NEUTAUR · Privacy Policy
Privacy Policy
Last updated: August 4, 2026
1. Information We Collect
- Email address (account identification + notifications)
- Google OAuth sign-up: name, profile image, Google account identifier (sub claim)
- Subscription billing: Stripe-tokenized payment information (raw card data is never stored on NEUTAUR servers)
- Marketing analytics (collected at signup, server-side): IP address, User-Agent string, HTTP referrer URL, UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content), first-seen timestamp, cumulative login count. Used solely to measure marketing channel attribution, fraud signals, and product engagement cohorts. Lawful basis: GDPR Article 6(1)(f) legitimate interest, CCPA service personalization, Korean PIPA Article 15(1)(4) marketing analysis.
- Product-behavior analytics (first-party, collected as you use the app): pages viewed, industries and companies (tickers) you open, searches you run, watchlist additions and removals, and checkout steps — together with a random device identifier stored in your browser, a session identifier, approximate device and viewport, and the UTM parameters above. For signed-in members these events are associated with your account (the association is made server-side from your authenticated session; the identifier on its own is anonymous). We do not capture what you type beyond the search terms you submit. Lawful basis: GDPR Article 6(1)(f) legitimate interest (product measurement and improvement). You can opt out at any time — see Section 5.
- Advertising conversion measurement (only if you arrive from one of our ads): when you land on NEUTAUR and when you complete signup, we send Meta Platforms a page-view and a registration event. What is sent: the page address, your IP address and User-Agent, Meta’s own advertising cookies (
_fbp,_fbc), and — from our server only — an irreversible SHA-256 hash of your email address and account identifier so Meta can match the signup to the ad you clicked. We never send your email address, name, or any other identifier in readable form, and we never send anything about which industries, companies, or watchlist items you view. Lawful basis: GDPR Article 6(1)(f) legitimate interest (advertising effectiveness measurement). You can turn this off entirely — see Section 5. - Service usage logs: sign-up timestamp, slot usage history, subscription lifecycle events
2. How We Use Your Information
- Account identification and service delivery (dashboard, slots, notifications)
- Subscription billing and refund processing (Stripe-compliant)
- Service quality improvement and fraud prevention
- Marketing channel attribution and product analytics — measuring which acquisition channels deliver engaged users, evaluating onboarding funnel conversion, and improving creative/copy decisions. We never sell your personal information. The only data we share with an advertising network is the conversion measurement described in Section 1 (page view and signup, sent to Meta Platforms), and only when advertising measurement is enabled and you have not opted out. Your product-behavior data — the industries, companies, searches, and watchlist items you open — is never shared with any advertising network.
- Legal obligation compliance (tax reporting, dispute resolution)
3. Data Retention
Account data is deleted immediately upon withdrawal request. Payment records are retained separately per US IRS 7-year retention obligation and Korean e-Commerce Act 5-year retention obligation. Service usage logs are automatically anonymized after 6 months.
4. Third-Party Service Providers
- Supabase — Authentication + database hosting (us-east-1)
- Vercel — Web hosting (us-east-1)
- Stripe — Payment processing (PCI-DSS Level 1)
- Google OAuth — Social login provider
- DigitalOcean — Backend infrastructure (NYC1)
- Meta Platforms — Advertising conversion measurement (Meta Pixel and Conversions API). Receives only the events described in Section 1, with email and account identifier hashed. Active only while we are running advertising campaigns.
5. Cookies and Tracking Technology
We use essential cookies for session management and Supabase Auth token storage. We also persist non-sensitive attribution cookies for up to 30 days (SameSite=Lax, JavaScript-readable) that record UTM parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and the first-seen timestamp captured at your first visit. These cookies are read once at signup to record acquisition channel attribution and are not themselves shared with advertising networks.
Advertising cookies. While an advertising campaign is running we load the Meta Pixel, which sets Meta’s own cookies (_fbp, and _fbc if you arrived from a Meta ad) in your browser and reports the two events described in Section 1. We also set a short-lived first-party cookie (nt_fb_reg, 10 minutes) that carries only a random event identifier used to keep the browser-side and server-side report of the same signup from being counted twice; it contains no personal information. The same opt-out described below turns the Meta Pixel and the server-side reporting off together.
For product-behavior analytics we store a random first-party identifier in your browser’s local storage (key neutaur_anon) plus a per-session identifier. These are first-party only and are never shared with third-party advertising networks. You can opt out at any time: choose “Opt out” on the privacy notice shown on your first visit, or enable your browser’s “Do Not Track” or Global Privacy Control signal — either one turns product-behavior analytics off entirely, prevents the identifier from being created, and also stops the advertising conversion measurement described above, in the browser and on our server alike.
6. Your Rights
You may request access, correction, deletion, or processing restriction of your personal information by contacting us at the address below. We will respond within 48 hours.
7. Contact
Email: help@neutaur.com
Operating Entities: Neutaur, Inc. (Delaware, USA) / Efdent Corp. (KR, Business Registration No. 745-81-03017)