Privacy Policy
This Privacy Policy explains what data Neolith — the operating surface for AI-born companies — collects during its private beta, how we use it, and the choices you have. It applies to the workspaces, accounts, and people who use the service.
This page is a representative draft for the private beta and is not legal advice. A final, jurisdiction-specific policy and a Data Processing Addendum are issued with your design-partner agreement, which controls where the two differ.
01Scope & who we are
Neolith is operated by Neolith Pte Ltd, a Singapore-incorporated adaptic.ai company ("Neolith", "we", "us"). This policy covers personal data we process to provide the beta. For most Customer Content, your organization is the controller and Neolith is a processor acting on its instructions; where we decide how and why data is processed (for example, account administration and security), we act as a controller.
02Information we collect
- Account & workspace data. Names, work emails, roles, and the organization you belong to — provided by you or your identity provider when a workspace is provisioned.
- Customer Content. The messages, documents, decisions, charters, and data your members and AI colleagues create or upload inside a workspace.
- Usage & device data. Logs of how the service is used — pages, actions, timestamps, IP address, and browser/device information — to operate and secure it.
- Compute & Fleet signals. Operational telemetry from the machines that run your AI colleagues: model in use, status, temperature, uptime, and spend. These power the Fleet surface and your cost reporting.
- Support & feedback. Anything you send us directly during the design-partner engagement.
03How we use information
- to provide the service — run your workspace, your AI colleagues, and the surfaces they act on;
- to secure it — authenticate members, enforce access controls, and detect abuse;
- to meter compute — attribute spend to colleagues so "compute is payroll" stays honest;
- to support and improve the beta, working closely with design partners.
We do not sell personal data, and we do not use Customer Content to train foundation models.
04AI processing & model providers
Running an AI colleague means sending the context it needs — relevant Customer Content — to the model provider that powers it (for example, the provider behind the model named in Fleet). We route only what is necessary to perform the requested work, under agreements that prohibit those providers from training their models on your content. You can run colleagues on our managed models or on your own provider keys; in the latter case, that provider's terms also apply to the traffic you send it.
05Data residency
Where the service offers regional routing, Customer Content for a workspace can be processed in a chosen region — for example EU → Frankfurt, US → us-east, APAC → Singapore. Residency commitments for your workspace are set in your agreement and surfaced in the product. Operational metadata (logs, billing) may be processed centrally to run the service.
06Sharing & subprocessors
We share personal data only with subprocessors that help us deliver the service — cloud and compute providers, the model providers behind your AI colleagues, and the tools you explicitly connect through Integrations (such as your code host, comms, or data warehouse). Each is bound by contract to protect the data and use it only to provide its service. We also share data where required by law, or to protect the rights and safety of users and the public. A current subprocessor list is available to design partners on request.
07Retention & deletion
We keep Customer Content for as long as your workspace exists, and operational logs for a limited period needed to run and secure the service. The audit timeline (the "one event spine") is intentionally append-only so the record stays trustworthy. When you delete content or end the engagement, we delete or de-identify personal data in the ordinary course — except where we must retain it by law — in a way that preserves the integrity of the remaining audit trail. Export is available before deletion.
08Security
We protect data with encryption in transit and at rest, role-based access controls (RBAC), SSO through your identity provider, scoped secrets, and least-privilege access for our own staff. No system is perfectly secure, but consequential and irreversible actions in the product are gated on a named human and written to the audit spine, so activity stays attributable and reviewable.
09Your rights & choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict certain processing. Because your organization usually controls Customer Content, please direct those requests to it; we will help our customers honor them. For data we control, contact us using the details below. You can also manage members and access from within your workspace settings.
10International transfers
We may process data in countries other than your own, including to run model providers and cloud infrastructure. Where we transfer personal data across borders, we rely on appropriate safeguards — such as standard contractual clauses — and honor the residency commitments set for your workspace.
11Cookies & local storage
The marketing site and the product use a small number of strictly-necessary cookies and browser storage to keep you signed in, remember your theme, and run the app. We don't use advertising cookies. You can clear or block storage in your browser, though parts of the service may stop working.
12Changes & contact
We may update this policy as the beta evolves; material changes will be communicated to design partners. Questions, or a privacy request? Write to privacy@neolith.ai.