Privacy notice

Your family’s data, handled like it matters.

The full notice, in plain English first.

the short version

Neutrily carries messages between two separated parents. Everything goes through “Sam”, our neutral messenger, who rewrites each message into calm, factual language and delivers it. To do that job — and to keep an honest record both parents can rely on — we store the messages, the rewrites, the delivery and read receipts, and the facts about your children that the messages are about.

We never sell your data, never advertise to you, and never let our AI provider train its models on your family’s messages. Your Neutrily record is stored in the EU (Ireland, on Amazon Web Services). The rewriting is done by an AI provider outside the UK, under UK GDPR transfer safeguards — we explain plainly below exactly what is and isn’t yet in place.

Here is the part most policies won’t tell you plainly: when you delete your account, we delete your login, your settings, and your contact details — but we do not wipe the record of messages that were already sent. That record is shared with your co-parent and it’s about your children, so it isn’t yours alone to erase. It also protects both of you — nobody should be able to delete their way out of what was said before a family court sees it. We keep that record for six years, then delete it.

Both parents have rights over their own data — including the parent who never signed up (with some honest limits we explain below). If you only want one thing from this page: email us at privacy@neutrily.com and we’ll help.

Last updated: 24 July 2026. This notice describes what we do today. Where a protection is intended but not yet finalised, we say so rather than imply it’s done.

1. Who we are, and what Neutrily does

Neutrily is a service provided by Neutrily Ltd (company number 16159614), a company registered in England and Wales. Neutrily Ltd is the data controller for the information described here — the organisation that decides how and why your data is used and is legally accountable for it under UK data protection law (the UK GDPR and the Data Protection Act 2018).

You can reach our privacy team any time at privacy@neutrily.com. Full contact details, including how to complain, are in Section 9.

What the service is. Neutrily is a communication firewall for separated co-parents who find it hard to message each other directly. Instead of messaging each other, both parents message Sam (sam@neutrily.com) — a neutral messenger persona operated by Neutrily’s team and software. Sam is not a real individual: it is an automated system, supervised by trained Neutrily staff. Sam reads each message, works out whether it’s meant to be passed on or is just for us, rewrites the ones to be passed on into neutral, factual, respectful language that keeps every date, time and arrangement intact, and delivers them by WhatsApp or email — with delivery and read receipts.

The two-parent structure matters for your rights. Every Neutrily “case” has two people in it:

  • The primary — the parent who set up and pays for the account. They have a Neutrily login (email and password) and, in the app, can sign in with Apple.
  • The co-parent — the other parent, who never signed up, never pays, and has no account or app. They use Sam through WhatsApp or email, on the phone they already have.

Both parents are data subjects, and this notice is written for both of you. If Sam has been in touch with you and you didn’t sign up, Section 2 and Section 7 are the parts written for you — there’s also a plainer summary at neutrily.com/you, which the first message Sam sent you links to.

2. What we hold, and where it comes from

We hold different information about different people. Here is the honest inventory.

From the primary (the account holder)

  • Account and sign-in: your name, the email and password you sign in with (the password is stored only as a secure hash — we never see it), and your phone number.
  • Your preferences: quiet-hours settings, whether you choose to see original wording alongside the rewrites, and your display theme.
  • Subscription status: whether your subscription is active and through which route. Payments are handled by Stripe (web sign-ups) or Apple (in-app sign-ups) under their own terms — we do not store your card details.

The messages (the heart of the service)

For every message that passes through Sam we hold: the original wording, the neutralised (rewritten) version, the classification (to pass on, or just for us), the thread it belongs to, its timestamps, and the delivery and read receipts. This record is the product — it’s what lets Sam deliver faithfully and lets both parents rely on what was said.

Your children’s facts

Because the messages are about arrangements for children, we hold the facts those messages contain: your children’s first names, dates of birth and schools, and the arrangements and schedules (handovers, contact, activities) you agree or dispute. These are given by the primary at setup, or noticed by Sam from the messages and offered to you to confirm. Your children are separate people in the eyes of data protection law, and this is their information as much as yours.

