Skip to content

Legal

Privacy

Last updated 2 September 2026

Rendel is a service that app developers embed in their own apps. That gives this page two audiences, and they are owed different answers, so it is written in two halves: the people whose apps run the copilot, and the people using those apps.

Neon Apps is the data controller for the first half and a processor acting on the developer’s instructions for the second. Contact: support@neonapps.co.

If you use an app that has a copilot in it

The company whose app you are using decides what the copilot can do and what it is told about you. We hold that data for them.

  • What you type. Your messages are stored so the conversation has a history and so the app’s developer can review what was asked. Before any message reaches a model, email addresses and phone numbers in it are replaced with typed placeholders, and card-like numbers are removed entirely. The placeholder values are encrypted at rest and deleted when the conversation closes.
  • What the app tells us about your session. A developer can send state such as which screen you are on or what is in your cart. What is sent is their choice, not ours.
  • A device identifier. A random value generated inside the app, used to group a conversation, to apply rate limits, and to connect you to an account if the developer identifies you. Depending on how the developer set the SDK up it either lasts for one run of the app or for as long as the app stays installed. It is not an advertising identifier, it is not shared with anyone, and it cannot follow you into another app: it is meaningless outside the one that generated it.
  • An account identifier, if the developer sends one. Their id for you, plus any attributes they attach. We do not enrich it or combine it with data from anywhere else.
  • A rating, if you give one. You can mark an answer helpful or not. We store the rating, the answer it was about and your device identifier, so that one device counts once rather than a hundred times. If you type a reason, it goes through the same masking as a message before it is stored — an email address or a phone number in a complaint is replaced the same way it would be in a question.

We do not sell this data, use it for advertising, or use it to train models. To have your data removed, ask the company whose app you used: they control it, and they can ask us to delete it on your behalf.

If you build on Rendel

  • Your account. Email address and a password hash, held by our authentication provider so you can sign in.
  • Your configuration. Apps, keys (stored only as hashes), registered actions, knowledge sources, persona and appearance settings.
  • Usage. Conversation and message counts, token counts and model names, for limits and billing.
  • If you contact us. The demo form asks for your name, work email, company, app link, platform and what you want the copilot to do. We use it to reply, and for nothing else.

Who else processes it

These are our subprocessors. We will give notice here before adding one that handles conversation content.

  • Anthropic — the models that generate answers. Content sent for a completion is not used to train models. Anthropic deletes API inputs and outputs on a short, fixed schedule; longer retention applies only where their usage policies require it.
  • Supabase (on AWS, Frankfurt, eu-central-1) — the database and authentication.
  • Vercel — hosting for the API and the web surfaces.
  • Resend — email delivery: the notification that tells us you asked for a demo, and the warnings we send a customer as their app approaches its monthly limit. It never carries conversation content.
  • An embeddings provider — only for apps that enable the knowledge base, and only for the text of the knowledge sources and the search query. Named on request; not enabled by default.
  • An error reporting service — listed here before it is switched on rather than after. When a request fails, a crash report can contain the technical detail of that failure, which in the worst case includes a fragment of the data being handled. Nothing is sending reports today; when one is, it will be named on this line and dated at the top of this page.

Who at Neon can see it

Access to the operations panel is an explicit list of named people, not anyone with an email address at our domain, and it can be revoked without touching anyone’s mailbox. Every time one of us opens one of your conversations, a record is written to your own audit log — the same log that records every change made to your organization, and it is visible to you in the console under Settings. We would rather you be able to check this than take our word for it.

Where it is kept, and for how long

Conversation data lives in Frankfurt. Each app has its own retention window, set by its developer and 365 days by default; a nightly job deletes conversations past it, along with the encrypted values behind any placeholders in them. Placeholder values are also deleted as soon as a conversation closes, which happens after 24 hours of inactivity. Account and configuration data is kept while the account exists.

Your rights

If you are in the EU or the UK you have the right to access, correct, export or delete your personal data, and to object to processing. Write to support@neonapps.co and we will answer within 30 days. If you reached us through an app rather than as a customer, we will route your request to the developer who controls that data and tell you we have done so.

Changes

When this page changes materially we will date it and, for customers, say so by email before the change takes effect.