Privacy Policy
Last updated: July 6, 2026
This Privacy Policy explains how LMKdev ("NeLocker," "we") handles personal data when you use nelocker.com. We are the data controller for your information.
1. Information We Collect
- Account data: email address, and optional display name.
- Payment data: handled by Stripe. We do not store your full card details — only a subscription status and customer/subscription IDs.
- Content you submit: messages you post (e.g., the Supporters wall) and your prompt selections.
- Technical data: IP address, device/browser info, and essential cookies needed to keep you signed in.
- Usage analytics: when you copy a prompt, we log the copy event — which prompt, the model variant, and the text taken (which may include text you entered) — together with your approximate location (country, region, city) derived from your IP address. We use this to rank popular prompts and improve the library.
- Email analytics: emails we send (like the daily prompt or the weekly digest) may include an open-tracking pixel and tracked links (links pass briefly through our email provider before reaching their destination). This tells us whether our emails are useful — deliveries, opens, and clicks. It never reads your inbox or anything beyond our own messages. You can switch any email stream off at notification settings or stop everything at unsubscribe — every email also carries a one-click unsubscribe.
- Prompt feedback: if you answer the optional “how did that prompt go?” question, we store the rating (and note, if you add one) to improve prompt quality. Answering is never required and works without an account.
- Documents you save to your vault: if you use the NeLocker connector to save documents (from ChatGPT, Claude, Gemini, or another AI), we store the titles and contents you choose to save so you can retrieve them from any AI. Your vault key is stored only as a one-way hash, never in plain text. Your documents are private to your account (row-level security) and you can delete them, or revoke the key, anytime.
2. How We Use It
- To provide the Service (authentication, access control, billing).
- To process subscriptions and send transactional email (e.g., sign-in links, receipts) via Resend.
- To send optional updates/marketing — only with your consent, and you can unsubscribe anytime.
- To understand which prompts are popular and improve the library (copy/usage analytics, including approximate location derived from IP).
- To secure the Service, prevent abuse, and comply with law.
The AI Connector & Your Document Vault
NeLocker offers an AI connector (an MCP server) you can add to assistants like ChatGPT, Claude, and Gemini. Through it, those assistants can (1) search and fetch our free, public prompts and templates, and (2) — only when you supply your vault key — save documents to, and read documents from, your personal vault. We receive only what a tool call sends us (a search term, a prompt id, or a document you explicitly ask to save); we do not receive your broader AI conversation. Saved documents are stored in our database (Supabase), private to your account, and you can delete them or revoke your vault key anytime from your account.
3. Legal Bases (GDPR / UK GDPR)
We process data on these bases: contract (to provide the Service you signed up for), consent (optional marketing and non-essential cookies), legitimate interests(security, improving the Service), and legal obligation (tax, accounting).
4. Who We Share With (Sub-processors)
We share data only with service providers that help us run NeLocker, under contract:
- Supabase — database, authentication, hosting of your account data.
- Stripe — payment processing.
- Resend — transactional and marketing email delivery.
- Google Workspace — our business email.
- Vercel — application hosting.
We do not sell your personal data.
5. Cookies
We use essential cookies to keep you signed in, and (with consent) optional cookies to improve the Service. See our Cookie Policy and the consent banner.
6. Data Retention
We keep your data while your account is active and as needed for legal, tax, and security purposes. You can request deletion (below).
7. Your Rights
If you are in the EU/UK (GDPR): you have the right to access, correct, delete, restrict, port, and object to processing of your data, and to withdraw consent. You may also lodge a complaint with your local data protection authority.
If you are in California (CCPA/CPRA): you have the right to know what we collect, request deletion, correct it, and opt out of "sale"/"sharing" — we do not sell or share your data for cross-context advertising.
To exercise any right, email support@nelocker.com. We will verify and respond within the time required by law.
8. International Transfers
Your data may be processed in the United States and other countries. Where required, we rely on appropriate safeguards (e.g., Standard Contractual Clauses) with our providers.
9. Children's Privacy
NeLocker is not intended for children under 13 (or under 16 where local law sets that age), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact support@nelocker.com and we will delete it. This Service is not a child-directed service under COPPA.
10. Security
We use industry-standard measures (encryption in transit, access controls, encrypted secrets). No system is perfectly secure, but we work to protect your data.
11. Changes
We may update this Policy; material changes will be posted here with a new date and notified where required.
12. Contact
Data controller: LMKdev, North Carolina, USA. For privacy requests, email support@nelocker.com with the subject "Privacy."
Questions about this policy? Contact support@nelocker.com.