At a glance
- We do not sell personal data, and we do not share it for cross-context behavioural advertising.
- We never train shared or general-purpose models on your data. Any custom model we build for you stays yours and is never used to serve another customer. See section 7.
- For the trace data you send us, you are the controller and we are your processor — we act on your instructions, not our own purposes.
- You control how long we keep trace data, and whether it contains personal data at all — our PII redaction option strips it before storage.
- Every third party that touches your data is listed by name in section 8.
01 Who we are and what this covers
Neatlogs Inc. (“Neatlogs”, “we”, “us”, “our”) is a Delaware corporation with its registered office at 16192 Coastal Highway, Lewes, Delaware 19958, United States. We operate the Neatlogs platform — an observability and debugging service for AI agents, which ingests, stores, analyses and presents traces, spans, evaluations and related telemetry from our customers' AI applications.
This Privacy Policy applies to:
- Our website at neatlogs.com and its subdomains, including marketing pages, documentation, and demo-booking forms.
- The Neatlogs platform — the web application, APIs, SDKs, command-line tools, and integrations.
- Our business interactions — sales enquiries, support conversations, events, and recruitment.
It does not apply to third-party services you choose to connect to Neatlogs, or to the model providers you configure with your own API keys. Those are governed by their own privacy policies, as explained in section 6 and section 8.
Use of the platform is also governed by our Terms and Conditions and User Agreement.
02 Our two roles: controller and processor
Under the GDPR, the UK GDPR and comparable laws, the same company can hold different roles for different data. Neatlogs holds two, and the distinction determines who you should contact and whose rules apply.
| Data | Our role | What it means |
|---|---|---|
| Account and website data Your name, work email, company, billing details, support tickets, product usage, site visits. |
Controller | We decide why and how this data is processed. This policy is the complete description, and you exercise your rights directly with us. |
| Customer Content The traces, spans, prompts, completions, evaluations, attachments and metadata your application sends to Neatlogs — including any personal data of your own end users inside it. |
Processor | Our customer decides why and how this data is processed. We act only on that customer's documented instructions, under our Data Processing Addendum. If you are an end user of a customer's application, contact that customer — they are your controller. |
If you are an end user, not a Neatlogs customer
If a company you use has instrumented its AI application with Neatlogs, your data may appear inside their traces. We hold that data on their behalf and cannot lawfully grant access, correction or deletion requests directly. Please contact that company. If you reach us instead, we will tell you so and, where we can identify the customer, forward your request within five business days.
03 Personal data we collect
3.1 Data you give us
- Account data — name, work email address, password credential or federated identity, profile picture, job title, and the organisation and workspaces you belong to.
- Organisation and billing data — company name, billing address, tax identifiers, purchase-order references, and the contact details of your billing and administrative users. Card and bank details are collected and stored by our payment processor, not by us.
- Support and sales data — the content of your messages, demo requests, enquiry forms, meeting notes, and any files you attach.
- Recruitment data — applications, CVs, and interview records where you apply for a role.
3.2 Data we collect automatically
- Authentication and session data — sign-in timestamps, session identifiers, and the identity provider used.
- Product usage data — features opened, actions taken, queries run, errors encountered, page and API latency, and aggregate volumes such as spans ingested and evaluations executed. This drives both product improvement and usage-based billing.
- Device and connection data — IP address, browser and operating system, device type, language, referring URL, and timestamps.
- Security and audit logs — records of access to production systems, administrative actions, API key use, and events relevant to detecting abuse or intrusion.
3.3 Data from third parties
- Identity providers — when you sign in with Google or another federated provider, we receive your name, email address, and profile image from that provider. We do not receive your password.
- Payment processor — subscription status, invoice and payment outcomes, and the last four digits and brand of your card.
- Business contact sources — publicly available professional information and enquiry data used for business-to-business outreach, processed under legitimate interests and always with a clear opt-out.
- Connected integrations — where a user in your workspace authorises an integration, we receive the identifiers and scopes needed to operate it, as described in the User Agreement.
3.4 Sensitive data
We do not seek special-category personal data (such as health, biometric, racial or ethnic, religious, political, or sexual-orientation data), government identifiers, payment card numbers, or children's data. Our platform is not designed or certified as an environment for protected health information, cardholder data, or classified government data, and you must not send such data to Neatlogs unless we have agreed to it in writing under an appropriate addendum. See User Agreement, Prohibited Data.
