NEPTOONER® · LEGAL INFORMATION
Privacy Policy
Last updated: 10 September 2026
This policy describes how personal data is processed when you visit the Neptooner® website and use the platform. Information about the app is based on confirmed product details. Technical details that cannot yet be verified are explicitly marked.
Working draft: the app configuration and the details marked below are still missing. The move to Hostinger hosting has not yet been completed. This is not yet a fully reviewed privacy policy for public launch.
1. Data controller
MG Dynamics LLC3833 Powerline Road
Suite 302-C
Fort Lauderdale, FL 33309
USA
Represented by Mike Gassen. For privacy enquiries: info@neptooner.ai.
EU representative: for a regular service specifically directed at Germany, the obligation to appoint a representative under Article 27 GDPR must be reviewed. The name and contact details of such a representative have not yet been supplied. Any obligation to appoint a data protection officer must also be reviewed.
2. Why we process data
We process data to provide the website, manage user accounts, create and edit designs, activate purchased access and respond to enquiries. Article 6(1)(b) GDPR is the legal basis for processing necessary to provide the service. Processing required by law is based on Article 6(1)(c) GDPR. Security measures and reliable technical operation may be based on Article 6(1)(f) GDPR; our legitimate interest is in securing and providing the service.
Where optional processing requires consent, Article 6(1)(a) GDPR is the legal basis. You may withdraw that consent with effect for the future.
3. Website, hosting and server logs
Hostinger is the intended hosting provider. Accessing a website involves processing technically necessary connection data, particularly the IP address, time and destination of the request, and device and browser information transmitted by the browser. Server logs may be needed for delivery, troubleshooting and prevention of misuse. The legal basis is Article 6(1)(f) GDPR.
Additional services in the existing project: the current preview is delivered through OpenAI Sites and Cloudflare. These providers may process connection data and, where applicable, access data. The preview sign-in is separate from a Neptooner® user account. Before launch, the actual hosting company, final deployment, contracts, log contents and retention periods must be confirmed. The Hostinger VPS shown is configured for Frankfurt; this does not establish that this preview or all app data is processed there.
4. User account and Google Firebase
According to confirmed product information, Google Firebase is used for sign-in, authentication and database functions. This involves processing data required for the account and access, such as the supplied email address, an account identifier and the status needed for authentication. This processing provides and secures your access.
The available landing-page code contains no Firebase SDKs or Firebase project configurations. The actual Firebase products, stored account data and designs, active sign-in methods, regions, retention periods and authentication storage must be confirmed from the app code. Firestore and Storage are therefore not listed here as verified products in use.
5. Image generation through the OpenAI API
According to confirmed product information, the OpenAI API is used for requested AI image generation. Your image description and technically necessary data may be transmitted to OpenAI for this purpose. Where a feature processes reference images, those images may also be transmitted for the requested editing. Article 6(1)(b) GDPR is the legal basis for necessary processing.
Please do not enter other people’s personal data unless you are authorised to process it. Such data is not needed to create many types of artwork.
The API integration and model used are not included in the existing project. The receiving company, exact fields transmitted, storage, retention periods and any use for training must be checked against the actual API configuration. No unverified assurances are made here.
6. Enlargement and image editing
According to product information, an open-source upscaler is used. It processes the selected image to create the output you request; where personal data is involved, necessary processing is based on Article 6(1)(b) GDPR.
The library and execution location cannot be verified from the landing-page code. It must be confirmed whether processing takes place exclusively on the operator’s own server. Use of an external upscaling provider is not assumed. If such a service is used, recipients and transfers must be added before use.
7. Purchases and Digistore24
Paid subscriptions and additional purchases are handled exclusively through Digistore24. The seller and contractual party for the purchase is the Digistore24 reseller named at checkout. During that ordering process, the data required for ordering, payment, invoicing, subscription, cancellation or reversal is processed under that reseller’s responsibility. Digistore24 provides the applicable privacy information during the purchase process.
You move to Digistore24 via a link or the ordering process. No Digistore24 checkout is embedded in this landing page. The current plan buttons open the app at app.neptooner.ai.
