Privacy Policy
1. Who we are
Neaion is operated by Rawly OÜ, Narva mnt 5, 10117 Tallinn, Estonia. You can reach us about privacy at hello@neaion.com.
2. Two roles, two kinds of data
Neaion answers customer messages on behalf of businesses. That means we handle personal data in two different capacities, and it matters which one applies:
- As controller — for the people who use Neaion to run their business (the "owners"): your account, your login, and how you use the service. This policy covers that data in full.
- As processor — for the customers who write to a business that uses Neaion. Here the business is the controller and decides why their data is processed; we act only on its instructions, under our Data Processing Agreement. If you are a customer of such a business, its own privacy notice is the one that applies to you, and it is the right place to exercise your rights. We will help it do so.
3. Data we collect about owners (controller)
| What | Why | Legal basis |
|---|---|---|
| Name, email address, company name, region | To create and run your account | Contract (Art. 6(1)(b) GDPR) |
| Password | To let you sign in. Stored only as a bcrypt hash; we cannot read it. | Contract |
| Records of what the service did for your company — messages answered, questions raised with you, actions allowed or blocked, model usage and cost | To show you what the AI did on your behalf, to bill fairly, and to investigate problems | Contract; legitimate interest in operating a safe service (Art. 6(1)(f)) |
| Failed sign-in attempts, counted per email address and per network address | To stop password-guessing attacks | Legitimate interest in security |
| A one-time link to choose a new password, when you ask for one — we keep only a fingerprint of it, and it expires after 30 minutes | To let you back into your account | Contract (Art. 6(1)(b) GDPR) |
| Your email address, to tell you something is waiting for you when you have not connected Telegram, and to send the summaries you choose (the evening summary, the morning briefing, the week ahead, the monthly report) — these emails carry counts and a link, never what a customer wrote | To run the service you asked for | Contract (Art. 6(1)(b) GDPR) |
| Your team: the names, email addresses and roles of the people you invite; an invitation link (we keep only a fingerprint of it, and it expires after 7 days); and the email telling a team member a conversation was given to them, which never contains what a customer wrote | To let the people you choose work in your office, each within their role | Contract (Art. 6(1)(b) GDPR) |
| Two-step sign-in, if you turn it on: your authenticator's secret, stored encrypted, and your recovery codes, stored only as fingerprints | To protect your account | Contract; legitimate interest in security |
| If you pay for a plan: your plan and its payment status, as our payment provider reports it. Card details are entered on Stripe's own page and never reach us. | To bill you and keep the records the law requires | Contract; legal obligation (Art. 6(1)(c) GDPR) |
We do not use advertising or analytics cookies. The web panel keeps your sign-in token in your browser's local storage so you stay signed in; it is not shared with anyone.
The Neaion phone app (iOS and Android). When you sign in on a phone we record that phone's type, the name the app gives it ("iPhone", "Android phone"), the app's version and when it was last used, so you can see your phones under Account & security and sign one out; the phone keeps its sign-in in the phone's own secure storage (the Keychain or the Android Keystore), and we keep only a fingerprint of it. If you allow notices, we keep the phone's push address to send them; a notice says only that something waits for you and opens the app — it never contains what a customer wrote, a name or an amount. The camera and your photos are used only when you choose to add a receipt or an invoice, and Face ID or a fingerprint, if you turn the lock on, is checked by the phone itself and never reaches us. The app contains no advertising, analytics or tracking. Signing out, or signing a phone out, deletes its sign-in and its push address. Legal basis: contract (Art. 6(1)(b) GDPR).
