Privacy Policy
This policy explains hub accounts, payments, product surfaces, and your GDPR rights.
Who we are
NDPMV is the controller for personal data that the hub and our products process. Registered trade names: NDPMV and NeuralDrift.
We operate from the Netherlands.
We have no Data Protection Officer. Send a privacy or deletion request to gdpr@ndpmv.org.
You can also use the contact form, or email info@ndpmv.org.
The Dutch supervisory authority is Autoriteit Persoonsgegevens.
Name, mailing address, and contact details are on the trader details page.
Scope
This policy applies to the ndpmv.org hub, products we publish, paid access, and related support. The effective date is September 3, 2026.
A product can publish its own terms, privacy policy, or refund policy.
Where a product page conflicts with the matching ndpmv.org page, the product page controls for that product.
The ndpmv.org page still applies where the product page is silent.
A product page cannot limit a mandatory consumer right or a GDPR right that the law gives you.
Every NDPMV product runs checkout on pay.ndpmv.org. Products do not process the payment.
Unless checkout or a product page states otherwise, the terms and policies on ndpmv.org apply to every payment through that flow.
The hub holds account, billing, and license data. Products store a user id and the data they need to run.
Customer data that we need to process a payment, or that law requires us to keep, can exist on ndpmv.org and on a product website.
That can include an email, a name, a billing address, a payment status, and an invoice record. We do not store full card numbers on NDPMV systems.
Mollie B.V. has its own privacy statement for payment data that you submit to Mollie.
This policy does not cover third-party sites that we link to, or host applications such as After Effects or Resolume.
Hub data
When you create an account, we process the email, the WorkOS user id, plan, payment status, entitlements, license keys, activations, and invoices.
When you use the contact form, we store the email, subject, and message, plus a hash of the network address and browser string, so we can answer you and limit abuse. Resend then sends a notice to us and a short receipt to you.
When you join a product list, such as the Neural Drift beta list, we store the email and the list. Resend then sends a short confirmation to that address. You can leave the list from the link in that mail.
We use this data to sign you in, grant access across products, charge renewals, send transactional mail, and keep tax records.
A product asks the hub what you may do. It does not receive your payment-method details.
A product can also store customer data that we need to process a payment or that law requires us to keep.
Product hosts
A product can run on its own host. After you sign in, that host can set its own session cookie.
Products process the data needed for that tool, such as project files, local settings, and uploads that you start.
- Neural Drift: https://neuraldrift.app
Uploads and moderation
When you upload a file to a product, we receive the file and the metadata needed to store it, such as a filename and project settings.
We use that copy to run your account and to restore the project on your devices. We do not sell your media.
We can review an uploaded file to moderate abuse, illegal content, or a breach of the Acceptable Use rules. We do not promise to watch every file.
We review uploads on our systems. We do not send your media to a separate moderation vendor unless this policy later names that vendor.
Other users cannot open your hosted files. You can ask us to delete an uploaded file, subject to legal retention. Send that request to gdpr@ndpmv.org.
When you use Neural Drift
Neural Drift stores a working copy of console settings, scenes, media, MIDI maps, and cache in your browser, including IndexedDB.
Live analysis of a file, a microphone, or a line-in stays on your device. That live stream does not upload.
Paid plans can upload media assets and store projects in your cloud library. When you upload, we receive media files, filenames, scenes, custom looks, and project settings.
Review of uploaded files follows the Uploads and moderation section.
That can include shader source inside a custom look. We use that copy to supply the console on this device or another device. We do not sell your media.
A cloud copy is not a backup promise. Free use does not include a cloud asset library.
Neural Drift asks for microphone, MIDI, or screen access only after you select that feature. We do not receive the contents of those streams.
Identity
WorkOS AuthKit handles login on login.ndpmv.org. WorkOS processes the email and authentication events needed to sign you in.
The hub stores the WorkOS user id and treats that as the identity root.
See the WorkOS privacy statement in the processor list.
Payments
When you buy paid access, Mollie B.V. processes the payment on pay.ndpmv.org.
Mollie receives the payment method, amount, currency, and the data that the selected method requires.
We receive payment status, method type, amount, currency, and a transaction identifier. We do not store full card numbers, CVC codes, or iDEAL session secrets.
We use this data to confirm paid access, handle refunds, prevent fraud, and keep tax records.
See Mollie's privacy statement at https://www.mollie.com/privacy.
Resend sends transactional mail from ndpmv.org. That includes login mail, invoices, SEPA pre-notification, dunning, transaction-lookup links, and contact-form notices.
Do not treat transactional mail as optional product mail. Optional product mail, if we offer it, needs your consent.
Analytics
A product may measure use only after you consent. Neural Drift uses PostHog in that way. We disable automatic capture and session recording there.
We send event names and limited data, such as counts, status codes, time ranges, browser family, and GPU backend.
We do not send media, prompts, filenames, URLs, or free-form text. We do not build advertising profiles.
You can reject analytics or change your choice at any time. Do Not Track in your browser also blocks analytics.
Errors and security
A product may record software errors and limited performance data so we can keep the service stable. Neural Drift uses Sentry for that.
We remove request bodies, local filenames, media data, prompts, shader source, and full URLs where our filters catch them.
We do not use error tools for advertising.
We use access control, encrypted connections, and processor contracts to protect personal data. No method is perfect. A breach can still occur.
AI features
Some products can send a prompt to a model provider to generate or edit a look. On Neural Drift, AI Look Studio is off unless we enable it for your account.
Do not put personal data, secrets, or other people's private media into a prompt. We treat provider logs as processor data for that feature.
Processors and recipients
We use service providers to host the hub, run login, store data, process payments, send mail, measure product use, and review errors.
