PRIVACY
Privacy Policy
Last updated: 16 August 2026
In short: Neo-Invest.AI Ltd is in development. If you only use this website, the only personal data we collect is aggregated analytics from our own self-hosted software. We ran a launch list until 16 August 2026; it is closed and its records have been deleted. If you use our mobile app, we also process the portfolio data you choose to import, and section 2 sets out exactly what that means. We never sell your data, and we don’t use tracking cookies.
1. Who we are
Neo-Invest.AI Ltd ("NeoInvest", "we", "us") is a company registered in England and Wales under company number 17358165, with its registered office at 128 City Road, London, EC1V 2NX. We are the data controller for the personal data described in this policy. You can contact us at hello@neo-invest.ai.
Neo-Invest.AI Ltd currently processes personal data only to tell people about the launch of its own product, and on this basis relies on an exemption from the ICO data protection fee. This does not affect our obligations under the UK GDPR, which apply in full and which we follow. That limited basis ends when our mobile app becomes publicly available, and we will complete our ICO registration before that release rather than after it.
2. What we collect
Launch list (closed)
This website ran a launch list until 16 August 2026. It is closed: there is no sign-up form, no new addresses are collected, and the records it held have been deleted. We hold no email address from it.
Website analytics
We use our own self-hosted analytics software running on our servers in the UK. It records aggregated information such as page views, referring site, country and device type, without cookies and without storing your IP address in a form that identifies you. No analytics data is sent to any third party, and we do not use advertising or profiling tools.
Correspondence
If you email us, we keep your message and contact details so we can reply.
NeoInvest mobile app
If you use our mobile app, we process:
- Your email address. It is how you sign in — either we email you a one-time link, or you sign in with Google and Google tells us the address. Either way we never ask for a password, so we never hold one for you at all.
- The investment data you choose to import. When you import a CSV export from your platform, the file's contents — your holdings, the units you hold, what you paid and when — are sent to our servers and stored against your account so the app can show you your portfolio and your costs. We only ever receive a file you pick yourself: the app has no connection to your broker or bank, and cannot read anything you do not hand it.
- Figures you type into the CGT scenario tool. Units, sale proceeds and your total annual income, used to produce the estimate you asked for.
- A profile picture, if you choose to set one. You pick one image from your photo library and it is uploaded to our own servers, where it is stored against your account and served from our own domain. It is not sent to any third party, and it is deleted when your account is deleted. Setting a picture is optional; the app works exactly the same without one.
- An account identifier we create for you, held in the sign-in token the app stores on your device.
What the app does not collect. No advertising identifier. No device identifier. No location. No contacts, camera or microphone access — the app asks for none of these permissions. It does not ask for access to your photo library either: choosing a profile picture uses your device's own picker, which runs outside the app and hands back only the single image you pick, so the app never sees the rest of your library. No usage analytics and no crash reporting: there is no third-party analytics or crash-reporting SDK in the app, so there is nothing in it that could report your behaviour to anyone, including us.
We do not track you across other companies' apps or websites, and we do not share app data with advertisers or data brokers.
On your device. Your sign-in token is held in your device's secure store — the Keychain on iOS, the Keystore-backed store on Android. The app stores nothing else locally.
We do not connect to your bank or your broker, and we never ask for their credentials.
Signing in with Google or Apple
The app offers Sign in with Google and Sign in with Apple as alternatives to the one-time link. Nothing is shared until you confirm it on Google's own screen. When you do, Google gives us:
- Your name and your Google profile picture. The app asks Google for the standard profile information, so both are included in what Google sends. Neither is stored. The app sends Google's signed token to our servers and we read only the address and the identifier out of it — the display name and the picture you see in the app are ones you set yourself, and if you set neither, the app shows neither.
- Your email address. Held against your account. It is how you sign in and how we reach you if we need to.
- Your Google account identifier. The number Google uses for your account. It is a permanent identifier: an email address can change, this cannot, and it is what returns you to your existing account instead of creating a second one. We store it for that reason and no other.
Why we process it. To create your account and sign you in — performance of our contract with you (UK GDPR Article 6(1)(b)).
Who is involved. Google LLC provides the sign-in. The information travels from Google to us, only at the moment you sign in. We send Google nothing about your portfolio, your holdings, or what you do in the app.
