Privacy Policy
Last updated: 18 August 2026
1. Who we are (Data Controller)
NeoInvests, operated by Harald Federspiel. Full postal address in our imprint. For any privacy question, contact us at neo@neoinvests.com.
2. What we collect and why
Your account. To create an account we store your email address, the authentication data needed to sign you in, your Neo profile and preferences (including language and theme), your plan and role, and account timestamps. We use this to run the service and to enforce plan allowances.
Portfolio and watchlist. Holdings you type in or import (name, ticker, asset type, amount or value, currency, units, entry mode) and the symbols or themes you keep on your watchlist. We use this to produce your briefings, briefs and answers.
Conversations and skill results. Your Ask Neo questions and Neo's answers, Portfolio Briefs, Market Briefs, Discover & Track results, your saved history and the memory entries you let Neo keep. We use this to generate the output and to show it to you again in your history.
Hype Check inputs. The claim text, links and public source URLs you submit, uploaded screenshots or images, uploaded or linked audio and video, the transcript Neo produces from that media, selected video frames, and the resulting check. If you follow a claim, we also store the follow, the claim snapshot and later claim updates. We use this to run the check, to re-check followed claims when qualifying new evidence arrives, and to keep the result in your history.
Social video links. When you paste a public TikTok, Instagram, YouTube, X or Facebook link into Hype Check, Neo receives the public link you submitted so it can read the spoken words in the video. Neo does not store the source video itself. The extracted transcript may be cached for up to 30 days so the same link is not processed again. The transcript is currently produced by our processor Supadata, see section 4.
Notifications. Your notification preferences, the alerts you configure and a record of deliveries we send you, so a given update is not sent twice and so you can see what was sent.
Billing records. If you buy a one-off Portfolio Brief or Neo Premium, we store your subscription or purchase state, plan, period dates, and the identifiers our payment provider gives us. We never store full card numbers.
Contact form. If you write to us through the contact form we store your name, email address, message and preferred language. We use this only to reply to you.
Technical data. Our hosting provider may process your IP address and browser user-agent in standard server logs for security and abuse prevention.
3. Legal basis (GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)): to run your account, the Neo skills you use, notifications you enable, and any paid plan.
- Consent (Art. 6(1)(a)): for the contact form and for optional features you switch on, such as Neo memory or email notifications. You can withdraw consent at any time.
- Legitimate interest (Art. 6(1)(f)): for basic security logging, abuse prevention and allowance enforcement.
- Legal obligation (Art. 6(1)(c)): for records we must keep, such as invoicing records.
4. Who processes data on our behalf
We use a small number of vetted processors to run the service:
- Lovable Cloud (managed database and hosting, EU region): stores your account data and runs server logic.
- AI model providers: OpenAI GPT models process what you submit to Neo (your questions, your portfolio context, claims, images and media for Hype Check), including speech to text and text to speech. OpenAI is the primary provider for AI tasks. As a bounded temporary fallback, and only for Ask Neo, Portfolio Brief and the final Hype Check analysis, a request can be routed through the Lovable AI Gateway to a Google Gemini model so the feature stays available. Gemini is not used for routine task routing. Perplexity is used for current research. Where contractually agreed with these providers, your inputs are not used to train their models. If we change the model mix, this page is updated.
- Supadata (video transcript processing): when you submit a public social video link to Hype Check, Supadata receives that link, reads the spoken words in the video and returns the transcript to us. Supadata does not receive your account identity, and the source video is not stored by us. The resulting transcript may be cached for up to 30 days.
- Google (Sign in with Google): if you choose Google sign-in, Google processes the sign-in itself and confirms your email address and account identifier to us. We do not receive your Google password.
- Market data, filings and news providers: receive the symbols or companies a request is about, in order to return quotes, filings, events and news. They do not receive your account identity.
- Payment provider: when you buy a paid plan, a regulated payment provider processes your billing details (name, email, payment instrument, transaction metadata) on our behalf. We never store full card numbers ourselves.
- Email delivery provider: used to send notifications to us and updates to you.
- CDN / hosting: serves the website.
All processors are bound by data-processing agreements and process data inside the EU/EEA where possible. Some AI model providers and payment providers may process data outside the EEA under EU Standard Contractual Clauses.
5. Connected AI assistants (MCP)
You can connect NeoInvests to a third-party AI assistant through our MCP interface. This connection is optional and never happens automatically: you have to connect NeoInvests explicitly through OAuth and grant access. Neo then receives only the declared arguments of the tool that is invoked, not your unrelated conversation inside the connected assistant.
Exactly three capabilities exist today:
- list_holdings (read-only): returns the name, ticker, asset type, amount or value, currency, units, and entry mode of the holdings you keep in NeoInvests.
- list_hype_checks (read-only): returns the claim, verdict, language, and creation time of your recent Hype Checks, so they can be listed in order.
- run_hype_check (state-changing): receives the claim text, an optional public source URL, and the output language. Running it consumes one Hype Check from your allowance and saves the result to your normal Hype Check history.
Tool results are returned to the connected assistant and may then be processed by that host provider under its own privacy policy. The MCP interface currently does not accept screenshot, image, audio, or video files.
Hype Checks created through a connected assistant follow the same account-history handling as Hype Checks created in Neo. Your holdings and your account-linked Hype Check history stay available while your account is active. Permanent account deletion is available in Settings, Account: your account record and your holdings are removed, while saved Hype Check assessment rows may remain after the link to you is removed.
You can disconnect the integration at any time in the connected assistant. Disconnecting stops any future access, but it does not delete results that were already returned to the connected assistant, and it does not delete Hype Checks that were already saved in Neo.
6. How long we keep data
- Account data: while your account exists. Deleting your account removes it, see section 7.
- Contact messages: up to 24 months after our last exchange.
- Server logs: typically 30 days.
- Billing records: for the statutory retention period that applies to accounting records.
7. Deleting your account
You can delete your account at any time in Settings, Account. Deletion is permanent and cannot be undone.
Removed with your account: your login record and email address, your Neo profile and preferences, your holdings, your watchlist, your conversations and chat history, your memory entries, your notification preferences and alerts, your claim follows and their updates, and your subscription record in Neo.
Kept without the link to you: saved Hype Check rows, Portfolio Brief rows and Ask Neo usage counters are separated from your account instead of being deleted, so no user is attached to them any more. We keep them in this de-identified form for abuse prevention and product quality. Records our payment provider must keep for accounting and tax purposes stay with that provider under its own retention obligations.
If you want de-identified content removed as well, or you want a copy of your data before deleting, email neo@neoinvests.com.
8. Your rights
Under GDPR you have the right to access, rectify, erase, restrict, port your data, and object to processing, as well as to withdraw consent at any time. To exercise any of these rights, email neo@neoinvests.com. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at).
9. Cookies and tracking
We use only strictly necessary cookies required to run the website. We do not run third-party advertising or behavioural tracking. If we ever add analytics, this page will be updated and a consent banner will be shown first.
10. No automated decision-making
We do not make any decision that has a legal or similarly significant effect on you based solely on automated processing.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the latest version.