04 Customer Content and end-user data
Neatlogs is an observability tool, so the content our customers send us is whatever their AI application produced — prompts, model outputs, tool calls, retrieved documents, user messages, and metadata. That content may contain personal data of our customers' end users, and the decision about whether it does rests entirely with the customer.
4.1 You control what reaches us
We give customers direct control over this:
- PII redaction on ingestion. Neatlogs offers a redaction capability that detects and removes personal data from traces as part of the ingestion pipeline, before the content is written to long-term storage. Customers who do not wish to transmit personal data to Neatlogs should enable it.
- Client-side control. Our SDKs let you decide what to attach to a span. The most reliable way to keep personal data out of Neatlogs is not to instrument it in the first place.
- Retention limits. Trace content is deleted automatically at the end of your plan's retention window, as set out in section 10.
4.2 What we do with it
We process Customer Content only to deliver the service to the customer that sent it: ingesting and indexing it, running the queries and evaluations that customer requests, generating the views and alerts they configure, providing support they ask for, and maintaining the security, integrity and availability of the platform. We do not mine Customer Content for our own commercial purposes, disclose it to other customers, or use it to build products for anyone else.
Neatlogs personnel do not access Customer Content routinely. Access is limited to named administrators, requires a documented operational or support reason, is granted on a least-privilege basis, and is logged.
05 Why we process data, and our legal bases
Where the GDPR or UK GDPR applies and we act as controller, we rely on the following legal bases.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and administering your account; providing the platform; authenticating you | Account, authentication, usage | Performance of a contract — Art. 6(1)(b) |
| Billing, invoicing, tax calculation, collections, and financial record-keeping | Organisation, billing, usage-metering | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Providing support and responding to your enquiries | Support, account | Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Securing the platform, detecting and preventing fraud, abuse and intrusion, enforcing our terms | Security logs, device, usage | Legitimate interests in operating a secure service — Art. 6(1)(f) |
| Understanding how the product is used, diagnosing faults, and improving features and performance | Product usage, device | Legitimate interests — Art. 6(1)(f); consent where set by non-essential cookies |
| Business-to-business marketing, event follow-up, and product announcements | Business contact | Consent — Art. 6(1)(a) where required; otherwise legitimate interests — Art. 6(1)(f), with opt-out in every message |
| Meeting legal, regulatory, audit and tax obligations, and responding to lawful requests | As applicable | Legal obligation — Art. 6(1)(c) |
| Corporate transactions, and establishing or defending legal claims | As applicable | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
For Customer Content, Neatlogs does not select a legal basis. Our customer, as controller, determines the purpose and legal basis, and instructs us through the Data Processing Addendum.
06 AI features and model providers
Several Neatlogs features are powered by large language models — AI-assisted debugging, automated evaluation and scoring, summarisation, classification, and suggestions. Using them means sending the relevant Customer Content to a model provider. How that works depends on which mode you choose, and the distinction matters for your own compliance analysis.
6.1 Bring your own key (customer-directed)
You configure a model provider and supply your own API credentials. Neatlogs transmits the content to the provider you named, using your key, under your agreement with that provider. In this mode the provider is not a Neatlogs sub-processor — it is your processor, your contract, and your data-transfer analysis. Neatlogs supports a large number of providers in this mode, including OpenAI, Anthropic, Google, Azure OpenAI, Mistral, DeepSeek, Groq, xAI, Together, Fireworks, Cerebras, and self-hosted or OpenAI-compatible endpoints you operate yourself. Credentials you supply are encrypted at rest and used only to service your own requests.
6.2 Neatlogs-hosted AI (our credits)
If you use Neatlogs-provided AI credits instead of your own key, we route the request through model providers we contract with on your behalf. Those providers are named as sub-processors in section 8. We select providers that contractually commit not to train their models on data submitted through their business APIs, and we pass that commitment through to you.
6.3 Custom models built for you
Neatlogs can build custom classifiers and similar models for an individual customer, trained on that customer's own data, to serve that customer's own use case. Where we do this:
- the model is built for you and used only to serve you;
- it is never made available to, reused for, or blended into any model serving another customer;
- the data used to build it stays within your tenancy for that purpose; and
- it is deleted along with your other data when your agreement ends, unless you ask us in writing to keep it.
Choosing not to use AI features
AI features are optional. If you do not enable them, no Customer Content is sent to any model provider by Neatlogs. Enterprise customers can have AI features disabled at the organisation level.
07 We do not train shared models on your data
This is a commitment, not a preference, and it is repeated in our Terms and Conditions so that it is contractually binding.