They process data only for those tasks, under a contract where GDPR requires one, except where a provider is an independent controller for its own legal duties.
Mollie B.V. acts as a payment service provider. Card networks and banks in your payment method can also receive the data they need to complete the payment.
- Vercel Inc.: hosting and content delivery for the hub and product sites we host there. Region: the United States and the European Union.
- WorkOS, Inc.: login, multi-factor authentication, and the hub session. Region: the United States and the European Union.
- Neon, Inc.: database that holds hub accounts, entitlements, licenses, and invoices. Region: the United States and the European Union.
- Resend, Inc.: transactional email from ndpmv.org. Region: the United States and the European Union.
- Mollie B.V.: payment processing for paid access. Region: the European Union.
- PostHog Inc.: product analytics on Neural Drift after you consent. Region: the European Union.
- Functional Software, Inc. (Sentry): error and performance monitoring on Neural Drift. Region: the United States and the European Union.
- BunnyWay d.o.o. (Bunny.net): cloud library file storage for Neural Drift. Region: the European Union.
- xAI: AI Look Studio on Neural Drift when that feature is on. Region: the United States.
International transfers
Some processors are in the United States or other countries outside the EEA.
Where GDPR applies, we rely on an adequacy decision or on standard contractual clauses, plus the provider's extra measures.
PostHog for Neural Drift uses the EU ingest host. Mollie processes payments in the European Union.
Cookies and similar storage
The hub and each product host use cookies and similar storage that the service needs, plus optional analytics storage after you consent.
Your browser can hold local project data. That storage is not a tracking cookie.
Each host that sets a cookie can show its own consent control. This policy is the single privacy text for those controls.
- wos-session: essential hub cookie on .ndpmv.org that keeps you signed in.
- Product session cookie: essential cookie on a product host after you complete the sign-in handoff.
- ndpmv-analytics-consent: essential local record of your analytics choice on the hub, when analytics is on.
- PostHog storage: optional on Neural Drift, only after you allow analytics.
- Sentry storage: error monitoring needed to operate Neural Drift, not used for ads.
- IndexedDB and local cache: your scenes, prefs, media, and MIDI maps on the Neural Drift device.
Legal bases
Where GDPR applies, we use the bases below. You can ask us which basis applies to a specific record.
- Contract: the account, paid access, entitlements, license keys, the cloud library, refunds, and support that you request.
- Consent: product analytics, and optional product mail beyond the messages needed to run the service.
- Legitimate interest: error monitoring, security, fraud prevention, moderation of uploads, and service improvement that does not override your rights.
- Legal obligation: invoices, tax records, and accounting retention in the Netherlands, and reports of illegal content where the law requires a report.
Required data
An email is required to create an account and to perform the contract.
Payment data that Mollie needs is required to buy paid access.
Analytics and optional mail are not required. You can refuse them.
How we receive data
You give us most personal data when you create an account, pay, upload, or contact us.
We also receive login events from WorkOS and payment status from Mollie.
Automated decisions
We do not make solely automated decisions that have legal effects or similarly significant effects.
Plan gates and fraud checks can block access. A person can review those outcomes if you ask.
Retention
Contact-form records stay until we close the request, then for a short period for abuse review.
Account, entitlement, and license data stay for the life of the account, then for a short period after the account ends.
After that period we delete product uploads, except where law requires a record.
If we review an upload for a report or a suspected breach, we keep that copy for the review. We then delete it unless law requires a record.
Payment and invoice records stay as long as Dutch tax law requires. That period is usually seven years.
Those records can exist on ndpmv.org and on a product website.
Send a deletion request to gdpr@ndpmv.org. We delete the hub account and the product copies that we may erase.
A deletion request does not erase records that law requires us to keep.
A GDPR deletion request starts at the hub user row, then the WorkOS user. Products also drop copies that we may erase.
Analytics events follow the product analytics retention. Error events follow the product error-tool retention.
Local browser or app data stays until you clear it.
Your rights
If GDPR or UK GDPR applies to you, you can use the rights below.
The rights are not absolute. Law can limit them, for example for tax records that we must keep.
Send a GDPR request, including a deletion request, to gdpr@ndpmv.org. You can also use the contact form.
We answer a GDPR request within one month. We may need to confirm your identity first.
- Access a copy of your personal data.
- Rectify inaccurate data.
- Erase data where the law allows.
- Restrict processing in the cases the law sets.
- Receive data you gave us, in a portable form, where the law allows.
- Object to processing based on legitimate interest.
- Withdraw consent for analytics or optional mail. Withdrawal does not affect prior processing.
- Complain to Autoriteit Persoonsgegevens or to your local supervisory authority.
Children
NDPMV is for people who can enter a contract. Do not use the paid service if you are under 18.
We do not aim the product at children under 16. If you believe we hold data of a child under 16, email gdpr@ndpmv.org so we can delete it.
Your choices
You can reject analytics or change your choice at any time through the analytics control on the site that offers it.
You can clear local site data in your browser or app. Export a project backup first if you do not have a cloud copy.
You can revoke microphone, MIDI, or screen permission in the browser.
You can ask us to delete uploaded files or an account email, subject to legal retention for payments. Email gdpr@ndpmv.org.
Complaints
Email gdpr@ndpmv.org first so we can try to fix a privacy issue.
You can also complain to Autoriteit Persoonsgegevens at https://www.autoriteitpersoonsgegevens.nl.
If you live in another EEA country or in the United Kingdom, you can complain to your local authority instead.
Changes
We can change this policy. The new version applies after we publish it on this page with a new date.
If a change is material, we also give notice in the product or by email when we have an account email.
If a product starts to process a new class of data, we add a section here, or that product publishes its own privacy policy.