Skip to main content
Lioma

Back to home

Privacy Policy

Last updated: July 2026

Data Processing Agreement (DPA) →

1. Introduction & Data Controller

This Privacy Policy explains how Lioma ("we", "us", "our") collects, uses, and protects your personal data when you use our AI-powered automation application.

Data Controller:

Lioma e.U.

Radetzkystraße 10

9020 Klagenfurt am Wörthersee, Austria

Email: privacy@lioma.eu

We are committed to protecting your privacy and processing your data in compliance with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the California Consumer Privacy Act (CCPA/CPRA).

Data Protection Officer: We are not required to appoint a Data Protection Officer under Article 37 GDPR. For all data protection queries, please contact privacy@lioma.eu.

2. Data We Collect

A. Account Information

  • Email address, name, phone number, timezone
  • Authentication credentials (securely hashed passwords, passkeys)
  • OAuth identifiers (if you sign in with Google or GitHub)
  • Language and notification preferences

B. Conversation & Automation Data

  • Conversation transcripts with our AI assistant
  • Goals, reflection entries, and other content you create
  • Energy level data (productivity readiness indicator)
  • AI-generated summaries and insights
  • Voice data (processed in real-time for transcription, not permanently stored)

C. Usage & Behavioral Data

  • Check-in preferences and schedules
  • Feature usage patterns (recorded by default under legitimate interests; you can object in Settings)
  • Session duration and engagement metrics (recorded by default under legitimate interests; you can object in Settings)

D. Payment Information

  • Subscription plan and billing status
  • Stripe customer and subscription identifiers (web purchases)
  • RevenueCat anonymous user ID and entitlement status (mobile app purchases)
  • Note: Your payment card details are processed directly by Stripe, Apple, or Google and never touch our servers

E. Technical Data

  • IP address (in server logs)
  • Browser type and device information
  • Push notification endpoints (if enabled)
  • Authentication tokens

F. Calendar Data (Optional)

  • If you connect Google or Microsoft Calendar: we read your event titles and times
  • We use event titles to suggest smarter focus times (e.g., "after your standup" or "before that client call")
  • We can create focus time events in your calendar when you explicitly request it
  • Calendar data is not permanently stored - we query it in real-time when needed
  • Your calendar data is never shared with third parties

G. AI Assistant Data (If Enabled)

  • Task execution logs and activity history
  • Emails sent on your behalf (content and metadata)
  • Browser session recordings (URLs visited, actions taken)
  • Connected service credentials (stored encrypted)
  • Workspace files created by the assistant
  • Confirmation decisions (approved/rejected actions)

3. Prospects & Third-Party Contacts

This section explains how we handle personal data about people who are not Lioma users: the business contacts ("prospects") that our customers reach through Lioma's outreach features, and the professional contacts our customers store in Lioma. These outreach features are provided for business use only (see our Terms and our Data Processing Agreement).

Our Two Roles

  • Processor for customer outreach: When a customer runs outreach, that customer is the data controller and Lioma acts as their processor. The customer decides whom to contact and why; we source, prepare, send, and track outreach on their documented instructions under a Data Processing Agreement. Business customers are responsible for having a lawful basis to contact each prospect and for honouring objections.
  • Controller for our prospect-research database: To provide the service efficiently, we maintain a central store of business-contact and publicly available professional information that may be used across customers. Because we determine the purpose and means of that database, Lioma acts as controller for it.

Categories of Data

Business name, business email address, employer, job title, city and country, LinkedIn profile URL, publicly available professional information, and a short AI-generated research summary used to tailor outreach. For outreach a customer sends, we also process the message content (in text or, where used, AI-generated voice), delivery status, any reply, and the prospect's interactions with the personalised landing page created for them. The personalised landing page uses only first-party, privacy-friendly analytics (such as page visits) and does not set advertising or cross-site tracking cookies. We process business/professional-context data only and do not knowingly collect special categories of data (Art. 9 GDPR) about prospects.

