The full notice, in plain English first.
Neutrily carries messages between two separated parents. Everything goes through “Sam”, our neutral messenger, who rewrites each message into calm, factual language and delivers it. To do that job, and to keep an honest record both parents can rely on, we store the messages, the rewrites, the delivery and read receipts, and the facts about your children that the messages are about.
We never sell your data, never advertise to you, and never let our AI provider train its models on your family’s messages. Your Neutrily record is stored in the EU (Ireland, on Amazon Web Services). The rewriting is done by an AI provider outside the UK, under UK GDPR transfer safeguards. We explain plainly below exactly what is and isn’t yet in place.
Here is the part most policies won’t tell you plainly: when you delete your account, we delete your login, your settings, and your contact details; but we do not wipe the record of messages that were already sent. That record is shared with your co-parent and it’s about your children, so it isn’t yours alone to erase. It also protects both of you: nobody should be able to delete their way out of what was said before a family court sees it. We keep that record for six years, then delete it.
Both parents have rights over their own data, including the parent who never signed up (with some honest limits we explain below). If you only want one thing from this page: email us at privacy@neutrily.com and we’ll help.
Last updated: 24 July 2026. This notice describes what we do today. Where a protection is intended but not yet finalised, we say so rather than imply it’s done.
Neutrily is a service provided by Neutrily Ltd (company number 16159614), a company registered in England and Wales. Neutrily Ltd is the data controller for the information described here: the organisation that decides how and why your data is used and is legally accountable for it under UK data protection law (the UK GDPR and the Data Protection Act 2018).
You can reach our privacy team any time at privacy@neutrily.com. Full contact details, including how to complain, are in Section 9.
What the service is. Neutrily is a communication firewall for separated co-parents who find it hard to message each other directly. Instead of messaging each other, both parents message Sam (sam@neutrily.com), a neutral messenger persona operated by Neutrily’s team and software. Sam is not a human being: they are an automated assistant, supervised by trained Neutrily staff. Sam reads each message, works out whether it’s meant to be passed on or is just for us, rewrites the ones to be passed on into neutral, factual, respectful language that keeps every date, time and arrangement intact, and delivers them by WhatsApp, with delivery and read receipts.
The two-parent structure matters for your rights. Every Neutrily “case” has two people in it:
Both parents are data subjects, and this notice is written for both of you. If Sam has been in touch with you and you didn’t sign up, Section 2 and Section 7 are the parts written for you. There’s also a plainer summary at neutrily.com/you, which the first message Sam sent you links to.
We hold different information about different people. Here is the honest inventory.
For every message that passes through Sam we hold: the original wording, the neutralised (rewritten) version, the classification (to pass on, or just for us), the thread it belongs to, its timestamps, and the delivery and read receipts. This record is the product: it’s what lets Sam deliver faithfully and lets both parents rely on what was said.
Because the messages are about arrangements for children, we hold the facts those messages contain: your children’s first names, dates of birth and schools, and the arrangements and schedules (handovers, contact, activities) you agree or dispute. These are given by the primary at setup, or noticed by Sam from the messages and offered to you to confirm. Your children are separate people in the eyes of data protection law, and this is their information as much as yours.
If you are the co-parent, you didn’t give us your details directly, so the law requires us to tell you exactly what we hold and where it came from:
That’s the whole of it. We do not buy data about you, build a profile of you, or track you anywhere else. This notice, together with the first introduction message Sam sent you (which links to neutrily.com/you), is how we meet our duty under Article 14 of the UK GDPR to tell you.
Messages between parents can sometimes contain sensitive information: a child’s health, or the context of an abusive relationship. We don’t ask for it and we don’t build the service around it, but we can’t stop it appearing in what one parent writes to another. Section 4 explains, honestly, how we handle that.
Our website, neutrily.com, uses a small number of cookies. Some are essential: they simply make the site work. Others are for analytics (we use Google Analytics to understand how the site is used), and these are only set if you agree through the cookie banner when you first visit; you can change your choice at any time. We don’t use advertising or cross-site tracking cookies, and the Neutrily app itself doesn’t use them at all.
We want to be straight about a limit that many privacy policies gloss over.
Most message content does not only live with us. When you send a message to Sam, or receive one, that message also exists on your own phone, on your co-parent’s phone, and on WhatsApp’s systems (Meta). Meta carries the message as part of running WhatsApp, under its own privacy terms, as an independent controller for its own platform; that part is outside our control.
The honest consequence: we cannot delete a message from your phone, from your co-parent’s phone, or from Meta’s systems. When this notice talks about deleting or keeping “the record”, we mean the record held inside Neutrily. The words that landed in a WhatsApp chat are outside our reach, the same as any other message you’ve ever sent. We’d rather say that plainly than let you believe we can erase something we can’t.
We use your data to run the service you (or your co-parent) are using: to receive each message, classify it, rewrite it to be calm and faithful, check that rewrite mechanically before it sends, deliver it, and keep the shared record and receipts. Uncertain rewrites, and anything touching a child’s or adult’s safety, are reviewed by trained Neutrily staff under confidentiality (see our Safeguarding notice). A machine never decides those alone.
