Privacy Policy
Draft version: 1 October 2026
1. Scope and operator
This notice describes the current Neoceis pilot. The operator’s legal identity and privacy contact are awaiting confirmation. Agencies may also handle your information under their own privacy notices. White-label branding does not remove the platform’s involvement in processing.
2. Information processed
We process account email, salted password hashes, session records, subscription identifiers and status, usage records, business setup information, schedules, explicit business memory, messaging identifiers, bot credentials and any uploaded social metrics. Agent conversations and generated files may be stored in customer runtime folders and backups. Avoid submitting sensitive personal information that is unnecessary for the task.
3. Purposes and recipients
Information is used to authenticate accounts, deliver requested AI work, schedule tasks, meter usage, process subscriptions, support customers and protect the service. Depending on enabled features, content is sent to DeepSeek or OpenAI for AI processing, Telegram for messaging, DataForSEO for research, and Stripe for payments. Hosting and backup providers process stored information. Resellers can see their assigned clients’ email, plan, subscription status, setup status and runtime status; their dashboard does not expose chat content or provider credentials. We do not receive full card details through our application.
4. International processing
Providers may process data outside Australia. The operator must confirm the selected hosting regions, overseas recipients and likely processing countries before publication. Provider retention and training policies must be checked against the configured accounts and agreements; this draft does not promise that every provider has zero retention or never uses submitted information.
5. Storage and security
Passwords are stored as salted hashes, session tokens as hashes, and stored bot/customer API credentials are encrypted. Access checks separate customer and reseller records. These controls do not guarantee absolute security. Runtime files and backups may contain private information; backup archives are not inherently encrypted by the current application.
6. Retention and deletion
Sessions expire after 24 hours; invitation links expire after seven days and pairing links after ten minutes. Expiration does not necessarily remove every related database record immediately. The pilot has no comprehensive automatic retention/deletion policy for account data, conversations, generated images, billing records or backups. Cancellation retains data. Final retention periods and a verified deletion process must be established before public launch.
7. Cookies and local storage
A necessary HttpOnly session cookie keeps you signed in. Session storage can remember a selected plan; a local-storage timestamp coordinates logout across browser tabs. Current application pages do not include advertising trackers. Payment or messaging services may use their own cookies and policies.
8. Requests and complaints
You may request access, correction or deletion and raise privacy complaints through the operator’s privacy contact, which must be supplied before launch. Identity may need verification; legal obligations and backup handling may affect deletion. Agency clients may also contact their agency. Where applicable, unresolved privacy complaints can be raised with the Office of the Australian Information Commissioner.
9. Changes
This notice must be updated when integrations, recipients, retention or data practices change. Email sending has not yet been integrated; any future email provider must be disclosed before use.