Your data, your model, your code. Here is exactly what we collect, why, and how long we keep it.
Last updated: June 2026
Neo Graphs ("we", "us", "our") is the operator of the Neo Graphs code generation service, accessible at this domain. Neo Graphs generates production-ready Neo4j graph layers from relational entity models submitted by its users.
For privacy inquiries, contact us at our contact page.
When you use the sandbox at /sandbox.html, no personal data is collected. The sandbox runs a fixed, pre-generated sample model that lives entirely in server memory. You download a ZIP — we receive a standard HTTP request with your IP address (retained for up to 24 hours in server access logs for security purposes, then discarded).
When you call POST /api/generate/graph or /api/generate/graph/from-excel, your entity model is processed entirely in memory. The generated ZIP is streamed back in the response. No model data, no generated code, and no user-identifying information is written to disk or any database. The only log entry is a standard access log line (timestamp, HTTP method, path, response code, byte count).
When you call POST /api/jobs/graph, your model and the resulting generated ZIP are stored in an in-memory queue until you download the result or the job expires (1 hour). After expiry the job record and all associated data are permanently deleted from memory. No disk persistence occurs.
To operate a paid account we collect:
If you submit a message via /contact.html, we collect your name, email address, and the message you send. This is used solely to respond to your enquiry.
We do not use your entity model or generated code for AI training, product analytics, or any secondary purpose.
We keep data for the shortest time necessary to operate the service.
| Data type | Retention period | Reason |
|---|---|---|
| Sandbox model + generated output | Never stored — in-memory only | Stateless; fixed sample served from cache |
| Synchronous API model + output | Never stored — in-memory only | Streamed response; zero persistence |
| Async job model + output | 1 hour after generation | Gives user time to download; auto-purged |
| Server access logs (IP, path, status) | 24 hours | Security monitoring; no personal data beyond IP |
| Contact form message | 90 days after resolution | Support reference; deleted after close |
| Account email address | Duration of account + 30 days | Account management; deleted on closure + grace period |
| Billing records (Stripe) | 7 years | Legal / tax compliance requirement |
| Cookie preference (localStorage) | Until you clear browser storage | Stored client-side only; not sent to server |
To request early deletion of any data we hold about you, contact us. We will action the request within 30 days.
We do not sell, rent, or share your personal data or entity models with any third party, except:
We never share your schema, model, or generated code with any third party for any commercial purpose.
All traffic is encrypted in transit using TLS 1.2+. The generation engine runs in an isolated container with no network egress. Generated ZIP files are held in-memory with a 1-hour TTL; no customer model data is written to persistent storage on our servers. Access to production systems is restricted to authorised personnel only.
Enterprise customers can additionally negotiate private cloud deployment, where the generator runs entirely within their infrastructure and no data ever leaves their network.
If you are in the European Economic Area, UK, or another jurisdiction with data protection laws, you have the right to:
To exercise any of these rights, contact us. We will respond within 30 days.
Neo Graphs uses a minimal set of browser storage mechanisms. We do not use advertising cookies, cross-site tracking, or third-party analytics scripts.
| Name / key | Type | Purpose | Expires |
|---|---|---|---|
gf_cookie_pref |
localStorage | Stores your cookie consent choice ("all" or "essential") so we don't show the banner on every visit. | Until browser storage cleared |
| ASP.NET session cookie | HTTP cookie (session) | Server-side session identifier for authenticated API calls. Issued only to logged-in Pro/Enterprise users. | Browser session end |
| XSRF-TOKEN / antiforgery | HTTP cookie (session) | Cross-site request forgery protection for form submissions. Issued only on form pages. | Browser session end |
To reset your cookie preference and see the consent banner again, open your browser's developer tools and run:
localStorage.removeItem('gf_cookie_pref');
Then refresh the page. You can also clear all site data from your browser's privacy / site settings.
Essential cookies (session, antiforgery) are required for the service to function correctly. Selecting "Essential only" in the cookie banner still allows these. Preference cookies (gf_cookie_pref) are stored in localStorage, not sent to the server, and do not track you.
We do not use third-party tracking cookies (Google Analytics, Facebook Pixel, etc.). If we add analytics in the future, it will appear in this section and in the consent banner before being activated.
We may update this policy to reflect changes in how we operate the service or to comply with applicable law. Material changes will be communicated to account holders by email at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the most recent revision. Continued use of the service after the effective date constitutes acceptance of the revised policy.
For privacy enquiries, data subject requests, or questions about this policy: