NEOAMISHNEOAMISH
LEGAL·Last updated May 2026

Privacy
Policy.

Your data, your rules. This page explains — in plain language — what Neoamish collects, how we use it, and the controls you have over every byte.

GDPR-compliant · EU-hosted · No third-party trackers

Our promise to you

We never sell your data

No advertisers, no data brokers, no exceptions.

Encrypted, EU-hosted infrastructure

TLS in transit, encryption at rest, daily backups.

Full GDPR rights, always

Access, export, delete — one email away.

Essential cookies only

No third-party trackers, no marketing pixels.

§ 01

What we collect

Only what we genuinely need to run the platform — nothing more.

When you create an account we collect the information you provide directly: your email address, chosen username, display name, and an optional profile picture. If you sign up through a third-party provider, we receive a basic identifier from that provider and nothing more.

Once inside the platform, we store the content you create — projects, comments, favorites, AI chat history — so we can show it back to you and, where you've made it public, to other users.

We also receive technical metadata your browser sends to any website: IP address, user agent, and approximate timestamps. We keep this strictly for security, abuse prevention, and basic uptime monitoring.

§ 02

How we use your data

To deliver the product you signed up for, and to improve it carefully.

Your data powers the features you interact with: authentication, project storage, collaboration, the AI assistant, and notifications. Without it, the platform cannot function.

We aggregate anonymized usage signals to understand which features matter, fix bugs faster, and prioritize what comes next. These insights never identify individual users.

We will only send you product emails (release notes, account alerts, security notices). We do not run marketing campaigns and we do not pass your address to any advertiser.

§ 03

Where & how we store it

Encrypted at rest and in transit, hosted entirely inside the European Union.

Our primary database runs on NeonDB infrastructure located in the EU, with automated daily backups retained for 14 days. All traffic between your browser and our servers is encrypted via TLS 1.3.

Authentication secrets, API keys, and any sensitive credentials are encrypted at rest. Password hashes use industry-standard algorithms with per-user salts — your password is never stored in readable form.

If we ever detect a security incident affecting your data, we will notify you by email within 72 hours and report it to the relevant authority as required by GDPR.

§ 04

Who we share it with

A short list of essential service providers. No advertisers. Ever.

We rely on a handful of carefully chosen subprocessors to run the platform. Each one is bound by a data processing agreement and processes data only on our instructions.

  • Hosting & renderingVercel (EU regions)
  • DatabaseNeonDB (EU)
  • Transactional emailResend
  • Product analyticsPostHog (EU cloud, IP anonymized)

§ 05

Cookies & tracking

Only what we need to keep you signed in and remember your language.

We use a single session cookie to keep you authenticated, plus a small preference cookie that remembers your interface language. Both are first-party and essential — there is no banner because there is nothing to consent to beyond strictly necessary cookies.

We do not use Google Analytics, Facebook Pixel, or any cross-site tracking technology. Our product analytics tool is configured to anonymize IP addresses and ignore Do-Not-Track and ad-blocker rules.

§ 06

Your rights under GDPR

You're in charge. Use any of these at any time, for any reason.

European data protection law gives you a robust set of rights over your personal data, and we honor every single one — regardless of where you live in the world.

  • AccessRequest a copy of everything we hold on you
  • RectifyCorrect anything inaccurate or outdated
  • EraseDelete your account and personal data permanently
  • ExportDownload your projects and content in open formats
  • ObjectOpt out of any non-essential processing
  • ComplainLodge a complaint with your national authority (CNIL in France)

§ 07

How long we keep it

As long as your account is active — and not a day longer than necessary.

While your account is active, we keep your data so the platform works. The moment you delete your account, we purge your personal information from our production systems within 30 days. Encrypted backups roll off our retention schedule within 90 days at the latest.

Limited records may be retained beyond this window only where required by law — for example, transactional logs needed for accounting compliance — and only for as long as the law mandates.

§ 08

Changes to this policy

We update this document when our practices change. You'll always know first.

Material changes — anything that affects how we collect, use, or share your data — will trigger an email to every registered user at least 14 days before the new policy takes effect. Minor edits (typos, clarifications) are made silently with an updated revision date at the top of this page.

Previous versions are kept in version control and are available on request.

A real human reads every privacy email.

Questions, deletion requests, exports, or just curious how something works? Write to us and you'll get a reply within seven days — usually much sooner.

contact@davidguerin.fr

Document version of May 2026. Previous revisions available on request.