4. Data we process for businesses (processor)
When a business uses Neaion, we process, on its instructions and only for the parts of the service it uses:
- messages its customers send it — by email, in the chat on its website, and on Telegram (its own Telegram bot, or the owner's own Telegram account) — including the sender's name and address;
- the replies Neaion writes and sends, the conversation history needed to reply in context, what each conversation is about (a question, a booking, an order, a complaint), and whether a customer found an answer helpful;
- the business's own "playbook" — its rules, prices, policies and saved answers — and which of them each answer rested on;
- the answers the business owner gives when Neaion asks a question it cannot answer alone, and the notes the business's team writes on a conversation;
- appointments: the customer's name, contact and time, in the business's own calendar, and a waiting list for a full day; which of the business's people does the job; for a job at the customer's place, the address the customer gave (and their phone number if they gave one) — checked against the business's service area by our own code, with a public US Census list of ZIP codes and no map service;
- orders: one order's status, read from the business's shop when that order's own customer asks about it;
- reviews of the business on its Google profile, and the replies its owner approves;
- repeating appointments the business sets up with a customer (every so many weeks or months): the rule, the dates it books and why one could not be booked — each booked only after the customer said yes; and, if the business turns them on, "time for your service" reminders: one message some months after a job, by the same rules and with the same way out as a review request;
- review requests, if the business turns them on: after an appointment that took place or an invoice paid, one message asking the customer to review the business on Google — every customer alike, at most once in 180 days, and in the EU and Türkiye only to a customer who agreed to the business's marketing messages. We keep whom it asked, when and why not, and the customer's own "do not ask me again" — kept as a fingerprint of their address even after their data is erased, so that they are not asked again; pressing it also withdraws their consent to the business's marketing emails;
- estimates the business prepares for its customers: the customer's name and email address when the business gives them, what they asked for, the lines priced from the business's own price list, and whether the customer accepted. The customer reads and answers it on a page that shows nothing about them; we keep only a fingerprint of that page's link, never the link itself;
- questions shoppers ask about the business's products on the marketplaces it connects (Trendyol, Hepsiburada, n11): the question, the product and the answer the business approves — never the shopper's name, id or order;
- money: the receipts and invoices the business sends in or that reach it as e-invoices — by mail, or from its e-invoice integrator (its suppliers' names, tax numbers, bank accounts and figures; an e-invoice is read from its data by our own code, with no AI), the invoices the business issued (its customers' names, email addresses and amounts — entered by it or read from its invoicing tool), the draft invoices it asks Neaion to write in its invoicing tool for finished appointments (the customer's name, the service, its date and price), and the payment reminders it asks Neaion to send;
- problem reports its customers or its crash-reporting tools send it;
- for its social media employee, Tess: public posts that ask for what the business does, name it, or name a competitor — on Reddit, X, LinkedIn, YouTube, forums, Hacker News, Bluesky, Yelp and Trustpilot, and in the Facebook groups and Nextdoor neighbourhood its owner opens with the browser extension — kept as the post's link, at most 500 characters of its words, when, and a place it names, never its author (no name, handle, profile or picture; email addresses and phone numbers in the words are cut out); the replies Tess drafts (each checked against the business's own rules and settings, and, when a post asks for a time and the business's calendar is connected, offering free times read from that calendar — only the free times, never what the calendar holds), the ones the owner sends or posts from their own account (and, for each press of Send, the words, where and how it went), the replies to them for 14 days, and whether a customer said they found the business there. A reply is posted only when the owner presses Send on it (see Send); An estimate or a review request for a customer found there waits in the same list and goes the same way, on the owner's press. Tess never likes, follows or messages anyone;
- for its owner's own assistant: the mail from the people the owner names (an accountant, a bank…), kept for 30 days to brief the owner, the replies drafted for the owner to send, the owner's to-dos and the calendar changes the owner approves; and a description of the files those people attach (a contract, a quote) — kept until the owner removes it, so the owner can find the file again, while the file itself stays in the owner's mailbox.
For an email inbox, Neaion reads new messages, labels the ones it has handled, sends replies in the same thread, and writes drafts for the owner to send. It uses Google's gmail.modify permission, which allows reading, labelling, drafting and sending, and does not allow permanently deleting mail.
An Outlook or Microsoft 365 mailbox is connected with Microsoft's Mail.ReadWrite and Mail.Send permissions: Neaion reads new messages, marks the ones it has handled with its own category, replies in the same thread and writes drafts. Any other mailbox is connected over IMAP and SMTP with its password — encrypted connections only, and only to the provider's public servers. The password is stored encrypted and erased when the mailbox is disconnected; Neaion marks the messages it has handled with its own keyword, keeps a record of their numbers (never their content) for 30 days so that nothing is answered twice, and files a copy of each reply in the mailbox's Sent folder. It never changes whether a message was read, and never deletes a customer's mail.
