Privacy & Data Protection Notice

This notice explains what personal data LiquidLM processes, why, on what legal basis, and the rights you have. It is written to satisfy both the Brazilian General Data Protection Law (LGPD, Lei nº 13.709/2018) and the EU General Data Protection Regulation (GDPR).

Who is responsible (controller)

The controller of your personal data is Carlos Eduard Medeiros de Souza Tecnologia da Informação LTDA (trading as LiquidLM), CNPJ 67.282.069/0001-26, registered at Rua Aquino Manoel Quintino 536, Apt 607 Torre 1, Floresta, Joinville/SC, CEP 89.212-180, Brazil. You can reach our data protection contact at [email protected].

What data we process

  • Account and identity data: the identifier and email from your sign-in (managed through our identity provider).
  • Content you add: files, notes, links, and recordings you upload to your vaults, plus the text, summaries, entities, and metadata extracted from them.
  • Usage and technical data: logs, audit events, quota and usage counters, and limited diagnostic information.
  • Billing data: for paid plans, payment and subscription identifiers handled by our payment processor (Stripe). We do not store full card details — Stripe processes payment data directly.

Why we process it and on what legal basis

We process your data to provide the service you ask for (performing our contract with you): indexing your sources, answering your queries, and operating your account. We process limited technical and security data on the basis of our legitimate interests in keeping the service secure and reliable, and where required, on the basis of your consent (for example, non-essential cookies).

Connected sources (connectors)

You can connect external sources — currently GitHub repositories — and have their content synced into your vaults. We fetch only the file contents of the repositories you select, index them like uploads, and keep them updated when the source changes; items removed at the source move to the vault's trash. We never store your GitHub password or personal tokens: access works through the GitHub App installation you grant, and uninstalling the app on GitHub revokes it. Disconnecting a source stops syncing immediately; already-synced content stays in your vault until you remove it, and then follows the normal trash and retention lifecycle. Connected platforms such as GitHub are sources you choose to read from — they are not sub-processors of ours.

Service providers (sub-processors)

We use a small set of providers to run the service. Each processes data only on our instructions:

  • Amazon Web Services (AWS) — compute, storage, and the indexing pipeline.
  • OpenAI — model inference for extraction, summaries, and answers.
  • DeepInfra — model inference for the open-weight models we use to build the search index and to rank results.
  • Cloudflare — content delivery, DNS, and security/anti-abuse.
  • Amazon SES — transactional email (account, sign-in, and invitation emails).
  • Stripe — payment processor for paid plans (handles checkout, subscriptions, and the customer portal).
  • Google Analytics (Google) — consent-gated, aggregate usage measurement; loads only after you opt in and is off by default.

International transfers

Some providers process data outside your country. Where that happens, we rely on appropriate safeguards (such as standard contractual clauses) as required by the LGPD and GDPR.

How we protect your content

All traffic to the service is encrypted in transit, and stored data is encrypted at rest — but your files and the content we derive from them are protected differently, and the difference is worth stating plainly. Your original files are encrypted in our object storage under a single key belonging to the environment they are stored in. Database content — titles, summaries, tags, link previews, file and folder names, connected repository paths, the names of people and organisations we find, the document text we index, and your chat history — is encrypted under scoped content keys. Vault-owned data uses a key held separately for each vault; account-scoped chat history uses a separate key for your account. Each scoped key is in turn wrapped by the environment key. Our own staff are denied the use of every one of these keys through infrastructure permissions: only the running service may ask for one, and it decrypts transiently to index your content and to answer your own requests. Staff have no standing ability to read your content.

Each time the service unwraps a vault key, the request is recorded in an audit trail the application itself cannot alter. It is the unwrapping that is recorded, not each individual decryption: once unwrapped, a key stays in the service's memory for up to fifteen minutes, so that an active vault costs one key request rather than one for every document it touches. A key withdrawn at the infrastructure level therefore stops working within that window rather than the same instant.

Some data derived from your content is not covered by those keys and does remain readable to us: the numeric vectors used for semantic search, the opaque tokens that let us filter and search without decrypting — which reveal that two items share a tag or a name, though not what it is — and the operational record around each item, such as its type, size, format and indexing status. These are held under the same at-rest encryption and access controls as the rest of the service. We would rather list them than imply a guarantee we do not give.

Feedback you send us through the app is different from content you store: our team reads it, because that is the point of sending it. Please do not paste anything into a feedback message that you would not want us to see.

We retain a deliberate path to obtain content when we are compelled by valid legal process — a court order, subpoena, or law-enforcement request we are obliged to answer. Using it requires a recorded change to our infrastructure; it is not available for support troubleshooting or for investigations of our own. We do not promise to notify you when it is used, because a legal order may prohibit us from doing so. This is not a zero-knowledge system: we can obtain your content, and these are the only circumstances in which we would.

We do not use your content to train AI models. Our model providers process your content only to generate the extractions, summaries, search index, and answers you request — not for training.

How long we keep it

We keep your content for as long as your account is active. Deleted items follow a reversible trash window and are then purged. Account deletion removes your knowledge and associated records, subject to limited retention required by law or for security.

Your rights

Under the LGPD and GDPR you can request access, correction, deletion, portability, and information about how your data is processed, and you can object to or restrict certain processing or withdraw consent. The app already supports exporting and deleting your knowledge. To exercise any right, contact [email protected]. You may also lodge a complaint with the Brazilian ANPD or your local supervisory authority.