Neatlogs does not use Customer Content to train, fine-tune, or improve any model that is used to serve any other customer. That includes general-purpose or foundation models, shared classifiers, shared evaluators, and any model offered as part of the Neatlogs product to our customer base at large. We do not permit our model providers to do so either.
The only models trained on your data are the customer-specific models described in section 6.3 — built for you, used only for you.
Separately, we produce aggregated, de-identified statistics about platform operation — for example total spans ingested per hour, error-rate distributions, median query latency, and feature-adoption counts. These are computed at a level that does not identify any customer, end user, or the content of any trace, and we do not attempt to re-identify them. We use them to run capacity planning, meter usage for billing, and prioritise engineering work.
08 Sharing and sub-processors
We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We do not disclose Customer Content to any party except as set out below.
8.1 Sub-processors
These are the third parties we engage to process personal data on our behalf. Each is bound by a written contract imposing confidentiality and data-protection obligations no less protective than those we owe you.
| Sub-processor | Purpose | Data categories | Primary location |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, compute, object storage, managed databases and networking — the production platform | All Service Data, including Customer Content | United States (us-west-1) |
| Amazon Web Services, Inc. (Amazon Bedrock) | Managed model inference for Neatlogs-hosted AI features | Content submitted to AI features | United States |
| OpenAI, L.L.C. | Model inference for Neatlogs-hosted AI features | Content submitted to AI features | United States |
| Anthropic, PBC | Model inference for Neatlogs-hosted AI features | Content submitted to AI features | United States |
| Confluent, Inc. | Managed event streaming within the trace ingestion pipeline | Customer Content in transit | United States |
| Microsoft Corporation | Machine translation for product features | Text submitted for translation | United States |
| Stripe, Inc. | Payment processing, invoicing, and tax determination | Billing contact and payment data | United States |
| PostHog, Inc. | Product analytics and platform telemetry | Product usage, device, account identifiers | United States |
| Autosend | Transactional and product notification email delivery | Account contact data, message content | United States |
| Google LLC | Business email and collaboration; federated sign-in; website tag management and analytics | Account contact, support correspondence, website usage | United States |
Internal corporate systems that may incidentally hold business-contact or support information — but never Customer Content — include Slack, Notion, Linear, GitHub and Sprinto.
8.2 Changes to our sub-processors
We maintain the authoritative list above and will update it before engaging a new sub-processor that processes Customer Content. Customers with an executed Data Processing Addendum may subscribe to change notifications at privacy@neatlogs.com and will receive at least thirty (30) days' advance notice, with a right to object on reasonable data-protection grounds as set out in the DPA.
8.3 Not sub-processors: integrations you authorise
When a user in your workspace connects a third-party tool — Slack, Discord, Jira, Linear, Notion, Asana, Basecamp, or similar — Neatlogs sends data to that tool at your direction. Those services are your vendors, not our sub-processors, and their handling of the data is governed by your agreement with them. The same applies to model providers you configure with your own API key under section 6.1. You can review and revoke connected integrations at any time in your workspace settings.
8.4 Other disclosures
- Professional advisers — lawyers, accountants, auditors and insurers, under duties of confidentiality.
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and to this policy continuing to apply to the transferred data. We will notify affected customers.
- Legal requirements — where we are compelled by valid legal process, or where disclosure is necessary to protect the rights, property or safety of Neatlogs, our customers, or the public.
8.5 Government and law-enforcement requests
We assess every request for validity and scope, and we narrow or challenge requests that are overbroad or defective. Where a request concerns Customer Content, our position is to redirect the requester to the customer. Where we are legally required to produce data, we will give the affected customer notice before disclosure unless a court order or statute prohibits it, so that the customer has an opportunity to seek protective relief. We publish no volunteered access, and we have not built any mechanism for undisclosed bulk access to customer systems.
09 International data transfers
Neatlogs is a United States company and the platform is hosted in the United States (AWS us-west-1). If you are located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, using Neatlogs involves transferring personal data to the United States.
Our personnel and authorised service providers may also access data from other locations, including India, in order to operate and support the platform. All such access is subject to the same contractual, technical and organisational safeguards described in this policy.
9.1 Transfer mechanisms
- EU/EEA — the European Commission's Standard Contractual Clauses (Decision 2021/914), incorporated into our Data Processing Addendum, with the modules appropriate to each transfer.
- United Kingdom — the UK International Data Transfer Addendum to the SCCs, issued under section 119A of the Data Protection Act 2018.
- Switzerland — the SCCs as adapted for Swiss law, with the Federal Data Protection and Information Commissioner recognised as the competent authority.