From and about the co-parent — and how we got it (UK GDPR Article 14)

If you are the co-parent, you didn’t give us your details directly, so the law requires us to tell you exactly what we hold and where it came from:

  • Your first name and your phone number or email — given to us by your co-parent when they set up their account, so Sam could introduce itself to you.
  • Your messages to and through Sam (both your original wording and the neutralised version), and their delivery and read receipts — these come from your own messages.

That’s the whole of it. We do not buy data about you, build a profile of you, or track you anywhere else. This notice, together with the first introduction message Sam sent you (which links to neutrily.com/you), is how we meet our duty under Article 14 of the UK GDPR to tell you.

A note on sensitive information

Messages between parents can sometimes contain sensitive information — a child’s health, or the context of an abusive relationship. We don’t ask for it and we don’t build the service around it, but we can’t stop it appearing in what one parent writes to another. Section 4 explains, honestly, how we handle that.

Cookies on our website

Our website, neutrily.com, uses a small number of cookies. Some are essential — they simply make the site work. Others are for analytics (we use Google Analytics to understand how the site is used), and these are only set if you agree through the cookie banner when you first visit; you can change your choice at any time. We don’t use advertising or cross-site tracking cookies, and the Neutrily app itself doesn’t use them at all.

3. The WhatsApp reality — the honest limit of what we can delete

We want to be straight about a limit that many privacy policies gloss over.

Most message content does not only live with us. When you send a message to Sam, or receive one, that message also exists on your own phone, on your co-parent’s phone, and on WhatsApp’s systems (Meta). Meta carries the message as part of running WhatsApp, under its own privacy terms, as an independent controller for its own platform — that part is outside our control.

The honest consequence: we cannot delete a message from your phone, from your co-parent’s phone, or from Meta’s systems. When this notice talks about deleting or keeping “the record”, we mean the record held inside Neutrily. The words that landed in a WhatsApp chat are outside our reach, the same as any other message you’ve ever sent. We’d rather say that plainly than let you believe we can erase something we can’t.

4. How we use your data, who processes it, and our lawful bases

What we do with it

We use your data to run the service you (or your co-parent) are using: to receive each message, classify it, rewrite it to be calm and faithful, check that rewrite mechanically before it sends, deliver it, and keep the shared record and receipts. Uncertain rewrites, and anything touching a child’s or adult’s safety, are reviewed by trained Neutrily staff under confidentiality (see our Safeguarding notice) — a machine never decides those alone.

The AI provider

The classification and rewriting are done by Anthropic PBC (the maker of Claude), acting as our data processor under contract. A fast model (“Haiku”) sorts messages; a more careful model (“Sonnet”) rewrites, verifies and gates them. To do this, message content is sent to Anthropic. Here is the honest position on how Anthropic handles it:

  • Anthropic does not use what we send through its API to train its models — that is the default under its commercial terms, and it is contractual.
  • We are working to put a zero-data-retention agreement in place with Anthropic, so that no copy of message content is kept after processing. This agreement is not finalised yet. Until it is, all message content we send — including anything sensitive — may be held by Anthropic for a limited period (up to around 30 days) under its standard commercial terms, for safety and abuse-monitoring, and is then deleted. We will update this notice the moment zero-retention is in force. We are not claiming it is done when it isn’t.

Anthropic processes and stores this message content in the United States. For now we rely on Anthropic’s standard commercial terms, which include the appropriate international transfer safeguards (Standard Contractual Clauses with the UK Addendum). We are finalising a formal data-processing agreement (including a UK International Data Transfer Agreement / Addendum) and will confirm here once it is signed.

Automated processing, and your right to a human

Neutrily works by processing messages automatically: the models described above classify each message (is it to pass on, or meant only for Sam?), rewrite it into neutral language, and run an automated safety check. That automation is what lets messages move quickly and calmly.

