Privacy Policy
Last updated: September 2026
Who is responsible
neonloops is operated by Ender Yildirim e.U., Vienna, Austria. We are the controller for your account data, billing data and the security records described below. Contact: hi@neonloops.com. We have not appointed a data protection officer, because the law does not require one for our processing.
For the content a workspace processes — workflows, tables, files, run inputs and outputs — the business that owns the workspace is the controller and we are its processor. Our Data Processing Agreement at neonloops.com/dpa governs that processing.
What we collect
Account data you provide — name, email, profile picture, notification preferences, and the workspaces you belong to. If you sign in with Google, Google shares your name, email and profile picture with us.
Invitations — if a workspace member invites you, we receive your email address from them. We use it only to send the invite and, if you accept, for your account.
Workspace content — the projects, workflows, tables, files and skills a workspace creates, and the inputs and outputs of every run. Workspaces may put personal data about other people into workflows; the workspace's business is responsible for informing those people.
Billing data — your workspace's usage and invoices, and the billing details you give when you add a card. Card details are collected and held by Stripe; we never see or store the full card number.
Security records — sign-in records including IP address, server logs, a record of each call an external agent makes through our MCP server (which tool, when, the outcome — not the values sent), and a salted hash of the IP address of anyone who submits a public workflow form.
Advertising measurement — on neonloops.com and in the app, Google Analytics 4 records the pages you visit while the tag runs, and Google Ads records whether a visit that came from one of our ads leads to a sign-up or a card being added. See "Measuring our advertising" below. We do not run any other product analytics scripts.
Product videos — the product videos on neonloops.com are click-to-load: nothing is requested from YouTube until you press play. See "Product videos" below.
Why we use it, and on what legal basis
Running your account, workspaces and workflows, sending invites, approval, spend-limit and billing emails, and billing your workspace: to perform our contract with you (Art. 6(1)(b) GDPR).
Keeping invoices and tax records: our legal obligation (Art. 6(1)(c) GDPR).
Security records, abuse and fraud prevention: our legitimate interest in keeping the service and your workspace secure (Art. 6(1)(f) GDPR).
Sending an invite to someone a workspace member names: our and that workspace's legitimate interest in letting members add their team (Art. 6(1)(f) GDPR).
Advertising measurement: for visitors in the EEA, the UK and Switzerland, your consent (Art. 6(1)(a) GDPR, §165(3) TKG 2021). For visitors elsewhere, our legitimate interest in measuring our own advertising (Art. 6(1)(f) GDPR) — see "Your right to object" below for how to object.
We do not sell your data, we do not use it to train models, and we make no decisions about you based solely on automated processing.
What you need to give us
You need to give us your name and email to create an account, and a payment card and billing details before work can run. Without them we cannot provide the service.
Model access and the credentials you store
AI requests run on provider accounts we operate, so you are never asked for an API key.
Secrets a workflow needs are encrypted at rest with AES-256. When you connect an app, its sign-in is held by Composio and we store only a reference to it. Credentials are only ever used to make the requests your workflows trigger — never sold, never shared, never used to train anything.
The AI providers' commercial terms prohibit them from training models on the data we send. They may keep it for a short period, typically up to 30 days, to detect misuse. Agent sessions and agent memory are stored with Anthropic until they are deleted.
Cookies
The app sets cookies it needs to work: your sign-in session, short-lived cookies used while you sign in and while you connect an external agent, and one that remembers the workspace you last opened for up to a year.
Google's advertising-measurement cookies, described in "Measuring our advertising" below, are set on the shared ".neonloops.com" domain, so they are sent to the app as well as to the marketing website. Neither site sets any other tracking cookie on load. If you press play on a product video, YouTube's player may set its own cookies — see "Product videos" below.
Measuring our advertising
We run Google Ads campaigns for neonloops.com and measure them with Google Ads conversion tracking and Google Analytics 4 (the Google tag). The tag runs on neonloops.com and in the app at app.neonloops.com — Google's cookies are set on the shared ".neonloops.com" domain, so the same visit is recognized on both. In the app it reports two events: account created, the first time you reach onboarding, with your account id as the transaction id; and card added, when a payment method is added to your workspace (counted once per workspace), with your workspace id as the transaction id. Page-view measurement in the app is limited to the fact that a page was viewed, without the page's URL parameters. We do not send the content of your workflows or runs to Google.
With your consent to "ad_user_data", we also send Google Ads a SHA-256 hash of your email address ("enhanced conversions") to improve ad matching; without that consent we send none.
For visitors in the EEA, the UK and Switzerland, we use Google's Consent Mode Basic: the Google tag does not load at all until you consent — a cookie banner on neonloops.com and in the app asks first, on the basis of your consent (Art. 6(1)(a) GDPR, §165(3) TKG 2021). You can withdraw consent at any time from "Cookie settings" in the footer.
For visitors elsewhere, the tag runs by default, on the basis of our legitimate interest in measuring our own advertising (Art. 6(1)(f) GDPR). You can object at any time from the same "Cookie settings" link in the footer, and we honour the Global Privacy Control signal as an opt-out wherever it is sent.
For collecting and transmitting this data through the Google tag, we and Google Ireland Ltd are joint controllers under Art. 26 GDPR, under Google's Advertising Controller-Controller Data Protection Terms — Google Ireland Ltd is the Google entity EEA, UK and Swiss visitors contract with. For Google Ads conversion tracking after that, Google acts as an independent controller under the same terms. For Google Analytics 4, Google acts as our processor under the Google Ads Data Processing Terms, for as long as the property stays unlinked from Google Ads with Google signals and data sharing off; if we ever link them for conversion import or audiences, Google processes the linked data as a controller and we will update this section. Either way, the data leaves the EEA on the basis of Google's certification under the EU-US Data Privacy Framework; the UK Extension to that framework covers transfers from the UK, and the Swiss-US Data Privacy Framework covers transfers from Switzerland.
Cookies and browser storage this sets:
"_gcl_au" — Google, associates an ad click with your visit, 90 days.
"_gcl_aw" — Google, associates an ad click with a conversion, 90 days.
"_ga" — Google, distinguishes visitors, up to 2 years.
"_ga_<container id>" — Google, session state for GA4, up to 2 years.
"nl_consent" — us, remembers your cookie choice, 12 months.
"nl_ad_attribution" — us, keeps the ad-click parameters from your landing visit until you open the app, only with advertising consent; this browser session.
"nl_ads_conv_signup", "nl_ads_conv_cardAdded" — us, remembers that a conversion was already reported so it is not sent twice; kept in this browser until you clear it.
Product videos
The product videos on neonloops.com show a local thumbnail and a play button; nothing is requested from YouTube until you press play. When you do, your browser loads the video player from "youtube-nocookie.com" — Google's cookie-reduced embed domain. Loading it sends your IP address to Google and lets the player write its own cookies and browser storage on that domain, on the basis of your action in pressing play (Art. 6(1)(f) GDPR, our and your interest in the video you asked for actually playing).
This is a one-off request tied to that click, not something we run on every visit. Google Ireland Ltd is an independent controller for this processing, under Google's own privacy policy at policies.google.com/privacy. Data may transfer to the United States; Google's certification under the EU–US Data Privacy Framework covers that transfer.
Where it is stored, and who processes it
neonloops runs on servers we operate at Hetzner in Helsinki, Finland, subject to EU and Austrian law. The database, sign-in and job execution are software we host there ourselves. We disclose data to a public authority only when the law requires it, after checking the request, and we tell the workspace owner unless the law forbids it.
We use these processors, each under a data processing agreement: Hetzner Online GmbH, Germany (hosting); Anthropic Ireland Ltd (AI models, agent sessions and agent memory); OpenAI Ireland Ltd and Google (AI models), and another AI provider only when a workflow is set to use it; Google Ireland Ltd (Google Analytics 4, as described under "Measuring our advertising"); Sampark, Inc. (Composio), USA (the apps you connect); Plus Five Five, Inc. (Resend), USA (email); and Migadu-Mail GmbH, Switzerland (our support mailbox). The current list, and changes to it, are published at neonloops.com/dpa.
Stripe Payments Europe Ltd, Ireland, processes payments and acts as an independent controller for fraud prevention and its own legal obligations, under its own privacy policy. If you sign in with Google, Google's own processing is covered by Google's privacy policy.
Some providers process data in the United States. Transfers to Google, Resend and Stripe rely on their certification under the EU–US Data Privacy Framework. Transfers to Anthropic, OpenAI and Composio rely on the European Commission's Standard Contractual Clauses; email us for a copy. Switzerland is covered by an adequacy decision.
How long we keep it
Account data: while your account exists. When you delete your account, your sign-in, profile, memberships and notifications are deleted after 14 days; what you created inside a workspace stays with that workspace.
Workspace content and run history: until the workflow, project or workspace they belong to is deleted. Files produced by runs and Studio are deleted after your workspace's retention window — 90 days unless you change it — unless you save them. Agent memory at Anthropic is kept until you clear it or ask us to delete it.
Invoices and billing records: seven years from the end of the calendar year they relate to, as Austrian tax law (§ 132 BAO) requires.
Security records: only as long as we need them to keep the service secure and investigate incidents. Records of external agent calls are kept with the workspace.
How we protect it
All connections are encrypted in transit, workflow secrets are encrypted at rest, access is limited by workspace roles, and access tokens for external agents expire after 7 days and can be renewed for up to 60. If a breach puts your data at risk, we notify the Austrian Data Protection Authority within 72 hours and tell you without undue delay where the law requires.
Your rights
You can delete a workflow, project, or workspace at any time, which removes its associated run data. You can delete your account from your account settings; deletion takes effect after 14 days, and you can cancel it until then.
Under the GDPR you have the right to access, correct, delete, restrict and port your data. Email hi@neonloops.com to exercise any of them. For workspace content, we pass your request to the business that owns the workspace.
You can also complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, dsb@dsb.gv.at.
Your right to object
Where we rely on our legitimate interests, you can object at any time, for reasons relating to your situation. We then stop, unless we have compelling legitimate grounds or need the data for legal claims. Email hi@neonloops.com.
Children
neonloops is for businesses and is not meant for anyone under 18. We do not knowingly collect their data.
Changes to this policy
When we change this policy in a way that matters, we tell workspace owners by email or in the product before the change takes effect.
Contact
Questions about privacy? Email hi@neonloops.com.