Sources

  • Our customers
  • B2B contact-data providers (currently Apollo)
  • Publicly accessible sources (company websites, public professional profiles, business registers and imprints)
  • Address-validation providers

Legal Basis

We rely on our and our customers' legitimate interests (Art. 6(1)(f) GDPR) in initiating and conducting business-to-business relationships and outreach. We have weighed these interests against the interests and rights of the data subjects and limited the processing to a professional context, business-relevant information, frequency caps, and an easy opt-out.

Retention

We keep prospect records only as long as they remain useful for the service. After 12 months without activity we anonymise the record: every identifying field and the research summary are erased, and only the outcome of the campaign remains, which is no longer information about you. Where a person opts out, we retain the minimum information necessary to continue honouring that opt-out (suppression), and nothing more.

Recipients

To deliver outreach, prospect data may be shared with our letter production and postal provider (Scribeless, United Kingdom), address-validation providers, the relevant messaging channel (for example LinkedIn or our email provider), and our EU hosting provider (AWS, Frankfurt).

Your Rights If You Are a Prospect

You have the right to access, rectification, restriction, erasure, and data portability, and an unconditional right to object to direct marketing at any time (Art. 21(2) GDPR). To exercise these rights, email privacy@lioma.eu or use the "remove me" link on the landing page or letter you received. An objection or erasure removes you from our prospect database and suppresses future contact across the entire Lioma platform. You may also contact the customer who reached out to you; we will assist them as their processor.

Source of Your Data (Art. 14 GDPR)

Where we did not obtain your data from you directly, we obtained it from the sources listed above. Every letter we send carries a short notice naming the source, us as the controller, and the address of the full notice at lioma.app/brief, which sets out all of the information required by Article 14 in one page and in your own language. That notice and this policy together satisfy our obligations under Article 14 GDPR.

4. How We Use Your Data & Legal Basis

Under the General Data Protection Regulation (GDPR), we must have a valid legal basis for each processing activity. The table below provides a comprehensive overview of what data we process, for what purposes, and our legal justification under Article 6(1) GDPR.

Legal Bases We Rely On

  • Art. 6(1)(a) GDPR - Consent: You have given clear consent to process your personal data for a specific purpose.
  • Art. 6(1)(b) GDPR - Contract: Processing is necessary for the performance of a contract with you, or to take steps at your request before entering into a contract.
  • Art. 6(1)(c) GDPR - Legal Obligation: Processing is necessary to comply with a legal obligation to which we are subject.
  • Art. 6(1)(f) GDPR - Legitimate Interests: Processing is necessary for legitimate interests pursued by us, except where overridden by your interests or fundamental rights.

Detailed Data Processing Overview

Data Category Specific Data Processing Purpose(s) Legal Basis
Account InformationEmail addressAccount creation, authentication, password reset, transactional communicationsArt. 6(1)(b) - Contract
Account InformationEmail addressMarketing communications, weekly summaries, remindersArt. 6(1)(a) - Consent
Account InformationName, timezone, language preferencePersonalization, displaying correct times, service deliveryArt. 6(1)(b) - Contract
Phone NumberPhone numberSMS/WhatsApp/Signal check-in reminders, voice call check-insArt. 6(1)(b) - Contract
Phone NumberPhone numberEnabling the SMS/WhatsApp/Signal/voice channel (requires explicit opt-in)Art. 6(1)(a) - Consent
Authentication DataHashed password, passkeys, OAuth identifiersSecure authentication, account accessArt. 6(1)(b) - Contract
Authentication DataMagic link tokens, 2FA secretsPasswordless login, enhanced account securityArt. 6(1)(b) - Contract
Conversation ContentConversation transcripts with AI assistantProviding AI automation service, generating personalized responses, displaying historyArt. 6(1)(b) - Contract
Conversation ContentAI-generated summaries and insightsPattern detection, personalized automation recommendationsArt. 6(1)(b) - Contract
Reflections & JournalingReflection entries, energy level dataJournaling feature, productivity tracking, AI-powered pattern analysisArt. 6(1)(b) - Contract
Reflections & JournalingPhotos attached to reflection entriesEnriching reflection entries, displaying your content back to youArt. 6(1)(b) - Contract
Goals & ProgressDaily goals, goal completion statusGoal tracking feature, progress visualization, AI contextArt. 6(1)(b) - Contract
GamificationStamps, streaks, ranks, letters, patternsAchievement system, motivation features, progress trackingArt. 6(1)(b) - Contract
Voice DataVoice audio (real-time, not stored)Real-time transcription for voice conversation featureArt. 6(1)(a) - Consent + Art. 6(1)(b) - Contract
Calendar DataCalendar events (titles, times)Suggesting optimal focus times, context-aware schedulingArt. 6(1)(a) - Consent
AI Assistant DataActivity logs, emails sent, browser sessions, connected services, workspace filesAutomated task execution, email sending, browser automation, service integrationArt. 6(1)(b) - Contract
AI Assistant DataConnected service credentials (OAuth tokens, session cookies)Accessing third-party services on your behalfArt. 6(1)(a) - Consent
Check-in DataReminder schedules, check-in responsesDelivering scheduled reminders, recording progressArt. 6(1)(b) - Contract
Subscription & PaymentSubscription status, Stripe/RevenueCat IDsDetermining feature access, payment processingArt. 6(1)(b) - Contract
Subscription & PaymentPayment history, invoicesTax compliance, accounting records, dispute resolutionArt. 6(1)(c) - Legal Obligation
Technical DataPush notification endpointsDelivering push notifications for reminders and updatesArt. 6(1)(b) - Contract
Technical DataIP address, browser/device infoSecurity monitoring, fraud prevention, abuse detectionArt. 6(1)(f) - Legitimate Interests
Analytics DataFeature usage, session data, page viewsService improvement, understanding user needs, fixing bugsArt. 6(1)(f) - Legitimate Interests (on by default, first-party only, object in Settings)
Consent RecordsConsent timestamps, consent method, IP at time of consentDemonstrating GDPR compliance, audit trailArt. 6(1)(c) - Legal Obligation
Server LogsRequest logs, error logsDebugging, security monitoring, service reliabilityArt. 6(1)(f) - Legitimate Interests

Legitimate Interests Assessment

Where we rely on legitimate interests (Art. 6(1)(f) GDPR), we have conducted a balancing test to ensure our interests do not override your fundamental rights. Our legitimate interests include:

  • Security: Protecting our service and users from fraud, abuse, and unauthorized access. This is essential for maintaining trust and service integrity.
  • Debugging: Identifying and resolving technical issues to ensure service reliability.

You have the right to object to processing based on legitimate interests. Contact privacy@lioma.eu to exercise this right.

Special Categories of Data

We do not intentionally collect special categories of personal data as defined in Article 9 GDPR (racial or ethnic origin, political opinions, religious beliefs, health data, etc.).

Energy Level Data: Lioma allows you to log your "energy level" as a productivity readiness indicator. This is explicitly not health data. Energy level is a subjective productivity metric (similar to "how focused do you feel?" or "how ready are you to tackle your goals?") - not a medical, diagnostic, or mental health measurement. We do not use this data to infer health conditions, provide health recommendations, or for any medical purpose.

5. Third-Party Service Providers

We work with trusted third-party providers to deliver our service. All providers are bound by data processing agreements and appropriate safeguards.

Infrastructure & Hosting

  • Amazon Web Services (AWS): Application hosting on ECS Fargate and database on RDS PostgreSQL (EU region - Frankfurt, eu-central-1)
  • AWS EC2: Cloud servers for AI assistant workers (EU region - Frankfurt, eu-central-1)
  • AWS S3: Cloud storage for generated images and media files (EU region - Frankfurt)
  • AWS CloudFront: Content delivery network for the web application (EU edge locations)
  • Cloudflare: DNS, CDN, and network security for our domains (receives request metadata such as IP address)

Authentication (optional)