The classification and rewriting are done by Anthropic PBC (the maker of Claude), acting as our data processor under contract. A fast model (“Haiku”) sorts messages; a more careful model (“Sonnet”) rewrites, verifies and gates them. To do this, message content is sent to Anthropic. Here is the honest position on how Anthropic handles it:
Anthropic processes and stores this message content in the United States. We rely on Anthropic’s standard commercial terms, which include the appropriate international transfer safeguards (Standard Contractual Clauses with the UK Addendum).
Neutrily works by processing messages automatically: the models described above classify each message (is it to pass on, or meant only for Sam?), rewrite it into neutral language, and run an automated safety check. That automation is what lets messages move quickly and calmly.
It is never the whole story, though. Anything uncertain, and anything touching a child’s or an adult’s safety, is routed to trained Neutrily staff before it takes effect: a person, not a machine, makes those calls. And you have a right under Article 22 of the UK GDPR not to be subject to a solely-automated decision that significantly affects you: if an automated step ever affects you and you aren’t happy with it, you can ask us for a person to review it, tell us your side, and challenge the outcome, at privacy@neutrily.com.
We do not use your data to profile you, score you, or make advertising decisions about you.
We don’t ask for sensitive information and we don’t rely on it, but it can appear in what one parent writes. Where a message contains sensitive information, it is handled the same way as all message content described above, including the current position that, until zero-retention is signed, it may sit with Anthropic for up to around 30 days before deletion. Our condition for processing it, and for keeping it, is UK GDPR Article 9(2)(f): the establishment, exercise or defence of legal claims. That is what the service is for: a record both parents can rely on and a court can read (Section 6). We minimise what passes through, and both parents are knowingly using a stated intermediary in the interests of a child.
We never sell your data, and we never share it for advertising.
We don’t monitor your messages in order to police you, and we won’t hand your data to anyone outside the providers listed above, except in two situations:
When we share for either reason, we disclose only what is necessary and proportionate, and we keep a record of what we shared and why. These disclosures rest on our legal obligations and, for reporting a crime, the public interest in preventing and detecting crime, not on monitoring or profiling you.
Protecting your family’s messages is central to how Neutrily is built. Your data is handled with real care and strong safeguards at every stage.
One honest boundary: this is strong transport and storage encryption with tightly-controlled access; it is not end-to-end encryption of the kind where nobody but you and your co-parent could ever read a message. Neutrily has to be able to read and rewrite messages to do its job, and a small, confidential, trained team provides oversight. That is the deliberate trade that makes neutralisation and a trustworthy record possible.
| Whose data | What for | Lawful basis |
|---|---|---|
| The primary | Providing the account and service they signed up and pay for | Contract: UK GDPR Art. 6(1)(b) |
| The co-parent | Carrying and recording messages faithfully between the two parents | Legitimate interests. UK GDPR Art. 6(1)(f): calm, accurate, accountable communication about a child, which the co-parent knowingly takes part in through Sam, balanced against their privacy, which is why they can opt out from the very first message |
| Either parent / the child | Keeping records that contain sensitive information | UK GDPR Art. 9(2)(f): legal claims (see above and Section 6) |
For the co-parent, we have carried out a legitimate interests assessment; a professional adviser can ask us for a summary at privacy@neutrily.com.
Deletion in a two-parent record is only coherent once you’re honest about whose data is whose. Neutrily’s whole design rests on separating five things:
The rest of this notice follows from that taxonomy: you can always erase what is genuinely yours; you cannot, on your own, erase what belongs to another person or is co-owned.
Your login and personal profile (login, preferences, live contact identifiers) are kept while your account is open, and are deleted or scrubbed when you delete your account (Section 7).
The shared record of messages (what was sent and what Sam relayed, plus receipts, classification and threading) and your children’s facts and arrangements are kept for a finite period of six years after a case ends, and then deleted.
We want to be precise about why we’re permitted to keep these, because it’s easy to over-claim:
An unsent draft, a message you have started writing to Sam and not yet sent, is kept so that it is still there when you come back, including on a different device. We keep it for 30 days after you last edit it, and then delete it. It is also deleted the moment you send it, and when you delete your account.
We keep drafts on a different basis from the shared record, and the difference matters: a draft was never sent to anyone. It is not part of the record either parent relies on, so the Article 17(3)(e) basis above does not cover it and we do not claim it does. A draft is yours alone (your co-parent never sees it, in any state), which is why it is deleted with your account while the shared record is not.
A device identifier for app alerts. If you use the Neutrily iPhone app and allow notifications, Apple issues us a device token, an identifier for that installation of the app on that phone. We store it so we can tell your phone that something has arrived. We keep it while the app stays installed and signed in, and delete it when you sign out, when you delete your account, when Apple tells us the token is no longer valid, or after 90 days without the app checking in, whichever comes first.
