Privacy Policy

Last updated: July 1, 2026

This privacy policy explains how personal data is processed when using NEO Oracle. It is written in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR).

Controller

Andreas Giesen
Hammerschmidtstr. 13
47798 Krefeld
Germany

Phone: 015123267538
Email: andreas@open-mindwork.org

We object to the use of contact details published as part of legal disclosure duties for unsolicited advertising.

Data Minimization

NEO Oracle is designed according to the principle of data minimization. The service does not store complete oracle conversations on the server as a persistent chat history. Questions and answers are processed to provide the requested oracle response, but they are not saved in the local account database as a conversation archive.

Local request statistics are content-free. They may include request type, language codes, signifier, provider, token or usage data, and question length, but not the text of questions, answers, rejected messages, or model reasoning.

Personal Accounts

NEO Oracle may be used with a personal account. Personal accounts are optional in the current account system and are kept intentionally sparse.

Stored account data:

  • Email address
  • Password hash, never the plain-text password
  • Account role, such as user or administrator
  • Account status, such as active or disabled
  • Creation time, update time, and last login time

There is no real-name requirement. We do not require profile data such as name, address, date of birth, gender, or phone number for a normal user account.

Not stored in the user account:

  • Oracle questions
  • Oracle answers
  • Complete chat or session histories
  • Image prompts containing personal context
  • Local server-side question-and-answer logs

The purpose of account processing is to provide personal access, administer accounts, and, if activated in the future, assign credits, purchases, or refunds to an account. The legal basis is Art. 6(1)(b) GDPR where processing is necessary to provide the service, and Art. 6(1)(f) GDPR for administrative security and abuse prevention.

Account data is stored for as long as the account exists. If an account is deleted, account data is deleted unless legal retention duties require longer storage.

OpenAI Processing

NEO Oracle uses services provided by OpenAI, L.L.C. and the OpenAI group of companies to generate oracle responses, classify or route user input, support language detection, and optionally generate images.

When a user submits an oracle request, the necessary content is transmitted server-side to OpenAI. This may include:

  • The question entered by the user
  • Relevant context from the current session, only where needed for a coherent response
  • The selected oracle signifier and related oracle texts
  • Technical instructions for response generation
  • For image generation, a derived image prompt

The transmission is used to provide the requested oracle response, classification, or image generation. These contents are not stored by us as a persistent local chat history.

For image generation, personal information is, where technically provided for, translated into symbolic, visual, and archetypal motifs rather than direct descriptions of a real person. Image prompts are not logged by us unless separate prompt logging has explicitly been enabled.

OpenAI processes submitted content as the provider of the AI services. According to OpenAI's business/API terms, OpenAI does not use customer content to develop or improve its services unless the customer explicitly agrees to such use. OpenAI may process content where necessary to provide the service, comply with law, enforce policies, and prevent abuse.

The legal basis for transmitting data to OpenAI is Art. 6(1)(b) GDPR where processing is necessary to provide the requested oracle or image functions. For technical security, abuse prevention, and service stability, Art. 6(1)(f) GDPR may also apply.

OpenAI may process data outside the European Union or European Economic Area. In such cases, the transfer mechanisms and safeguards provided by OpenAI apply. Users should not enter information they do not want to transmit to an external AI service, especially highly sensitive data, health data, confidential credentials, or personal data of third parties.

More information is available in the OpenAI Privacy Policy and the OpenAI Services Agreement.

Generated Images

Generated images are stored outside the public web root in private server storage and are delivered only through an authenticated image endpoint. File names are randomized. Image access is protected by the same application authentication mechanism.

Generated images may be available during the authenticated session and for export by the user. They are not stored in a public media directory.

Feedback

If users submit feedback, we process the submitted feedback text. If the user explicitly chooses to attach a conversation PDF, that PDF is processed and stored or sent together with the feedback. This is optional and requires the user's active choice.

The purpose is to review feedback, improve the service, and respond where appropriate. The legal basis is Art. 6(1)(f) GDPR and, where the feedback concerns a requested service, Art. 6(1)(b) GDPR.

Payments and Credits

Payment and credit features are prepared in the account database structure but may not yet be active. If paid features, credits, purchases, or refunds are activated, payment-related events may be stored. These may include payment provider, payment status, amount, currency, external payment reference, and related credit ledger entries.

Payment data is processed only where necessary for purchase, billing, refund handling, abuse prevention, and legal record-keeping. Actual payment processing may be handled by an external payment service provider. In that case, the provider's own privacy information also applies.

Hosting, Server Logs, and Security

To operate NEO Oracle, hosting services are used, including infrastructure, storage, database services, security, and technical maintenance. The hosting provider is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. NEO Oracle is operated on an IONOS cloud server or virtual server with a self-managed Ubuntu system and Plesk. IONOS provides the hosting infrastructure and may process technical data, including IP addresses and server log data, as a processor within the meaning of Art. 28 GDPR. Server, operating system, Plesk, and application administration are carried out by the controller. Further information is available in the IONOS privacy information.

The hosting provider may process technical data such as requested pages or files, date and time of access, transferred data volume, browser type and version, operating system, referrer URL, IP address, and requesting provider.

Server logs are processed for security, stability, and abuse investigation on the basis of Art. 6(1)(f) GDPR. They are deleted when no longer required, unless a longer retention period is necessary for evidence or legal reasons.

The website should be accessed via HTTPS so that data is encrypted during transmission.

Cookies and Local Storage

NEO Oracle uses technically necessary cookies for authentication sessions. Without these cookies, protected areas and API endpoints cannot be used reliably.

The browser may also store local preferences such as the selected light or dark theme and the current interface language. These preferences are stored locally in the user's browser and are used to restore the chosen interface state.

Users can delete cookies and local storage through their browser settings. Doing so may log the user out or reset local interface preferences.

Contact

If users contact us by email, phone, feedback form, or another communication channel, we process the information provided in order to handle the request. The legal basis is Art. 6(1)(b) GDPR where the request relates to a service, and Art. 6(1)(f) GDPR for general communication and documentation.

Legal Bases

Where this policy does not name a more specific legal basis, the following applies: consent is processed under Art. 6(1)(a) GDPR; service-related processing under Art. 6(1)(b) GDPR; legal obligations under Art. 6(1)(c) GDPR; and legitimate interests such as security, stability, abuse prevention, communication, and technical operation under Art. 6(1)(f) GDPR.

Processors and Third Parties

We share personal data with processors or third parties only where this is legally permitted or necessary for the service, for example with hosting providers, OpenAI as AI service provider, email or SMTP providers for feedback, and future payment providers if payment functions are activated.

Where required, processors are engaged on the basis of Art. 28 GDPR.

Deletion and Retention

Unless stated otherwise in this policy, personal data is deleted when it is no longer required for the purpose for which it was collected and no legal retention obligation applies. If data must be retained for legal reasons, its processing is restricted to those purposes.

Your Rights

Under the GDPR, data subjects have the following rights where the legal requirements are met:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing under Art. 21 GDPR
  • Right to withdraw consent with effect for the future
  • Right to lodge a complaint with a supervisory authority

To exercise these rights, please contact the controller named above.

Changes to This Policy

This privacy policy may be updated when legal requirements change or when NEO Oracle features change in a way that affects personal data processing. The current version available on this page applies.

© 2001-2026 Andreas Giesen • Imprint • Privacy Policy
Beta v0.6.26