neon layer

Privacy Policy

A plain-language summary of what data Neon Layer handles for Carousel Builder, the website, support requests, billing, and privacy-conscious analytics.

1. Who we are

Milán Töreky operates Carousel Builder and the related website experience under the Neon Layer brand from Hungary. For GDPR purposes, Milán Töreky is the data controller for the website, support, billing-related flows, and the Carousel Builder app data described in this policy.

Controller details: Milán Töreky Brand: Neon Layer Individual entrepreneur 2600 Vác, Bimbó utca 49/B, Hungary info@neonlayer.studio

No data protection officer has been appointed. Privacy requests can be sent to info@neonlayer.studio.

2. What this policy covers

This Privacy Policy explains how Neon Layer handles personal data when you use Carousel Builder, our website, billing-related flows, or our support channels. If a future Neon Layer product has a product-specific privacy policy, that policy will apply to that product instead.

3. What data we may collect

Depending on how you use the service, we may collect personal data directly from you, from Canva, from Lemon Squeezy, our payment provider and Merchant of Record, and automatically from your use of the website or app.

This may include Canva-related user and app identifiers, pseudonymous local user IDs, session and checkout tokens, prompts, briefs, ideas, instructions, generated carousel output, page settings, support contact details and messages, limited billing-related customer, order, transaction, and subscription information from Lemon Squeezy, and technical data such as IP-related request data, browser or device metadata, page URLs, request IDs, error data, security logs, and product interaction events.

Carousel Builder currently uploads user-selected images to Canva for use inside the Canva design flow. The backend generation request is text-based for the MVP; image asset references and preview thumbnails may still be used inside the Canva app experience so you can place and preview images.

4. Where data comes from and why it is needed

You provide data when you enter prompts, use the support form, send email, or complete checkout. Canva provides app context and user identifiers needed to run the app. Lemon Squeezy provides billing and subscription status needed to activate and manage paid access. Technical data is collected automatically when the website, API, or app is used.

Some data is required to provide the service. For example, without app identifiers we cannot keep usage limits or subscription status in sync, without prompt text we cannot generate a carousel, and without contact details we cannot reply to support requests.

5. How we use the data

We use personal data to authenticate access to the app, generate and refine content, return results inside Canva, maintain billing and subscription status, process support requests, send service-related communications, secure the service, investigate failures or abuse, and understand broad product usage so we can improve reliability and usability.

We do not use your data to sell personal data to advertisers.

6. Legal bases

Where the GDPR applies, we rely on performance of a contract to operate the app, process generation requests, provide support connected with the service, maintain subscription access, and deliver paid features requested by you.

We rely on legitimate interests to secure the service, prevent abuse, troubleshoot failures, understand broad usage, improve reliability and usability, and protect our legal position. We rely on legal obligations where tax, accounting, consumer protection, or other laws require us to keep or disclose information. We rely on consent where consent is legally required, for example for optional non-essential cookies or similar technologies if introduced later.

7. Third-party service providers

We use third-party providers to operate the service. These may include OpenAI for AI-assisted content generation, Lemon Squeezy for hosted checkout, subscription billing, payment receipts, tax/VAT handling, and customer-portal actions, Render for hosting and infrastructure, PostHog for limited privacy-conscious analytics, Resend for support email delivery, and Canva for the Canva app environment and design workflow.

We share only the data reasonably needed for each provider to perform its role. We do not receive or store full payment card details; payment details are handled by Lemon Squeezy.

8. International transfers

Some providers we use may process data outside the European Economic Area, including in the United States or other countries where those providers operate. Where that happens, we rely on appropriate safeguards or other lawful transfer mechanisms required by applicable law, such as adequacy decisions, standard contractual clauses, or provider data-processing terms.

9. Retention

We keep personal data only for as long as reasonably necessary to provide the service, troubleshoot issues, respond to support requests, maintain security, investigate abuse, preserve service history where needed, and meet legal, tax, accounting, or compliance obligations.

Usage, subscription, and billing records may be kept while your account or subscription is active and afterwards where needed for accounting, tax, fraud prevention, dispute handling, or legal claims. Support messages are handled through email and may be kept for a reasonable follow-up period. Security, request, and error logs are kept for operational troubleshooting and abuse prevention, then deleted or anonymized when no longer needed.

If Canva notifies us that you uninstall the app, we mark the local user record as uninstalled and release active in-flight reservations. Some billing, security, usage, and legal records may still be retained where required or reasonably necessary.

10. Your rights

Where applicable, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to request a copy of your personal data or data portability where applicable. You may also withdraw consent where processing is based on consent. To exercise a privacy right, contact info@neonlayer.studio.

We may need to keep certain information where required for legal, security, fraud-prevention, or accounting reasons, even if you request deletion of other data.

You may also lodge a complaint with your local data protection authority. In Hungary, the supervisory authority is: Hungarian National Authority for Data Protection and Freedom of Information (NAIH) Falk Miksa utca 9-11, H-1055 Budapest, Hungary +36 1 391 1400 ugyfelszolgalat@naih.hu https://www.naih.hu/

11. Analytics, cookies, and local storage

The website may use limited privacy-conscious analytics to understand broad usage of the site and support flows. In the current setup, PostHog analytics is configured in cookieless mode, autocapture is disabled, person profiles are limited to identified users only, and session recording is disabled.

Lemon Squeezy may use cookies or similar technologies when checkout or the customer portal is opened. Carousel Builder may use local browser or Canva app storage for product preferences, such as saved color presets. Strictly necessary storage is used to run the service and protect it from abuse.

If we introduce additional non-essential cookies or similar technologies beyond what is strictly necessary, we will update this page and provide any notice or choices required by applicable law.

12. Security

We use reasonable technical and organizational measures to protect the service and the data we handle. No system is perfectly secure, and we cannot guarantee absolute security.

We do not use automated decision-making or profiling that produces legal or similarly significant effects on users. AI-assisted generation helps produce content, but users remain responsible for reviewing and deciding how to use the output.

13. Contact and updates

If you have a privacy question, contact info@neonlayer.studio.

Last updated: May 3, 2026. We may update this Privacy Policy from time to time, and the latest version will always be posted on this page.