The Neaion browser extension. A business owner may install Neaion's extension for Chrome and connect it to their office with a one-time code. It works only in the owner's own browser, on Facebook group pages (www.facebook.com/groups/…) and Nextdoor (nextdoor.com), and only on the posts the owner has on their screen — no other site, no other part of Facebook. For each post whose words match the owner's own keywords it sends the owner's office the post's link, at most 500 characters of its words and the group's name; under a post the owner answered, the words of its comments. It never sends a person's name, profile, photo, who reacted or who commented; email addresses, phone numbers and @handles are removed before anything leaves the browser, and again on arrival. It never posts, likes, comments, sends messages, follows, joins groups or clicks anything, and never signs in anywhere — the one thing it writes is a reply the owner pressed Send for, into the comment box the owner clicks into, on Reddit, in a Facebook group or on Nextdoor (see Send). In the browser it stores only the office's address, its key, the office's name, how many looks were made that day and how the last one ended; Neaion keeps only the key's SHA-256, and the owner can disconnect it at any time. What it sends is kept like every post Tess finds (30 days).
Send. A reply Tess drafted goes only when the owner presses Send on that one reply. On Bluesky, if the owner connected their account with an app password (used once to open a session and never kept; the session is stored encrypted), Neaion posts the reply under the post from that account — the reply's words and the post it answers reach Bluesky — and searches Bluesky as that account with the same search words as above. On YouTube, if the owner gave Google's consent, Neaion posts the reply under the comment or video from the owner's channel. On X nothing reaches X from Neaion: the owner's browser opens X's own reply box with the words, and the owner presses Post. On Reddit, in a Facebook group or on Nextdoor, the post opens in the owner's browser and the Neaion extension writes the reply into the comment box the owner clicks into; the owner presses the site's own button. On Reddit the extension runs only on a post's page and reads nothing there; on any of these pages it looks only at the box it wrote in, and tells Neaion only that the reply was written and that the owner posted it — never a word of the page. Elsewhere the reply is copied for the owner to post. For each press Neaion keeps the words, the post, how it went (and the platform's link to the reply), for as long as the post itself (30 days).
Social media posts. When the owner switches it on, the office plans a week of posts from the business's own photos, rules and profile, writes them, and makes the pictures and videos — the avatar's through HeyGen, settings and scenes through fal.ai, voices and music through ElevenLabs (each receives only the business's own words or a description, never what a customer wrote). Once a week, before the week is planned, the office asks a search service (Perplexity) what is being talked about in the business's field — the question carries only the business's category, its city and the topics of its own posts — and a post may take up such a topic only where the business's own rules can support it. Every post is checked before anyone sees it. A post goes out only when the owner presses Share — or, if the owner switched autopilot on after accepting its warning, without asking (the time and the words they accepted are kept). It goes out on the accounts the owner connected — X, Instagram, the Facebook Page, TikTok — and reaches that platform with its words, its picture or video, and on TikTok the settings the owner chose. Instagram and Facebook fetch the file from an address that works for one hour and for that one file only. Every post carries the platform's AI label or the words “Made with AI”. Neaion keeps the posts, how and when each went out and its platform's link, and the figures each post earned (views, likes, comments, shares, new followers), with the company's data; the files are deleted with the company or when the owner deletes them.
“Look through my groups”. Off until the owner switches it on in their panel, after reading that Facebook's and Nextdoor's terms may count it as automation. Then, and only when the owner presses for it — in the extension or in their panel, in the same browser — the extension opens the groups the owner chose (at most ten) and their Nextdoor feed one by one, in a tab the owner can see, and only scrolls them, slowly, so that the posts come on screen and are read exactly as described above: the same link and words, never a person. It clicks nothing. It stops at once when the owner touches the page, closes the tab or presses Stop, and at any security check, captcha or sign-in page, which it never tries to get past. It runs only under the owner's own account, in their own browser — Neaion's servers never sign in to Facebook or Nextdoor — for a few minutes at most, three times a day at most. For each look Neaion keeps when it was asked for and ran, how many pages and posts it covered and how it ended (and why it stopped), for 30 days.
The business's "Book online" page. A business may publish a booking page on Neaion. A visitor who books there gives their name, email address and — if they wish — phone number, and, for a job at their place, the address; the time is held for 15 minutes and booked only when they confirm their email with the link we send them. An unconfirmed booking is released. Their confirmation emails carry a link to change or cancel the booking without signing in; only a fingerprint (SHA-256) of each link is stored. The booking becomes a conversation in the business's inbox. A job's address is never written into an email, and a business's staff see only the addresses of the jobs given to them. The page loads nothing from any other site; we keep a shortened fingerprint of the visitor's network address for at most as long as the booking, to limit abuse.
