Sub-processors
These are the third parties that process personal data for Neaion, what each receives, and where. We announce changes to this list at least 30 days in advance, as our Data Processing Agreement requires.
| Sub-processor | What it does for us | What it receives | Location |
|---|---|---|---|
| Hetzner Online GmbH | Hosting: the servers and database Neaion runs on | All service data, stored | Germany (EU) |
| Anthropic, PBC | AI models that write replies and check them | Message content, conversation context, relevant playbook excerpts, the owner's answers; and, for the parts of the service a business uses, the receipts and invoices it sends in (a photo or a PDF — an e-invoice's XML is read by Neaion's own code and never sent to a model), reviews of it, problem reports, and the owner's own mail the assistant is asked to read, with the text of the files attached to it; and the public posts Tess (the social media employee) reads for a business — their words, never their author — with the replies she drafts | United States |
| Voyage AI, Inc. | AI search: turning playbook text and incoming questions into vectors so the right rule can be found | Playbook text; the text of incoming customer questions; one-line summaries of the questions an owner answered, to notice the ones asked again; short descriptions of the files the owner's own people send, and the owner's searches for them; the words of a public post Tess drafts a reply to, to find the business's rules for it | United States |
| Perplexity AI, Inc. | Web search for Tess: public posts on Reddit, LinkedIn, forums and Q&A sites, Yelp, Trustpilot and Bluesky | Search words only: what the business does, its place, the owner's keywords, and the business's and its competitors' public names — never customer content | United States |
| X.AI LLC | Live search of public posts on X (and LinkedIn's public posts) for Tess | The same search words only, and the date to search from — never customer content | United States |
| Google LLC (YouTube Data API) | Search of public YouTube videos and their comments for Tess | The same search words, a country and a language; to follow a reply, the id of the comment the owner answered — never customer content | United States |
| HeyGen Technology Inc. | Social media: the business's AI avatar — the talking video made once from the picture chosen, and avatar videos | The avatar's picture (a fictional person, or the owner's own photo with their recorded consent), the voice chosen, and the script the avatar says — the business's own words, never a customer's | United States |
| Features & Labels, Inc. (fal.ai) | Social media: the avatar's candidate pictures and short AI scenes (settings and backgrounds — never a product) | A short description of the picture or scene wanted, built from the brand kit and the business profile — never customer content | United States |
| ElevenLabs, Inc. | Social media: voices and generated music, licensed for commercial use | The words a voice reads (the business's own script) and the music mood chosen — never customer content | United States |
| X Corp. | Social media: publishing the posts the owner shares (or autopilot covers) on the owner's X account, and reading what they did | The post's words and its picture or video, through the account the owner connected; reads of the business's own posts' figures | United States |
| Meta Platforms Ireland Ltd. / Meta Platforms, Inc. | Social media: publishing on the owner's Instagram professional account and Facebook Page, and reading the posts' insights | The post's words and its picture or video (fetched by Meta from a signed address valid for one hour, for that one file), through the accounts the owner connected | Ireland (EU); United States |
| TikTok Pte. Ltd. / TikTok Technology Ltd. | Social media: publishing videos on the owner's TikTok account (private until TikTok approves Neaion), with the settings the owner chose, and reading their figures | The video and its caption, the owner's choices for it (who may see it, comments, duets, stitches, commercial content), through the account the owner connected | Singapore; Ireland (EU); United States |
| Cloudflare, Inc. | DNS for our domain; storage for encrypted-at-rest backups | Backups of service data | Backups: EU (jurisdiction-restricted storage); DNS: global |
AI providers: what is and is not sent
Every call Neaion makes to an AI model with customer content — and every reading of a public post Tess found — is classified as carrying personal data, and the code allows such calls to reach only Anthropic and Voyage AI. The search services listed for Tess (Perplexity, xAI, Google's YouTube Data API) receive search words only, built in code from the business's own Social settings and checked before every call; nothing a customer wrote can be part of them. Tess also reads Hacker News (through Algolia's public HN Search and Hacker News' own API) and Bluesky (its public AppView, or — when the owner connected their own Bluesky account — Bluesky's search as that account), with the same search words or the link of a post the owner answered. Neaion's code can address other AI providers too, but in production none of them receives any data; if that ever changes, this page changes first.
