Privacy Policy

Last updated: March 30, 2026

NeonAgent ("NeonAgent", "we", "our", "us") provides the NeonAgent website at neonagent.ai, related APIs, and the NeonAgent X Chrome Extension (together, the "Services"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and what rights you have.

This policy is written to be practical and transparent for users, customers, and store reviewers. It should be read together with our Terms of Service and any product notices shown at runtime.

PUBLISHER

Website and Services publisher: NeonAgent

Website: https://neonagent.ai

General contact: contact@neonagent.ai

Privacy contact: privacy@neonagent.ai

If your jurisdiction requires specific legal-entity registration details, we provide them in legal notices and contractual documents.

PERSONAL DATA COLLECTED

A. Account and identity data

  • Internal user and account identifiers
  • Authentication provider identifiers (e.g. Clerk user ID)
  • Email address and profile metadata provided by you or your login provider
  • Account state, subscription status, and plan metadata

B. X (Twitter) account and session data

  • X user ID, username, and connection status
  • X session cookies (auth_token and ct0 token) used to authenticate your account connection with NeonAgent
  • Session cookies are encrypted using AES-256 before storage and are transmitted exclusively over HTTPS
  • Token hashes used for deduplication and account matching without exposing raw credentials
  • Proxy assignment metadata (country, city) used for connection routing
  • Chat PIN (encrypted) used for DM access when you enable DM features
  • Operation mode preference (e.g. Co-pilot) indicating how the agent interacts with your account

C. X engagement and content data

  • Posts created by or through the agent (content, type, timestamps, engagement metrics)
  • Engagement records: replies, quotes, likes performed on tracked account content
  • Engagement recommendations generated by the opportunity engine (target tweet, suggested text, score, user action taken)
  • Tracked account usernames and their public tweet data (content, metrics, timestamps) fetched for engagement scoring
  • User-added tracked accounts (up to 20 per user) including username and status
  • Contact records: usernames of accounts you have engaged with, interaction counts, and DM activity metadata
  • Style profile data derived from your posting history to generate content that matches your voice
  • Content calendar and scheduling data (posting times, timezone preferences)

D. Telegram and Discord connection data

  • Telegram user ID, username, connection status, and presence preference
  • Discord account identifiers and connection metadata
  • Chat/server IDs, channel IDs, and channel filtering configuration
  • Token-related connection data necessary to provide account-operation functionality requested by the user

E. Agent configuration and operational data

  • Agent name, personality, custom rules, instructions, and metadata
  • Strategy configuration: posting ratios, engagement budgets, active hours, DM settings, auto-plug settings
  • Account health score and activity configuration metadata
  • Ghost mode and rate-limit configuration preferences
  • Performance profiles computed from engagement data to optimize posting times and content types

F. Chrome Extension data

  • X session cookies captured from your browser to link your X account (see section B above for handling details)
  • X username detected from the page DOM, stored locally in extension storage for recommendation polling
  • Recommendation accept/dismiss actions sent to our backend to update recommendation status
  • Tweet text read from the X compose box when you use the inline content generation feature
  • Environment preference (production or staging) stored locally to route API calls to the correct backend

G. Technical and security telemetry

  • IP address, user agent, request IDs, and API access logs
  • Error logs, reliability metrics, and operational diagnostics
  • Proxy usage logs (action type, estimated bandwidth) for connection management
  • Audit and security events used to detect misuse and incidents

H. Payment and billing data

  • Plan type, subscription status, billing customer IDs, and invoice metadata
  • Limited processor metadata (for example Stripe references). We do not receive full payment card numbers through processor-hosted checkout flows.

Please do not submit unnecessary sensitive personal data (for example government identifiers, health records, or complete card numbers) in free-text fields.

PURPOSES OF PROCESSING AND LEGAL BASIS

Contractual necessity (service delivery)

  • Create and manage user accounts and sessions
  • Link X, Telegram, and Discord accounts and run configured agents
  • Deliver engagement recommendations and AI-generated content
  • Provide analytics, performance tracking, and account management features
  • Provide customer support and account operations

Legitimate interests

  • Service security, fraud prevention, and abuse detection
  • Reliability monitoring, incident debugging, and performance improvements
  • Recommendation quality improvement based on accept/dismiss patterns
  • Product analytics needed for service quality and operational planning

Consent

  • Non-essential cookies and similar technologies where required by law

Legal obligations

  • Compliance with tax/accounting rules and lawful authority requests
  • Compliance with applicable data-protection laws

SECURITY

NeonAgent implements technical and organizational safeguards appropriate to risk, including:

  • AES-256 encryption for stored session credentials and sensitive tokens
  • HTTPS-only communication between all clients, extensions, and backend services
  • Token hashing for account matching without exposing raw credentials in database queries
  • Access controls and least-privilege principles across infrastructure
  • Environment isolation between staging and production systems
  • Rate limiting controls to prevent excessive usage
  • Monitoring, alerting, and incident response workflows

Security is continuously reviewed and improved, but no system is fully immune to threats. Where a reportable data incident occurs, we notify affected users and authorities as required by law.

YOUR DATA PROTECTION RIGHTS

Depending on your jurisdiction, you may have rights to:

  • Be informed about data collection and use
  • Access personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete personal data (including disconnecting X accounts and removing stored credentials)
  • Restrict processing
  • Object to processing based on legitimate interests
  • Data portability (where applicable)
  • Withdraw consent for consent-based processing
  • Complain to a competent supervisory authority

To exercise rights, email privacy@neonagent.ai. We may request identity verification to prevent unauthorized disclosure or deletion.

We generally respond within timelines required by applicable law. Complex requests may require additional time where legally permitted.

CHILDREN'S PRIVACY

The Services are not directed to children under 13 (or a higher minimum age where required by local law). We do not knowingly collect personal data from children. If you believe a child provided personal data, contact us and we will investigate and take appropriate action.

THIRD-PARTY LINKS AND SERVICES

Our Services integrate with third-party platforms including X (Twitter), Telegram, and Discord. Our extension operates on x.com to provide its functionality. These platforms have their own terms of service and privacy policies. We recommend reviewing those policies. NeonAgent is not responsible for the privacy practices of third-party platforms.

PRIVACY POLICY CHANGES

We may update this Privacy Policy to reflect legal, technical, and product changes. The updated version is effective when published on this page. Material changes may also be communicated through in-product notices or email where required.