It is never the whole story, though. Anything uncertain, and anything touching a child’s or an adult’s safety, is routed to trained Neutrily staff before it takes effect — a person, not a machine, makes those calls. And you have a right under Article 22 of the UK GDPR not to be subject to a solely-automated decision that significantly affects you: if an automated step ever affects you and you aren’t happy with it, you can ask us for a person to review it, tell us your side, and challenge the outcome, at privacy@neutrily.com.

We do not use your data to profile you, score you, or make advertising decisions about you.

Sensitive information (UK GDPR Article 9), stated truthfully

We don’t ask for sensitive information and we don’t rely on it, but it can appear in what one parent writes. Where a message contains sensitive information, it is handled the same way as all message content described above — including the current position that, until zero-retention is signed, it may sit with Anthropic for up to around 30 days before deletion. Where a record we keep contains sensitive information, our condition for keeping it is UK GDPR Article 9(2)(f) — the establishment, exercise or defence of legal claims (the same reason we keep the shared record at all — Section 6). The day-to-day handling of sensitive content as we rewrite it is an area we keep under active legal review as the service grows; for now we minimise it, we are securing the zero-retention agreement, and both parents are knowingly using a stated intermediary in the interests of a child. We will not overstate our footing on this.

The other organisations that help us run the service

  • Twilio — delivers messages over WhatsApp and SMS.
  • Supabase / Amazon Web Services — host our database, in the EU region (Ireland, AWS eu-west-1).
  • Stripe — takes web payments; Apple — takes in-app payments.
  • Anthropic PBC — classification and rewriting (see above).
  • Meta (WhatsApp) — carries the messages (see Section 3).

We never sell your data, and we never share it for advertising.

When we’d share with the police or a court

We don’t monitor your messages in order to police you, and we won’t hand your data to anyone outside the providers listed above — except in two situations:

  • When the law requires it. If we receive a court order or another valid, legally-binding request from an authority, we’re obliged to comply.
  • To report a crime. If, in the course of running the service — including our safety checks — we become aware that a message discloses a criminal offence (for example, a credible threat of violence), we may report it to the police.

When we share for either reason, we disclose only what is necessary and proportionate, and we keep a record of what we shared and why. These disclosures rest on our legal obligations and, for reporting a crime, the public interest in preventing and detecting crime — not on monitoring or profiling you.

How we keep your data secure

Protecting your family’s messages is central to how Neutrily is built. Your data is handled with real care and strong safeguards at every stage.

  • Encrypted in transit and at rest. Everything travels over encrypted connections (industry-standard TLS): between the app and Neutrily, between Neutrily and the providers above, and on to your co-parent. WhatsApp’s own delivery leg is end-to-end encrypted using the Signal Protocol, and email is delivered over TLS. Your Neutrily record is held in the EU (Ireland, AWS eu-west-1) on infrastructure that encrypts data at rest, and Anthropic likewise encrypts message content in transit and at rest while it processes it.
  • A serious, independently-audited AI provider. Anthropic is externally certified to SOC 2 Type II, ISO/IEC 27001:2022 (information security) and ISO/IEC 42001:2023 (AI management). Access there follows least-privilege principles — by default its staff cannot read customer content — and, as above, it does not train its models on what we send. That content is processed in the United States (see the transfer note above).
  • Least-privilege access on our side. The keys that can read the record live only on our servers — never in the app. The Neutrily staff who provide human oversight are bound by written confidentiality agreements, and access to your data is restricted to those who genuinely need it to run the service.
  • If something goes wrong. In the unlikely event of a personal-data breach, we follow a defined incident-response process and notify the ICO — and you — where the law requires.

One honest boundary: this is strong transport and storage encryption with tightly-controlled access — it is not end-to-end encryption of the kind where nobody but you and your co-parent could ever read a message. Neutrily has to be able to read and rewrite messages to do its job, and a small, confidential, trained team provides oversight. That is the deliberate trade that makes neutralisation and a trustworthy record possible.