  • Google OAuth: Sign-in (receives email, name, profile picture)
  • Apple Sign-In: Sign-in (receives email, name - may be anonymized by Apple)
  • Microsoft/Entra ID: Sign-in (receives email, name)
  • GitHub OAuth: Sign-in (receives email, name, username)

AI & Voice Processing

  • AWS Bedrock: Primary AI model hosting and inference via the Bedrock Converse API (receives conversation context for text and anonymized scene descriptions for image generation; processed in the EU region - Frankfurt, eu-central-1, with US - us-east-1 failover for availability)
  • Anthropic: AI model provider used as a fallback only (receives conversation context for generating responses via the Anthropic API when Bedrock is unavailable)
  • AssemblyAI (optional): Speech-to-text transcription (receives voice audio)
  • Inworld (optional): Text-to-speech synthesis (receives response text)

Communications

  • Brevo: Email delivery (receives email address, message content)
  • Twilio (optional): SMS and voice calls (receives phone number, message content)
  • WhatsApp (self-hosted bridge) (optional): WhatsApp messaging via a self-hosted bridge (WhatsApp Web-based) running on our own EU-based infrastructure. Messages still transit WhatsApp/Meta servers and are end-to-end encrypted by WhatsApp (receives phone number, message content)
  • Signal (via signal-cli-rest-api) (optional): Signal messaging (receives phone number, message content). Hosted on our own EU-based infrastructure
  • Apple Push Notification Service (APNs) (optional): iOS push notifications (receives device token, notification content)
  • Firebase Cloud Messaging (FCM) (optional): Android push notifications (receives device token, notification content)

Calendar Integrations (optional)

  • Google Calendar API: Calendar read/write access (receives event titles, times, availability - see Section 18 for details)
  • Microsoft Graph: Calendar integration for Microsoft/Outlook calendars (receives event titles, times, availability)

Prospecting & Outreach (business use)

  • Apollo: B2B contact-data provider used to source business prospects (receives search criteria; provides business-contact data)
  • Scribeless: Letter production and postal delivery of physical letters (receives recipient name, business address, and letter content; United Kingdom, covered by the UK adequacy decision)
  • Loqate: Postal address validation (receives address data)
  • Google Places / Maps: Business address resolution (receives business name and location queries)
  • Tavily, Jina: Web research to prepare outreach (receive search queries and public web content)
  • TheirStack: Public job-posting data used to judge whether a company is hiring for a role that makes it a relevant prospect (receives company domains and job titles)
  • Composio: Integration layer for connecting third-party tools you authorise
  • LinkedIn: Delivery of LinkedIn outreach from your own connected LinkedIn account, which you authorise us to act through on your behalf

Payments

  • Stripe: Web payment processing (PCI-DSS Level 1 compliant)
  • Apple App Store: In-app purchases on iOS (processed by Apple)
  • Google Play: In-app purchases on Android (processed by Google)
  • RevenueCat: Subscription management for mobile apps (receives anonymous user ID, purchase receipts, subscription status)

Analytics

We collect usage analytics on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in understanding how Lioma is used and improving it. Analytics are on by default. We record which features you use, how long sessions last, and the funnel steps you pass through; we do not record the content of your letters or conversations for this purpose. This data is written to our own database within the European Union, is never transferred to a third party, and is not shared with any third-party analytics provider. We do not use advertising or cross-site tracking analytics (such as Google Analytics). You have the right to object at any time (Art. 21 GDPR): switch "Product analytics" off under Settings, Account, and we stop recording immediately. Records we must keep for other purposes, such as your account and your billing history, are unaffected.

