Privacy Policy

Version 0.17 · last updated 5 October 2026

1. Who we are

Neaion is operated by Rawly OÜ, Narva mnt 5, 10117 Tallinn, Estonia. You can reach us about privacy at hello@neaion.com.

2. Two roles, two kinds of data

Neaion answers customer messages on behalf of businesses. That means we handle personal data in two different capacities, and it matters which one applies:

3. Data we collect about owners (controller)

WhatWhyLegal basis
Name, email address, company name, regionTo create and run your accountContract (Art. 6(1)(b) GDPR)
PasswordTo let you sign in. Stored only as a bcrypt hash; we cannot read it.Contract
Records of what the service did for your company — messages answered, questions raised with you, actions allowed or blocked, model usage and costTo show you what the AI did on your behalf, to bill fairly, and to investigate problemsContract; legitimate interest in operating a safe service (Art. 6(1)(f))
Failed sign-in attempts, counted per email address and per network addressTo stop password-guessing attacksLegitimate interest in security
A one-time link to choose a new password, when you ask for one — we keep only a fingerprint of it, and it expires after 30 minutesTo let you back into your accountContract (Art. 6(1)(b) GDPR)
Your email address, to tell you something is waiting for you when you have not connected Telegram, and to send the summaries you choose (the evening summary, the morning briefing, the week ahead, the monthly report) — these emails carry counts and a link, never what a customer wroteTo run the service you asked forContract (Art. 6(1)(b) GDPR)
Your team: the names, email addresses and roles of the people you invite; an invitation link (we keep only a fingerprint of it, and it expires after 7 days); and the email telling a team member a conversation was given to them, which never contains what a customer wroteTo let the people you choose work in your office, each within their roleContract (Art. 6(1)(b) GDPR)
Two-step sign-in, if you turn it on: your authenticator's secret, stored encrypted, and your recovery codes, stored only as fingerprintsTo protect your accountContract; legitimate interest in security
If you pay for a plan: your plan and its payment status, as our payment provider reports it. Card details are entered on Stripe's own page and never reach us.To bill you and keep the records the law requiresContract; legal obligation (Art. 6(1)(c) GDPR)

We do not use advertising or analytics cookies. The web panel keeps your sign-in token in your browser's local storage so you stay signed in; it is not shared with anyone.

The Neaion phone app (iOS and Android). When you sign in on a phone we record that phone's type, the name the app gives it ("iPhone", "Android phone"), the app's version and when it was last used, so you can see your phones under Account & security and sign one out; the phone keeps its sign-in in the phone's own secure storage (the Keychain or the Android Keystore), and we keep only a fingerprint of it. If you allow notices, we keep the phone's push address to send them; a notice says only that something waits for you and opens the app — it never contains what a customer wrote, a name or an amount. The camera and your photos are used only when you choose to add a receipt or an invoice, and Face ID or a fingerprint, if you turn the lock on, is checked by the phone itself and never reaches us. The app contains no advertising, analytics or tracking. Signing out, or signing a phone out, deletes its sign-in and its push address. Legal basis: contract (Art. 6(1)(b) GDPR).

4. Data we process for businesses (processor)

When a business uses Neaion, we process, on its instructions and only for the parts of the service it uses:

For an email inbox, Neaion reads new messages, labels the ones it has handled, sends replies in the same thread, and writes drafts for the owner to send. It uses Google's gmail.modify permission, which allows reading, labelling, drafting and sending, and does not allow permanently deleting mail.

An Outlook or Microsoft 365 mailbox is connected with Microsoft's Mail.ReadWrite and Mail.Send permissions: Neaion reads new messages, marks the ones it has handled with its own category, replies in the same thread and writes drafts. Any other mailbox is connected over IMAP and SMTP with its password — encrypted connections only, and only to the provider's public servers. The password is stored encrypted and erased when the mailbox is disconnected; Neaion marks the messages it has handled with its own keyword, keeps a record of their numbers (never their content) for 30 days so that nothing is answered twice, and files a copy of each reply in the mailbox's Sent folder. It never changes whether a message was read, and never deletes a customer's mail.

The Neaion browser extension. A business owner may install Neaion's extension for Chrome and connect it to their office with a one-time code. It works only in the owner's own browser, on Facebook group pages (www.facebook.com/groups/…) and Nextdoor (nextdoor.com), and only on the posts the owner has on their screen — no other site, no other part of Facebook. For each post whose words match the owner's own keywords it sends the owner's office the post's link, at most 500 characters of its words and the group's name; under a post the owner answered, the words of its comments. It never sends a person's name, profile, photo, who reacted or who commented; email addresses, phone numbers and @handles are removed before anything leaves the browser, and again on arrival. It never posts, likes, comments, sends messages, follows, joins groups or clicks anything, and never signs in anywhere — the one thing it writes is a reply the owner pressed Send for, into the comment box the owner clicks into, on Reddit, in a Facebook group or on Nextdoor (see Send). In the browser it stores only the office's address, its key, the office's name, how many looks were made that day and how the last one ended; Neaion keeps only the key's SHA-256, and the owner can disconnect it at any time. What it sends is kept like every post Tess finds (30 days).