9.2 Supplementary measures
Alongside those clauses we apply encryption in transit for all data crossing networks, access control and least-privilege administration, logging of production access, a documented process for assessing and challenging government requests, and a commitment to notify customers of compelled disclosure where law permits. We will carry out and share a transfer impact assessment on request.
10 How long we keep data
We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires.
| Category | Retention |
|---|---|
| Customer Content — traces, spans, evaluations, attachments | Determined by your plan's retention window, after which it is deleted automatically. Current defaults: Free 14 days, Starter 30 days, Pro 90 days (an extended-retention add-on is available), Enterprise as set out in your Order Form. The Pricing page carries the authoritative figures. |
| Account and workspace records | For the life of the account, then deleted within 30 days of account closure. |
| Billing, invoice and tax records | Seven (7) years, as required by US tax and corporate record-keeping rules. |
| Security and audit logs | Twelve (12) months. |
| Support correspondence | Twenty-four (24) months from resolution. |
| Marketing and sales contact data | Until you opt out, or 24 months after the last meaningful interaction, whichever is sooner. |
| Backups | Deleted data persists in encrypted, access-controlled backups until they age out on a rolling cycle not exceeding 35 days. |
| Recruitment data | Twelve (12) months after a decision, unless you consent to a longer period. |
On termination, we retain Customer Content for thirty (30) days so you can export it, then delete it. Customers may request earlier deletion in writing. Where a legal hold or statutory obligation requires longer retention, we isolate the data and delete it once the obligation ends.
11 How we protect data
We operate an information security management system aligned to ISO/IEC 27001:2022, with controls monitored continuously through a dedicated compliance platform. Our principal measures are:
- Encryption in transit — TLS 1.2 or higher on every external endpoint, including ingestion, API and web application traffic.
- Encryption at rest — AES-256 encryption on object storage holding trace archives, attachments and model-invocation logs, and on supported managed data stores. Extending at-rest encryption across all remaining production data stores is an active, tracked programme.
- Access control — least-privilege IAM, multi-factor authentication enforced on all staff accounts through our identity provider, periodic access reviews, and prompt revocation on offboarding.
- Change management — every production code change goes through pull request with mandatory peer review and branch protection enforced on all repositories, including for administrators.
- Segregation — logical separation of customer data by organisation and project, enforced in the application and data layers.
- Monitoring and resilience — continuous control monitoring, infrastructure metrics and alerting, automated database backups, and a documented disaster-recovery plan.
- Vulnerability management — dependency and software-composition scanning on all repositories with defined remediation timelines.
- Vendor risk management — a risk-scored vendor register reviewed periodically, covering every sub-processor listed above.
- People — background checks where lawful, confidentiality obligations, and security and privacy training on hire and periodically thereafter.
11.1 Compliance programme
Neatlogs maintains a SOC 2 (Security and Availability) readiness programme with continuous control monitoring, and an ISMS built to the ISO/IEC 27001:2022 structure. We do not currently hold a completed SOC 2 Type II report or an ISO/IEC 27001 certificate, and we will not claim otherwise. Prospective customers can request our current security documentation, system description, and control status at security@neatlogs.com, and we will state plainly where we stand.
11.2 Incident response
We maintain a documented incident response plan. Where a personal data breach affects Customer Content, we will notify the affected customer without undue delay and in any event within seventy-two (72) hours of becoming aware, with the information the customer needs to meet its own notification duties. Where we are controller, we notify the relevant supervisory authority and affected individuals as the law requires. Report a suspected vulnerability or incident to security@neatlogs.com.
No system is perfectly secure. We do not promise that our measures are impenetrable, only that they are the measures we actually operate and that we will tell you the truth about them.
12 Your privacy rights
Subject to your jurisdiction and to verification of your identity, you may have the right to:
- Access the personal data we hold about you, and receive a copy.
- Correct data that is inaccurate or incomplete.
- Delete your personal data, where we have no overriding basis to keep it.
- Restrict or object to processing, including processing based on legitimate interests and any direct marketing.
- Port your data — receive it in a structured, commonly used, machine-readable format, or have it sent to another controller where technically feasible.
- Withdraw consent at any time, where processing is based on consent.
- Complain to your local supervisory authority. In the EEA that is the authority in your country of residence or work; in the UK it is the Information Commissioner's Office. We would appreciate the chance to address your concern first.
12.1 How to exercise them
Email privacy@neatlogs.com with the request and enough information for us to identify you. We respond within thirty (30) days, and will tell you if we need a permitted extension. We do not charge a fee unless a request is manifestly unfounded or excessive. Much of your account data can also be viewed and edited directly in your workspace settings, and account deletion is available in the application.