Monitoring & Observability

  • Sentry: Error tracking and performance monitoring (receives error reports, user context for debugging)
  • Logtail (Better Stack): Centralized log management (receives application logs, request metadata)

Security

  • Have I Been Pwned: Password breach checking (receives only partial password hash prefixes via k-anonymity protocol - your password is never transmitted)

6. Voice & AI Data Processing

Lioma uses AI to provide personalized automation. Here's how your voice and conversation data is processed:

How Voice Conversations Work

  1. Your voice is streamed to AssemblyAI for real-time transcription
  2. The transcription is sent to Claude AI to generate a response
  3. The response text is converted to speech via Inworld
  4. The full conversation transcript is saved to your account

Important Information

  • Raw audio is NOT permanently stored: it's processed in real-time only
  • Transcripts ARE stored in your account history (you can delete them)
  • AI responses are generated, not pre-written or human-reviewed
  • No automated decisions with legal effects: AI provides suggestions only
  • You control your data: delete conversation history anytime in Settings

No Biometric Data Collection

We do NOT create, store, or use voiceprints or any biometric identifiers derived from your voice. Voice audio is processed solely for real-time transcription and is not used for speaker identification, authentication, or any biometric purpose. Your voice characteristics are never analyzed, stored, or compared for identification purposes.

7. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), primarily the United States, where our service providers operate.

Safeguards we use:

  • EU-US Data Privacy Framework (DPF) for certified providers
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Supplementary technical measures (encryption in transit and at rest)
  • Data Processing Agreements (DPAs) with all processors

Provider-Specific Transfer Mechanisms

Provider Purpose Processing Location Transfer Mechanism
AWS BedrockPrimary AI inference, responses and image generationEU (Frankfurt) primary, US (us-east-1) failoverEU-primary; US failover under DPF + SCCs
ApolloB2B prospect data sourceUSSCCs
TheirStackPublic job-posting signal dataEU (Spain; AWS data centres)No transfer (EU-based); TheirStack's own onward transfers under SCCs
ScribelessLetter production and postal deliveryUnited KingdomUK adequacy decision
AnthropicFallback AI model provider (Claude)USSCCs
AssemblyAISpeech-to-textUSDPF certified
InworldText-to-speechUSSCCs
AWS (ECS, RDS, S3, CloudFront)Application hosting, database & storageEU (Frankfurt)No transfer (EU-based)
AWS EC2AI assistant cloud serversEU (Frankfurt)No transfer (EU-based)
StripePayment processingEU/USDPF + SCCs
TwilioSMS/Voice callsUSDPF + SCCs
BrevoEmail deliveryEU (France)EU-based

Other sub-processors listed in Section 5 may process limited data outside the EEA; where they do, we rely on Standard Contractual Clauses and/or the EU-US Data Privacy Framework.

8. Data Retention & Deletion

We retain your data only as long as necessary:

Data Category Retention Period
Account data (email, name)Until account deletion (then anonymized)
Conversation transcriptsUntil you delete them or delete account
Reflection entries & goalsUntil you delete them or delete account
Stamps & patternsUntil account deletion
Payment/subscription records7 years (legal/tax requirement)
Magic login tokens24 hours
Voice recordingsNot stored (real-time processing only)
Server logs90 days
Database backups30 days (rolling)
AI assistant activity logsUntil account deletion
Connected service credentialsUntil you disconnect the service or delete account
Browser session dataPersists for the duration of the task execution, then automatically cleaned up
Prospect research data (business contacts)Anonymised after 12 months of inactivity; erased on request or opt-out
Suppression / opt-out listRetained as long as needed to honour the opt-out

Account Deletion Process

When you delete your account, the following happens immediately:

  • Permanently deleted: Goals, reflection entries, conversations, letters, stamps, patterns, calendar integrations, check-in schedules, and passkeys
  • Anonymized: Your user record is kept but anonymized (email becomes anonymous, name becomes "Deleted User", password cleared) for accounting purposes
  • Retained: Subscription record with payment provider IDs (required for tax/accounting compliance for 7 years)
  • Canceled: Any active subscription is automatically canceled

To delete your account, you must confirm via email for security. For detailed instructions, see our account deletion guide.

