Skip to content

Privacy Policy

What personal data LiteSurface collects, why, who receives it, how long we keep it, and the rights you have over it.

Effective
September 24, 2026
Last updated
September 24, 2026
Version
1.1 (early access)
On this page
  1. Who we are and what this covers
  2. Our role: controller or processor
  3. Personal data we collect
  4. Website measurement and sign-up attribution
  5. Product updates list
  6. Where the data comes from
  7. How we use data and our legal bases
  8. How we share data
  9. International transfers
  10. How long we keep data
  11. How we protect data
  12. Your rights
  13. Children
  14. Emails we send
  15. Changes to this policy
  16. Contact and supervisory authority

1.Who we are and what this coversLink to section 1

LiteSurface, Inc. (“LiteSurface,” “we,” “us”) provides LiteSurface, a product-discovery decision system for teams, and operates this website. Our address is [Registered address to be confirmed].

This Privacy Policy explains how we handle personal data when you visit our website, create an account, use the Service, or communicate with us. Terms such as “Service,” “Customer Content,” and “workspace” have the meanings given in our Terms of Service.

2.Our role: controller or processorLink to section 2

2.1When we are the controllerLink to clause 2.1

We decide how and why personal data is processed, and so act as a controller (or “business” under California law), for account and sign-in data, billing and support records, security and service logs, usage and cost telemetry, website visits, and our communications with you.

2.2When we are a processorLink to clause 2.2

Customer Content, including any personal data inside it (for example, names in interview notes or in a source you add), is processed on behalf of the customer that owns the workspace. For that data we act as a processor (or “service provider”), the customer is the controller, and our Data Processing Addendum applies. If your data is in a customer’s workspace, that customer’s privacy notice explains its practices, and requests should go to it first.

3.Personal data we collectLink to section 3

3.1Account and identity dataLink to clause 3.1

Your name, email address, whether your email is verified, and a securely hashed password if you set one (we never store passwords in readable form). If you sign in with Google or GitHub, we receive your name, email address, profile image URL, and an account identifier from that provider. We also store your workspace and project memberships, roles, and invitations, including the email addresses of people invited.

3.2Customer ContentLink to clause 3.2

Objectives, strategy profiles, capability selections, sources (URLs, pasted text, and the text of pages fetched at your direction), extracted claims and observations, concepts and their versions, evaluations and scores, assumptions, experiments and outcomes, decisions and notes, artifacts, and exports. It contains personal data only if you or your colleagues include it. We process it as a processor, as described above.

3.3Usage, cost, and AI telemetryLink to clause 3.3

For each AI call we record the provider, model, task, prompt version, token counts, latency, estimated cost, status and error codes, and a hash of the input. The usage ledger records model, search, and fetch usage against workspace and project budgets. We record run progress and in-app notifications. We do not write raw prompts or raw model responses to our logs by default.

3.4Security and service logsLink to clause 3.4

Session records (IP address, browser user agent, and timestamps), an append-only audit log of significant actions in a workspace (who acted, what changed, request identifier, and IP address), rate-limiting counters, and application logs. Logs are redacted so they do not contain API keys, session tokens, signed download links, or full private documents.

3.5CommunicationsLink to clause 3.5

Messages you send to us, and delivery information for emails we send you, such as whether a sign-in link or invitation was delivered.

3.6Billing dataLink to clause 3.6

When paid plans are available, billing contact details, plan, seats, and invoice history. Card details are collected by our payment processor; we do not store full card numbers.

3.7Website visitsLink to clause 3.7

This website uses no cookies and no third-party analytics, advertising, or tracking pixels. It counts visits with anonymous, first-party events that carry no identifier, and keeps where your visit came from in session storage for sign-up links; both are described in Website measurement and sign-up attribution. Our hosting provider processes standard server logs (IP address, user agent, requested page, and time) to deliver the site and protect it from abuse.

3.8Cookies and local storageLink to clause 3.8

The apps use strictly necessary sign-in cookies and store appearance preferences in your browser. This website uses session storage only, cleared when you close the tab. See the Cookie Policy for the full list.

4.Website measurement and sign-up attributionLink to section 4

We want to know which pages help people decide, without knowing who they are. So this website counts a few events, first-party and without cookies: a page view, a click on a sign-up or other call-to-action link, use of the scorecard demo, viewing the sample evaluation, submitting the updates form, and clicking an email address.

  • What an event contains: the event name, the page path without any query string, the referring website’s host name (on the first page of a visit only), the campaign parameters of the link you arrived by (utm_source, utm_medium, utm_campaign, utm_term, utm_content), and for clicks, which link, where on the page, where it leads, and the plan chosen.
  • What it does not contain: cookies, device or user identifiers, your IP address, your user agent, anything you type into a form, or anything that lets us join events into a profile. Each event goes to this website’s own server, which forwards it to our database without your IP address or user agent.
  • Sign-up attribution: on the first page of a visit, your browser keeps the campaign parameters, a ref code if the link had one, and the referring host in session storage (if.attribution). When you click a link to sign up, they are added to the sign-up address. If you then create an account, the sign-up page saves them with your account, together with the plan and the link you chose, so we know which page or campaign led to sign-up.
  • Your choice: if your browser sends Global Privacy Control or Do Not Track, we send no events and store no attribution. Automated browsers are skipped too.
  • Legal basis and retention: our legitimate interest in understanding, in aggregate, how visitors use this website and where sign-ups come from. Events are kept for up to 24 months and then deleted.

5.Product updates listLink to section 5

If you enter your email address in a product-updates form on this website, we store the address, the page you subscribed from, and when you subscribed, confirmed, or unsubscribed. We first send one confirmation email; you are added only after you click its link (double opt-in). Updates arrive about once a month, and every one has a one-click unsubscribe link.

We use the address only to send product updates, through our email delivery provider (see Subprocessors). Our legal basis is your consent, which you can withdraw at any time by unsubscribing. Addresses that are never confirmed are deleted after 30 days. After you unsubscribe we keep the address, marked unsubscribed, so we can honour that choice; write to privacy@litesurface.com to have it deleted entirely.

6.Where the data comes fromLink to section 6

  • From you, when you create an account, fill in your profile, add content, or contact us.
  • From your organization, when a workspace owner or admin invites you or assigns you a role.
  • Automatically, from your use of the Service and our website.
  • From sign-in providers, such as Google or GitHub, if you choose to use them.
  • From public sources, when you ask the Service to fetch a web page or run research. That content becomes part of Customer Content.

7.How we use data and our legal basesLink to section 7

We use personal data for the purposes below. Where the EU or UK General Data Protection Regulation (“GDPR”) applies, we rely on the legal basis listed.

Purposes of processing and legal bases
PurposeData usedLegal basis (GDPR)
Provide the Service, including accounts, workspaces, roles, and sharingAccount data, Customer Content, membershipsPerformance of a contract; for users invited by a customer, our and the customer’s legitimate interest in providing the service it purchased
Sign you in and keep your session secureAccount data, session records, cookiesPerformance of a contract; legitimate interests in security
Send sign-in links, verification, password reset, invitations, and notificationsName, email address, notification contentPerformance of a contract
Run AI tasks and research on the customer’s instructionsCustomer ContentProcessed as a processor on the customer’s instructions; the customer determines the legal basis
Meter usage, enforce budgets, and billUsage and cost telemetry, billing dataPerformance of a contract; legal obligations for tax and accounting records
Protect the Service, prevent abuse, and keep an audit trailLogs, audit events, session recordsLegitimate interests in security and accountability; legal obligations
Provide supportAccount data, communications, relevant logsPerformance of a contract; legitimate interests
Improve reliability and performanceAggregated, de-identified telemetry (never Customer Content)Legitimate interests in improving the Service
Send product updates to business contactsName, email addressLegitimate interests, or consent where the law requires it; you can opt out at any time
Send product updates to people who subscribe on this websiteEmail address, source page, subscription datesConsent (double opt-in); withdraw at any time by unsubscribing
Count website visits and see which pages and campaigns lead to sign-upAnonymous website events; campaign parameters and referring host passed with a sign-upLegitimate interests in understanding, in aggregate, how the website is used
Comply with law and enforce our agreementsAny relevant dataLegal obligations; legitimate interests in establishing or defending legal claims

We do not use Customer Content to train or fine-tune AI models. We do not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. Scores in the Service evaluate product concepts, not people.

8.How we share dataLink to section 8

8.1Subprocessors and service providersLink to clause 8.1

We use vendors for hosting, database, object storage, email delivery, web search, and AI inference. They may process personal data only on our instructions and under written terms. The current list, with each vendor’s purpose and location, is on the Subprocessors page.

8.2AI providersLink to clause 8.2

AI tasks send the parts of Customer Content needed for the task to the providers your workspace allows (currently OpenAI and Anthropic). Fields classified as sensitive and not for models are removed first. When a workspace uses its own provider keys, the provider processes that data under the customer’s own agreement with it.

8.3Web search and fetchingLink to clause 8.3

Research sends search queries derived from your project to our search provider. Fetching a page you add sends a request from our servers to that website, identified by our crawler’s user agent; it does not include your personal data.

8.4Within your workspaceLink to clause 8.4

Other members of a workspace or project can see content and activity according to their role. If a project is transferred, its data moves to the receiving workspace.

8.5Legal, safety, and corporate eventsLink to clause 8.5

We may disclose data to comply with law or valid legal process, to protect the rights, safety, or property of any person, to our professional advisers under confidentiality, or to a successor in a merger, acquisition, or sale of assets, subject to this policy.

8.6No sale, no sharing for advertisingLink to clause 8.6

We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the past 12 months.

