Legal
Privacy Policy
Last updated: April 20, 2026
1. Introduction
Welcome to NEIT. We take the protection of your personal data seriously. This privacy policy explains what data we collect, for what purpose, and how we protect it, in accordance with the General Data Protection Regulation (GDPR) and applicable laws.
2. Data Controller
The data controller is NEIT. For any question regarding your data, you can reach us at: privacy@neit.ai.
3. Data Collected
We collect the following data:
- Identity data: name, email address, password (encrypted).
- Account data: profile information, preferences, generated content.
- Platform connection data: OAuth access tokens for Instagram, TikTok and other connected social networks.
- Usage data: browsing logs, IP address, browser type.
- Payment data: processed and stored directly by our payment provider (Stripe). We do not store any raw banking data.
4. Purposes of Processing
Your data is processed to:
- Create and manage your user account.
- Provide NEIT services: content generation, automated publishing, AI persona management.
- Process your payments and manage your subscriptions.
- Improve our services and carry out usage analysis.
- Send you service-related communications (transactional only, unless explicit consent is given for marketing).
- Comply with our legal obligations.
5. Legal Basis for Processing
- Contract performance: processing necessary to deliver the subscribed service.
- Legitimate interest: security, fraud prevention, service improvement.
- Consent: for marketing communications and non-essential cookies.
- Legal obligation: retention of data required by law.
6. Data Sharing
We never sell your data. We may share it with:
- Supabase: database hosting.
- OpenAI: AI content generation (text, images).
- Stripe: payment processing.
- Meta / Instagram & TikTok: publishing content to your connected accounts.
- Vercel: application hosting.
These sub-processors are contractually required to maintain the confidentiality and security of your data.
7. Data Retention
Your data is retained for as long as your account is active or as necessary to provide the service. Upon termination, your data is deleted or anonymised within 30 days, unless a longer retention period is required by law.
8. Your Rights
Under the GDPR, you have the following rights:
- Right of access: obtain a copy of your data.
- Right to rectification: correct inaccurate data.
- Right to erasure: request deletion of your data.
- Right to data portability: receive your data in a structured format.
- Right to object: object to certain processing activities.
- Right to restriction: request suspension of processing.
To exercise these rights, contact us at privacy@neit.ai. You also have the right to lodge a complaint with your national data protection authority.
9. Cookies
NEIT uses cookies essential to the operation of the service (authentication, session). No advertising or third-party tracking cookies are placed without your explicit consent.
10. Security
We implement appropriate technical and organisational measures to protect your data: TLS encryption in transit, encryption at rest, strict access control, and monitoring for abnormal access.
11. International Transfers
Some of our service providers (OpenAI, Stripe, Vercel) are based in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) or other recognised adequate protection mechanisms.
12. Changes to This Policy
We may update this policy. In case of material changes, we will notify you by email or via an in-app notification at least 14 days before the changes take effect.