← Back to NeoCEO

Privacy Policy

Last updated: October 4, 2026

This policy describes what data NeoCEO ("the Service") collects, how it is used, and how it is protected. The Service is operated by ELERMOND STUDIO SRL ("we", "the company"). For any privacy question, write to privacy@neoceo.me.

1. What NeoCEO is

NeoCEO is a conversational executive assistant, accessible via Telegram and a web dashboard, that helps the user manage email, calendar, tasks, reminders and a simple CRM pipeline from natural-language requests.

2. What data we collect

2.1 Account data

Email address, display name and profile photo, obtained via Google sign-in, plus the internal Google account identifier (sub).

2.2 Messaging and conversation data

Messages sent to the assistant (via Telegram or the dashboard) and the generated replies, kept to maintain conversation history and allow continuing a discussion. The link between your Telegram account and your NeoCEO account is made via a temporary linking code.

2.3 Email and calendar data (if you choose to connect Gmail)

If you authorize Gmail access, we use the following Google permissions, strictly for the features you activate — reading and sending email, organizing calendar events, and reading contacts and Drive files when a request of yours requires it:

Permission (scope)Used for
gmail.sendSending emails, always with your explicit confirmation before sending
gmail.modifyReading messages to answer requests ("summarize today's emails"), archiving, marking as read, moving to another folder
contacts.readonlyRecipient suggestions when composing an email
calendar.eventsCreating and reading calendar events
drive.readonlyReading files on request (e.g. relevant attachments)

NeoCEO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use data from Gmail/Calendar/Drive/Contacts for advertising, we do not sell it, and we do not share it with third parties beyond what's strictly necessary to deliver the functionality you requested (see section 4). Data received from Google Workspace APIs is never used to develop, improve or train generalized AI/ML models.

2.4 Email accounts connected via IMAP/SMTP

If you connect another (non-Gmail) email account, we store the server host, port and credentials required for the connection. The password/token is encrypted in the database before being saved and is never kept in plain text beyond the strict duration of the connection request.

2.5 Telegram

If you use the Telegram bot, we receive the conversation identifier (chat ID) and the content of messages sent to the bot, needed to reply and to deliver reminders.

2.6 Technical data

Session cookies (required for authentication, not marketing/tracking) and, in case of an error, technical reports sent to our error-monitoring provider (Sentry) — see section 4.

2.7 ChatGPT and other connected AI apps (MCP)

If you connect NeoCEO to ChatGPT (or another app that uses the Model Context Protocol), you approve it on a NeoCEO consent screen. When you ask it to, that app can then read your NeoCEO tasks, calendar events, CRM contacts and deals, and the email NeoCEO has indexed (sender, subject, date, a short excerpt, and the text of a message you ask about), and it can draft reminders that are saved only after you confirm. It cannot send email or delete anything. Reminders are delivered only to you, never to other people. What it reads is sent to that app's provider (for ChatGPT: OpenAI) inside your conversation and is then governed by that provider's own privacy policy. NeoCEO stores only what the connection needs: the app's registration (name and redirect address), hashed access and refresh tokens, and when the connection was created and last used.

3. How we use the data

We do not use the content of your conversations to train our own models and we do not sell it to third parties.

4. Who we share data with

We do not sell your data. We only share it with the providers strictly necessary for the Service to function, each acting as a data processor on our behalf:

5. How long we keep the data

We keep account data and conversation history for as long as the account is active. You can request deletion of your account and associated data at any time, at privacy@neoceo.me. Google access tokens can be revoked at any time directly from your Google account settings.

Connections to ChatGPT or other connected apps: access tokens expire after one hour and refresh tokens after 30 days. You can revoke an app's access at any time in NeoCEO under Settings → Connected apps, with immediate effect; changing your password also revokes every connected app. Records of revoked or expired tokens stay stored in hashed, unusable form until your account is deleted. Removing the app in ChatGPT stops new requests, but data already shared in a ChatGPT conversation remains under OpenAI's control.

6. Security

Each account is isolated at the database level. Email credentials connected via IMAP/SMTP are encrypted at rest. Communication with the Service happens exclusively over HTTPS. Internal access is restricted and audited.

7. Your rights (GDPR and the Republic of Moldova's data protection legislation)

No matter where you are, you have the right to:

You can exercise these rights by writing to privacy@neoceo.me.

8. Children

The Service is not intended for individuals under 16 and we do not knowingly collect data from them.

9. Changes to this policy

We may update this policy periodically. Significant changes will be communicated via the Service or by email.

10. Contact

ELERMOND STUDIO SRL — privacy@neoceo.me