If your request concerns data inside a customer's traces, see section 2 — we will direct you to the controller.
13 United States state privacy rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another US state with a comprehensive privacy law, this section supplements the rest of this policy.
13.1 What we collect, in statutory categories
In the twelve months preceding the effective date we have collected: identifiers (name, email, IP address, account ID); commercial information (subscription and transaction records); internet and network activity (product usage, device and log data); professional information (employer, job title); inferences drawn for product-improvement purposes; and, within Customer Content submitted by our business customers, whatever categories those customers choose to send. Sources, purposes and recipients are described in sections 3, 5 and 8.
13.2 Sale and sharing
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding twelve months — and we do not do so now. We do not knowingly sell or share the personal information of anyone under 16.
13.3 Sensitive personal information
We do not collect sensitive personal information for the purpose of inferring characteristics, and we do not use or disclose it beyond the purposes permitted under Cal. Civ. Code § 1798.121.
13.4 Your rights
You may request to know, access, correct, delete, and obtain a portable copy of your personal information; to opt out of any sale, sharing, or targeted advertising (none of which we conduct); and to limit the use of sensitive personal information. You will not be discriminated against for exercising these rights. Requests go to privacy@neatlogs.com. An authorised agent may act for you with written permission and verification. If we deny a request, you may appeal by replying to our decision with the word “appeal”; we will respond within forty-five (45) days with our reasoning, and tell you how to contact your state attorney general if you remain dissatisfied.
13.5 Our role for business customers
Where we process Customer Content for a business customer we act as a service provider or processor. We do not retain, use, or disclose that information for any purpose other than performing the services, and we do not combine it with personal information from other sources except as permitted by law.
14 Cookies and website analytics
On the Neatlogs web application we use strictly necessary cookies to keep you signed in, maintain session state, remember interface preferences, and protect against cross-site request forgery. These cannot be switched off without breaking the service.
On our marketing website we additionally use analytics and tag-management technologies to understand how visitors find and use the site. Where consent is legally required, these are set only after you give it, and you can change or withdraw your choice at any time through the cookie controls on the site. You can also block or delete cookies in your browser, though parts of the application may then stop working.
Because there is still no uniform standard for honouring browser “Do Not Track” signals, we do not currently respond to them. We do honour Global Privacy Control signals as an opt-out of sale and sharing where applicable law requires it — noting that we do not sell or share personal information in any event.
15 Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. The platform runs automated evaluation, classification and scoring against Customer Content, but those outputs are engineering signals for our customers — they are configured by the customer, reviewed by the customer, and are not decisions Neatlogs makes about you.
16 Children
Neatlogs is a business tool intended for organisations and their personnel. It is not directed at children, and you must be at least eighteen (18) years old to create an account. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@neatlogs.com and we will delete it.
17 Data Processing Addendum
Where Neatlogs processes personal data as a processor on a customer's behalf, that processing is governed by our Data Processing Addendum (DPA), which incorporates the Standard Contractual Clauses and the UK Addendum. The DPA covers the subject matter, duration, nature and purpose of processing; the categories of data and data subjects; our obligations of confidentiality and security; sub-processor terms and objection rights; assistance with data subject requests and impact assessments; breach notification; and deletion or return of data on termination.
If there is any conflict between the DPA and this Privacy Policy in respect of Customer Content, the DPA prevails. Request a copy for execution at privacy@neatlogs.com.
18 Changes to this policy
We may update this policy as our product, vendors or legal obligations change. When we do, we revise the version number and effective date at the top and publish the new version here. For changes that materially affect how we handle personal data, we will give at least thirty (30) days' notice by email to account administrators or by prominent in-product notice before the change takes effect. Continuing to use Neatlogs after the effective date means the updated policy applies. Prior versions are available on request.
19 How to contact us
Our Privacy Officer oversees this policy and our data protection programme. We would rather hear from you directly than have you go to a regulator, and we answer every message.
- Entity
- Neatlogs Inc., a Delaware corporation
- Registered office
- 16192 Coastal Highway, Lewes, Delaware 19958, United States
- Privacy matters
- privacy@neatlogs.com — data rights, DPAs, sub-processor notifications
- Security matters
- security@neatlogs.com — vulnerability reports, incidents, security review packs
- Legal notices
- legal@neatlogs.com
- General support
- neatlogs-support@neatlogs.com
Related documents: Terms and Conditions