Legal

Privacy Policy

Last updated: June 24, 2026 · Effective: June 24, 2026

Lytics AI (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at lytics.ai (the “Service”). Please read this policy carefully. If you disagree, please discontinue use of the Service.

1. Information We Collect

Account information: When you create an account, we collect your name, email address, and password (hashed). If you sign in via OAuth (Google, GitHub), we receive the profile information you authorize.

Usage data: We log actions you perform on the platform (creating projects, running transformations, sharing reports) along with timestamps, IP addresses, and browser/device metadata. This data is used for security audits and to improve the Service.

Data you upload: Files, database content, and any data you import into the Service are stored in your team's isolated storage. We do not read your data except as necessary to operate the Service or as you instruct via AI transformations.

Payment information: Billing is handled by Stripe. We do not store raw card numbers. We receive and store non-sensitive billing metadata (plan type, billing period, last-four digits).

Communications: If you contact us by email or through the contact form, we retain those communications to resolve your query and improve support.

2. How We Use Your Information

  • To create and manage your account and team workspace.
  • To operate, maintain, and improve the Service.
  • To process payments and send billing-related notices.
  • To send transactional emails (password reset, invitation, expiry notices).
  • To detect and prevent fraud, abuse, or security incidents.
  • To comply with legal obligations.
  • To respond to your inquiries and provide customer support.
  • To send product updates and feature announcements (you can opt out at any time).

We do not sell your personal data or use it to train third-party AI models without your explicit consent.

3. How We Share Your Information

We do not sell or rent your personal data. We share information only in the following circumstances:

  • Service providers: We share data with vendors who help us operate the Service (hosting, payments, email delivery, analytics). These providers are contractually bound to protect your data.
  • Team members: Data within a team workspace is accessible to all members of that team. Admins can see activity logs for all members.
  • Share links: When you publish a report via a share link, anyone with the link can view the report data. You control this entirely and can revoke links at any time.
  • Legal requirements: We may disclose information if required by law or in response to valid legal process.
  • Business transfers: In the event of a merger or acquisition, your data may be transferred. We will notify you before data is subject to a different privacy policy.

4. Data Retention

We retain your account data for as long as your account is active. If you delete your account, your data is removed within 30 days, except where retention is required by law. Anonymized aggregated analytics data may be retained indefinitely.

Uploaded datasets and reports are retained until you delete them. Deleted datasets are removed from primary storage immediately and from backups within 30 days.

5. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate personal data.
  • Deletion: Request deletion of your personal data (“right to be forgotten”).
  • Portability: Receive your data in a machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Restriction: Request that we restrict processing in certain circumstances.

To exercise any of these rights, please contact us at privacy@lytics.ai. We will respond within 30 days.

6. Cookies and Tracking

We use strictly necessary cookies to maintain your login session and prevent CSRF attacks. We also use analytics cookies (with your consent) to understand how the Service is used. You can disable non-essential cookies in your browser settings without affecting core functionality.

We do not use cross-site tracking pixels or share cookie data with advertising networks.

7. Security

We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, Row Level Security (RLS) at the database level, and regular security audits. However, no system is completely secure and we cannot guarantee absolute security.

In the event of a data breach that affects your personal data, we will notify you within 72 hours as required by applicable law.

8. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or by posting a prominent notice on our website at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or your personal data, please contact us: