NeuEra Apps Data Practices Charter
Every app we build eventually raises the same question: what should we measure about the people who use it? This document is our answer, written down in advance and applied to every NeuEra Apps product.
We publish it because a data practice that only exists inside a company is not a commitment. It is an intention, and intentions drift.
1. What This Is, and What It Is Not
This Charter applies to NetCloak VPN, Play Lounge, Odo, and Kalum, and to every app NeuEra Apps releases after the effective date above.
It is not a Privacy Policy and does not replace one. Each app has its own Privacy Policy, and that policy is the operative legal disclosure for that app: it lists the specific data, the sub-processors, the retention periods, and your rights. This Charter sits above those documents and explains the rule we apply before any of it gets written — the reasoning that decides whether a field exists at all.
If this Charter and an app's Privacy Policy ever conflict, the app's Privacy Policy governs, and we will treat the conflict as a defect in this Charter and correct it.
2. The Test We Apply
2.1 Why "no personal information" is not our test
The common industry standard is to promise that no "personally identifiable information" is collected. We do not use that standard, for two reasons.
First, it is not the standard the law applies. Under the GDPR and comparable frameworks, the protected category is personal data, which is considerably broader: a record carrying no name at all is still personal data if it can be linked back to a person or a device. A row reading "device 4f2a looked up rates to Mexico at 19:41" contains no name, no phone number and no email, and is unambiguously personal data.
Second, and more practically, it is not a standard that protects you. "No PII" permits detailed, timestamped, per-device behavioural records — the exact material from which a profile is built.
2.2 The test we use instead
We classify every measurement into one of two tiers before we build it.
- Tier A — counted, not recorded. No identifier, no timestamp, no row per event. Only running totals. A Tier A measurement can tell us "1,204 rate lookups were for Mexico." It cannot tell us who, when, in what order, or even whether two of those lookups came from the same person — not because we promise not to look, but because the information does not exist in what we hold. It cannot be un-aggregated by us, by a future employee, by a buyer, or by someone who steals it.
- Tier B — everything else. Any measurement that keeps an identifier, a time, or a row per event. Tier B is sometimes genuinely necessary: Kalum cannot bill you for a call without recording that the call happened, when, and for how long. But Tier B is never casual. It requires a lawful basis, a specific disclosure in that app's Privacy Policy, and a matching declaration in the app store listing — before the first row is written, not after.
Tier A is the default. Our working rule is that a product question must be attempted in Tier A first, and may only move to Tier B when we can state plainly why the aggregate cannot answer it. In practice most product questions — what do people want, what are we failing to offer, which feature earns its keep — turn out to be Tier A questions that the industry habitually answers with Tier B data out of convenience.
3. The Five Rules
3.1 Purpose before collection
We write down the question before we collect the data that answers it. We do not collect data speculatively, store it against a future use, or keep a field because it might one day be interesting. If we cannot name the decision a measurement will inform, we do not build the measurement.
3.2 Aggregate by default
Tier A unless Tier B is argued for and disclosed. See Section 2.2.
3.3 Count what we could not serve
We deliberately count our own failures: the search that returned nothing, the destination we do not cover, the feature someone looked for and did not find. This is the most useful measurement we take and, not coincidentally, one of the least intrusive — a record that something was unavailable says far more about our product than about you.
It also guards against a specific failure. A product that only measures what it already does successfully will keep getting better at what it already does and never discover what it is missing.
3.4 Caveats travel with the number
Every measurement is distorted by how it was taken. We record the known distortion of a measurement alongside the measurement itself, permanently, so that it cannot be quoted without it.
This is an engineering rule with a privacy consequence. A metric whose bias has been forgotten gets treated as more precise than it is, and the standard response to an untrustworthy metric is to collect more granular data about individuals until confidence returns. Honest error bars remove the pressure to over-collect.
3.5 We do not join data across our apps
Our apps do not share an account system, an analytics identifier, or any other key that would let one app's records be lined up against another's. Using Kalum tells us nothing about your use of Play Lounge, and we have not built — and commit here not to build — the means to connect them.
What is shared across NeuEra Apps is this method, not the data. Two separately harmless collections become something else entirely once they can be joined, and that transformation is easy to perform by accident.
4. What This Means in Each App Today
A summary. The linked Privacy Policy for each app is the complete and operative disclosure.
