Back to home
Neurofund

Privacy Policy

Last updated: 4 June 2026

1. Information We Collect

Account information. When you create an account, we collect your name, email address, password (stored as a one-way hash), and optional phone number.

Identity verification (KYC) information. When you trigger identity verification (at withdrawal, or when your account balance, single deposit, or single transaction reaches USD $5,000 or AUD equivalent), our identity verification partner (currently Sumsub, with Onfido as an alternative in some jurisdictions) collects: government-issued ID documents (passport, driver licence, or national ID); a selfie or video for biometric liveness comparison; date of birth; residential address; jurisdiction; and information from public Politically Exposed Persons (PEP), sanctions, and adverse-media lists, used to screen you in line with applicable AML laws.

Payment information. For software subscription payments, Stripe collects and processes your card details directly; we receive only the last four digits, card brand, expiry, and a Stripe customer reference. For card deposits used to fund allocations, the on-ramp partner (e.g. MoonPay, Transak, Banxa, Mercuryo, Ramp Network) collects payment information directly under its own terms; we receive only the deposit confirmation and amount.

Wallet, transaction, and trading data. We store records of your deposits, withdrawals, allocations, trading activity, performance, and fees. When you connect an external exchange account (e.g. Bybit), we access your trading data through that exchange’s API. We do not store exchange passwords or API secret keys beyond the encrypted storage necessary for the integration to function.

Usage and device data. We collect IP addresses, device information, browser type, pages visited, click and scroll interactions, and limited fraud-detection signals (including Cloudflare Turnstile bot-detection signals at sign-in surfaces).

2. How We Use Your Information

We use the information we collect to:

  • provide, operate, and improve the Service;
  • process deposits, withdrawals, allocations, fees, and subscription billing;
  • verify your identity and screen against PEP, sanctions, and adverse-media lists (initial and ongoing);
  • detect, prevent, and respond to fraud, abuse, money laundering, terrorist financing, and security incidents;
  • send transactional notices, security alerts, support communications, and (where you have opted in) marketing;
  • comply with our legal, regulatory, accounting, and tax obligations across the jurisdictions we operate in (including the United States, United Kingdom, European Economic Area, Singapore, and Australia).

3. Data Sharing

We do not sell your personal information. We share information with the following categories of recipient, only as needed to provide the Service or to meet legal obligations:

Payment and on-ramp partners. Stripe (software subscription billing); Onramper and its underlying card on-ramp partners (MoonPay, Transak, Banxa, Mercuryo, Ramp Network) for card-to-wallet deposits; NOWPayments for cryptocurrency deposits and payouts. The card on-ramp partner is the merchant of record for the card payment and operates under its own privacy policy.

Banking partners. Wise Business (international USD/multi-currency balances) and National Australia Bank (Australian dollar balances).

Identity verification, AML, and fraud partners. Sumsub (primary) and Onfido (alternative) for KYC, PEP and sanctions screening, biometric liveness checks, and ongoing AML monitoring. Cloudflare for security and bot detection.

Trading execution partners. Bybit and other exchange partners we may add, where you have an allocation that trades through those exchanges.

Infrastructure providers. Hosting (Railway), database hosting, email delivery, error monitoring, and analytics providers, each bound by contractual confidentiality and data-protection obligations.

Authorities. Where required to do so under applicable law, we may share information with regulators, law enforcement, courts, or tax authorities. This includes (without limitation) threshold transaction reports, suspicious activity reports, and responses to lawful information requests under FATF-aligned AML regimes such as US FinCEN, UK FCA / NCA, EU AMLD6 and MiCA, Singapore MAS, and Australia AUSTRAC.

Corporate transactions. If Neurofund is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred subject to standard confidentiality protections.

4. Data Security

We implement industry-standard security measures including 256-bit SSL/TLS encryption for data in transit, AES-256 encryption for data at rest, bcrypt password hashing, regular security audits and penetration testing, and role-based access controls for internal systems. While we strive to protect your data, no method of electronic transmission or storage is 100% secure.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. Trading history and transaction records are retained in accordance with applicable financial regulations. You may request deletion of your account and associated data, subject to our legal retention obligations.

6. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data; port your data to another service; opt out of marketing communications; restrict or object to certain processing; and withdraw consent at any time. These rights are not absolute and may be limited where we are required to retain data for legal, AML, accounting, or audit purposes.

European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR / FADP). You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local data protection authority.

California, United States (CCPA / CPRA). You have rights to know, delete, correct, limit use of sensitive information, and opt out of sale or sharing of personal information. We do not sell your personal information.

Australia (Privacy Act 1988). You may access and correct your personal information, and complain to our Privacy Officer or, if unsatisfied, to the Office of the Australian Information Commissioner (OAIC).

To exercise any of these rights, contact privacy@neurofund.com.au.

7. Cookies and Tracking

We use essential cookies to maintain your session and preferences, analytics cookies to understand platform usage, and functional cookies to enable personalized features. You can control cookie settings through your browser. Disabling essential cookies may affect platform functionality.

8. International Transfers

Your personal information is processed and stored in countries other than your own. Our primary infrastructure, banking, payment, and verification partners are based in the United States, United Kingdom, European Economic Area, Singapore, and Australia.

Where personal data of an EEA, UK, or Swiss resident is transferred outside of those jurisdictions, we rely on appropriate safeguards including the European Commission’s Standard Contractual Clauses and supplementary technical and organisational measures as required. Where personal data of an Australian resident is transferred overseas, we take reasonable steps to ensure the recipient handles the data in line with the Australian Privacy Principles.

9. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will take steps to delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.

11. Contact

For privacy-related inquiries, contact our Data Protection Officer at privacy@neurofund.com.au.