1. Who we are
This policy explains how Betide Studio, Inc. (“Betide Studio”, “we”, “us”) handles your personal data when you use NeoStack — our AI-powered agent and development tools for Unreal Engine — accessible at neostack.dev, through our Unreal Engine plugin, and through our desktop and mobile apps as they release.
Data controller: Betide Studio, Inc., a corporation incorporated in the State of Delaware, United States, with registered office at 16192 Coastal Highway, Lewes, DE 19958, USA.
Privacy contact: privacy@neostack.dev. We do not currently operate under a designated Data Protection Officer; at our scale this is not required under GDPR Art. 37.
2. What data we collect and why
We only collect the data we need to run the service you signed up for. The categories below describe what we process.
- Account identity
- Name, email address, and organisation membership, managed through our identity provider Clerk. Sign-in credentials (passwords, passkeys, OAuth identities) are held by Clerk — we never see or store your password.
- Organisation & team data
- Organisations you create or join, your role within them, and seat assignments on paid plans.
- Devices & sessions
- Devices you connect (name, type, online status, last-seen time) and agent sessions: your prompts, the agent's responses, tool activity, and related project context from your Unreal project, so sessions can be viewed live and replayed across your devices.
- Repository content
- Source-control repositories you host with us: the files, revision history, branches, and metadata you push. Processed solely to provide hosting, browsing, and sync for your organisation; access follows your organisation's membership and roles.
- Playtest recordings
- With Playtest capture on, we record your in-editor playtest sessions — just the game viewport and your keyboard and mouse, plus basics like map and duration — and use them to teach NeoStack to play and test games. Every session shows up in your project's Playtesting tab.
- Billing data
- Subscription status, seat counts, and usage-based billing events, processed by Polar. We never see or store payment-card details.
- Product analytics & waitlist
- Product usage events (for example page views, starting a session, or joining the platform waitlist, including the email address and platform choices you submit there), processed by PostHog.
- Server logs
- Short-term request logs from Cloudflare Workers, including IP address, URL, and timestamp. Used for debugging and abuse mitigation.
3. Why we're allowed to process this (legal basis)
Under GDPR Art. 6 and UK GDPR Art. 6, we rely on the following legal bases, selected per purpose:
- Contract (Art. 6(1)(b)) — creating and operating your account, authenticating you, running organisations and seats, connecting devices, running agent sessions, and processing subscriptions.
- Legitimate interests (Art. 6(1)(f)) — short-term server logs for security, debugging, and abuse prevention, and first-party product analytics to understand and improve how NeoStack is used. You can object at any time (see “Your rights”).
- Consent (Art. 6(1)(a)) — the release waitlist: you choose to give us your email, and we use it only to tell you when your platform ships. Withdraw any time by emailing us.
- Legal obligation (Art. 6(1)(c)) — retaining limited records where required by applicable tax or corporate law.
4. Who we share data with (sub-processors)
We don't sell your data. We share data with the following sub-processors strictly so they can provide infrastructure we use to run NeoStack. Each sub-processor has a Data Processing Addendum (DPA) and Standard Contractual Clauses (SCCs) in place with us where required.
- Cloudflare, Inc.
- Hosting (Workers, Durable Objects), object storage, and content delivery. Data transferred to the United States. Covered by the Cloudflare Customer DPA and SCCs.
- PlanetScale
- Managed database for the session and device catalog. Data transferred to the United States. Covered by the PlanetScale DPA and SCCs.
- Amazon Web Services, Inc.
- Storage and compute for hosted source-control repositories (object storage, database, and the servers your pushes reach). Data stored in the United States. Covered by the AWS Data Processing Addendum and SCCs.
- Clerk, Inc.
- Authentication and organisation management (accounts, sign-in, sessions, OAuth providers you choose). Data transferred to the United States. Covered by the Clerk DPA and SCCs.
- PostHog, Inc.
- Product analytics and the release waitlist (US Cloud). Data transferred to the United States. Covered by the PostHog DPA and SCCs.
- Polar Software Inc.
- Payment processing and billing for paid plans, acting as merchant of record. Polar handles checkout, payment-card processing, applicable sales tax / VAT, and invoicing. Data transferred to the United States. Covered by Polar's DPA.
- OpenRouter, Inc.
- AI model routing. When an agent works, your prompts and relevant project context are sent through OpenRouter to the selected large-language-model provider to generate the response. Covered by OpenRouter's data policies and DPA.
- fal.ai
- Media generation. When you use media features, the generation request (prompt and any inputs you supply) is processed by fal.ai. Covered by fal.ai's DPA.
- Betide Studio account service (internal)
- Our own account-linking service, used when you connect the Betide Studio account where you verified or purchased your Fab plugin.
- Betide Studio Private Limited (India)
- Engineering and customer-support personnel acting on our behalf. India-based; access to user data is least-privilege and audit-logged.
We'll update this list when we add or replace a sub-processor. Material changes will be notified to affected users.
5. International transfers
Betide Studio is based in the United States and our sub-processors operate principally from the United States and India. Where your personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (or their UK/Swiss equivalents), plus the additional technical measures offered by each sub-processor (encryption in transit and at rest, access controls).
6. How long we keep it
- Account data
- Until you delete your account (or ask us to). After deletion, residual references are removed within 30 days.
- Organisations you own
- Until you delete them, along with their sessions and devices.
- Agent sessions & transcripts
- Retained while your organisation keeps them, so they can be replayed across devices; deleted with the session, organisation, or account.
- Device records
- Until the device is removed or the organisation is deleted.
- Waitlist emails
- Until the release announcement for your chosen platform is sent, or earlier on request.
- Server logs
- 30 days, then permanently deleted.
- Backups
- Database snapshots held for up to 30 days; deleted data may persist in backups until the relevant snapshot expires.
7. Your rights
If you're in the EEA, UK, or a similar jurisdiction, you have the right to:
- Access (Art. 15) — a copy of the data we hold about you.
- Rectify (Art. 16) — update inaccurate data. Name and email are editable in your account settings.
- Erase (Art. 17) — delete your account and associated data.
- Port (Art. 20) — receive your data in a machine-readable format.
- Restrict (Art. 18) or Object (Art. 21) to processing, including our analytics based on legitimate interests.
- Complain to your supervisory authority (e.g. the UK ICO, France's CNIL, Ireland's DPC) if you feel we've mishandled your data.
To exercise any of these rights, email privacy@neostack.dev. We respond to all rights requests within 30 days (extendable by 60 days for complex cases per Art. 12(3)) and don't charge a fee unless the request is manifestly unfounded.
9. Security
Sign-in credentials are managed by Clerk — we never see or store your password. All data is encrypted in transit via TLS. Session tokens are short-lived and scoped. We run on Cloudflare Workers' isolation model and do not operate long-lived compute instances. Despite these measures, no system is perfectly secure. If we become aware of a personal-data breach that's likely to result in a risk to your rights, we'll notify our supervisory authority within 72 hours and notify you without undue delay where the risk is high (Art. 33–34).
10. Children
NeoStack is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has created an account, please email us and we'll delete it.
11. Changes to this policy
We'll update this policy as our service evolves. Material changes will be announced via email to registered users and reflected in the “Last updated” date above. Continued use of the service after an update constitutes acceptance of the revised policy.
12. Grievance Officer (India)
For complaints relating to user-generated content, privacy concerns, or any other grievance arising from your use of NeoStack, users in India may contact our designated Grievance Officer — appointed in accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and also designated to respond to communications from Data Principals under the Digital Personal Data Protection Act, 2023:
- Name
- Devesh Mishra
- grievance@neostack.dev
- Postal
- 105 T7 Alaknanda Enclave, Awadh Vihar Yohna, Shaheed Path, Lucknow, Uttar Pradesh 226002, India
We aim to acknowledge complaints within 24 hours of receipt and resolve them within 15 days (or within 8 days for content reported as impersonation, non-consensual intimate imagery, or similar sensitive material, as required by the IT Rules). Court-ordered or government-ordered takedowns are actioned within 24 hours.
13. Contact us
Questions, rights requests, or security concerns: privacy@neostack.dev.
Postal: Betide Studio, Inc., 16192 Coastal Highway, Lewes, DE 19958, USA.