOT Sell Your Data

We share data only with essential service providers who are contractually bound to protect it.

🗄️
Supabase
Database & Auth. Email and account info only. Secure cloud infrastructure.
📨
Gmail SMTP
Security alert emails only. Triggered only when alert occurs. Your email + alert details.
💬
Meta WhatsApp
Pro users only. Only if you provide your number and explicitly enable it.
⚖️
Section 06

Your GDPR Rights

Art. 15
👁️ Right to Access
Request a copy of all data we hold. Email us. Response within 30 days.
Art. 16
✏️ Right to Rectify
Correct inaccurate data via Settings → Account in the extension.
Art. 17
🗑️ Right to Erasure
Delete face data or full account anytime via Settings. Instant and permanent.
Art. 20
📦 Data Portability
Request your data in machine-readable format. Contact us by email.
Art. 21
✋ Right to Object
Pause detection at any time via the extension toggle.
Art. 7
↩️ Withdraw Consent
Disable extension, delete enrollment, or delete account at any time.
Section 07

Consent

Before enrolling your face, we show a clear consent screen explaining exactly what data is collected, how it is stored, and how to delete it. You must actively click "I Agree" to proceed.

🍪
Section 08

Cookies & Tracking

🎉 We Are Completely Tracking-Free
  • No cookies of any kind
  • No analytics (no Google Analytics, Mixpanel, etc.)
  • No tracking pixels or fingerprinting
  • No advertising networks whatsoever
  • No cross-site tracking
⏱️
Section 09

Data Retention

Data TypeRetention PeriodHow to Delete
Biometric Face DataUntil you delete itSettings → Face Data → Delete
Account DataUntil account deletion + 30 daysSettings → Delete Account
Alert Photos30 days — auto deletedAutomatic / Manual in History
Auth TokensSession only (browser close)Automatic
Server Logs7 days — auto deletedAutomatic
📬
Section 10

Contact Us