Legal

Privacy Policy

What we collect, why we collect it, exactly who else touches it, and how to make us delete it.

Version: draft 0.1Last updated: 31 July 2026Status: not yet in force

Who is responsible for your data

LimePipe is the controller of the personal data described on this page — it decides why and how the data is used. The controller's legal name and registered address are [[LEGAL ENTITY DETAILS — TO BE CONFIRMED]] and will be published on the Contact page once confirmed.

Controller details to complete
Privacy contact
hello@limepipe.io [[DEDICATED PRIVACY INBOX? — TO BE CONFIRMED]]
EU / UK representative
[[ARTICLE 27 REPRESENTATIVE — REQUIRED IF NON-EU ENTITY SERVES EU USERS — PENDING LEGAL REVIEW]]
Data protection officer
[[DPO REQUIRED? — LAWYER TO ADVISE — LIKELY NOT AT THIS SCALE]]

This policy covers the limepipe.io website, the waitlist, and the LimePipe application. It does not cover third-party sites we link to.

What we collect

Information you give us

  • Waitlist. Your email address, and the time you submitted it.
  • Account data. Your name, email address, password (stored only as a salted hash — we never see it), and organisation name where relevant.
  • Billing data. Your billing name, billing address, country, tax identifiers where applicable, and a record of your plan, invoices and payment status. We do not receive or store your full card number — card details go directly to our payment provider.
  • Content. The prompts and instructions you write, files you upload, documents the Service generates for you, and any brand or reference material you save. This content may itself contain personal data, and if it does, you decide what goes in.
  • Support and correspondence. Emails and messages you send us, including anything you attach to them.

Information collected automatically

  • Technical data. IP address, browser and device type, operating system, language, and timestamps.
  • Usage data. Which features you use, documents generated, generation volume and errors, so we can bill correctly, enforce plan limits and fix faults.
  • Server logs. Requests to our servers, kept for security, troubleshooting and abuse prevention.
Confirm the analytics answer

[[ANALYTICS / ERROR TRACKING TOOLS IN USE — TO BE CONFIRMED]] If any product analytics, session-recording or error-tracking service is added (for example Plausible, PostHog, Google Analytics or Sentry), it must be named here and in the processor table below, and the cookie section must be updated to match. As drafted, this page states that no third-party analytics or advertising trackers are used — do not publish that claim if it is not true.

What we do not collect

We do not buy personal data from data brokers, we do not build advertising profiles, and we do not knowingly collect special category data (health, biometrics, political opinions, and so on). Please do not upload special category data unless you have a lawful basis for doing so.

Why we use it, and our legal basis

The "legal basis" column uses UK/EU GDPR terminology. If the operating entity is outside the UK/EU, the equivalent local framework applies — [[APPLICABLE PRIVACY LAW — DEPENDS ON JURISDICTION — PENDING LEGAL REVIEW]].

PurposeData usedLegal basis
Providing the Service — generating, storing and exporting your documentsAccount data, content, technical dataPerformance of a contract
Billing and tax — taking payment, issuing invoices, keeping recordsBilling data, usage dataPerformance of a contract; legal obligation
Support — answering your questions and fixing faultsCorrespondence, account data, relevant contentPerformance of a contract; legitimate interests
Security and abuse prevention — rate limiting, fraud and misuse detectionTechnical data, usage data, logsLegitimate interests (protecting the Service and its users)
Improving the product — aggregate and de-identified usage statisticsUsage dataLegitimate interests
Service emails — receipts, security notices, changes to termsAccount data, billing dataPerformance of a contract; legal obligation
Waitlist and marketing emailEmail addressConsent (you asked to join; unsubscribe any time)
Legal claims and complianceWhatever is relevantLegal obligation; legitimate interests

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time (see section 7).

How your content is processed by AI

This is the part most people care about, so it gets its own section.

  • When you ask the Service to generate or edit a document, your prompt and the relevant parts of your content are sent to a large language model provider so the request can be answered. That transmission is what makes the product work.
  • The providers we may route requests to are named in the processor table below. Which provider handles a given request depends on the task and on availability.
  • Providers process the content to return a response, and typically retain it for a short period for abuse monitoring before deleting it. Retention periods are set by each provider.
  • Calculations, formula evaluation and document assembly happen on our own systems, not at the model provider.
The training question — confirm before publishing

[[MODEL TRAINING POSITION — TO BE CONFIRMED]] The intended statement is: "Your content is not used to train AI models. We use provider API tiers and contractual terms under which submitted data is excluded from model training." Verify this against each provider's actual API terms and account settings before publishing it. This is a promise customers will rely on and regulators will test.

Third parties who process data for us

We use a small number of service providers. Each one is contractually required to process data only on our instructions and to keep it secure. We do not sell personal data, and we do not share it for advertising.

