← Back to home

Legal

Privacy Policy

Effective date: September 5, 2026

This Privacy Policy describes how NeroEngine (“we,” “us,” or “our”) collects, uses, and shares information when you visit our website or use our platform. By using NeroEngine, you agree to the practices described in this policy.

1. Information We Collect

Account information. When you register, we collect your name, email address, company name, and password (stored as a hashed value). We never store your password in plaintext.

Business data. Information you enter into the platform — contacts, deals, proposals, quotes, and notes — is stored in our database and associated with your organization.

AI API keys. If you add an API key for OpenAI, Anthropic, or another provider, it is encrypted at rest using AES-128 symmetric encryption. The plaintext key is only held in memory during an active AI request.

Usage and analytics data. We use Google Analytics to understand how visitors interact with our marketing website (neroengine.io). Google Analytics collects information such as pages visited, time on page, general geographic region, browser type, and device type. This data is associated with a cookie and processed by Google. The analytics tag is not loaded inside the authenticated application, so your activity within the product — the records you open, the pages you work on — is never sent to Google.

Connected Google account data. If you connect Google Search Console or Google Analytics in the SEO section, we retrieve performance data for the properties you authorise — search queries, page URLs, impressions, clicks, positions, sessions, traffic sources, and campaign cost and conversion figures — and store it so the dashboards and reports can show change over time. We receive this under your own Google OAuth credentials, and the refresh token authorising it is encrypted at rest. You can disconnect at any time, which revokes our access.

Integration credentials. Tokens and secrets for the integrations you enable — Slack, Microsoft SSO, Google — are encrypted at rest and used only to operate the integration you configured.

Account security data. We record the time of your last sign-in and whether your email address has been confirmed. To rate limit sign-in attempts and password resets, we temporarily hold a counter keyed to your network address and email address; these counters expire automatically within an hour and are not used for any other purpose.

Waitlist information. If you join our waitlist, we collect your email address and the plan tier you selected.

Communications. If you contact us by email, we retain that correspondence.

2. How We Use Your Information

  • To provide, operate, and improve the NeroEngine platform.
  • To send transactional emails — account creation, password resets, team invitations, and waitlist confirmations.
  • To understand how our marketing website is used and improve it (via Google Analytics).
  • To respond to your support requests and communications.
  • To enforce our Terms of Service and detect abuse.

3. Google Analytics and Cookies

Our marketing website uses Google Analytics, a web analytics service provided by Google LLC. Google Analytics uses cookies — small text files stored in your browser — to collect standard internet log information and visitor behavior data. This information is transmitted to and stored by Google on servers in the United States.

Google may use this data in accordance with its own Privacy Policy. We have enabled IP anonymization, meaning your full IP address is not stored by Google.

Opting out. You can prevent Google Analytics from collecting your data by installing the Google Analytics Opt-out Browser Add-on. You can also manage cookies through your browser settings.

4. How We Share Your Information

We do not sell your personal data. We share information only in the following limited circumstances:

  • AI Providers. When you use AI features, input data is sent to your configured AI provider (OpenAI, Anthropic, etc.) to fulfill the request. This is governed by that provider's terms and privacy policy.
  • Google Analytics. Usage data from our marketing website is shared with Google as described in Section 3.
  • Email delivery. We use Resend to send transactional emails. Your email address is shared with Resend solely for delivery purposes.
  • Payments. Subscription billing is handled by Stripe. We share the billing contact and subscription details needed to process payment. Card details are entered directly with Stripe and never reach our servers.
  • Integrations you enable. Where you connect a third-party service, data moves between NeroEngine and that service to make the integration work: Google (Search Console and Analytics performance data for your properties), Slack (the messages and reactions in the channels you configure for lead capture), and Microsoft (authentication, if you enable single sign-on). None of these are enabled unless you turn them on.
  • Hosting and infrastructure. The platform runs on servers we operate at a third-party hosting provider. Data is stored there in encrypted transit and at rest on the underlying volumes.
  • Legal requirements. We may disclose information if required by law, court order, or to protect the rights and safety of NeroEngine or others.

5. Data Retention

We retain your account and business data for as long as your account is active. To close an account and have its data deleted, email support@neroengine.io — we will delete it within 30 days, except where we are required to retain records for legal or compliance purposes. Waitlist emails are retained until you request removal.

Data retrieved from a connected Google property is deleted when you disconnect the integration. Rate-limiting counters expire automatically within an hour. Password reset and email confirmation links are stored only as a one-way hash and are removed once used or expired.

6. Your Rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data. To exercise these rights, contact us at support@neroengine.io. We will respond within 30 days.

If you are in California, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request deletion. We do not sell personal information as defined by CCPA.

7. Security

We use industry-standard measures to protect your data. Connections are encrypted in transit (TLS, with HTTP Strict Transport Security), passwords are stored only as bcrypt hashes, and credentials such as API keys and integration tokens are encrypted at rest. Each organization's data is isolated at the database query level so it cannot be reached from another account.

Sign-in requires a confirmed email address and is rate limited against repeated attempts. Changing or resetting your password ends sessions on every other device. Password reset and confirmation links are single-use, time-limited, and stored only as hashes.

We carry out internal reviews of the platform's security and remediate what they identify. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Children

NeroEngine is not directed at children under 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. The effective date at the top of this page reflects the date of the most recent revision. Continued use of NeroEngine after a revision constitutes acceptance of the updated policy.

10. Contact

If you have questions or concerns about this Privacy Policy or how we handle your data, contact us at support@neroengine.io.