Payment links — the money never passes through Neaion. A business may give its customers a way to pay: the page of its own invoicing tool for that invoice (Stripe, QuickBooks, Xero or Zoho Books), or its own payment link (a Stripe Payment Link, Square, PayPal, Venmo, Mollie, SumUp or iyzico), in a payment reminder and on an accepted estimate's page as the deposit. Neaion never receives, holds or forwards the money, never sees a card or bank detail the customer enters, and is no party to the payment: the customer pays the business directly, on the payment service's own page, under that service's terms and privacy notice. We keep only the link (a tool's link to the invoice is removed when the customer is erased), the amount the business asked and whether it was paid — as the business marks it, or as its own invoicing tool or Stripe account reports it (then also the payment's reference, never the payer's details). The estimate's page opens the payment link without telling the payment service which page it came from.
Subscribers to a business's news. When a business sends news or offers with Neaion, we keep, on its behalf, the subscriber's email address and the record of their consent (how and when it was given — for a signup, the confirmation by email). Every such email carries a link that unsubscribes at once, without signing in; the consent record is kept, marked as withdrawn, so the address is not written to again. A business may also import people who agreed elsewhere, on its own statement of their consent; someone who unsubscribed is never added back.
5. How AI is used
- Replies are written by large language models, grounded in the business's own playbook. When the playbook does not cover a question, Neaion does not guess: it tells the customer it will check, and asks the owner.
- Customer content is sent only to the AI providers approved for it — see Sub-processors. This routing is enforced in code and cannot be switched off by configuration.
- We do not use your data, or your customers' data, to train AI models. We use our AI providers only through their commercial APIs, under data processing agreements with them.
- Neaion does not pretend to be a person. Asked whether it is an AI, it says so. See AI Transparency.
6. Who else processes data
We use a small number of sub-processors — hosting, AI inference and search, DNS and backup storage. The full list, with what each receives and where, is on the Sub-processors page. Our servers are in Germany. Some providers are in the United States; transfers there rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
Services a business chooses to connect — for example its own Gmail, Outlook or other email account, calendar, Google profile, shop, marketplace seller account, invoicing tool or Telegram — are that business's own providers, governed by its agreements with them.
7. Security
- Traffic to Neaion is encrypted with TLS.
- Each company's data is separated from every other company's by the database itself (row-level security and separate, least-privilege database roles), not only by application code — and verified by automated tests that try to cross that boundary.
- Credentials for connected accounts (such as an inbox's access token) are encrypted with AES-256-GCM under a key unique to each company; the master key is never stored in the database.
- The AI layer cannot be reached from the internet — only our own backend can talk to it — and every action the AI proposes, including every message it sends to a customer, passes a rule engine the AI cannot override.
- Backups are taken daily and stored off the server with a provider that encrypts stored data.
8. How long we keep data
Public posts Tess finds are kept for 30 days and then deleted — only counts of them stay (how many were found, answered and replied to, per channel and month); a customer who asks to be erased takes with them the post they came from. The record of each “Look through my groups”, and of each reply sent with Send, is deleted after 30 days too (with the post it answered).
Account data and the records of what the service did are kept for as long as your account is active — the record of what the AI did on your behalf is part of what you are paying for. You can close your account yourself on the Account screen: the service stops at once, its data is permanently deleted 14 days later, and backups containing it expire within a further 30 days. You can also ask us in writing, and we do the same within 30 days. We may keep what the law requires us to keep (for example, invoices).
9. Your rights
You can download all of your data, and close your account, yourself on the Account screen. You can also ask us for access to your personal data, and to correct, delete, restrict or port it, or object to its processing. Write to hello@neaion.com; we answer within one month. You can also complain to your data protection authority. If you are the customer of a business that uses Neaion, please contact that business first — it controls your data, and we will support it in answering you.
10. Changes
We will post changes here and update the version and date above. Material changes affecting businesses under our Data Processing Agreement are announced to them in advance.
11. United States: California and other state privacy laws
This section is for residents of California — under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA", Cal. Civ. Code § 1798.100 and following, and its regulations, Cal. Code Regs. tit. 11, § 7000 and following) — and of the other US states whose consumer privacy laws give similar rights, to the extent those laws apply to us. It adds to sections 1 to 10; it does not replace them.