Send. A reply Tess drafted goes only when the owner presses Send on that one reply. On Bluesky, if the owner connected their account with an app password (used once to open a session and never kept; the session is stored encrypted), Neaion posts the reply under the post from that account — the reply's words and the post it answers reach Bluesky — and searches Bluesky as that account with the same search words as above. On YouTube, if the owner gave Google's consent, Neaion posts the reply under the comment or video from the owner's channel. On X nothing reaches X from Neaion: the owner's browser opens X's own reply box with the words, and the owner presses Post. On Reddit, in a Facebook group or on Nextdoor, the post opens in the owner's browser and the Neaion extension writes the reply into the comment box the owner clicks into; the owner presses the site's own button. On Reddit the extension runs only on a post's page and reads nothing there; on any of these pages it looks only at the box it wrote in, and tells Neaion only that the reply was written and that the owner posted it — never a word of the page. Elsewhere the reply is copied for the owner to post. For each press Neaion keeps the words, the post, how it went (and the platform's link to the reply), for as long as the post itself (30 days).

Social media posts. When the owner switches it on, the office plans a week of posts from the business's own photos, rules and profile, writes them, and makes the pictures and videos — the avatar's through HeyGen, settings and scenes through fal.ai, voices and music through ElevenLabs (each receives only the business's own words or a description, never what a customer wrote). Once a week, before the week is planned, the office asks a search service (Perplexity) what is being talked about in the business's field — the question carries only the business's category, its city and the topics of its own posts — and a post may take up such a topic only where the business's own rules can support it. Every post is checked before anyone sees it. A post goes out only when the owner presses Share — or, if the owner switched autopilot on after accepting its warning, without asking (the time and the words they accepted are kept). It goes out on the accounts the owner connected — X, Instagram, the Facebook Page, TikTok — and reaches that platform with its words, its picture or video, and on TikTok the settings the owner chose. Instagram and Facebook fetch the file from an address that works for one hour and for that one file only. Every post carries the platform's AI label or the words “Made with AI”. Neaion keeps the posts, how and when each went out and its platform's link, and the figures each post earned (views, likes, comments, shares, new followers), with the company's data; the files are deleted with the company or when the owner deletes them.

“Look through my groups”. Off until the owner switches it on in their panel, after reading that Facebook's and Nextdoor's terms may count it as automation. Then, and only when the owner presses for it — in the extension or in their panel, in the same browser — the extension opens the groups the owner chose (at most ten) and their Nextdoor feed one by one, in a tab the owner can see, and only scrolls them, slowly, so that the posts come on screen and are read exactly as described above: the same link and words, never a person. It clicks nothing. It stops at once when the owner touches the page, closes the tab or presses Stop, and at any security check, captcha or sign-in page, which it never tries to get past. It runs only under the owner's own account, in their own browser — Neaion's servers never sign in to Facebook or Nextdoor — for a few minutes at most, three times a day at most. For each look Neaion keeps when it was asked for and ran, how many pages and posts it covered and how it ended (and why it stopped), for 30 days.

The business's "Book online" page. A business may publish a booking page on Neaion. A visitor who books there gives their name, email address and — if they wish — phone number, and, for a job at their place, the address; the time is held for 15 minutes and booked only when they confirm their email with the link we send them. An unconfirmed booking is released. Their confirmation emails carry a link to change or cancel the booking without signing in; only a fingerprint (SHA-256) of each link is stored. The booking becomes a conversation in the business's inbox. A job's address is never written into an email, and a business's staff see only the addresses of the jobs given to them. The page loads nothing from any other site; we keep a shortened fingerprint of the visitor's network address for at most as long as the booking, to limit abuse.

Payment links — the money never passes through Neaion. A business may give its customers a way to pay: the page of its own invoicing tool for that invoice (Stripe, QuickBooks, Xero or Zoho Books), or its own payment link (a Stripe Payment Link, Square, PayPal, Venmo, Mollie, SumUp or iyzico), in a payment reminder and on an accepted estimate's page as the deposit. Neaion never receives, holds or forwards the money, never sees a card or bank detail the customer enters, and is no party to the payment: the customer pays the business directly, on the payment service's own page, under that service's terms and privacy notice. We keep only the link (a tool's link to the invoice is removed when the customer is erased), the amount the business asked and whether it was paid — as the business marks it, or as its own invoicing tool or Stripe account reports it (then also the payment's reference, never the payer's details). The estimate's page opens the payment link without telling the payment service which page it came from.

Subscribers to a business's news. When a business sends news or offers with Neaion, we keep, on its behalf, the subscriber's email address and the record of their consent (how and when it was given — for a signup, the confirmation by email). Every such email carries a link that unsubscribes at once, without signing in; the consent record is kept, marked as withdrawn, so the address is not written to again. A business may also import people who agreed elsewhere, on its own statement of their consent; someone who unsubscribed is never added back.