How long we keep it. For as long as your account exists. Deleting your account deletes your email address and the Google identifier with it, on the same schedule as everything else in section 6.
Sign in with Apple. Apple sends us your email address and an identifier for your Apple account. Apple sends the address on the first authorisation and may leave it out afterwards, so what identifies a returning account is the identifier, not the address — the same reason we keep the Google one. If you use Apple's private relay address, that relay address is what we hold; we have no way to see the address behind it and do not try to.
A device identifier, from the sign-in SDK. Google's sign-in library declares in its own machine-readable manifest that it collects a device identifier, along with a phone number, coarse location and usage data. Our code asks for none of those and stores none of them — but the library ships inside the app, so the collection is declared for the app. We record it here rather than leave it to the store listing, because a thing that is true of the app you installed belongs in the policy you were pointed at.
Purchases. If a paid plan is bought, it is bought from the App Store or Google Play and the purchase is managed by RevenueCat, which we use to tell the app what you are entitled to. RevenueCat declares that it collects purchase history, that it is not linked to your identity and not used for tracking. We never receive your card details; the store holds the payment method and issues the receipt.
No crash reporting, no analytics SDK in the app. The app ships no diagnostics tool: no crash reporter, no performance monitoring, no third-party analytics. If a crash happens we do not see it — which is a real cost, and the reason crash reporting is planned for a later release. When it arrives, this policy says so before it ships, because adding it adds a kind of data we do not collect today.
Taking it back. You can remove this app's access at any time from your Google Account, under the page listing your connections to third-party apps. That stops any future sign-in. It does not delete what we already hold — to do that, delete your account in the app or email us.
3. Why we process it, and our lawful basis
- To operate the app and show you your own portfolio — performance of our contract with you (UK GDPR Article 6(1)(b)).
- To operate and secure the website — legitimate interests (Article 6(1)(f)) in running a functional, secure service.
- To respond to your enquiries — legitimate interests in communicating with people who contact us.
4. Who we share it with
We share personal data only with service providers who process it on our behalf under written agreements: our email delivery provider and our hosting provider (Amazon Web Services, London region). Our analytics run on our own servers, so no analytics data is shared with anyone. We do not sell, rent or trade personal data, and we do not share it with advertisers. Signing in with Google runs the other way round: Google LLC gives us the information described above, and we send Google nothing about you or your portfolio. Payments run the same way: the store takes the payment and holds the payment method, RevenueCat tells the app what was bought, and no payment data of yours is held by us. Terms section 6 says the same thing from the other side.
5. Where your data is stored
Your data is stored on servers located in the United Kingdom (AWS London region). If any provider processes data outside the UK, we ensure appropriate safeguards such as UK International Data Transfer Agreements are in place.
6. How long we keep it
The launch list is closed and its records have been deleted, so there is nothing left of it to keep. Correspondence is kept for up to 24 months.
App data. Deleting your account deletes the data that belongs to it — the accounts, holdings and lots imported from your CSV, your profile picture, your email address and — if you signed in with Google — the Google account identifier, go at the same time, not on a later cycle. Copies held in our encrypted backups fall out within 30 days.
7. Your rights
Under UK data protection law you have the right to access your data; to have inaccurate data corrected; to have your data erased; to restrict or object to processing; to data portability; and to withdraw consent at any time. To exercise any of these, email hello@neo-invest.ai. We will respond within one month.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk. We would appreciate the chance to address your concerns first.
8. Complaints about how we handle your data
If you are unhappy with how we have handled your personal data, you can complain to us directly. Email hello@neo-invest.ai with "Data protection complaint" in the subject line, or write to us at Neo-Invest.AI Ltd, 128 City Road, London, EC1V 2NX.
We will acknowledge receipt of your complaint within 30 days, investigate it, and tell you the outcome and the reasons for it. If we need longer to complete the investigation, we will explain why and keep you updated.
Complaining to us first does not affect your right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk — but we would appreciate the opportunity to put things right ourselves.
9. Security
We use encryption in transit, access controls, and regular backups. No system is perfectly secure, but we take our obligations seriously and will notify you and the ICO of any qualifying personal data breach as required by law.
10. Children
Our website is not intended for anyone under 18, and we do not knowingly collect data from children.
11. Changes to this policy
We will update this page when our processing changes and revise the "last updated" date. Material changes affecting your rights will be notified by email where we hold your address.