// privacy policy

Privacy Policy

Last updated: August 2026

1. Data Controller

The controller responsible for processing your personal data is Rosaldo Alves, an individual established in São Carlos/SP, Brazil, provider of the NeoGoApp service. Contact: [email protected].

2. The Principle: your data stays with you

NeoGoApp is designed to process as little as possible. Neo runs inside your own Claude, with your Anthropic account, and the container runs on your machine.

That is why we do not have access to and do not store:

  • the content of your tasks, instructions, or outputs
  • the credentials of the services you connect to your Claude
  • your payment data (card or bank details)
  • your IP address, browser, or any browsing telemetry

There is no database of ours where such content could reside.

One honest exception: the terminal. When you open the terminal in your dashboard (Access your Neo), your Neo's screen and the files you send or download pass through our server in transit — it is the bridge between your browser and your machine, which may be on different networks. That content is never stored, never logged, and never read: the server only copies data from one side to the other, encrypted in transit (HTTPS/TLS). From the terminal we record only that a session was opened, for which account and installation, how long it lasted, and why it ended.

3. Data We Collect

  • Email address — provided at subscription. It is the only direct personal data we process. Used for authentication and service communications.
  • Account language — so we can send communications in your language.
  • Installation details — platform (Linux/macOS/Windows), architecture, machine name (hostname), and the image version in use. The hostname is optional and exists for security: it is shown when you authorize an installation, so you can recognize the machine and reject requests that are not yours.
  • Installation activity signal — the date and time the container last checked in, to show whether it is active.
  • Claude sign-in status on the installation — whether your Claude is signed in inside the container (yes/no), so the dashboard can tell you when it signs out. We have no access to your Claude account or its credentials.
  • Terminal session records — when a session was opened and closed, for which account and installation, and why it ended. Never the screen content, never the files.
  • Subscription identifiers — identifiers generated by Stripe, plus subscription status and validity. No card data.
  • Technical event log — event type and date (e.g. "installer downloaded"), with no content or personal data, for support and diagnostics.

Login codes and access tokens are stored only as a cryptographic hash — never in readable form. A leaked copy of the database would not grant access to your account.

4. Purpose of Processing

  • Authentication and account access control
  • Delivery of the contracted service
  • Bridging your access to your own Neo (the dashboard terminal)
  • Payment processing and subscription management
  • Transactional communications (login code, subscription notices)
  • Security and technical diagnostics

5. Legal Basis (LGPD)

Under Brazilian Law No. 13.709/2018:

  • Performance of a contract (art. 7, V) — processing of email, language, installation and subscription data, indispensable to providing the service.
  • Compliance with a legal obligation (art. 7, II) — retention of subscription records for tax purposes.
  • Legitimate interest (art. 7, IX) — account security and technical diagnostics.

We do not process data for marketing or profiling.

6. Data Sharing

Your data is not sold. We share it only with:

  • Stripe (payment processing) — receives only your email address. Card details are provided by you directly to Stripe; they never pass through us.

Anthropic (Claude) and the services you connect are your own direct relationships — governed by their terms and privacy policies. We neither intermediate nor send data to those services.

7. Where Data Is Processed

Your account data is held on a dedicated server located in Germany (European Union). Payment processing takes place at Stripe, which operates internationally — a transfer necessary for the performance of the contract (art. 33, LGPD).

8. Data Retention

  • Account and email — for as long as the account exists. Besides deletion on request, the account is anonymized automatically 6 months after the subscription period ends — the same window during which the dashboard stays reachable so you can resubscribe.
  • Subscription records — retained after account deletion, as a tax obligation.
  • Technical event log — retained after deletion, with no personal data (event type and date only).
  • Login codes and tokens — they expire and cease to be valid within minutes or hours; expired records remain inert (hashes with no value) until removed.

9. Account Deletion

When you request deletion, we run a procedure that, in a single operation:

  • revokes all access tokens;
  • deletes the records of your installations and your login codes;
  • replaces your email with an anonymous identifier, making the account no longer attributable to you.

Subscription records are retained as a tax obligation, already unlinked from your identity.

10. Your Rights (LGPD)

You have the right to: confirmation that processing exists; access to your data; correction; anonymization, blocking, or deletion; portability; information about sharing; and objection to processing.

To exercise these rights: [email protected].

11. Cookies

We use only strictly necessary cookies to keep your session authenticated. We do not use tracking, advertising, or analytics cookies.

12. Security

We apply technical and organizational measures to protect your data: encryption in transit (HTTPS/TLS), storage of login codes and tokens as hashes only, privilege separation in the database (the running service has no permission to alter the data structure), and restricted access control.

Our web server logs are deliberately minimal — host, method, route, status and size. They do not record your browser, and never the query strings that carry single-use secrets. What passes through the terminal is not logged at all.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated by email at least 15 days in advance.