Last updated · August 11, 2026
This Privacy Policy explains how Neyra Labs Pte. Ltd., a company incorporated in the Republic of Singapore ("Neyra", "we", "our"), collects, uses, stores and shares information when you use Neyra Studio — our AI film production operating system — and any related websites, applications, APIs and services (together, the "Services"). We handle personal data in line with Singapore's Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU/UK GDPR, the CCPA/CPRA and other data-protection laws.
We are a privacy-first product. We collect only what we need to deliver the Services, keep your account secure, generate the cinematic content you ask for, and comply with the law. We never sell your personal information.
Neyra Labs Pte. Ltd. (Singapore) is the data controller — and, under the PDPA, the organisation responsible — for personal information processed through the Services. You can reach our Data Protection Officer at hello@neyra.ai for any privacy-related question, access request, correction request or deletion request.
If you choose to sign in with Google, we receive a limited profile package based on the OAuth scopes you approve:
openid — to authenticate your session.email — to identify your Neyra account.profile — your name and profile picture.We do not request access to your Gmail, Google Drive, Calendar or any other Google service unless you explicitly connect such an integration in product (in which case the additional scopes are shown to you on the Google consent screen before connection).
Our use and transfer of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements.
We do not use your private creative inputs or outputs to train third-party foundation models, and we never sell your personal data. If we ever introduce a general model-training program it will be strictly opt-in.
Where you hold a commercial license, we may build a private, custom or fine-tuned model on your own material at your direction. Such a Custom Model is kept logically isolated, is used only for you, and is governed by your Master Services Agreement and license schedule (which define ownership, hosting, export and deletion). It is never used to train or serve another customer. See section 4.13 of our Terms of Use.
To execute a brief, Neyra routes specific tasks to vetted AI model providers (such as text-to-video, voice, image and music vendors). These providers receive only the inputs needed for that task and act as sub-processors under contract. Categories include:
We keep a current, version-controlled sub-processor list. Enterprise customers may, under their Master Services Agreement or Data Processing Addendum, restrict processing of their Confidential Information to an approved set of providers, receive advance notice of new sub-processors, and object on reasonable data-protection grounds.
We share personal data only when necessary: with sub-processors above; with your team workspace members; with authorities when required by law; or in the context of a corporate transaction (in which case we will notify you). We do not sell personal information.
When you file a claim through our claim form — for copyright, trademark, likeness (NIL), privacy, illegal content or misuse of Neyra's own technology — we process the details you provide (your identity and capacity, the protected work, the material complained of and your evidence) to investigate, act on and keep a record of the claim. We may share the substance of a claim with the affected user so they can respond or file a counter-notice, and with authorities, insurers or advisers where required or reasonably necessary. Claim records are retained for at least 24 months to operate our repeat-infringer policy and to defend legal claims.
For security, abuse prevention and licence enforcement we also log account activity, access patterns, generation prompts and provenance signals, and may use them to detect prohibited use — including unauthorised copying, scraping, reverse engineering or cloning of the Services under Sections 4.10–4.12 of our Terms of Use. The legal basis is our legitimate interest in protecting the Services, our users and our intellectual property (and, where applicable, compliance with legal obligations).
Depending on your region (Singapore, EEA, UK, California, Brazil and others) you have rights to access, correct, delete, port, restrict or object to processing of your personal data, and to withdraw consent at any time. Under Singapore's PDPA you may request access to and correction of your personal data and withdraw consent to its collection, use or disclosure. To exercise any of these rights email hello@neyra.ai. We respond within 30 days.
If you are in Singapore and believe we have not handled your personal data in accordance with the PDPA, you may lodge a complaint with the Personal Data Protection Commission (PDPC). Users in other regions may contact their local data-protection authority.
You can also revoke Google's access to your Neyra account at any time at myaccount.google.com/permissions.
We use TLS in transit, encryption at rest, role-based access controls, signed URLs for private assets, logical isolation of customer environments and audit logging. We work in good faith toward recognised certifications (such as SOC 2) and, for enterprise customers, support a reasonable annual security review or questionnaire on request. No system is perfectly secure — please use a strong password and report any suspected incident to hello@neyra.ai.
If a personal-data breach affecting you occurs, we will notify affected users and, where required, the relevant authority without undue delay and within 72 hours of confirming the breach, and will cooperate in investigation and remediation. Enterprise breach-notification commitments are set out in the applicable Data Processing Addendum.
Neyra is based in Singapore and operates globally, so your information may be processed in countries other than your own. When we transfer personal data across borders we ensure a comparable standard of protection as required by the PDPA, and — where personal data is transferred outside the EEA or UK — we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and equivalent safeguards. We require all sub-processors to be bound by contractual data-protection obligations.
The Services are not directed to children under 16 (or the local digital age of consent). We do not knowingly collect personal data from children.
We may update this Policy. Material changes will be announced via email or in-product banner at least 7 days before they take effect.
Neyra Labs · hello@neyra.ai.