We use these providers only through their commercial APIs, and we do not use your data, or your customers' data, to train AI models. Each provider's handling of API data is governed by its own commercial terms and our data processing agreement with it.
Services you connect
Some services are not our sub-processors but your own providers, which you choose to connect and which act under your agreement with them:
- Google (Gmail) — if you connect an inbox, Neaion reads, labels and replies to mail in it, and writes drafts in it for you to send, through Google's API on your instruction.
- Microsoft (Outlook, Microsoft 365) — if you connect an Outlook mailbox, Neaion reads, marks (with its own category) and replies to mail in it, and writes drafts in it for you to send, through Microsoft's Graph API on your instruction.
- Your email provider (for example IONOS, Strato, GMX, WEB.DE, Telekom, Yandex 360, Zoho Mail, iCloud or your hosting company) — if you connect a mailbox with its password (an app password where the provider offers one), Neaion signs in to it over encrypted connections only (IMAP and SMTP with TLS) to read, mark and answer mail, file a copy of each reply in its Sent folder and write drafts in it. The password is stored encrypted, used only for this mailbox, and erased when you disconnect it.
- Telegram — if you connect your own Telegram account, questions Neaion cannot answer are sent to you there. A question includes the customer's message, shortened to at most 500 characters, so you can answer without opening the panel. If you connect your business's own Telegram bot, or let Neaion answer the customers who write to your Telegram account (Telegram Business), your customers' messages there are read and answered through Telegram's API on your instruction.
- Google (Calendar) — if you connect your calendar, Neaion reads when you are busy and adds the appointments your customers book; a customer who writes by email receives Google's invitation.
- Google (Business Profile) — if you connect it, Neaion reads your reviews and posts the replies you approve; nothing is posted without you.
- Bluesky — if you connect your account with an app password, Neaion posts a reply Tess drafted under the post it answers, from your account, only when you press Send on that reply; and searches Bluesky as you. The app password is used once and never kept; the session is stored encrypted and ended when you disconnect.
- Google (YouTube) — if you connect it, Neaion posts a reply under a YouTube comment or video from your channel, only when you press Send on that reply.
- Your shop — Shopify, ikas, or your own WooCommerce or Shopware — if you connect it, Neaion reads one order's status when that order's own customer asks about it (never an address).
- The Neaion browser extension — if you install it and connect it to your office, it reads the Facebook group or Nextdoor page you have open, in your own browser, and sends your office the posts that ask for what you do: each post's link and at most 500 characters of its words, never a name, a profile or who commented. When you press Send for a reply on Reddit, in a Facebook group or on Nextdoor, it writes that reply into the comment box you click into — it never presses the site's button, and on Reddit it reads nothing. See Privacy, the browser extension and Send.
- Trendyol, Hepsiburada, n11 — if you connect your seller account with its API details, Neaion reads the questions shoppers ask about your products (the question, the product and any answer already given — never the shopper's name, id or order) and sends the answers you approve; nothing is sent without you. The API details are stored encrypted and erased when you disconnect.
- Your invoicing tool (lexoffice, sevDesk, easybill, Billomat, Moneybird, Holded, Stripe, QuickBooks, Xero, FreshBooks, Zoho Books or Paraşüt) — if you connect one, Neaion reads the invoices you issued (number, amount, dates, the customer's name and email address) to follow them until they are paid. It never changes, finalises or sends an invoice there. If you use invoice drafts (lexoffice), Neaion writes a draft invoice there for a finished appointment — on your press, or each morning if you switch that on: the customer (looked up among your lexoffice contacts by their email address, or else by name), the service, its date and its price. A draft is only a draft: finalising and sending it stays yours.
- Your e-invoice integrator (Nilvera) — if you connect it with an API key, Neaion reads the e-invoices your suppliers sent you there (the invoice's XML: the parties and their tax numbers, the lines, the taxes, the totals and the bank account it asks to be paid to), to put them in your ledger. It reads only: it never accepts, rejects, sends or marks an invoice there, and it does not read the invoices you issued. The key is stored encrypted and erased when you disconnect.