Whose data, and who answers
- Owners and their team — the people who use Neaion to run their business. For this data we are the "business" (CCPA) or "controller" (other states), and this section is our notice to you.
- Customers of a business that uses Neaion — people who write to it, book with it, or subscribe to its news. For this data we are that business's "service provider" (CCPA) or "processor" (other states): the business decides why it is processed, and we use it only to provide Neaion to that business, under our Data Processing Agreement. Please send your request to the business. If you send it to us, we will tell you that we act for the business, pass your request on to it, and help it answer within the time the law sets.
What we collect about owners, and why (the last 12 months)
| Category (as the CCPA names it) | What, in Neaion | Why |
|---|---|---|
| Identifiers | Your name, email address and account id; the network address of a failed sign-in; a phone's push address, if you allow notices on the phone app | To create and run your account, to stop password-guessing, to send you notices you asked for |
| Personal information in Cal. Civ. Code § 1798.80(e) | Your name and email address; your business's postal address, if you give it (it appears in the emails your business sends, as US law requires); whether your plan is paid — card details are entered on Stripe's page and never reach us | To run your account and the service, and to bill you |
| Commercial information | Your plan, its payment status and history | To bill you and keep the records the law requires |
| Internet or other electronic network activity information | The record of what the service did for your company and when you used it; sign-in attempts; when a phone last used the app | To show you what the AI did on your behalf, to secure your account, to investigate problems |
| Professional or employment-related information | The company you act for, your role in it, and the team you invite | To let each person work within their role |
| Sensitive personal information | Your account log-in: your email address with your password (kept only as a bcrypt hash we cannot read) and, if you turn it on, your two-step sign-in secret (encrypted) | Only to let you sign in and protect your account — never to infer anything about you |
We do not collect characteristics of protected classifications, biometric information (if you turn on Face ID or a fingerprint in the phone app, the phone checks it and nothing reaches us), precise geolocation, or inferences to build a profile of you. Sources: you; your devices, as you use Neaion; the owner who invites you to a team; our payment provider (whether a payment went through); and the accounts you choose to connect (for example which mailbox you connected). How long: as section 8 says. Disclosed for a business purpose: the categories above, to the service providers listed on our Sub-processors page, only to run Neaion for you.
We do not sell or share your personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising — not yours, and not that of the customers of the businesses we serve — and we have not done so in the last 12 months. Neaion has no advertising or analytics cookies and no tracking pixels. Because there is nothing to opt out of, we do not show a "Do Not Sell or Share" link, and there is nothing for a Global Privacy Control signal from your browser to switch off. We have no actual knowledge of selling or sharing the personal information of anyone under 16. We use sensitive personal information only for the purposes the CCPA permits (signing you in and keeping your account secure), so there is no use of it to limit. We do not disclose personal information to third parties for their own direct marketing (Cal. Civ. Code § 1798.83).
Your rights, and how to use them
- To know and to access: what personal information we hold about you, where it came from, why, and with whom we shared it — and a copy of it. You can download all of your data yourself on the Account screen.
- To delete: you can close your account yourself on the Account screen (section 8 says what happens then), or ask us.
- To correct inaccurate personal information: most of it you can change yourself in Settings; ask us for the rest.
- To opt out of the sale or sharing of your personal information, of targeted advertising and of profiling with legal or similarly significant effects — we do none of these.
- Not to be discriminated against for using any of these rights: we will not refuse you the service, charge you differently or give you a lesser service because you did.
How. Write to hello@neaion.com with "Privacy request" in the subject, from the email address of your account where you can. We confirm that we received your request within 10 business days, and answer within 45 calendar days of receiving it. If we need longer, we tell you why within those 45 days and take at most 45 days more. To make sure we give your data only to you, we check that the request comes from the account's own email address or a signed-in session, and may ask you to confirm by a link we send to it. Someone you authorise may ask for you: we will ask for your signed permission and may still confirm with you directly.
Appeal. If we decline your request in whole or in part, we tell you why. You can appeal by replying to our answer with "Appeal" in the subject; someone who did not decide the request reviews it, and we answer within 45 days, saying what we did and why. If the appeal is declined, we tell you how to contact the attorney general of your state.