Privacy Policy
Neiliro is a household organizer built around a simple promise: your family's data belongs to your family. This policy describes what we actually collect, where it lives, and what you can do with it — in plain language, because a privacy policy you can't read isn't one.
Who we are
Neiliro is operated by Denis Burtsev. For anything in this policy: [email protected].
This policy covers the hosted service (your family's space at yourfamily.neiliro.com), the public demo, and this website. The self-hosted edition runs on your own server under your own control — nothing from it ever reaches us.
What we collect
- Waitlist: your email address, and nothing else.
- Account: your name, email address, and a password hash (we never store the password itself). If you enable two-factor authentication, its secret.
- Your family's content: the tasks, notes, calendar entries, financial records, uploaded files, and mail received at your family's address. This is your data, stored so the product can show it back to you — we do not read it, analyze it, or use it for anything else.
- Technical records: server logs (which never include the contents of your requests), your active sessions with IP address and last-seen time (shown to you under Devices, so you can spot an unfamiliar login), and a daily per-family activity count — how many requests, never what was in them.
What we deliberately don't do
- No analytics scripts, no trackers, no advertising — on this site or in the app. That's why there is no cookie banner: the only cookies are the ones that keep you signed in.
- No email open or click tracking. Mail your family receives is not inspected beyond automated spam and size limits.
- No selling or sharing of data with anyone, for any purpose. There is no version of Neiliro's business that involves your data being the product.
Where your data lives
In the European Union. The hosted service runs on DigitalOcean servers in Amsterdam, Netherlands. Each family's data is a separate, isolated database. Backups are encrypted and expire within 14 days.
We rely on three infrastructure providers (our only subprocessors):
- DigitalOcean — servers (Amsterdam, EU)
- Cloudflare — DNS, this website, and the waitlist
- Mailgun (EU region) — receiving and sending email for your family's address, processed and stored in the EU
Your rights — built in, not on request
- Export: download your family's complete archive from settings, anytime, free, on any plan. It restores into a self-hosted Neiliro — leaving is always possible, by design.
- Deletion: deleting your family removes its database and files; backups expire within 14 days after that.
- Correction: everything is editable in the app.
- For anything else GDPR grants you (access, restriction, objection, complaint to a supervisory authority), write to [email protected].
Children
Neiliro is made for households, and family spaces are created and managed by an adult administrator. Accounts for children exist only when a parent or guardian creates them inside their own family. The service is not directed to children, and we never knowingly collect data directly from a child under 13.
The public demo
The demo at demo.neiliro.com gives every visitor a throwaway sandbox that is deleted when you log out or after two hours of inactivity. We keep anonymous counters about demo visits (how many, which modules were opened, where visitors came from) — never who you are or what you typed.
If something goes wrong
If a breach affects your personal data, we will notify you and the relevant authority within 72 hours of discovering it, and tell you plainly what happened and what we're doing about it.
Changes
If this policy changes in any way that matters, we'll email account holders before the change takes effect. The current version always lives at this address.