5. How AI is used

6. Who else processes data

We use a small number of sub-processors — hosting, AI inference and search, DNS and backup storage. The full list, with what each receives and where, is on the Sub-processors page. Our servers are in Germany. Some providers are in the United States; transfers there rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

Services a business chooses to connect — for example its own Gmail, Outlook or other email account, calendar, Google profile, shop, marketplace seller account, invoicing tool or Telegram — are that business's own providers, governed by its agreements with them.

7. Security

8. How long we keep data

Public posts Tess finds are kept for 30 days and then deleted — only counts of them stay (how many were found, answered and replied to, per channel and month); a customer who asks to be erased takes with them the post they came from. The record of each “Look through my groups”, and of each reply sent with Send, is deleted after 30 days too (with the post it answered).

Account data and the records of what the service did are kept for as long as your account is active — the record of what the AI did on your behalf is part of what you are paying for. You can close your account yourself on the Account screen: the service stops at once, its data is permanently deleted 14 days later, and backups containing it expire within a further 30 days. You can also ask us in writing, and we do the same within 30 days. We may keep what the law requires us to keep (for example, invoices).

9. Your rights

You can download all of your data, and close your account, yourself on the Account screen. You can also ask us for access to your personal data, and to correct, delete, restrict or port it, or object to its processing. Write to hello@neaion.com; we answer within one month. You can also complain to your data protection authority. If you are the customer of a business that uses Neaion, please contact that business first — it controls your data, and we will support it in answering you.

10. Changes

We will post changes here and update the version and date above. Material changes affecting businesses under our Data Processing Agreement are announced to them in advance.

11. United States: California and other state privacy laws

This section is for residents of California — under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA", Cal. Civ. Code § 1798.100 and following, and its regulations, Cal. Code Regs. tit. 11, § 7000 and following) — and of the other US states whose consumer privacy laws give similar rights, to the extent those laws apply to us. It adds to sections 1 to 10; it does not replace them.

Whose data, and who answers

What we collect about owners, and why (the last 12 months)

Category (as the CCPA names it)What, in NeaionWhy
IdentifiersYour name, email address and account id; the network address of a failed sign-in; a phone's push address, if you allow notices on the phone appTo create and run your account, to stop password-guessing, to send you notices you asked for
Personal information in Cal. Civ. Code § 1798.80(e)Your name and email address; your business's postal address, if you give it (it appears in the emails your business sends, as US law requires); whether your plan is paid — card details are entered on Stripe's page and never reach usTo run your account and the service, and to bill you
Commercial informationYour plan, its payment status and historyTo bill you and keep the records the law requires
Internet or other electronic network activity informationThe record of what the service did for your company and when you used it; sign-in attempts; when a phone last used the appTo show you what the AI did on your behalf, to secure your account, to investigate problems
Professional or employment-related informationThe company you act for, your role in it, and the team you inviteTo let each person work within their role
Sensitive personal informationYour account log-in: your email address with your password (kept only as a bcrypt hash we cannot read) and, if you turn it on, your two-step sign-in secret (encrypted)Only to let you sign in and protect your account — never to infer anything about you

We do not collect characteristics of protected classifications, biometric information (if you turn on Face ID or a fingerprint in the phone app, the phone checks it and nothing reaches us), precise geolocation, or inferences to build a profile of you. Sources: you; your devices, as you use Neaion; the owner who invites you to a team; our payment provider (whether a payment went through); and the accounts you choose to connect (for example which mailbox you connected). How long: as section 8 says. Disclosed for a business purpose: the categories above, to the service providers listed on our Sub-processors page, only to run Neaion for you.

We do not sell or share your personal information

We do not sell personal information, and we do not share it for cross-context behavioral advertising — not yours, and not that of the customers of the businesses we serve — and we have not done so in the last 12 months. Neaion has no advertising or analytics cookies and no tracking pixels. Because there is nothing to opt out of, we do not show a "Do Not Sell or Share" link, and there is nothing for a Global Privacy Control signal from your browser to switch off. We have no actual knowledge of selling or sharing the personal information of anyone under 16. We use sensitive personal information only for the purposes the CCPA permits (signing you in and keeping your account secure), so there is no use of it to limit. We do not disclose personal information to third parties for their own direct marketing (Cal. Civ. Code § 1798.83).

Your rights, and how to use them

How. Write to hello@neaion.com with "Privacy request" in the subject, from the email address of your account where you can. We confirm that we received your request within 10 business days, and answer within 45 calendar days of receiving it. If we need longer, we tell you why within those 45 days and take at most 45 days more. To make sure we give your data only to you, we check that the request comes from the account's own email address or a signed-in session, and may ask you to confirm by a link we send to it. Someone you authorise may ask for you: we will ask for your signed permission and may still confirm with you directly.

Appeal. If we decline your request in whole or in part, we tell you why. You can appeal by replying to our answer with "Appeal" in the subject; someone who did not decide the request reviews it, and we answer within 45 days, saying what we did and why. If the appeal is declined, we tell you how to contact the attorney general of your state.