Privacy Policy

Last updated: 8 September 2026

1. Who we are

Digiscope bv (Antwerp, Belgium) is the data controller for laimonade.com. Questions about this policy, or any request about your data, go to support@laimonade.com.

2. What we collect

What you give us

  • Your name, email address and profile image, through our authentication provider. We never receive your password — credentials are held and verified by Clerk.
  • Everything you put into a project: backlog items, roadmaps, sprints, files you attach, and your conversations with Laimon.
  • Billing contact details, when you subscribe. Card numbers go to Stripe and never reach us.
  • Anything you send us by email or through the contact form.

What we collect automatically

  • Standard request data — IP address, browser and device type — in server and CDN logs.
  • Product analytics, only if you accept analytics cookies. See section 5.
  • Records of what Laimon did on your behalf, and how many AI credits it used.

3. AI processing

This is the section most worth reading, because it is what the product is. Laimonade is built on large language models, and using it means your project content is sent to a model provider.

  • What is sent: the backlog items, roadmap context and messages relevant to the request being made — for example, the items on your board when you ask Laimon to groom them. Item titles and descriptions are also sent to an embeddings provider so similar items can be found.
  • When: at the moment a request is made, whether by you or by Laimon acting on its schedule. Nothing is sent in bulk and nothing is sent in advance.
  • Who: xAI, and Mistral for projects configured to use it. Embeddings go to Voyage AI. All three are listed in section 4.
  • What we do not do: we do not train any model on your content, and we do not use one customer’s content to answer another customer’s request. Every request is scoped to a single project.

What each provider does with an API request is governed by that provider’s own terms and our data-processing agreement with them. We name the providers in section 4 rather than paraphrase their policies here, because a paraphrase of someone else’s terms goes stale without anyone noticing.

4. Who else processes your data

These are every third party that receives customer data, and what each one is for. The first group applies to every account; the second only if you turn that feature on.

Always

ProcessorWhat forWhat it receives
ClerkAuthentication and session managementName, email address, profile image, sign-in metadataPasswords are never held by us — Clerk stores and verifies credentials.
MongoDB AtlasPrimary databaseAll project content: backlog items, roadmaps, sprints, conversations with Laimon
Fly.ioApplication hostingAll request traffic in transitPrimary region Frankfurt (fra).
HetznerObject storage for uploaded filesAttachments you or Laimon add to itemsFalkenstein, Germany.
CloudflareCDN, DNS and hosting for the marketing site and app shellRequest metadata, including IP address
xAIAILarge language model — the reasoning behind LaimonBacklog content, roadmap context and your messages to Laimon, at the moment a request is made
Voyage AIAIText embeddings, used to find semantically similar itemsItem titles and descriptions
StripePayments and subscription managementBilling contact and payment details — card numbers are handled by Stripe and never reach us
ResendTransactional emailEmail address and message content for the mail being sent

Only if you enable it

ProcessorWhat forWhat it receives
MistralAIAlternative large language model, enabled per projectThe same content as above, when a project is configured to use it
PostHogProduct analyticsPageviews, feature usage and identified user id, after consentEU cloud (eu.i.posthog.com). Loaded only if you accept analytics cookies.
GitHubReading commits and pull requests for a connected repositoryRepository metadata, commit messages and CI resultsOnly if you install the GitHub app.
TogglReading tracked time for a connected Toggl workspaceTime entries and workspace metadataOnly if you connect a Toggl account. There is no UI for this yet; the connection is made through the API.
SlackDelivering and receiving messages in a connected workspaceMessages exchanged with Laimon, and files you share with itOnly if you connect a Slack workspace.

We will update this list before adding a processor that receives customer content. Beyond these, we share data only with your consent, to meet a legal obligation, or as part of a merger or sale of the business — in which case this policy travels with it.

5. Cookies and analytics

Analytics load only after you accept them. Until then no analytics cookie is set — the consent choice is checked before the analytics client starts, not after. Declining, or withdrawing later, stops collection and clears the cookies it set.

  • Our analytics provider is PostHog, on its EU cloud.
  • Session recording is off. We do not record your screen, your mouse movements or your keystrokes.
  • Autocapture is off. We record named events we chose deliberately — pageviews and specific button clicks — rather than every interaction on the page.
  • A cookie recording your consent choice is set either way, because we have to remember that you answered.

Our Cookie Policy lists the individual cookies.

6. How long we keep things

These periods are enforced by the database itself rather than by a policy someone has to remember: the records are removed when they expire.

WhatKept for
Project content — backlog items, roadmaps, sprints, conversationsUntil you delete it or close the account
AI usage records, used for credit accounting90 days
Records of a guard catching an incorrect claim by Laimon90 days
Sent-email records180 days
Application logs30 days
Error groupings30 days
Delivered development digests30 days
Platform anomaly records365 days

Deleting a project deletes its content. Backups are kept on a rolling window and expire with it.

7. Connecting an AI Assistant (MCP Connector)

Laimonade can be connected to an AI assistant such as Claude through our MCP connector, so that a coding agent can read the work in your project and hand finished work back for review. This section describes exactly what that connection does with your data. It applies only if you choose to connect one.

What the connection stores

  • An access token bound to one person and to the projects that person approved at sign-in. It is stored hashed, it expires, and refreshing it revokes the previous one.
  • One activity record for each action the assistant takes, holding the name of the action, whether it succeeded, an error code if it did not, how long it took, and a session identifier.

That record captures which action ran. It does not capture the conversation that led to it: we do not store your prompts, the assistant's replies, or any part of the discussion around the work.

What we never access

The connector does not read your AI assistant's memory, your chat history, your conversation summaries, or files you have uploaded to it. It has no mechanism to do so and never requests them.

What the assistant can reach

Only the projects you approved when you connected: their backlog items, sprints, roadmap and the project rules you have stored in Laimonade. A connection reaches nothing outside the projects granted at sign-in, and where more than one was granted, each request names the project it is for and each reply records the project that answered. You can change the granted set at any time.

How long it is kept

Tokens last until they expire or are replaced, and are revoked immediately when you disconnect. Removing someone from a project ends their connector access the next time their assistant refreshes, without any action on their part. Activity records are retained for operational and security review and are deleted with the project.

Who else sees it

The content of your backlog is sent to the AI assistant you connected, which is the point of connecting one — that assistant's own privacy policy governs what it does with what it receives. Laimonade separately uses AI providers to power its own features, described in section 4. We do not sell connector data or use it to train models.

Questions about the connector specifically can go to the contact address in section 12.

8. Your rights

Under the GDPR you can ask us to do any of the following, and we will answer within one month:

  • Access — a copy of the personal data we hold about you.
  • Rectification — correct anything inaccurate.
  • Erasure — delete your account and its content.
  • Portability — export your project data in a machine-readable form.
  • Objection and restriction — object to a particular use, or ask us to pause it.
  • Withdraw consent — for analytics, at any time, from the cookie banner.

Write to support@laimonade.com. You also have the right to complain to your local supervisory authority; in Belgium that is the Gegevensbeschermingsautoriteit.

9. Security and location

Traffic is encrypted in transit. Access to production data is limited to people who need it to run the service. Our application servers run in Frankfurt and uploaded files are stored in Germany. Some processors in section 4 operate outside the EEA; where they do, transfers rely on the European Commission’s standard contractual clauses.

10. Children

Laimonade is a tool for software teams and is not directed at children. We do not knowingly collect data from anyone under 16.

11. Changes

The date at the top changes when this document does, and every version is kept in our public repository history, so earlier text can be retrieved. We will tell account holders by email before a change that materially affects how their data is used.

12. Contact

Digiscope bv, Antwerp, Belgium — support@laimonade.com