Neccessory logoNeccessory
  • Metrics
  • Benefits
  • Models
  • Use Cases
  • FAQ
  • Pricing
  • Contact
Get API key

Privacy Policy

This Privacy Policy explains how Neccessory collects, uses, shares, retains, and protects personal data across the website, the developer console, the documentation, our SDKs, and the cloud measurement API.

Last updatedAugust 24, 2026

Privacy Policy

On this page

  • 1.Scope and operator
  • 2.Controller and processor roles
  • 3.Data we collect
  • 4.Measurement tiers and what is transmitted
  • 5.What a cloud measurement never leaves behind
  • 6.Batch uploads
  • 7.Consent for cloud measurements
  • 8.The demo on this website
  • 9.Health data, biometric data, and lawful bases
  • 10.Sharing with providers and customers
  • 11.International data transfers
  • 12.Retention
  • 13.Your rights and choices
  • 14.Security
  • 15.Children
  • 16.Changes and contact

Legal

Privacy contact

Use this email for privacy questions, access or deletion requests, the current subprocessor list, and the data processing agreement for the cloud tier.

support@neccessory.com
Back to home

Legal

What this policy covers

  • It covers the public website and its in-browser demo, the developer console, the documentation, the web and iOS SDKs, and the cloud measurement API.
  • The two measurement tiers are not equivalent: on the on-device tier nothing leaves the device during a measurement, while the cloud tier transmits face crops to our servers for processing.
  • Cloud frames live only in the memory of the running session — they are never written to disk, to logs, or to object storage — and only the resulting metrics are retained.
  • When a business customer measures its own end users through our SDK or API, that customer is the controller and we act as its processor.
1.

Scope and operator

This policy applies to the public Neccessory website and the measurement demo it hosts, the developer console, the documentation site, the web and iOS SDKs we distribute, the cloud measurement API, and support and sales communications that reference this policy.

It is provided by Individual Entrepreneur Ilia Egorov, who operates Neccessory.

If a separate written agreement, order form, or data processing agreement applies to your use, that document controls to the extent of any conflict with this policy.

2.

Controller and processor roles

For console accounts, organizations, billing records, website analytics, and support correspondence, we act as the controller and decide the purposes of processing.

For measurement data that a business customer processes about its own end users through the SDK or the cloud API, that customer is the controller and we act as a processor on its documented instructions. The data processing agreement for the cloud tier and the current list of subprocessors are available on request.

If you were measured inside a product built by one of our customers, that organization holds the relationship with you. Send your request to it first; requests that reach us are forwarded to the responsible customer.

3.

Data we collect

We collect data you provide directly, data generated when you use the console and the API, and technical data collected automatically to run and protect the service.

  • Account and organization data — name, email address, organization name, membership role, administrator status, and authentication events. Sign-in is handled by our managed authentication provider.
  • API key metadata — label, mode (live, test, or on-device), configured limits, and creation, rotation, and revocation events. Key secrets are never stored: we keep only a SHA-256 hash, which cannot be reversed into the secret.
  • Usage, billing, and audit records — API request logs, cloud job records (frames received, frames dropped, seconds processed, status, and the node that processed the job), token ledger entries, top-ups, and administrative actions.
  • Measurement results produced or submitted through the API — heart rate, HRV, breathing rate, stress, signal quality, and, where the integration enables them, blood pressure, SpO2, emotion, and gaze estimates, together with the optional pseudonymous user reference the integrator supplies. Results never contain images.
  • Access requests and correspondence — contact name, email address, company details, and the content of the messages you send us.
  • Technical and analytics data — pages viewed, referrer and campaign parameters, browser and device information, IP address, rate-limit counters, and security logs.
4.

Measurement tiers and what is transmitted

What leaves the device depends entirely on the tier the integration chose.

Because these inputs are derived from a person's face, we treat them as biometric personal data regardless of their resolution.

