Liminalis
Legal

Privacy Policy

Draft · last updated PLACEHOLDER: date

Draft. Section structure is in place; operative wording is marked with placeholders and has not been reviewed by a lawyer. This document is not yet in force.

1. Who is responsible for your data

PLACEHOLDER: controller identity, registered address, and a data protection contact.

2. What we collect

Account data

Email address and authentication details. If you sign in through a third-party identity provider, we receive the identifier that provider gives us. PLACEHOLDER: exact fields, and what is received from each supported identity provider.

Content you create

The documents, folders, chats and projects you create or upload, together with the artifacts the system derives from them — passage embeddings, extracted entities and relationships, facts, summaries, motif tags and index entries.

Usage and billing records

A ledger of model calls made on your behalf, including which model, which role, how many tokens, and the cost. This is what makes your bill auditable. PLACEHOLDER: retention period for usage records.

Technical data

PLACEHOLDER: log data, IP addresses, device and browser information, error reports, and whether any analytics are used.

3. Audio and speech

Where the desktop client transcribes speech, transcription runs on your own machine. Audio is not uploaded to us, not buffered on our servers, and not sent to a third-party transcription service. The resulting text becomes part of your project content and is treated like anything else you type. PLACEHOLDER: confirmation of local model storage location and any diagnostic data the client sends.

4. Third-party model providers

To answer your requests, relevant portions of your content are sent to third-party language model and embedding providers. This is intrinsic to how the Service works.

PLACEHOLDER: the list of providers, where each processes data, whether any zero-retention or no-training terms are in place, and links to their policies.

5. Why we process your data

PLACEHOLDER: the purposes and, where applicable, the lawful bases — performing the contract, legitimate interests, consent, and legal obligation.

6. Sharing

Content you place in a shared project is visible to the other members of that project according to their role. Beyond that, we share data with the processors needed to run the Service — hosting, model providers and payment processing. PLACEHOLDER: the processor list, and the position on legal disclosure requests.

7. International transfers

PLACEHOLDER: where data is hosted and processed, and the transfer mechanism relied on where data leaves that region.

8. Retention

PLACEHOLDER: how long content, derived artifacts, backups, usage records and logs are kept, both during an active account and after deletion.

9. Security

PLACEHOLDER: encryption in transit and at rest, access controls, key handling and the breach notification process.

Two design properties are worth stating regardless of the final wording: access restrictions on documents are applied before material is assembled into a model request rather than filtered out of a response afterwards; and your documents are stored as ordinary files, so an export is a copy of what is actually there.

10. Your rights

Depending on where you live, you may have rights to access, correct, export, restrict or delete your data, and to object to certain processing. PLACEHOLDER: how to exercise each right, response times, and the supervisory authority you may complain to.

Deletion is described in detail at Account & Data Deletion.

11. Children

PLACEHOLDER: minimum age and the position on accounts for minors.

12. Cookies and similar technologies

PLACEHOLDER: which cookies are set, whether any are non-essential, and how consent is handled if so.

13. Changes to this policy

PLACEHOLDER: how changes are notified and when they take effect.

14. Contact

PLACEHOLDER: privacy contact address. See also Support.