Deleting Individual Data

You can delete specific data without deleting your entire account:

  • Reflection entries: Tap on an entry in Reflections, then tap the delete icon
  • Check-in reminders: Go to Check-ins and tap the trash icon next to any reminder
  • Bulk deletion: Contact privacy@lioma.eu to delete all reflection entries, goals, or conversation history while keeping your account

Third-Party Data Retention

When you delete your account, we instruct our service providers to delete your data. However, some providers may retain data according to their own policies:

  • Stripe/RevenueCat: Payment records retained for their legal compliance requirements
  • AI providers (AWS Bedrock): May retain conversation data per their data retention policies (typically 30 days for abuse monitoring)
  • Communication providers (Twilio, Brevo): Message logs retained per their policies

9. Your Rights (GDPR)

Under GDPR, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete data
  • Right to Erasure (Art. 17): Delete your account and all data ("right to be forgotten")
  • Right to Restriction (Art. 18): Limit how we process your data
  • Right to Data Portability (Art. 20): Export your data in a structured, commonly used, machine-readable format (JSON)
  • Right to Object (Art. 21): Object to processing based on legitimate interest
  • Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

How to Exercise Your Rights

  • Email: privacy@lioma.eu
  • In-app: Settings → Delete Account
  • Response time: Within 30 days

Supervisory Authority

You have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Vienna, Austria
dsb@dsb.gv.at

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

Categories of Personal Information Collected

  • Identifiers: Name, email, phone number, IP address
  • Commercial information: Subscription and payment history
  • Internet activity: Usage data, conversation history
  • Audio information: Voice processed for transcription (not stored)
  • Inferences: AI-generated insights, productivity patterns

Your CCPA Rights

  • Right to Know: Request disclosure of data we've collected
  • Right to Delete: Request deletion of your data
  • Right to Correct: Request correction of inaccurate data
  • Right to Opt-Out: We do NOT sell your personal information
  • Right to Non-Discrimination: No penalty for exercising your rights

"Do Not Sell My Personal Information"

Lioma does not sell your personal information. We do not share your data for cross-context behavioral advertising. Your data is only shared with service providers necessary to operate our service.

How to Exercise CCPA Rights

Email: privacy@lioma.eu
Response time: Within 45 days
Verification: We verify requests via email confirmation to your registered account.

Business Prospect Data

Where we process the personal information of California residents as business prospects, they have the same rights described above, including the rights to know, delete, and correct. We do not sell prospect data. To exercise these rights or to be removed, email privacy@lioma.eu or use the removal link in the message you received.

11. Cookies & Browser Storage

We use localStorage for essential functions:

  • Authentication token (to keep you logged in)
  • Language preference
  • Voice mute setting

Analytics

We collect usage analytics on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in understanding how Lioma is used and improving it. Analytics are on by default. We record which features you use, how long sessions last, and the funnel steps you pass through; we do not record the content of your letters or conversations for this purpose. This data is written to our own database within the European Union, is never transferred to a third party, and is not shared with any third-party analytics provider. We do not use advertising or cross-site tracking analytics (such as Google Analytics). You have the right to object at any time (Art. 21 GDPR): switch "Product analytics" off under Settings, Account, and we stop recording immediately. Records we must keep for other purposes, such as your account and your billing history, are unaffected.

We do NOT use:

  • Google Analytics or similar advertising analytics
  • Advertising cookies or trackers
  • Cross-site tracking pixels

Other third-party cookies: May be set by Stripe (during checkout) or Google (during OAuth sign-in). These are subject to their respective privacy policies.

12. Children's Privacy

  • Lioma is not intended for users under 16 years of age
  • We do not knowingly collect personal data from children under 16
  • If we discover we have collected data from a child under 16, we will delete it promptly
  • Parents or guardians may contact us at privacy@lioma.eu

13. Payment Processing

Web Payments (Stripe)

  • Payments are processed securely by Stripe, a PCI-DSS Level 1 certified processor
  • We never see or store your full credit card number
  • We only receive: transaction confirmations and subscription status
  • Stripe's privacy policy: stripe.com/privacy

Mobile App Purchases (Apple & Google)

  • In-app purchases on iOS are processed by Apple through the App Store
  • In-app purchases on Android are processed by Google through Google Play
  • We use RevenueCat to manage subscriptions across platforms
  • RevenueCat receives: anonymous user ID, purchase receipts, and subscription status
  • We never see your payment method details for in-app purchases
  • RevenueCat's privacy policy: revenuecat.com/privacy
  • Apple's privacy policy: apple.com/legal/privacy
  • Google's privacy policy: policies.google.com/privacy

