Phoenix AI Policy
This policy explains how Phoenix uses artificial intelligence, what happens to the things you tell it, and the rights you have under the UK GDPR, the Data Protection Act 2018 and the EU GDPR. It is written in plain words. Our privacy page covers the rest of the service.
At a glance
- You are talking to an AI. Phoenix is a computer program. It is not a person, a therapist, a doctor or a crisis service.
- Your chats stay on your device unless you choose to make a free account. NeuroHub does not store or log the messages you send to Phoenix AI.
- Messages are processed by Anthropic. When you use Phoenix AI, your message goes through our server to Anthropic’s Claude model, which writes the reply. The built-in helper never sends anything anywhere.
- Nobody makes decisions about you. Phoenix does not profile you, score you or decide anything that affects your rights.
- Safety does not depend on the AI. Crisis detection and the red Help button run inside the app.
- You are in control. You can switch the AI off, stop any sharing, download your data, or delete it, at any time in Settings.
1. About this policy
Who we are. Phoenix is made and run by NeuroHub Community Ltd (“NeuroHub”, “we”, “us”). For the personal data described below, NeuroHub is the data controller, and NeuroHub Community Ltd is registered with the Information Commissioner’s Office (ICO), registration reference ZC088866.
What it covers. Every way of using Phoenix: the web app at phoenix.neurohubcommunity.org, the installed app, the desktop companion and the Phoenix widget that other websites can add. It covers the AI features: chat, voice chat, memory notes, document drafting, and the suggestions of guides and courses.
Laws it follows. The UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and, for people in the European Economic Area, the EU General Data Protection Regulation (EU GDPR). We also follow the transparency and AI literacy duties of the EU AI Act (Regulation 2024/1689) as they apply to a service like this.
2. What Phoenix is and is not
Phoenix is a free, neuro-affirming companion for autistic and otherwise neurodivergent people. It helps you think things through, use tools such as daily check-ins and breathing exercises, draft documents, and find reading and training.
Phoenix is
- An AI chat assistant that is always clear that it is an AI.
- Built on knowledge written by NeuroHub and by authors who have given permission or openly license their work, credited by name when used.
- A place for reflection and practical help.
Phoenix is not
- A therapist, counsellor, doctor or crisis service. It cannot diagnose, treat or prescribe, and it does not give medical advice.
- A way to get urgent help. Nobody monitors conversations and we cannot contact you.
- A medical device or a tool for deciding anything about your care, employment, benefits, education or legal position.
3. How the AI works
Phoenix has two ways of answering you. You can use either, and you can switch at any time in Settings.
Built-in helper
Answers come from rules and writing stored in the app. It runs entirely on your device and works offline. Nothing you type leaves your device.
Phoenix AI
- You send a message. The app adds Phoenix’s instructions and, where relevant, short reference extracts and the memory notes you have chosen to keep.
- That bundle goes to NeuroHub’s server, which checks that it is a genuine Phoenix request and then forwards it to Anthropic’s Claude model.
- The reply streams straight back to you. NeuroHub does not store or log your messages or the replies. We keep only anonymous counters and a hashed, short-lived record to apply daily limits.
- Only the most recent part of the conversation is sent, up to a fixed length, so older messages are not passed on.
What the AI is not allowed to do
- It does not run on its own. It only replies when you send a message.
- It does not make decisions about you, produce a score or label about you, or take any action outside the chat.
- It does not try to detect your emotions from your voice, face or body. Voice is turned into text by your browser, and Phoenix does not record, keep or send audio.
- It does not use your messages to train a model. NeuroHub does not train models, and Anthropic’s commercial terms do not permit it to train on content sent through its API by default.
Automated safeguards
Some checks run on your device before and after the AI, for example spotting words that suggest a crisis, handling questions about medicines with a careful built-in answer, and checking that helpline numbers in a reply are the verified ones. These checks protect you. They do not produce any decision about you that has legal or similarly significant effects, so Article 22 of the GDPR (automated decision-making) does not apply.
4. Data we handle and why
We only handle what the feature needs. This table shows each use, the data involved and our lawful basis. Where we rely on consent, you can withdraw it at any time and it will not affect what happened before.
| Purpose | Data | Lawful basis (UK and EU GDPR) | Who sees it |
|---|---|---|---|
| Phoenix AI replies | The messages you send, Phoenix’s instructions, reference extracts, and any memory notes you have kept | Article 6(1)(b), providing the service you ask for. For any health details you choose to type, Article 9(2)(a), your explicit consent given when you send them after being told how they are used | Anthropic as our processor, for the moment it writes the reply. NeuroHub does not keep the content |
| Chats, check-ins, documents, settings on your device | Everything you create in the app | Held on your device only. NeuroHub is not a recipient | You |
| Optional account and sync | A one-way fingerprint of your email address, and your synced chats, check-ins, documents and notes, encrypted | Article 6(1)(b), providing the account. Article 9(2)(a) for any health information in synced content | You. NeuroHub staff do not read the content. The email service sends the sign-in code |
| Memory notes | Short notes Phoenix keeps about you, which you can view, edit, switch off and delete | Article 6(1)(a), your consent, which you give by leaving notes switched on | You. The notes go to Anthropic with a message so Phoenix can use them |
| Optional sharing of check-in scores | The date, seven numbers from 1 to 5 and a random ID made on your device | Articles 6(1)(a) and 9(2)(a), explicit consent. Off until you turn it on. 16 and over only | Authorised NeuroHub admins, as group results only |
| Daily limits and abuse prevention | A hashed, truncated network identifier and a counter | Article 6(1)(f), our legitimate interest in stopping abuse and keeping a free service affordable | NeuroHub systems only |
| Anonymous usage counts | Daily totals, coarse device type, country code, referring site. No cookies, no IP address, no identifier | Article 6(1)(f), our legitimate interest in knowing how Phoenix is used. You can switch it off. We honour Do Not Track and Global Privacy Control | Authorised NeuroHub admins |
| Safety, security and legal duties | Technical logs held by our host, and information needed to respond to a legal request | Article 6(1)(f) and Article 6(1)(c) | Our host. Authorities where the law requires |
Cookies and similar technologies. Phoenix sets no advertising or tracking cookies. It stores your settings and data in your own browser storage because the service you asked for needs it. That is allowed without consent under PECR and the ePrivacy rules.
What we never do. We do not sell personal data, use it for advertising, or build marketing profiles. Phoenix does not use your messages to market anything to you. Occasional suggestions of guides or courses are matched on your device and can be switched off in Settings. They are labelled with the price and say when they come from NeuroHub.
5. Health and other sensitive information
Conversations with Phoenix can touch on health, neurotype, sexuality, beliefs and other special category data. We treat all of it with extra care.
- You choose what to write. Phoenix never needs you to type health details to use it.
- By default your chats are not stored by NeuroHub. If you make an account, they are stored encrypted, so staff cannot read them.
- Check-ins are not sent to the AI unless you allow it. With the default setting they go only to a local AI.
- After a crisis conversation Phoenix does not write memory notes.
- We carry out a Data Protection Impact Assessment for the features that handle wellbeing information, and review it when those features change.
6. Who receives data
We use a small number of providers, each only for the job below and each bound by a data processing agreement under Article 28 of the GDPR.
| Provider | Role | What it receives |
|---|---|---|
| Anthropic | Processor. Runs the Claude model that writes Phoenix AI replies | The content of a Phoenix AI request, at the moment you send it |
| Netlify | Processor. Hosts the website, the app, the server functions and the encrypted account store | Ordinary server data such as IP addresses in short-lived logs, and encrypted account data |
| Brevo | Processor. Sends the one-time sign-in code by email | Your email address, at sign-in, so the code can be delivered |
| Your browser vendor (Google or Microsoft) | Independent. Turns speech into text if you use voice in Chrome or Edge | Audio from your microphone while listening. This happens in your browser, not through NeuroHub, and is covered by their privacy terms |
We do not give personal data to anyone else, except where the law requires it. Results we may publish about wellbeing are combined and anonymous, and are never shown for fewer than five people.
7. Transfers outside the UK and the EEA
Anthropic, Netlify and Brevo may process data outside the UK and the European Economic Area, including in the United States. Where they do, we rely on one or more of these safeguards: an adequacy decision or the UK–US and EU–US data bridge arrangements where the provider is certified, or the standard contractual clauses approved by the European Commission together with the UK International Data Transfer Addendum. Where needed, we also assess the risk of the transfer and keep the data transferred to the minimum. You can ask us for a copy of the safeguards in use.
8. Keeping and deleting data
| Data | How long |
|---|---|
| Phoenix AI messages and replies | Not kept by NeuroHub. They pass through and are discarded |
| Data on your device | Until you delete it in Settings or clear your browser data |
| Account data | Until you delete your account. Deleting is permanent and removes all synced data |
| Shared check-in scores | Until you withdraw and delete them, and in any case no longer than two years |
| Daily limit counters | Days to one month |
| Anonymous usage totals | As totals, for as long as they are useful. They contain nothing about you |
| Host server logs | A short period set by the host, for security and operation |
9. Your rights
Under the UK GDPR and the EU GDPR you have these rights. Most you can use yourself in Settings. For the rest, contact us. We reply within one month and do not charge, unless a request is clearly unfounded or excessive.
Because your email address is not stored and your chats are not held by us, we can only find shared data through the random ID on your device. If you ask us to act on data we cannot link to you, we may need you to provide that ID.
10. Safety and limits
- Crisis support. Detection of distress and the Help panel run inside the app and never depend on the AI. Replies in a crisis are checked so they contain only verified helplines, which we review regularly.
- Medicines and medical questions. Phoenix gives a careful built-in answer and points you to a professional, instead of letting the AI guess.
- Usage limits. Phoenix AI has daily and monthly limits so that a free service stays running. The built-in helper and the safety tools are never limited.
- Pause. NeuroHub can pause Phoenix AI at any time if it misbehaves. The built-in helper keeps working.
- Reporting. If a reply is wrong, unsafe or upsetting, tell us using the contact details below. We review reports and fix the causes.
11. Fairness, accuracy and transparency
- It can be wrong. AI replies can be inaccurate, incomplete or out of date, and may sound more certain than they should. Check anything important with a qualified person.
- Neuro-affirming by design. Phoenix’s instructions are written to respect neurodivergent people, avoid pathologising language and avoid pressure to mask. We test replies for harmful or stigmatising content, and we ask for feedback from the community we serve.
- Always labelled. Phoenix tells you it is an AI at the start and whenever you ask. Text written by the AI in documents you create is yours to review and edit before use.
- Sources are named. When Phoenix uses writing from NeuroHub, Helen Edgar or the Stimpunks Foundation sites, it names the source.
- Plain language. We aim for clear, accessible wording and offer accessibility settings throughout the app. Tell us if anything here is hard to read and we will provide it another way.
12. How we govern it
- Risk level. Under the EU AI Act we treat Phoenix as a limited-risk system that interacts directly with people. Our duty is transparency, which this policy and the in-app labelling meet. Phoenix does not use emotion recognition, biometric identification, social scoring or any practice the Act prohibits. We keep this assessment under review.
- Data protection by design. Chats stay on your device by default, email addresses are not stored, account data is encrypted, and results are shown only as groups of five or more.
- Access control. Only named NeuroHub people with the admin role can see group results, and they must sign in with a password and an authenticator code. Sign-ins are logged.
- Providers. We choose providers on security and privacy, keep agreements in place and review them when anything changes.
- Incidents. If a personal data breach is likely to put you at risk, we report it to the Information Commissioner’s Office and, where required, to the relevant EU authority within 72 hours, and tell you without undue delay when the risk is high.
- AI literacy. The people who run Phoenix are trained to understand what the system can and cannot do.
- Review. We review this policy at least once a year and whenever the AI features change materially.
13. Age
Phoenix is designed for adults. An account is for people aged 18 and over. Sharing check-in scores is for people aged 16 and over. If we learn that we hold data from someone below those ages, we will delete it.
14. Contact and complaints
NeuroHub Community Ltd. For questions, to use a right, or to report an AI reply that went wrong, write to enquiries@neurohubcommunity.org or use the form at neurohubcommunity.org/contact-us. Please include “Phoenix” in the subject line.
If you are unhappy, please tell us first and we will try to put it right. You also have the right to complain to a data protection authority at any time.
- In the UK: the Information Commissioner’s Office, ico.org.uk/make-a-complaint, telephone 0303 123 1113.
- In the EU or EEA: the supervisory authority in the country where you live, work or believe the issue happened. The European Data Protection Board lists them at edpb.europa.eu.
Quick questions
Does NeuroHub read my chats with Phoenix?
No. Chats are on your device. With Phoenix AI they pass through our server to Anthropic and are not stored or logged by us. If you make an account, synced chats are encrypted and staff cannot read them.
Is my data used to train AI?
No. NeuroHub does not train models, and Anthropic’s commercial terms do not allow it to train on API content by default.
Can I use Phoenix with no AI at all?
Yes. Choose the built-in helper in Settings. It works offline and sends nothing anywhere.
Do I have to make an account?
No. Everything except voice chat works without one.
What happens if the AI says something harmful?
Tell us. We review it, fix the cause and, if needed, pause Phoenix AI. Safety checks also run on your device independently of the AI.
Changes to this policy
Version 1.0, 4 October 2026. This is the first version. When we make a material change we will update the date and version, show a notice in the app, and keep earlier versions available on request.