1Scope
This Privacy Policy explains how Neox collects, uses, discloses, and protects personal information when you use the Neox desktop client, command-line tools, website, and cloud services.
For purposes of the EU General Data Protection Regulation (GDPR) and UK GDPR, we act as a data controller when processing your account and usage data for our own purposes, and as a data processor when handling content submitted by business customers, in which case our Data Processing Addendum applies.
2What We Collect
| Category | Details | Source |
|---|---|---|
| Account | Email address, password hash, display name, creation date, verification status | You provide |
| Subscription & billing | Plan, subscription status, order and payment reference IDs, platform balance and ledger, billing history | You / payment provider |
| Usage | Request counts, model names, token counts, images generated, timestamps, charge records | Collected automatically |
| Technical logs | IP address, request path, status code, latency, error messages, client version, upstream channel | Collected automatically |
| Device | Device fingerprint, device public key, operating system and client version | Collected automatically |
| Security events | Sign-in attempts, anomalous access, rate-limit triggers, abuse determinations | Collected automatically |
| Website analytics | Page paths visited, referrer, browser user-agent string, a one-way hash of your IP (no plaintext IP), country/region, and a random visitor ID stored in your browser (see the Cookie Policy) | Collected automatically |
| Device link relay | Metadata for phone-to-desktop forwarding: both device IDs, byte counts and timestamps (session content is end-to-end encrypted and the relay never decrypts it) | Collected automatically |
| Cloud feature content | Messages, memories, reminders and workspace file snapshots created when you use cloud features such as cloud sessions and the cloud assistant (currently available to a limited set of users) | You provide |
| Push tokens | The device push token your phone uses to receive notifications | Collected automatically |
| Support | Emails, feedback, and attachments you send us | You provide |
| Third-party accounts on your device | Access tokens left after you sign in from the desktop client (for example Google Calendar and Google Drive). Tokens stay on your computer, encrypted with a machine-derived key, and are not uploaded to our servers | You authorize |
We do not collect your card number. Paid subscriptions are sold through Waffo.com Limited as merchant of record, which takes payment and handles card data as the seller of that transaction; we store only the transaction reference and status. Your card number never passes through our servers and is not in our database.
3Your Code and Prompts
This is the question that matters most with an AI coding tool, so it gets its own section.
- BYOK mode
- Your prompts and code go directly from your device to the model provider you configured. They do not pass through our servers, and we cannot see them. Your API keys are encrypted locally and never uploaded.
- Subscription mode
- Requests — including conversations, code, file contents and text you ask to have read aloud — are forwarded through the Neox gateway to the upstream model provider needed to fulfil them, or to that provider's authorized resellers and aggregators. We use this content in transit to fulfil your request and do not retain it in full by default. Upstream providers handle requests under their own terms and privacy policies and may retain them temporarily for safety and abuse monitoring; providers of some free models may use requests to improve their services. Some models are provided by companies outside the United States (including in China); by choosing such a model you direct that the request be processed by that provider in its location.
- We do not retain prompt content by default
- Full-prompt capture at the gateway is disabled by default, and prompt content is stripped before request logs are written. We keep only the metadata needed for metering and troubleshooting — token counts, model, status code.
- Not used for training
- We do not use your code, prompts, or output to train or fine-tune any model, and we do not sell or rent them to third parties. How upstream model providers use request content is governed by their own policies, as described above.
Exceptions: when you submit a bug report and attach relevant content, we review it only as needed to investigate and delete it once the issue is closed. If content capture must be temporarily enabled to diagnose a serious incident, we limit it to the narrowest scope and shortest duration necessary, subject to the retention and security commitments in this policy.
4Google and other connected accounts
This section is what Google reviewers read: what Calendar and Drive data we touch after you click Sign in on the desktop.
When you connect a Google account in the Neox desktop client, the system browser asks Google for the scopes you approve. The public connectors today are Google Calendar and Google Drive. The scopes we request are: view and change events on calendars you authorize; read Drive files, and create or update files you choose through Neox.
- What we access
- Only what is needed for the step you asked for in the conversation — for example listing upcoming events, reading a Drive file you named, or writing an event or file you instructed.
- How we use it
- Only on your device, to complete the action you started. Not for ads, not sold, not used to train models, and not transferred to unrelated third parties.
- Where tokens live
- Access tokens from Google are stored only on your computer and encrypted with a machine-derived key. Our servers never receive the token, your calendar, or Drive file contents. The desktop calls Google APIs directly.
- How to delete
- Disconnect the connector in the Neox plugin panel to wipe the local token and grants immediately. You can also revoke Neox under your Google Account’s third-party app access. After you uninstall Neox, the local encrypted file is no longer used.
If we later connect Gmail or other Google services, new scopes will be listed on the consent screen and this section will be updated. Scopes that are not verified or not public will not be enabled for everyone.