9.International transfersLink to section 9

We are based in the United States, and our subprocessors may process data in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we use the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss equivalents, together with supplementary measures where appropriate.

You can request a copy of the relevant transfer terms by writing to privacy@litesurface.com.

10.How long we keep dataLink to section 10

We keep personal data only as long as needed for the purposes above. Default periods:

Retention periods
DataRetention
Account dataFor the life of the account, then deleted within 30 days of account deletion, except where we must keep records by law
Customer ContentUntil the customer deletes it or the workspace, or as described in the Terms after the agreement ends
Soft-deleted itemsRecoverable for 30 days, then purged
Raw text of fetched pagesMay be limited to 90 days by configuration, while extracted claims and source details remain
Export files7 days unless pinned; signed download links last minutes
Real-time run eventsUp to 24 hours
Application logs30 days; longer only as aggregated metrics without personal payloads
Audit log, AI call metadata, usage ledgerFor the life of the workspace, for accountability and billing
Deletion recordsKept without any deleted content, as proof of deletion
Website measurement eventsUp to 24 months, then deleted
Product-updates subscribersUnconfirmed addresses deleted after 30 days; confirmed addresses until you unsubscribe, then kept only as an unsubscribed record unless you ask us to delete it
BackupsRolling backups that expire in the normal course

11.How we protect dataLink to section 11

Our safeguards include:

  • encryption in transit (TLS) and encryption at rest provided by our infrastructure;
  • workspace and project scoping on every data access, with authorization checked on the server, and automated tests that attempt cross-tenant access;
  • HttpOnly, Secure session cookies and role-based access;
  • secrets kept in a secrets manager and redacted from logs, and provider keys never sent to browsers;
  • protections in the web fetcher against requests to private or internal networks, and size and time limits;
  • short-lived signed links for downloads, and an append-only audit log; and
  • regular database backups and restore testing.

No system is perfectly secure. We do not currently hold third-party security certifications. Report a suspected vulnerability to security@litesurface.com.

12.Your rightsLink to section 12

12.1EveryoneLink to clause 12.1

You can view and update your account details in the Service, export project data, and ask us to delete your account. You can also ask us what personal data we hold about you.

12.2EEA, UK, and Swiss residentsLink to clause 12.2

You have the right to access, correct, delete, or port your personal data, to restrict or object to its processing (including processing based on legitimate interests and direct marketing), and to withdraw consent at any time where we rely on it. You also have the right to complain to a supervisory authority (see Section 14).

12.3California and other US state residentsLink to clause 12.3

Under the California Consumer Privacy Act as amended by the CPRA, and similar state laws, you have the right to know what personal information we collect, use, and disclose; to access, correct, and delete it; to opt out of its sale or sharing (we do not sell or share it); to limit the use of sensitive personal information (we use it only as permitted, for example to secure your account); and not to be treated differently for exercising these rights. You may use an authorized agent.

In the past 12 months we collected these categories: identifiers (such as name, email, IP address); commercial information (plan and billing records); internet activity (usage and log data); professional information (workspace, role); and the content you submit. We collect them from the sources in Section 4, for the purposes in Section 5, and disclose them for business purposes to the service providers in Section 6. We treat browser Global Privacy Control signals as a request to opt out of sale or sharing.

12.4Data in a customer’s workspaceLink to clause 12.4

If your request concerns Customer Content, we will refer you to the customer that controls it, and help that customer respond.

12.5How to make a requestLink to clause 12.5

Email privacy@litesurface.com. We will verify your identity, usually by confirming control of your account email, and respond within one month (GDPR) or 45 days (California), extendable where the law allows. Requests are free unless they are manifestly unfounded or excessive.

13.ChildrenLink to section 13

The Service is for business use by adults. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact privacy@litesurface.com and we will delete it.

14.Emails we sendLink to section 14

Service emails, such as sign-in links, verification, password resets, invitations, security notices, and reminders you have set up, are part of the Service. Where offered, you can adjust notification preferences in the Service. Product update emails include a one-click unsubscribe link; see Product updates list.

15.Changes to this policyLink to section 15

We will post any update here with a new “Last updated” date. If a change materially affects how we use personal data, we will give notice by email or in the Service before it takes effect, and record it in the changelog.

16.Contact and supervisory authorityLink to section 16

Contact our privacy team at privacy@litesurface.com, or write to LiteSurface, Inc., [Registered address to be confirmed].

If you are in the EEA, you can complain to the data protection authority in your country of residence, work, or the place of an alleged infringement. In the UK, the authority is the Information Commissioner’s Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first.

Where the law requires us to appoint a representative in the EU or UK, we will list their contact details here.

Questions about this document

Write to legal@litesurface.com for legal questions or privacy@litesurface.com for privacy requests. Postal notices go to LiteSurface, Inc., [Registered address to be confirmed].