  • On-device tier — the measurement runs entirely in the browser or on the mobile device. No frames, no video, and no intermediate signals are transmitted. Only a finished result leaves the device, and only if the integration chooses to submit it.
  • Cloud streaming and frame batch — 36×36 face crops at up to thirty per second, plus optional quality telemetry. When the optional auxiliary module is enabled, a 448×448 face crop is sent up to twice per second; that crop is a recognizable photograph of a face.
  • Cloud video batch — the recorded video file the integration uploads for processing.
5.

What a cloud measurement never leaves behind

The following are properties of how the cloud tier is built, not intentions.

Because cloud frames are not retained, they are not used to train models.

  • Frames exist only in the memory of the running session. They are not written to disk, not written to a log, and not written to object storage.
  • The measurement result contains RR intervals and the pulse waveform. It never contains pixels.
  • Recurrent model state is destroyed when the connection ends. Nothing survives the session.
  • Job records hold counters and status, not content.
  • The session token is sent as the first message of the WebSocket connection rather than in a URL, so it cannot land in an access log.
6.

Batch uploads

Streaming writes nothing to disk at any point. Batch processing is the exception: an uploaded file has to exist somewhere until it is processed. That exception is bounded by hard rules.

An integration that cannot accept a stored file should use streaming delivery, or the on-device tier, where nothing is transmitted at all.

  • The file is deleted as soon as the job finishes, whatever the outcome.
  • A hard time-to-live of one hour applies from the moment the upload link is issued, and is swept independently of job status.
  • Versioning and backups on the storage bucket are switched off.
  • The upload link is treated as a credential: it is not logged and not surfaced anywhere else.
  • Frames and video never appear in the measurement result, in logs, or in metrics.
7.

Consent for cloud measurements

The cloud API rejects any session or job request that does not carry an explicit consent assertion.

That assertion is the integrator's, not ours. Collecting valid, informed, specific consent from the person being measured — and being able to evidence it later — is the integrator's responsibility as controller. The API refuses to proceed without the assertion so that nobody can claim they did not know frames were being uploaded.

In plain terms, this is what the person needs to be told:

  • Images of their face are transmitted to Neccessory for processing.
  • The images are not retained; the resulting metrics are.
  • The measurement is a wellness estimate, not a medical one.
8.

The demo on this website

The measurement demo on this website runs the engine in your browser. Camera frames are processed on your device and are not uploaded. The engine and its encrypted model files are downloaded from our domain and cached by a service worker so that a repeat visit does not download them again.

A result can be turned into a shareable link. The report is encrypted in your browser before it is sent: our server stores only the ciphertext, and the decryption key stays in the fragment of the link, which browsers never transmit to the server. Shared reports expire automatically and can be set to delete themselves after the first opening.

The demo does not create an account and does not save results to our servers unless you generate a share link yourself.

9.

Health data, biometric data, and lawful bases

Neccessory measures physiological signals, so the outputs may qualify as data concerning health under the GDPR, the UK GDPR, or comparable laws, and camera-derived inputs may qualify as biometric data.

Where those laws apply, we rely on performance of a contract for console, SDK, and API functionality, on legitimate interests for security, abuse prevention, and service reliability, and on consent for optional website analytics.

For measurements of a customer's end users, the lawful basis — in practice, explicit consent — is established by the customer as controller. We process that data only on its instructions.

10.

Sharing with providers and customers

We do not sell personal data, and we do not use measurement data for advertising or profiling. We share data only with providers that operate parts of the service on our behalf, and with the customer that owns the deployment you use.

The current list of subprocessors, with the role of each, is available on request and forms part of the data processing agreement for the cloud tier.

