Privacy Policy
Last updated: 8 September 2026
1. Who we are
Digiscope bv (Antwerp, Belgium) is the data controller for laimonade.com. Questions about this policy, or any request about your data, go to support@laimonade.com.
2. What we collect
What you give us
- Your name, email address and profile image, through our authentication provider. We never receive your password — credentials are held and verified by Clerk.
- Everything you put into a project: backlog items, roadmaps, sprints, files you attach, and your conversations with Laimon.
- Billing contact details, when you subscribe. Card numbers go to Stripe and never reach us.
- Anything you send us by email or through the contact form.
What we collect automatically
- Standard request data — IP address, browser and device type — in server and CDN logs.
- Product analytics, only if you accept analytics cookies. See section 5.
- Records of what Laimon did on your behalf, and how many AI credits it used.
3. AI processing
This is the section most worth reading, because it is what the product is. Laimonade is built on large language models, and using it means your project content is sent to a model provider.
- What is sent: the backlog items, roadmap context and messages relevant to the request being made — for example, the items on your board when you ask Laimon to groom them. Item titles and descriptions are also sent to an embeddings provider so similar items can be found.
- When: at the moment a request is made, whether by you or by Laimon acting on its schedule. Nothing is sent in bulk and nothing is sent in advance.
- Who: xAI, and Mistral for projects configured to use it. Embeddings go to Voyage AI. All three are listed in section 4.
- What we do not do: we do not train any model on your content, and we do not use one customer’s content to answer another customer’s request. Every request is scoped to a single project.
What each provider does with an API request is governed by that provider’s own terms and our data-processing agreement with them. We name the providers in section 4 rather than paraphrase their policies here, because a paraphrase of someone else’s terms goes stale without anyone noticing.
4. Who else processes your data
These are every third party that receives customer data, and what each one is for. The first group applies to every account; the second only if you turn that feature on.
Always
| Processor | What for | What it receives |
|---|---|---|
| Clerk | Authentication and session management | Name, email address, profile image, sign-in metadataPasswords are never held by us — Clerk stores and verifies credentials. |
| MongoDB Atlas | Primary database | All project content: backlog items, roadmaps, sprints, conversations with Laimon |
| Fly.io | Application hosting | All request traffic in transitPrimary region Frankfurt (fra). |
| Hetzner | Object storage for uploaded files | Attachments you or Laimon add to itemsFalkenstein, Germany. |
| Cloudflare | CDN, DNS and hosting for the marketing site and app shell | Request metadata, including IP address |
| xAIAI | Large language model — the reasoning behind Laimon | Backlog content, roadmap context and your messages to Laimon, at the moment a request is made |
| Voyage AIAI | Text embeddings, used to find semantically similar items | Item titles and descriptions |
| Stripe | Payments and subscription management | Billing contact and payment details — card numbers are handled by Stripe and never reach us |
| Resend | Transactional email | Email address and message content for the mail being sent |
Only if you enable it
| Processor | What for | What it receives |
|---|---|---|
| MistralAI | Alternative large language model, enabled per project | The same content as above, when a project is configured to use it |
| PostHog | Product analytics | Pageviews, feature usage and identified user id, after consentEU cloud (eu.i.posthog.com). Loaded only if you accept analytics cookies. |
| GitHub | Reading commits and pull requests for a connected repository | Repository metadata, commit messages and CI resultsOnly if you install the GitHub app. |
| Toggl | Reading tracked time for a connected Toggl workspace | Time entries and workspace metadataOnly if you connect a Toggl account. There is no UI for this yet; the connection is made through the API. |
| Slack | Delivering and receiving messages in a connected workspace | Messages exchanged with Laimon, and files you share with itOnly if you connect a Slack workspace. |
We will update this list before adding a processor that receives customer content. Beyond these, we share data only with your consent, to meet a legal obligation, or as part of a merger or sale of the business — in which case this policy travels with it.
