N
Neouid
Back to Neouid
Last updated: September 3, 2026

Privacy Policy

This Privacy Policy explains how Neouid, based at Lipik bb, Bosanska Krupa, 77240, Bosnia & Herzegovina, collects, uses, shares, and protects information when you use our website, mobile applications, and API (together, the "Service"). It should be read together with our Terms of Service.

On this page

1. Who We Are2. Information We Collect3. How We Use Your Information4. Legal Bases for Processing5. How We Share Information6. Law Enforcement & Legal Process7. International Data Transfers8. Data Retention9. Your Rights10. Children's Privacy11. Cookies12. Paddle Notice13. Security14. Changes to This Policy15. Contact

1. Who We Are

Neouid ("we," "us") is the data controller for personal data processed through the Service, except where stated otherwise (such as Paddle acting as an independent controller for payment data as our Merchant of Record — see Section 12). Our contact details are in Section 15.

EU representativeAs required by GDPR Article 27 and the EU Digital Services Act Article 13, Neouid has appointed an EU representative: [name and contact details of appointed EU representative].

2. Information We Collect

Account & profile data

Email address, username, password (hashed), avatar, profile information you choose to add, and Google account identifiers if you sign in with Google.

Security data

Two-factor authentication status, login history, and IP address and session data for each login and active session, used for account security and fraud prevention.

Usage & platform data

Bank memberships, roles, transaction history within a Bank's virtual currency, vouchers, orders, support-ticket content, and content you upload (images, banners, product listings, and digital product files offered for sale). Digital product files are stored on our infrastructure and released only to Members who have purchased the corresponding product.

Payment data

We do not store your full payment card details. Subscription billing is handled by Paddle.com, our Merchant of Record, which shares limited transaction metadata (such as subscription status and plan) with us.

API & integration data

API request logs (for rate limiting and abuse prevention), and data exchanged if you connect the Discord or Slack bot integrations.

Cookies

Essential cookies for authentication and session management, security cookies (such as reCAPTCHA), and — with your consent — analytics cookies from Google Analytics. See Section 11.

3. How We Use Your Information

  • To provide, maintain, and secure the Service, including authentication and 2FA;
  • To detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service;
  • To process subscription payments and manage billing;
  • To send account, security, and service-related notifications;
  • To respond to support requests;
  • To comply with legal obligations; and
  • To improve and develop the Service.

4. Legal Bases for Processing

Where GDPR or the Bosnia & Herzegovina Law on Personal Data Protection applies, we rely on the following legal bases: performance of a contract (to provide the Service you signed up for); legitimate interests (for security, fraud prevention, and IP/session logging — see our assessment available on request); legal obligation (for tax, accounting, and law-enforcement compliance); and consent (for optional communications, where applicable).

5. How We Share Information

We share information with service providers who process it on our behalf, including: our database and hosting infrastructure, Cloudflare (file storage for uploaded images and digital product files), Paddle.com (payments), Google (OAuth sign-in and reCAPTCHA), Resend (transactional email), and, if you enable them, Discord and Slack (bot integrations). We do not sell your personal data.

We may also share information in connection with a merger, acquisition, or sale of assets, and as described in Section 6.

6. Law Enforcement & Legal Process

We may disclose your information, including IP address and session/login history, to law enforcement or government authorities where we are required to do so by valid and enforceable legal process (such as a subpoena, court order, or warrant), or where necessary to prevent imminent harm to any person, to investigate suspected violations of our Terms, or to protect the rights, property, or safety of Neouid, our users, or the public.

Where legally permitted and where doing so would not compromise an investigation or risk harm, we will make reasonable efforts to notify affected users before disclosing their data in response to legal process. We will not always be able to provide such notice — for example, where we are prohibited by law, or in emergency circumstances.

7. International Data Transfers

As a company based in Bosnia & Herzegovina, some of your data may be transferred to and processed in other countries, including the countries where our service providers operate. Where such transfers occur between the EU/EEA and Bosnia & Herzegovina (for which no adequacy decision currently exists), we rely on appropriate safeguards such as Standard Contractual Clauses.

8. Data Retention

We retain account data for as long as your account is active. IP address and session logs are retained for 90 days for security purposes, after which they are automatically and permanently deleted, unless a longer period is required by law or an ongoing investigation. When you delete your account, we anonymize or delete your personal data as described in our account-deletion process, except where retention is required for legal, tax, or security purposes.

9. Your Rights

Subject to applicable law, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data; request a portable copy of your data; object to or restrict certain processing; and lodge a complaint with a data protection authority, including Bosnia & Herzegovina's Personal Data Protection Agency or, if you are in the EU/EEA, your local supervisory authority.

You can exercise most of these rights directly from Account Settings → Privacy, where you can export or delete your data at any time. For anything else, contact us using the details in Section 15.

10. Children's Privacy

Neouid is not directed at children and our minimum age is 16 (see our Terms of Service, Section 2). We do not knowingly collect personal data from anyone below this age. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Cookies

We use essential cookies required for you to log in and use the Service, and security cookies (such as Google reCAPTCHA) to prevent abuse. With your consent, we also use Google Analytics to understand site usage; this is not loaded until you accept it via our cookie banner. See our Cookie Policy for details.

12. Paddle Notice

Paddle.com Market Limited ("Paddle") is our Merchant of Record and an independent data controller for the payment data it processes when you subscribe to a paid plan. Please review Paddle's Privacy Statement for details on how Paddle collects and uses your data.

13. Security

We use industry-standard measures to protect your data, including encrypted connections, hashed passwords, and optional two-factor authentication. No system is completely secure, and we cannot guarantee absolute security.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email before they take effect.

15. Contact

For privacy questions or to exercise your rights, contact us at [privacy@neouid.com] or Neouid, Lipik bb, Bosanska Krupa, 77240, Bosnia & Herzegovina.