A record that we alerted your phone. When we send an app alert we keep a small record that we sent it: which message it was about, and when. It exists so that a retry cannot alert you twice about the same message. It holds no message content and no wording from anyone. We keep it for 30 days and then delete it, and it is deleted when you delete your account. It is not part of the shared record and your co-parent never sees it.
Two honest points about it. First, the alert never contains your message: not the text, not a preview, not the other parent’s name. It says only that there is something to read, exactly like the WhatsApp alert does, and for the same reason: a notification appears on a locked screen that other people can see. Second, we send these alerts directly to Apple rather than through a third-party notification service, so nobody outside Neutrily and Apple learns that a message passed between you.
Sign-up details, where you never finished signing up. If you start creating an account in the iPhone app and stop, we still hold what you had entered: your name, email and mobile number. We erase the email and mobile after 30 days, and sooner than that once they have been safely copied onto a live account. We do not keep them on the six-year basis above: you never became a customer, so that basis does not apply and we do not claim it.
One part is deliberately kept after the rest is erased: the record that you gave the three consents (the terms, the AI notice, and your confirmation that the mobile number was your own) and the times you gave them. We keep that because it is the only evidence that we asked and you agreed; erasing it would leave us unable to show that consent was ever obtained, which protects nobody. What it no longer contains, after erasure, is anything identifying: not the number, not the email. If instead you delete the account yourself from the app before then, everything goes at once, the consent record included: there is then no account left for a consent question to arise about.
Apple’s notices about your subscription (in-app sign-ups only). When you subscribe through the app, Apple sends us a signed notice each time something changes: a renewal, a cancellation, a refund, a failed payment. We keep Apple’s signed original, not just our summary of it, for 180 days, and then erase it. It contains no message content and no card details; it identifies the subscription and carries an identifier that links it to your account.
We keep the signed original rather than only our reading of it for one reason: because it is signed by Apple, it is proof of exactly what Apple told us and when. If your subscription state is ever disputed (you cancelled and we did not act, or you were charged and we did not give you access), that signed notice is what settles it, and our own summary would just be us marking our own homework. After 180 days we erase the notice itself and keep only a small entry recording that we received it, so that a repeated notice cannot be counted twice.
And deleting your account reaches them. When your account is deleted we erase these notices in the same action (the signed notice itself and the Apple identifiers inside it) rather than leaving them to age out over the remaining 180 days. What survives is a line recording that a notice arrived and when, which names nobody: we keep that much because it is what stops a repeated notice from Apple being counted twice.
One sentence of honesty about how we got here. An earlier version of this service stored those notices against the Apple subscription rather than against you, which meant account deletion could not reach them at all. We could have written that limitation down and left it standing. We built the erasure instead.
Operational and security logs (the plumbing that keeps the service running safely) are kept for a short period, no longer than around 90 days, and then deleted.
You have the full set of rights under UK data protection law: to access a copy of your data, to rectify anything wrong, to ask us to erase data, to restrict or object to processing, to data portability, and to ask for a person to review any automated decision (Article 22 of the UK GDPR). How you exercise them, and what actually happens, depends on which parent you are. We state this honestly, because a previous draft of this notice promised the co-parent more than the product delivers, and we won’t do that.
You can delete your account from within the app. When you do, straight away we:
Three things deletion does not do, and it’s only fair to tell you before you press the button:
One more thing: deleting your account does not automatically cancel your subscription. If you subscribed through Apple, cancel it in your Apple subscription settings; if through the web, contact us and we’ll cancel it. We’ll remind you of this at the point of deletion.
You have real rights, and we won’t pretend otherwise, but we won’t overstate them either. By emailing privacy@neutrily.com you can:
Separately, you can opt out of the WhatsApp relay at any time: just tell Sam, and it stops. Opting out never reveals to your co-parent that it was you who did so.
Two limits we’ll be straight about:
Email privacy@neutrily.com. We’ll respond within one month (if a request is complex we may take longer, and we’ll tell you why). You never have to become a customer to exercise your rights.
It would be simpler for us to hold less. We keep the record (including the read receipts) deliberately, and for your protection.
In high-conflict co-parenting, “I never got it” and “you never told me” are among the most common and most damaging disputes. Because Sam records what was sent, when it was delivered, and when it was read, that dispute stops being an argument and becomes a look-up: the same facts, visible to both parents, that neither can rewrite after the event. It takes those weapons off the table for both of you, and it lets an honest parent show a court exactly what they communicated and when.
That protective purpose is also why deletion doesn’t wipe the shared record. In a relationship where one person may have reason to make an inconvenient record disappear, a service that let either parent quietly delete the evidence before proceedings would fail the very people it exists to protect. Keeping a faithful, time-bounded record (see Section 6, How long we keep things) that neither parent can unilaterally erase is a safety property of the product, not an afterthought, and not data hoarding.
You also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office, at ico.org.uk or 0303 123 1113, though we’d genuinely rather you gave us the chance to fix things first.
This notice reflects how Neutrily actually operates today. It is our careful reading of what UK data protection law requires and permits, and we review it as the service grows; some wording will be refined with our advisers. We’ll always tell you plainly when it changes.