5. Cookies and analytics
Analytics load only after you accept them. Until then no analytics cookie is set — the consent choice is checked before the analytics client starts, not after. Declining, or withdrawing later, stops collection and clears the cookies it set.
- Our analytics provider is PostHog, on its EU cloud.
- Session recording is off. We do not record your screen, your mouse movements or your keystrokes.
- Autocapture is off. We record named events we chose deliberately — pageviews and specific button clicks — rather than every interaction on the page.
- A cookie recording your consent choice is set either way, because we have to remember that you answered.
Our Cookie Policy lists the individual cookies.
6. How long we keep things
These periods are enforced by the database itself rather than by a policy someone has to remember: the records are removed when they expire.
| What | Kept for |
|---|---|
| Project content — backlog items, roadmaps, sprints, conversations | Until you delete it or close the account |
| AI usage records, used for credit accounting | 90 days |
| Records of a guard catching an incorrect claim by Laimon | 90 days |
| Sent-email records | 180 days |
| Application logs | 30 days |
| Error groupings | 30 days |
| Delivered development digests | 30 days |
| Platform anomaly records | 365 days |
Deleting a project deletes its content. Backups are kept on a rolling window and expire with it.
7. Connecting an AI Assistant (MCP Connector)
Laimonade can be connected to an AI assistant such as Claude through our MCP connector, so that a coding agent can read the work in your project and hand finished work back for review. This section describes exactly what that connection does with your data. It applies only if you choose to connect one.
What the connection stores
- An access token bound to one person and to the projects that person approved at sign-in. It is stored hashed, it expires, and refreshing it revokes the previous one.
- One activity record for each action the assistant takes, holding the name of the action, whether it succeeded, an error code if it did not, how long it took, and a session identifier.
That record captures which action ran. It does not capture the conversation that led to it: we do not store your prompts, the assistant's replies, or any part of the discussion around the work.
What we never access
The connector does not read your AI assistant's memory, your chat history, your conversation summaries, or files you have uploaded to it. It has no mechanism to do so and never requests them.
What the assistant can reach
Only the projects you approved when you connected: their backlog items, sprints, roadmap and the project rules you have stored in Laimonade. A connection reaches nothing outside the projects granted at sign-in, and where more than one was granted, each request names the project it is for and each reply records the project that answered. You can change the granted set at any time.
How long it is kept
Tokens last until they expire or are replaced, and are revoked immediately when you disconnect. Removing someone from a project ends their connector access the next time their assistant refreshes, without any action on their part. Activity records are retained for operational and security review and are deleted with the project.
Who else sees it
The content of your backlog is sent to the AI assistant you connected, which is the point of connecting one — that assistant's own privacy policy governs what it does with what it receives. Laimonade separately uses AI providers to power its own features, described in section 4. We do not sell connector data or use it to train models.
Questions about the connector specifically can go to the contact address in section 12.
8. Your rights
Under the GDPR you can ask us to do any of the following, and we will answer within one month:
- Access — a copy of the personal data we hold about you.
- Rectification — correct anything inaccurate.
- Erasure — delete your account and its content.
- Portability — export your project data in a machine-readable form.
- Objection and restriction — object to a particular use, or ask us to pause it.
- Withdraw consent — for analytics, at any time, from the cookie banner.
Write to support@laimonade.com. You also have the right to complain to your local supervisory authority; in Belgium that is the Gegevensbeschermingsautoriteit.
9. Security and location
Traffic is encrypted in transit. Access to production data is limited to people who need it to run the service. Our application servers run in Frankfurt and uploaded files are stored in Germany. Some processors in section 4 operate outside the EEA; where they do, transfers rely on the European Commission’s standard contractual clauses.
10. Children
Laimonade is a tool for software teams and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes
The date at the top changes when this document does, and every version is kept in our public repository history, so earlier text can be retrieved. We will tell account holders by email before a change that materially affects how their data is used.
12. Contact
Digiscope bv, Antwerp, Belgium — support@laimonade.com