Our lawful bases

Whose dataWhat forLawful basis
The primaryProviding the account and service they signed up and pay forContract — UK GDPR Art. 6(1)(b)
The co-parentCarrying and recording messages faithfully between the two parentsLegitimate interests — UK GDPR Art. 6(1)(f): calm, accurate, accountable communication about a child, which the co-parent knowingly takes part in through Sam, balanced against their privacy — which is why they can opt out from the very first message
Either parent / the childKeeping records that contain sensitive informationUK GDPR Art. 9(2)(f) — legal claims (see above and Section 6)

For the co-parent, we have carried out a legitimate interests assessment; a professional adviser can ask us for a summary at privacy@neutrily.com.

5. Who owns what — the taxonomy that makes deletion make sense

Deletion in a two-parent record is only coherent once you’re honest about whose data is whose. Neutrily’s whole design rests on separating five things:

  1. Yours (the primary’s) — your login, your contact details, your preferences, your account. This is straightforwardly yours, and you can delete it.
  2. The co-parent’s — their name, their contact details, their own messages. Theirs to see, correct and object to — not yours to erase, and not ours to hand to you.
  3. Your child’s — names, dates of birth, schools, arrangements. Your child is a separate person with their own data-protection rights, and this outlives either parent’s account.
  4. The shared record — the messages that were actually delivered, and their receipts. Both parents are data subjects of the same messages, so neither of you owns it alone — one parent can’t unilaterally erase a conversation the other took part in and may need to rely on.
  5. Neutrily’s own records — our operational and security logs, held by us as controller for running the system safely.

The rest of this notice follows from that taxonomy: you can always erase what is genuinely yours; you cannot, on your own, erase what belongs to another person or is co-owned.

6. How long we keep things, and why we’re allowed to

Your login and personal profile (login, preferences, live contact identifiers) are kept while your account is open, and are deleted or scrubbed when you delete your account (Section 7).

The shared record of messages (what was sent and what Sam relayed, plus receipts, classification and threading) and your children’s facts and arrangements are kept for a finite period of six years after a case ends, and then deleted.

We want to be precise about why we’re permitted to keep these, because it’s easy to over-claim:

  • We are not claiming the law requires us to keep them.
  • UK GDPR Article 17(3)(e) permits an organisation to keep personal data where it’s needed for the establishment, exercise or defence of legal claims. Arrangements about children, and the record of what was communicated about them, frequently become the subject of proceedings — that is precisely the situation Neutrily exists to serve.
  • So we keep this record on that permitted basis, for a defined six years (broadly tracking the general limitation period for civil claims in England and Wales), and then we delete it. It is not indefinite, and not “kept forever.”
  • One honest caveat about children’s data: a child is a separate person, and a child’s own right to bring proceedings can run from their 18th birthday — which may fall outside a flat six-year window. We currently apply the same six-year default to children’s facts, and we keep that period under review against a child’s own limitation position. We’d rather flag this openly than pretend the single figure settles it.

Operational and security logs (the plumbing that keeps the service running safely) are kept for a short period — no longer than around 90 days — and then deleted.

7. Your rights, and what deletion really does

You have the full set of rights under UK data protection law: to access a copy of your data, to rectify anything wrong, to ask us to erase data, to restrict or object to processing, to data portability, and to ask for a person to review any automated decision (Article 22 of the UK GDPR). How you exercise them — and what actually happens — depends on which parent you are. We state this honestly, because a previous draft of this notice promised the co-parent more than the product delivers, and we won’t do that.

If you are the primary (the account holder)

You can delete your account from within the app. When you do, straight away we:

  • delete the login you sign in with — your email and password;
  • end your session immediately, so you’re signed out everywhere;
  • delete your preferences — quiet-hours, show-originals, theme;
  • scrub your live contact details — the phone number and email we were delivering to are removed from your active profile;
  • stop the relay — both the WhatsApp and email channels for your case are switched off, so no further messages are carried.

Three things deletion does not do, and it’s only fair to tell you before you press the button:

  1. Your name stays attached to the messages you already sent. Those delivered messages are part of the shared record (Section 5) — your co-parent received them and has rights in them — so your name as the attributed sender remains on that retained record. We remove your account and your live identifiers; we don’t rewrite history you already made.
  2. The shared record and your children’s facts remain for the six years described in Section 6, and are then deleted. As Section 5 explains, that record was never yours alone to erase.
  3. The WhatsApp copies stay — deleting your account does nothing to messages already on your phone, your co-parent’s phone, or Meta’s systems (Section 3).

One more thing: deleting your account does not automatically cancel your subscription. If you subscribed through Apple, cancel it in your Apple subscription settings; if through the web, contact us and we’ll cancel it. We’ll remind you of this at the point of deletion.

If you are the co-parent (you never signed up)

You have real rights, and we won’t pretend otherwise — but we won’t overstate them either. By emailing privacy@neutrily.com you can:

  • ask for a copy of the information we hold about you;
  • ask us to correct your own identifiers if we’ve got your name, number or email wrong;
  • object to our processing of your data.

Separately, you can opt out of the WhatsApp relay at any time — just tell Sam, and it stops. Opting out never reveals to your co-parent that it was you who did so.

Two limits we’ll be straight about:

  • You cannot single-handedly erase the shared record. Those messages were a two-way conversation about your children; the other parent is a data subject of them too, and we keep them on the UK GDPR Article 17(3)(e) basis explained in Section 6 (How long we keep things) below. You can object and ask for erasure, and we’ll weigh it properly against that basis and the other parent’s rights — but one parent cannot, on their own, delete a record the other relied on. This is the same limit that applies to the primary.
  • In this version of Neutrily, if the primary deletes their account and the case ends, we do not proactively notify you. The relay simply stops. You remain able to exercise every right on this page by contacting us. We think proactive notification is the right thing to build, it’s on our list, and it isn’t in place yet — so we won’t claim it is.

How to exercise any right (either parent)

Email privacy@neutrily.com. We’ll respond within one month (if a request is complex we may take longer, and we’ll tell you why). You never have to become a customer to exercise your rights.

8. Read receipts, and why we keep the record

It would be simpler for us to hold less. We keep the record — including the read receipts — deliberately, and for your protection.

In high-conflict co-parenting, “I never got it” and “you never told me” are among the most common and most damaging disputes. Because Sam records what was sent, when it was delivered, and when it was read, that dispute stops being an argument and becomes a look-up — the same facts, visible to both parents, that neither can rewrite after the event. It takes those weapons off the table for both of you, and it lets an honest parent show a court exactly what they communicated and when.

That protective purpose is also why deletion doesn’t wipe the shared record. In a relationship where one person may have reason to make an inconvenient record disappear, a service that let either parent quietly delete the evidence before proceedings would fail the very people it exists to protect. Keeping a faithful, time-bounded record (see Section 6, How long we keep things) that neither parent can unilaterally erase is a safety property of the product — not an afterthought, and not data hoarding.

9. How to contact us, and how to complain

  • Exercise a right, or ask us anything about your data: privacy@neutrily.com
  • Make a complaint: complaints@neutrily.com — please tell us first, and we’ll do our best to put it right.
  • General help with the service: help@neutrily.com
  • Sam (your day-to-day messenger): sam@neutrily.com
  • Data controller: Neutrily Ltd (company number 16159614), registered in England and Wales. Registered office: 86–90 Paul Street, London EC2A 4NE. ICO registration number: ZB854237.

You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office, at ico.org.uk or 0303 123 1113 — though we’d genuinely rather you gave us the chance to fix things first.

This notice reflects how Neutrily actually operates today. It is our careful reading of what UK data protection law requires and permits, and we review it as the service grows; some wording will be refined with our advisers. We’ll always tell you plainly when it changes.