- Odo — no collection of any kind. The app operates entirely offline and your mileage records never leave your device. There is no server to send them to. Privacy Policy
- Play Lounge — no accounts and no personal information required to play. Game sessions are transient. Optional push-to-talk voice in private games is relayed live and never recorded, stored, or transcribed. Privacy Policy
- NetCloak VPN — a no-logs VPN: we do not log the sites you visit or the contents of your traffic. The service is free and supported by advertising, which is the one place in our portfolio where a third party measures you on its own terms — see Section 5. Privacy Policy
- Kalum — necessarily the most data-collecting app we operate, because it is a paid telephony service. Call metadata (destination, duration, outcome, timestamps) and transaction records are Tier B: they are required to bill you accurately, to comply with financial record-keeping obligations, and to detect fraud, and they are disclosed in detail in the Privacy Policy. Separately, we measure which destinations people look up prices for — including the ones they price and then decide not to call — in order to negotiate better rates on the routes people actually want. That measurement is Tier A: a running count per destination, carrying no identifier, no timestamp and no per-event record. It cannot be connected to your account or to any call you placed. Privacy Policy
5. Where Third Parties Do Not Follow This Charter
This Charter binds us. It does not bind companies whose software we include, and we will not imply otherwise.
NetCloak VPN is free and supported by advertising through Google AdMob. AdMob operates its own advertising identifier and its own data practices, which are set by Google, not by us, and which do not follow this Charter. NetCloak requests the advertising ID permission for this reason. This is disclosed in the NetCloak Privacy Policy, and if you would prefer not to be measured by an advertising network, that is the honest thing to know before installing it.
Play Lounge, Odo, and Kalum contain no third-party advertising SDK and read no advertising identifier. In Kalum the Android AD_ID permission is explicitly removed from the app.
Our websites are a separate surface from our apps, and one page of one site carries an advertising tag. The Kalum marketing site at kalum.app loads a Google Ads conversion tag on a single landing page, /call-mexico/, so that we can tell whether a paid advertisement led to an install. That tag is Google's and follows Google's practices, not this Charter. It loads on that one page and nowhere else on the site — not on the homepage, not on any destination page. This site, legal.neuera.app, loads no third-party script at all.
Our paid and infrastructure providers — payment processors, telephony carriers, authentication and hosting providers — receive only what they need to perform their function, are bound by contract, and are listed by name in each app's Privacy Policy.
6. What We Use Measurements For
We use what we measure to decide what to build and what to improve: which destinations to negotiate better rates for, which features are worth keeping, where the product is failing to offer something people are looking for.
We do not use it to build a profile of you, to target advertising at you, or to make automated decisions that affect you.
We have never sold personal information for money, and we do not intend to. For completeness rather than comfort: the advertising in NetCloak described in Section 5 may constitute "sharing" for cross-context behavioural advertising as that term is defined under California law, and the NetCloak Privacy Policy is the operative disclosure for it.
7. Your Rights
Your rights over your personal data — access, correction, deletion, portability, objection, and complaint to a supervisory authority — are set out in each app's Privacy Policy, together with the lawful basis we rely on and how to exercise them. Contact hello@neuera.app for any request.
One clarification specific to this Charter: Tier A measurements cannot be delivered or deleted on request, because they contain nothing that identifies you. There is no record of your activity within them to find, extract, or remove — only totals. A small total may reflect a single measurement; even then there is nothing in it that says who, or when. This is a consequence of the design rather than a limitation of our willingness, and it is the reason we prefer Tier A wherever a question can be answered there.
8. How This Charter Changes
Every version of this Charter is dated, published, and permanently archived alongside every prior version, so that any change to what we have promised is visible and comparable. We will not quietly weaken it.
Where a change to this Charter is accompanied by a change in what an app actually collects, the corresponding Privacy Policy is updated at the same time and the app store listing is updated to match.
9. Contact
NeuEra Apps LLC, United States of America.
Privacy and data practices: hello@neuera.app
If you believe an app of ours is collecting something this Charter says it should not, we want to hear it at that address — that is a bug report, and we will treat it as one.
Summary
- We do not use "no personal information" as our test, because it is neither the legal standard nor a protective one.
- Tier A — totals with no identifier, no timestamp and no per-event row — is our default, and most product questions are answered there.
- Tier B — anything that keeps an identity, a time, or an event — requires a stated purpose, a lawful basis, a Privacy Policy disclosure and a store declaration, before the first row is written.
- We state the question before collecting the answer; we count what we failed to offer; we keep each measurement's known distortion attached to it.
- We do not join data across our apps, and have not built the means to.
- NetCloak is ad-supported and its ad network follows its own rules, not ours. Our other apps carry no advertising SDK.
- Each app's Privacy Policy remains the complete and operative disclosure for that app.