To activate and manage your access, we need information about the purchased plan and entitlement status. Where Digistore24 transmits this data to us, we process it to provide the purchased access.
The specific reseller company and the content and technical implementation of order-status transfers must be confirmed against the actual order and app integration. The landing-page code contains neither checkout URLs nor webhooks. Required details and privacy information must also match the actual checkout.
8. Contact and system emails
When you contact us by email, we process your sender address and the information you provide to handle your enquiry. For contract-related matters, the legal basis is Article 6(1)(b) GDPR; for other enquiries, it is our legitimate interest in responding under Article 6(1)(f) GDPR. Purchase-related emails are sent by Digistore24.
The provider used for login and authentication emails and the contact mailbox provider are not verified in the source code. Firebase Authentication may only be specifically named as the email service after checking the app configuration.
9. Cookies, browser storage and analytics
No marketing pixels or optional analytics scripts were found in the reviewed, actively included landing-page code. The website does not load advertising or analytics trackers embedded by us. No external consent management tool is integrated.
For expressly requested functions, necessary login, session or security information may be stored on or read from your device. Where strictly necessary, device access is governed by Section 25(2) TDDDG; subsequent processing of personal data additionally requires a legal basis under the GDPR. Optional technologies may only be loaded after any required consent has been given.
The complete storage inventory for the separate app and cookies set by the preview platform still need to be checked in the running system. An unused UI component contains the cookie name “sidebar_state”, but is not included on the public pages. This does not establish active cookie use on the landing page.
Cookie notice: When you close the notice, we store “neptooner_cookie_notice_v1” with the value “closed” in your browser’s session storage. This keeps the notice closed during that browser session. No personal identifier is stored and the value is not sent to a server. This storage supports the expressly selected display preference (Section 25(2), point 2 TDDDG). You can reopen the information using “Cookie information” in the footer. Closing the notice does not give consent to analytics or advertising.
10. Fonts, images and external links
In the reviewed production build, the Geist and Geist Mono fonts are delivered with the website as local font files. Images are also served by the website itself. The included landing-page code contains no videos or external iframes.
Links to the app, Digistore24 or other explicitly identified external pages open those services. Once you follow a link, the relevant provider’s privacy information also applies. External pages are not loaded here as embedded content.
11. Recipients and processing outside the EU
MG Dynamics LLC is based in the USA. The technical services mentioned may also involve processing or access outside the European Economic Area. The requirements for international data transfers under Article 44 et seq. GDPR must be met for each specific recipient.
The companies involved, processing locations, data processing agreements and transfer grounds still need to be documented. A valid certification or conclusion of standard contractual clauses is not claimed without evidence. Details of the safeguards actually used and how to obtain a copy must be added before public launch.
12. Retention and deletion
Personal data should only be kept for as long as necessary for its purpose. For account data, this is provision of the account; for support data, it is handling and necessary follow-up of the enquiry. Statutory retention obligations or the need to preserve legal claims may prevent immediate deletion. In that case, further use must be limited to the relevant retention purpose.
Specific retention periods and deletion procedures for server logs, accounts, inputs, images, support, order status and backups have not yet been supplied. These must be established using the actual systems, including procedures when an account is deleted.
13. Your rights
Subject to statutory conditions, you may request access, rectification, erasure, restriction of processing and data portability. Where processing is based on your consent, you may withdraw it at any time with effect for the future.
Right to object: You may object to processing based on legitimate interests on grounds relating to your particular situation. You may object at any time to any use of your data for direct marketing.
Please contact info@neptooner.ai. You may also complain to a data protection supervisory authority, particularly in the place of your habitual residence, workplace or a suspected infringement.
14. Required information and automated decisions
Without the information needed for an account, activation and requested image functions, those features cannot be provided. Contacting us is voluntary; without a reply address, we may be unable to respond.
No automated individual decisions producing legal or similarly significant effects are apparent in the reviewed landing-page code. AI image generation creates image content. Any additional automated account or risk checks in the separate app must be reviewed before launch.
