Skip to main content

Privacy Policy

Last updated: August 31, 2026

1.Scope and Controller

This Privacy Policy explains how Neo ID ("Controller", "we", "us") collects, uses, processes, and shares Personal Data when you use our identity and authentication services (the "Service"), including our website, APIs, and OAuth-based sign-in. This policy is compliant with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws.

2.Legal Basis for Processing

We process your Personal Data only when we have a legal basis to do so under GDPR Article 6: (a) performance of a contract (providing the Service you requested); (b) compliance with a legal obligation; (c) our legitimate interest (security, fraud prevention, service improvement); or (d) your explicit consent (where required). You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

3.Information We Collect

Depending on how you use the Service, we may collect: (a) Account information: email address, display name, password hash (bcrypt); (b) OAuth information: provider name and provider user identifier; (c) Passkey credentials: credential ID, public key, device name; (d) Multi-factor authentication data: TOTP secrets, email MFA status; (e) Session and security data: session identifiers, token identifiers, IP address, user agent, timestamps, GeoIP location data; (f) Connected applications you authorize; (g) Service usage data: API request logs, error logs, performance metrics. We do not collect or process special category data (GDPR Article 9).

4.Purposes of Processing

We process your Personal Data for the following purposes: (a) providing authentication and account features (contractual necessity); (b) managing passkeys and multi-factor authentication (contractual necessity); (c) maintaining sessions and issuing/verifying access tokens (contractual necessity); (d) protecting the Service from abuse, fraud, and security incidents (legitimate interest); (e) sending password reset emails and MFA verification codes (contractual necessity); (f) complying with legal obligations (legal basis); (g) troubleshooting, monitoring, and improving reliability and performance (legitimate interest); (h) sending service-related communications (legitimate interest).

5.Data Retention

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected: (a) Account data: retained while your account is active, deleted within 30 days of account deletion request; (b) Session and security logs: retained for up to 90 days for security purposes; (c) API logs: retained for up to 30 days for debugging and performance monitoring; (d) Backup data: may be retained for up to 90 days for disaster recovery. After the retention period, data is securely deleted or anonymized.

6.Your Rights under GDPR

Under GDPR, you have the following rights regarding your Personal Data: (a) Right of access (Article 15): request a copy of your Personal Data; (b) Right to rectification (Article 16): request correction of inaccurate data; (c) Right to erasure (Article 17): request deletion of your Personal Data; (d) Right to restriction (Article 18): request restriction of processing; (e) Right to data portability (Article 20): receive your data in a structured, machine-readable format; (f) Right to object (Article 21): object to processing based on legitimate interests; (g) Right to withdraw consent: withdraw consent at any time; (h) Right to lodge a complaint: file a complaint with your local supervisory authority. To exercise these rights, contact us at emilumiq@gmail.com. We will respond within 30 days.

7.Data Sharing

We share your Personal Data only in the following circumstances: (a) Connected applications: when you sign in, Neo ID provides an access token or user information necessary to complete authentication; (b) Infrastructure providers: to host and operate the Service (data processing agreements in place); (c) Legal requirements: to comply with valid legal requests, court orders, or governmental regulations; (d) Security: to protect the rights, property, or safety of Neo ID, our users, or the public. We do not sell, rent, or trade your Personal Data. We do not share your data with third parties for marketing purposes.

8.International Transfers

Your data may be processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place, including: (a) Standard Contractual Clauses (SCCs) approved by the European Commission; (b) adequacy decisions where applicable; (c) other lawful transfer mechanisms under GDPR Chapter V. By using the Service, you acknowledge and consent to such transfers, subject to the safeguards described.

9.Security Measures

We implement appropriate technical and organizational measures to protect your Personal Data, including: (a) password hashing with bcrypt; (b) encrypted tokens and secrets; (c) rate limiting and brute-force protection; (d) WebAuthn/FIDO2 for passkey security; (e) TLS encryption for data in transit; (f) access controls and authentication for administrative access; (g) regular security audits and vulnerability assessments. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10.Cookies and Tracking

We use strictly essential cookies and browser local storage for session and authentication functionality. We do not use marketing, analytics, or tracking cookies. We do not use third-party tracking scripts or pixels. Essential cookies are necessary for the Service to function and do not require consent under ePrivacy Directive.

11.Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on users. Security measures (rate limiting, IP blocking) are designed to protect the Service and do not constitute automated decision-making under GDPR Article 22.

12.Data Protection Officer

We have not appointed a Data Protection Officer as we do not engage in large-scale processing of special categories of data. However, all privacy-related inquiries are handled with the same level of care and responsiveness within the legally required timeframe.

13.Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect Personal Data from children under 16. If we become aware that we have collected data from a child under 16, we will delete it promptly. If you believe we have collected data from a child, please contact us immediately.

14.Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date indicates when changes were last made. Material changes will be notified via email or prominent notice on the Service at least 30 days before they take effect. Your continued use of the Service after changes become effective constitutes acceptance of the updated Policy.

15.Contact and Supervisory Authority

For privacy-related questions, requests, or complaints, contact Neo ID administration at emilumiq@gmail.com. You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights under GDPR have been infringed. This Privacy Policy is subject to our Terms of Service.

Ecosystem

  • Blog
  • API
  • NeoWatch

Community

  • Telegram
  • GitHub

Legal

  • Terms of Service
  • Privacy Policy
© 2024–2026 Neo-Open-Source