5How We Use Information
- Operate the service: authenticate you, route requests, meter usage, enforce plan allowances.
- Billing: process subscriptions and platform balance, handle refunds and disputes (receipts are issued by our merchant of record, Waffo).
- Security and abuse prevention: detect credential stuffing, mass registration, quota circumvention, and attack traffic.
- Reliability: troubleshoot failures, monitor performance, diagnose errors.
- Communication: send transactional messages such as verification, billing, and service change notices.
- Compliance: meet legal obligations and respond to lawful requests.
- Product improvement: improve features using aggregated statistics that do not identify individuals.
6Legal Bases (GDPR / UK GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the service, account management, billing | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Service improvement and aggregate analytics | Legitimate interests (Art. 6(1)(f)) |
| Marketing email, non-essential cookies | Consent (Art. 6(1)(a)), withdrawable at any time |
| Tax and accounting records, responding to legal process | Legal obligation (Art. 6(1)(c)) |
7Who We Share With
We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising as defined by California law. We disclose information to third parties only as needed:
- Model providers
- With a subscription or the Neox Platform API, your request content is forwarded to the upstream model provider required to fulfil it, or to its authorized resellers and aggregators, which may be located outside the United States (including in China).
- Third parties you authorize
- When you connect Google or similar accounts on the desktop, the client calls their APIs with the capabilities you granted. Those requests do not pass through our servers.
- Infrastructure and vendors
- Cloud hosting, email delivery, and payment processing providers. See our Subprocessors page for the categories involved.
- Legal requirements
- Where we believe in good faith that the law requires it, or where necessary to protect the rights, property, or safety of us, our users, or the public.
- Business transfer
- In a merger, acquisition, or asset sale, your information may transfer as part of that transaction. We will notify you in advance.
8Retention
| Data type | Retention period |
|---|---|
| Account information | While the account exists; purged within 30 days of deletion |
| Technical request logs | Deleted automatically after 30 days |
| Usage and metering records | Current and prior billing periods; aggregates up to 24 months |
| Billing records | Kept for a period to support reconciliation, refunds and disputes |
| Security and audit events | Up to 12 months |
| Website analytics | Deleted after 90 days |
| Device link relay metadata | Deleted automatically after 90 days |
| Cloud feature content | Kept until you delete the session; deleted with your account |
| Push tokens | While the account exists; deleted with your account |
| Support correspondence | 24 months after the issue is closed |
| Third-party tokens on device | Stay on your device until you disconnect or uninstall |
After these periods data is deleted or irreversibly anonymised. Where law requires longer retention — for example pending legal proceedings — the legal requirement prevails.
9Your Rights
Depending on where you live you may have the rights below. We offer access, export, and deletion to all users regardless of region.
- Access and portability
- Obtain a copy of the personal data we hold about you, exported in a machine-readable format.
- Correction
- Correct inaccurate or incomplete information.
- Deletion
- Request deletion of your account and associated data, subject to legal retention obligations.
- Restriction and objection
- Object to or restrict processing based on legitimate interests in certain circumstances.
- Withdraw consent
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Non-discrimination
- Exercising privacy rights will not result in degraded service or different treatment.
The "Data & privacy" page in account settings provides self-service data export and account deletion. You may also contact us by email; we respond within 30 days (one month under GDPR, extendable for complex requests).
If you are in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data protection authority.
10International Transfers
Our servers and vendors may be located outside your country, including in the United States. Some models you can choose with a subscription or the Neox Platform API are provided by companies in other countries (including China), and those requests are transferred to that country for processing. This means your information may be transferred to countries whose data protection laws differ from your own.
For transfers from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, with supplementary measures where required.
11Security
- TLS encryption in transit throughout; gateway requests carry HMAC signatures with replay protection.
- Passwords are stored salted with an industry-standard slow hash. We cannot read your original password.
- Local credentials and API keys are encrypted at rest with AES-256-GCM under restricted file permissions.
- Internal access follows least privilege, and administrative actions are recorded in audit logs.
- Rate limiting and abuse controls against credential stuffing, mass registration, and anomalous traffic.
No system is perfectly secure. We cannot guarantee absolute security of transmission or storage, but we invest continuously to maintain protection proportionate to the risk. If a security incident affects your personal data, we will notify you and the relevant authorities within the timeframes the law requires.
12Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect their personal information. If we learn we have, we will delete it promptly. Parents or guardians who believe a child has provided us personal information should contact us.
13Cookies and Local Storage
We use essential cookies to maintain your session and protect against abuse, and browser local storage for preferences such as language. See our Cookie Policy for detail.
14Changes to This Policy
We may update this policy. For material changes we will give advance notice by in-product message or email before they take effect. The "last updated" date at the top always reflects the current version.
15Contact Us
For privacy questions or to exercise your data rights, contact support@neox-dev.com.

