Privacy Policy
Last updated: June 20, 2026
1. Information we collect
- Account data: email, password (hashed), plan, and settings you provide.
- Workspace data: the brands, competitors, prompts, and configuration you add, plus the AI responses we collect on your behalf.
- Billing data: handled by our payment processor (Stripe). We store a customer/subscription reference, not your full card details.
- Usage & technical data: log data, device/browser info, and product analytics to operate and improve the service.
- Integrations (optional): if you connect Google Search Console / GA4 or WordPress, we store the access tokens you authorize, encrypted at rest.
2. How we use it
To provide and secure the service, run your tracking against third-party AI engines, process payments, send transactional email (verification, password reset, receipts, alerts you opt into), provide support, and improve the product. We do not sell your personal data.
3. Third parties & sub-processors
We share the minimum data needed with the service providers below. Each is contractually bound to process it only to provide their service to us, and we do not sell your personal data.
- Fly.io: application hosting & compute (US/Canada region).
- MongoDB Atlas: managed database storing your prompts and the AI responses we collect.
- Stripe: payment processing & subscription billing (we store a customer/subscription reference, not card numbers).
- AI engine providers (OpenAI, Anthropic, Google, Perplexity): run your tracking prompts; they receive the prompt text, not your account or billing details.
- Transactional email provider: sends verification, password-reset, receipt and opt-in alert emails.
- Google Analytics 4 & PostHog: privacy-respecting product analytics (aggregate usage, identified by a random id, never your email).
Enterprise self-hosting customers run llemmy in their own environment with their own AI keys, which narrows this list to the providers they choose. A current sub-processor list is available to customers on request.
4. Security
We use encryption in transit and encrypt sensitive credentials (LLM/provider keys, integration tokens) at rest. Access is scoped per tenant. No system is perfectly secure, but we work to protect your data and will notify you of material breaches as required by law.
5. Data retention
We keep your data while your account is active and for a reasonable period afterward, then delete or anonymize it. Some records may be retained longer where required for legal, tax, or security reasons. Self-hosting customers control their own retention.
6. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can manage much of this in your account settings or by contacting us. We honor applicable privacy laws (e.g. GDPR/CCPA) where they apply.
7. Cookies
We use essential cookies for authentication and session management, and limited analytics to understand product usage. You can control non-essential cookies through your browser.
8. International transfers
We may process data in countries other than yours. Where required, we use appropriate safeguards for cross-border transfers.
9. Changes & contact
We may update this policy; material changes will be communicated through the service or by email. For privacy questions or requests, contact us via the contact page. See also our Terms of Service.