Privacy policy
Last updated 31 August 2026
Responsibility
Thomas, operating as a French entreprise individuelle, is the data controller. No Data Protection Officer has been appointed.
Scope
This policy covers the website neren.ai and all services operated by the publisher under the Neren name, including the waitlist signup and any future product released by the publisher. The policy will be updated to reflect the data processing activities of the product when it becomes available.
Data collected
When you join the waitlist, the following data is collected:
- Email address
- Date and time of signup
- Explicit consent record
- First-touch attribution: traffic source and medium, referring address, and the page you first landed on
- User agent (browser and operating system, in standard form)
- Subscription status, used to manage the list
No other data is collected.
Anti-bot protection
Cloudflare Turnstile performs an invisible verification at signup to prevent automated abuse. This verification is processed by Cloudflare and does not result in personal data being stored by Neren.
Legal basis
| Purpose | Legal basis |
|---|---|
| Waitlist signup and follow-up communication | Explicit consent (Article 6.1.a GDPR) |
| First-touch attribution | Legitimate interest (Article 6.1.f GDPR): understanding where interest originates, without third-party profiling |
| Anti-abuse protection | Legitimate interest (Article 6.1.f GDPR): protecting the integrity of the service |
| Response to inbound email | Performance of pre-contractual steps at the request of the data subject (Article 6.1.b GDPR) |
Consent for the waitlist is collected through an unchecked opt-in box at signup. Consent can be withdrawn at any time by emailing thomas@neren.ai.
Recipients of the data
Personal data is accessed only by the publisher. The following processors are involved in the technical infrastructure, each under their own data processing terms:
- Supabase: database, hosted in the European Union (Frankfurt, Germany).
- Vercel: application hosting and delivery, served from Paris, France.
- Cloudflare: DNS and anti-bot verification.
- Namecheap: domain registration. No personal data of users is shared with the registrar.
No personal data is sold, rented, or shared with advertisers, brokers, or any third party for marketing purposes.
International transfers
Waitlist data is stored in the European Union. Vercel and Cloudflare are established in the United States and operate global networks: the delivery of pages and the anti-bot verification may therefore involve processing outside the European Union, under the transfer safeguards set out in their respective data processing terms.
Retention
| Data | Retention period |
|---|---|
| Waitlist contact data (email) | 36 months from the last verifiable interaction |
| First-touch attribution and user agent | 36 months from the last verifiable interaction |
| Consent record | Duration of the contact data retention, plus 3 years for evidence purposes |
| Inbound email content | As long as necessary to handle the request, then archived or deleted |
A verifiable interaction is the signup itself, the opening of or a reply to a Neren email, or a sign-in to the product once released. The retention clock restarts at each verifiable interaction.
Your rights
Under the GDPR, you have the right to:
- access your personal data (Article 15)
- rectify inaccurate data (Article 16)
- request erasure (Article 17)
- restrict processing (Article 18)
- object to processing based on legitimate interest (Article 21)
- receive your data in a portable format (Article 20)
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal
All requests can be sent to thomas@neren.ai. A response is provided within one month, in accordance with Article 12 GDPR. You also have the right to lodge a complaint with the French data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 Place de Fontenoy, 75007 Paris, France — www.cnil.fr.
Local storage
neren.ai does not use advertising cookies, tracking cookies, or third-party cookies. The website stores a single entry in your browser’s localStorage, recording the traffic source and referring address of your first visit. It contains no identifier, is never read by a third party, and is transmitted only if you choose to submit the waitlist form. You can clear it at any time from your browser settings.
Security
Personal data is stored in a PostgreSQL database operated by Supabase within the European Union. Row-level security is enforced on every table and no browser-facing credential can read the data: all reads and writes pass through server-side code. The website is served over HTTPS only.
Changes to this policy
This policy may be updated to reflect changes in the service or applicable law. The version date is shown at the top of the document. Material changes will be communicated to waitlist subscribers by email.