Loading Lithora...
Please wait
Loading Lithora...
Please wait
Version 2026-08-02 · Last updated 2 August 2026
What we collect, who processes it, where it goes and what you can do about it. Nothing non-essential runs on this website until you allow it, and we do not sell personal data or train AI models on your content.
This page — lithora.app/privacypolicy — is the authoritative copy of this document. Any version of it shown elsewhere, including inside the Lithora app, links here; if the two ever differ, this page governs.
Lithora (“we”, “our”, “us”) provides a work platform for engineering-led teams. This policy explains how we collect, use, disclose and safeguard information when you visit this website or use the Service. Where you use Lithora through your employer’s workspace, your employer is the controller of the content in that workspace and we act as its processor.
We use the information above to:
For visitors in the EEA and UK, our legal bases are: performance of a contract (providing the Service), legitimate interests (security, abuse prevention, and the in-product usage measurement described in section 6), consent (analytics on this marketing website, and marketing email) and legal obligation (tax and accounting records). You can object to anything we do on the basis of legitimate interests — see section 9.
Lithora’s AI features — drafting, decomposition, summarisation, review and the agent — run on Amazon Bedrock, operated by Amazon Web Services, Inc. The models used are from the Amazon Nova family and inference is performed in the AWS us-east-1 region, in the United States.
We share information only in these circumstances:
We do not sell personal information and we do not share it for cross-context behavioural advertising.
These providers process customer data on our behalf. Each is bound by a data processing agreement; transfers out of the EEA or UK rely on Standard Contractual Clauses. The full register — what each one receives, why, and where it runs — is published at lithora.app/subprocessors, and that page governs if this summary falls behind it.
Separately, the Service connects to third-party platforms youauthorise — GitHub, GitLab, Bitbucket, Jira, Linear, Slack, Discord, Notion, Figma, Google Drive, Microsoft Teams, Vercel, Cloudflare and others. Those are independent controllers governed by their own privacy policies, and data flows to them only for the integrations you switch on and only within the scopes you grant. You can revoke a connection at any time from Settings → Integrations.
We apply technical and organisational measures appropriate to the risk:
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach affects you, we will notify you and the relevant supervisory authority as required by law.
We keep your data for as long as your account is active or as needed to provide the Service. When you delete your account we delete your personal data within 30 days, except where we must retain records for legal, tax or accounting purposes. Backups containing deleted data expire on their normal rotation.
You can ask us to:
Email support@lithora.io and we will respond within 30 days. Exercising these rights never costs you access to the Service.
This website sets two kinds of cookie, and only one of them needs your permission.
lithora_consent, six months). These are exempt from consent because the site cannot work without them._ga, _ga_*), used to count visits and see which pages help people understand the product.Nothing analytics-related loads until you say yes.Until you accept, the Google tag is not downloaded at all — there is no request to Google and no analytics cookie. Consent Mode is set to deny storage by default for every visitor, with no region-based exception. We set no advertising cookies and run no ad networks.
If your browser sends a Global Privacy Control signal (or the older Do Not Track header), we treat it as a standing refusal and never ask again unless you opt in yourself.
You can change your decision whenever you like — from the “Cookie preferences” control in the footer of any page, or right here:
Declining, or withdrawing after accepting, also deletes the analytics cookies already stored on your device. Browser settings remain available to you as well, but they are not the mechanism we rely on for consent.
The Service is not intended for anyone under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us and we will delete it.
Lithora’s core infrastructure is located in the United States (AWS us-east-1, MongoDB Atlas), so if you are in the EEA, the UK or Switzerland, using the Service transfers your information there. Two processors sit elsewhere: error reporting is handled in the European Union, and demo bookings are handled in India. All of it is set out per provider on the sub-processor page. These transfers are made under the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), supported by encryption in transit and at rest and the access controls described in section 7. A copy of the relevant clauses is available on request. We do not offer a data-residency guarantee— there is no EU-only or region-pinned deployment of Lithora.
We may update this policy. Every change ships with a new version string and date at the top of this page, and material changes are announced by email or in the Service before they take effect.
If you are in the European Economic Area, the United Kingdom or Switzerland you also have the right to:
California residents have the right to:
Questions about this policy, or a request to exercise any of the rights above:
We respond within 30 days.