  • A managed database, authentication, and object storage provider hosted in the European Union, used for the console database, sign-in, and batch uploads.
  • A managed application hosting provider that serves the website, the API, the console, and the documentation.
  • A dedicated inference server in Germany, used to process cloud measurements.
  • Website analytics providers — Google Analytics, Mixpanel, and Amplitude — loaded on the public website only, and only where analytics consent applies and has been granted.
  • A public JavaScript CDN, from which the browser engine loads a face-landmark library; it receives the request metadata any CDN receives.
  • Professional advisers, auditors, and authorities where disclosure is required by law or reasonably necessary to establish or defend legal claims, and a successor in a merger, acquisition, or sale of assets, subject to confidentiality safeguards.
11.

International data transfers

Cloud measurements are processed in Germany. Every inference node declares the region it runs in as part of its configuration, and every finished job records which node processed it, so the location of a given measurement is answerable after the fact.

Be precise about this if you write it into your own compliance documentation: the region is declared and recorded, not enforced in code. It is an operational and contractual commitment backed by an audit trail, and should not be represented to your users or your regulator as something the system technically prevents.

Other components — hosting, database, analytics — may process data outside your country. Where required, we use standard contractual clauses or another lawful transfer mechanism.

If you are subject to data-localization requirements, talk to us before integrating the cloud tier. The on-device tier has no such exposure, because nothing is transmitted at all.

12.

Retention

Retention differs by data category.

  • Cloud frames and recurrent model state — not retained; discarded with the session.
  • Batch uploads — deleted when the job finishes, and in any case within one hour of the upload link being issued.
  • Measurement results and job records — kept in the customer's organization until the customer deletes them or instructs us to, and deleted or anonymized when the account is closed.
  • Token ledger entries, invoices, and other accounting records — kept for the periods required by tax and accounting law.
  • Console accounts, audit logs, and API request logs — kept while the account is active, then deleted or anonymized within a reasonable period.
  • Shared demo reports — deleted at expiry, or immediately after the first opening when that option was selected.
  • Support and sales correspondence, security logs, and website analytics — kept only as long as needed for the purpose they were collected for.
13.

Your rights and choices

To make a request, write to support@neccessory.com. We may need to verify your identity or your authority to act for an organization before completing it.

If you were measured through a product built by one of our customers, that organization decides what happens to your data. Contact it directly; we will forward a request that reaches us but cannot act on it alone.

  • You may request access, correction, deletion, portability, restriction, or objection, depending on where you are and which law applies.
  • You may withdraw consent where processing is based on it, including website analytics, without affecting processing that already took place lawfully.
  • In the console you can delete stored measurements, rotate or revoke API keys, and close the organization's account.
  • In your browser you can decline analytics, clear cached engine files, and revoke camera access at any time.
14.

Security

We use technical and organizational measures designed to protect the confidentiality, integrity, and availability of the data we hold.

No system can guarantee absolute security. Do not send credentials, payment card details, or patient records through public support or contact channels.

  • API key secrets are stored only as a SHA-256 hash and cannot be shown again. A lost secret is replaced by rotation, not by recovery.
  • SDK and API requests are signed with HMAC-SHA256 over a canonical request, with timestamp and nonce checks that reject replays.
  • Traffic is encrypted in transit, access to production systems is restricted, and administrative actions are written to an audit log.
  • Rate limits and quotas protect the service and each customer's balance from runaway or hostile use.
15.

Children

Neccessory is a developer platform. Console accounts are intended for adults acting on behalf of an organization, and we do not knowingly collect data from children through the website or the console.

If a customer measures minors inside its own product, establishing a valid legal basis — including parental consent where the law requires it — is that customer's responsibility as controller.

16.

Changes and contact

We may update this policy to reflect changes in the product, in our providers, or in the law. The current version takes effect when it is published with a revised date, and material changes affecting customers are communicated through the console or by email.

Questions about this policy, about the data processing agreement, or about a specific measurement can be sent to the address on this page.

Navigation

MetricsBenefitsModelsUse CasesFAQPricing

Documents

Terms of UsePrivacy PolicyRefund Policy