ProviderWhat it doesData involvedLocation
VercelWebsite and application hosting, CDN, request logsTechnical data, request logs, anything transmitted to the appUnited States and global edge network
SupabaseDatabase, authentication and file storageAccount data, content, uploaded and generated files[[SUPABASE PROJECT REGION — TO BE CONFIRMED]]
MailerLiteWaitlist and marketing email deliveryEmail address, subscription status, email engagementEuropean Union / United States
AnthropicLarge language model — document generation and editingPrompts and the content needed to answer themUnited States
OpenAILarge language model and text embeddings for document searchPrompts, content, embeddingsUnited States
OpenRouterRouting layer that forwards requests to model providersPrompts and the content needed to answer themUnited States
[[PAYMENT PROVIDER — STRIPE / PADDLE / RAZORPAY — TO BE CONFIRMED]]Payment processing, invoicing, and possibly merchant of recordBilling data, card data (held by them, not by us), transaction recordsDepends on provider
Keep this table true

[[FINAL PROCESSOR LIST — TO BE CONFIRMED]] The AI providers listed reflect the models the product can route to. Remove any that are not actually in production, and add any that are (including analytics, error tracking, customer support tooling and file conversion services). Payment providers check this table against what your site actually loads.

We may also disclose data to professional advisers, or to authorities where we are legally required to. If our business is sold or merged, data may transfer to the acquirer, who will remain bound by this policy or give you notice of a replacement.

How long we keep it

DataKept for
Account dataWhile your account is open, then deleted within [[30 DAYS? — TO BE CONFIRMED]] of closure
Your content and generated documentsUntil you delete it, or until your account is closed and the export window has passed — see the Refunds policy
BackupsRolling backups overwritten within [[BACKUP RETENTION WINDOW — TO BE CONFIRMED]]
Billing and tax recordsAs long as tax law requires — commonly 6–8 years. [[STATUTORY PERIOD — DEPENDS ON JURISDICTION]]
Server and security logs[[LOG RETENTION — TO BE CONFIRMED]]
Waitlist email addressUntil you unsubscribe, or until the waitlist is retired
Support correspondence[[SUPPORT EMAIL RETENTION — TO BE CONFIRMED]]

When a retention period ends we delete the data or irreversibly de-identify it.

Your rights

Subject to your local law, you can ask us to:

  • Access — give you a copy of the personal data we hold about you.
  • Correct — fix data that is wrong or incomplete.
  • Delete — erase your data, where we have no overriding legal reason to keep it (tax records, for example, we must keep).
  • Port — provide your data in a structured, machine-readable format, or send it to another provider. Your documents can also be exported directly from the Service at any time in their native file formats.
  • Restrict or object — pause processing, or object to processing based on legitimate interests.
  • Withdraw consent — for anything based on consent, such as marketing email. Every marketing email has a one-click unsubscribe link.

To exercise any of these, email hello@limepipe.io. We will respond within 30 days, and will ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

You also have the right to complain to a data protection authority. The right authority depends on where you live and where we are established — [[SUPERVISORY AUTHORITY — DEPENDS ON JURISDICTION — PENDING LEGAL REVIEW]].

If you are in California

We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives for personal information. You have the right to know, delete, correct, and to be free from discrimination for exercising those rights. [[CONFIRM CCPA APPLICABILITY THRESHOLDS WITH COUNSEL]]

Cookies and local storage

We keep this deliberately small.

WhatPurposeType
Session / authentication cookieKeeps you signed in and protects against cross-site request forgeryStrictly necessary
Theme preferenceRemembers whether you chose the light or dark version of these pages. Stored in your browser's local storage, never sent to usStrictly necessary / preference

As drafted, this site uses no advertising cookies and no third-party tracking pixels, which is why you are not being shown a consent banner. Strictly necessary cookies do not require consent. If any analytics or marketing tag is ever added, a consent mechanism must be added at the same time and this section updated — [[COOKIE POSITION — RE-CONFIRM AT LAUNCH]].

You can block or delete cookies in your browser settings, but the Service will not be able to keep you signed in without the session cookie.

International transfers

Our providers operate internationally, so your data may be transferred to and processed in countries other than your own — in particular the United States. Where personal data moves out of the UK, EEA or another region with transfer restrictions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the provider's certification under an approved framework.

Transfer mechanism depends on where the entity sits

Home jurisdiction: [[GOVERNING LAW JURISDICTION — TO BE CONFIRMED]]. The correct transfer mechanism, and whether a transfer impact assessment is needed, cannot be stated until that is fixed — [[TRANSFER MECHANISM — PENDING LEGAL REVIEW]]. If the entity is in India, the DPDP Act rules on cross-border transfer apply instead of the GDPR mechanism described above and this section must be rewritten.

You can ask us for details of the safeguards in place by emailing hello@limepipe.io.

How we protect it

  • Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting and database providers.
  • Customer workspaces are isolated at the database level, so one organisation's data is not reachable from another's.
  • Passwords are stored only as salted hashes.
  • Access to production systems is limited to people who need it.
  • The application is tested automatically before release, including security review of changes.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant authority and, where required, you — without undue delay and in any event within the period your law requires.

Children

The Service is for adults and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email hello@limepipe.io and we will delete it.

Changes to this policy

We will update this page when our practices change. If a change is material — a new category of data, a new purpose, or a new processor handling your content — we will tell you by email or in the Service before it takes effect. The last-updated date is at the top of this page.

Privacy requests and contact

Privacy requests

hello@limepipe.io

Access, deletion, correction, portability, objection.

Please put "Privacy request" in the subject line so it is routed correctly. See the Contact page for other enquiries and the postal address, once confirmed.