Privacy Policy.
Last updated: August 12, 2026. This is the legal document; the private architecture page is the technical one, written for people who want the mechanism, not the clauses.
Neeos is a private, personal assistant application. It reads the documents, notes, and health history you give it, and answers from them. This policy explains what data Neeos collects, how it is used, how it is stored and protected, and the choices you have. Neeos does not sell your data, and does not use it to train any model.
1. Who operates Neeos
Neeos is operated by its developer as a personal software project (the “Service”, “we”, “us”). If you have any question about this policy or your data, contact us at jake@neeos.ai.
2. Information we collect
Neeos only collects data you explicitly connect or provide:
- Documents, notes, and messages — anything you upload, write, or drag into your vault, plus the questions you ask and the conversations you have with Neeos. This is the material Neeos indexes so it can answer from it.
- Facts you confirm about yourself — the entries on the “You” screen inside the app, which you can read, edit, or delete at any time.
- WHOOP data — when you connect your WHOOP account, Neeos accesses the data you authorize through WHOOP’s official API. Depending on the permissions you grant, this may include your profile and basic body measurements, recovery scores, heart-rate variability (HRV) and resting heart rate, sleep (duration, stages, and performance), physiological cycles, and workouts/activities.
- Oura data — when you connect your Oura account, Neeos accesses the data you authorize through Oura’s official Cloud API. Depending on the permissions you grant, this may include your personal profile, daily sleep and sleep stages, readiness scores, heart-rate variability (HRV) and resting heart rate, daily activity (such as steps and active calories), and workouts.
- Apple Health data — when you grant permission on your device, Neeos reads health and fitness metrics from Apple Health, such as workouts and runs, body weight, sleep, resting heart rate, and HRV.
- Photos you choose to share — when you attach a photo to a chat message from your photo library, the image is uploaded so Neeos can read and respond to it. Neeos does not access your photo library on its own; only the specific images you pick.
- Voice — what you say, and what Neeos says back — when you dictate a message or hold a spoken conversation, the recording is sent to our server and on to the provider that turns it into text; the reply Neeos speaks is sent out as text to be turned into audio. Neeos does not listen unless you start a dictation or a call, and recordings are not kept after the words come back — what is stored is the message, in your sealed transcript, exactly as if you had typed it. This is the one part of Neeos that is not sealed on your device before it leaves. Everything else — your notes, your documents, your chats — is encrypted with a key only your devices hold. Speech cannot be: a recording nobody can open cannot be turned into words. We say so here rather than let “encrypted” imply something it does not cover.
- Account & technical data — the credentials and tokens needed to authenticate you and to keep your connected services linked, plus minimal operational logs needed to run the Service securely.
3. How we use your information
Your data is used solely to provide the Service to you:
- To index your documents, notes, and messages by meaning, so Neeos can answer questions from them with sources attached.
- To display your health trends and history, and to keep goals and tasks up to date.
- To keep connected accounts (such as WHOOP, Oura, and Apple Health) in sync.
- To operate, secure, and troubleshoot the Service.
Neeos does not use your documents, notes, or health data for advertising, and does not sell it or share it with data brokers.
4. How we store and protect your data
Your data is stored in a private, access-controlled backend. Data is encrypted in transit (TLS) and at rest with a customer-managed key. Access credentials and API tokens are held in a dedicated secrets store and are never exposed in the client app. Access to the Service is protected by authentication, and only the account owner can view their data. The full technical detail is on the private architecture page. Your data is stored on servers in the United States.
5. Wearable data (WHOOP & Oura) — additional disclosures
Neeos accesses WHOOP and Oura data through each provider’s official API and in accordance with their API terms. Specifically:
- Neeos accesses only the data scopes you approve during authorization with each provider.
- WHOOP and Oura data is used only to provide features to you within Neeos — never for advertising, resale, or sharing with third parties.
- You can disconnect WHOOP or Oura at any time (see “Your choices” below, or revoke access from the provider’s account settings). Disconnecting stops all further data access.
- When you disconnect a provider or delete your Neeos account, the data derived from it is deleted from Neeos as described in “Data retention” below.
6. How we share information
We do not sell, rent, or trade your personal data. We do not share your documents, notes, or health data with third parties for their own purposes. Data is only processed by the infrastructure providers that host the Service (for storage and compute) under confidentiality obligations, and only as needed to operate Neeos. We may disclose information if required by law.
7. AI processing (important)
Neeos indexes your documents, notes, and messages using a model that runs on your own device — that indexing never involves a third party, and never involves our servers either. Answering a question is different: Neeos answers you using large language models operated by OpenAI (which answers your questions, and also handles spoken voice and image generation) and Anthropic (Claude, used for some tasks). To answer you, the relevant parts of your data — which may include the passages retrieved from your documents and notes, health and fitness information (recovery, sleep, HRV, workouts, weight), financial information (balances, bills, debts and spending from a linked Atlas account, where connected), and photos you share in a chat message, along with your question and the conversation you are having — are sent to those providers solely to generate your response. Your library and your index as a whole are never part of that payload — only the specific passages retrieved for that question.
What this means: your data is processed by these providers only to serve you. It is not used for advertising, marketing, resale, or use-based data mining. Apple Health (HealthKit) data is only ever sent to generate your own responses inside Neeos — never for advertising, resale, use-based data mining, or to train any model.
If you would rather your health data not be sent for AI processing, disconnect the relevant source (Apple Health, WHOOP or Oura) in the app — see “Your choices” below.
8. Data retention and deletion
Neeos keeps your data only as long as your account is active or as needed to provide the Service. Deleted documents, notes, and chats hold a 30-day recovery window before they are purged. You can delete your account at any time from inside the app: Settings → Delete account. This removes your chats, memories, health logs, and documents from the live Service immediately; see “Backups” below for the one exception. Credentials for services you've connected (such as a Google account) are a separate case: we're closing the gap that currently lets one survive account deletion, and until that ships, contact jake@neeos.ai if you want a connected account's credentials removed by hand. Disconnecting a source (such as WHOOP or Apple Health) stops new data collection from that source and removes its stored data from Neeos.
Backups. Our database is backed up automatically, in encrypted form, and each backup expires after 7 days. Because a backup is a copy of the whole database taken at a moment in time, it cannot be edited record by record — so for up to 7 days after you delete something, or delete your account, a sealed copy can still exist inside a backup that has not yet expired. Those backups are used only to recover the Service from a failure, never to restore a deleted account, and the data in them is encrypted exactly as it is in the live database. After 7 days the backup is deleted by our hosting provider on its own schedule.
9. Your choices
- Disconnect a service — you can unlink WHOOP or Oura, or revoke Apple Health permissions, at any time from within Neeos or from the respective service.
- Access & deletion — you can request a copy of your data or its deletion by contacting us.
- Revoke authorization — you can revoke Neeos’s access to WHOOP or Oura directly in that provider’s connected-apps settings.
10. Children’s privacy
Neeos is not directed to children under 18 and does not knowingly collect data from them.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page.
12. Contact
Questions about this policy or your data? Email jake@neeos.ai.