14. Communication Services

Notification Categories

We send different types of notifications, each with its own consent requirements:

  • Transactional: Account-related messages (welcome emails, password resets, purchase confirmations). Sent to all users as necessary for service operation.
  • Check-in Reminders: Messages you schedule yourself (daily goal reminders, reflection prompts). Controlled by channel toggles in Settings.
  • Achievement Celebrations: Notifications about your progress (streaks, rank-ups, letter unlocks). Can be disabled in Settings.
  • Marketing & Nudges: Weekly digests, inactivity nudges, quarterly vision reminders. Requires explicit opt-in at signup or in Settings.

SMS is only used for check-in reminders you schedule - never for marketing or promotional content.

Email (via Brevo)

  • Used for: Magic links, password resets, check-in reminders, achievement celebrations, and (if opted-in) marketing digests
  • You can manage email preferences in Settings

SMS (via Twilio)

  • Used for: Check-in reminders only (if you opt in)
  • We do not send marketing or promotional SMS
  • Standard messaging rates may apply from your carrier
  • Text STOP to opt out at any time

WhatsApp (self-hosted bridge)

  • Used for: Check-in reminders and notification messages (if you opt in)
  • We operate our own self-hosted WhatsApp bridge (WhatsApp Web-based) on EU-based infrastructure. We do not use an official WhatsApp Business API relationship with Meta
  • When you opt in, messages are sent to and from your phone number over WhatsApp. As with any WhatsApp message, the content transits WhatsApp/Meta servers
  • Message content is end-to-end encrypted by WhatsApp
  • You can opt out at any time by replying STOP or updating your preferences in Settings
  • We do not use WhatsApp data for advertising purposes
  • Meta's WhatsApp privacy policy also applies to messages that transit WhatsApp: whatsapp.com/legal/privacy-policy

Signal (Self-Hosted)

  • Used for: Check-in reminders and notification messages (if you opt in)
  • We operate our own Signal bridge on EU-based infrastructure using the open-source signal-cli-rest-api
  • When you opt in, your phone number is used to send Signal messages
  • Message content is end-to-end encrypted by Signal
  • You can opt out at any time by updating your preferences in Settings
  • No data is shared with third parties for Signal messaging

Voice Calls (via Twilio)

  • Used for: Voice check-ins (if you opt in)
  • You control when and how often we call

Push Notifications

  • Browser and native app push notifications
  • Used for: check-in reminders, achievement celebrations, and (if opted-in) nudges
  • Achievement and marketing notifications respect your Settings preferences
  • Disable anytime in Settings or your device/browser preferences

Consent History

We maintain an immutable audit trail of all your consent decisions (when you opt in or out of marketing communications). This record includes the timestamp, method of consent, and IP address for compliance purposes. You can view your consent history in Settings.

15. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit: TLS 1.3 for all connections
  • Encryption at rest: Database encryption, encrypted OAuth tokens
  • Access controls: Role-based access, authentication requirements
  • Secure development: Regular security reviews, dependency updates
  • Password security: Bcrypt hashing, never stored in plain text

No system is 100% secure. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.

16. AI Assistant Infrastructure Security

Lioma's personal assistant is powered by a custom AI agent infrastructure built by the Lioma team. We deliberately chose not to use third-party or open-source AI agent frameworks, because they introduce security risks that are difficult to mitigate in a managed service: public skill marketplaces that allow untrusted third-party code, broad system access that expands the attack surface, and credential handling patterns that expose API keys to the AI model itself.

By building our own infrastructure, we control every layer of the stack and can enforce security guarantees that are not possible with general-purpose agent frameworks.

Isolated Environment

Every Lioma user receives a dedicated, isolated environment for their personal AI assistant. Your assistant runs under its own operating-system account with its own files, configuration, and credentials, isolated from other users at the operating-system layer, so no other user's assistant can access your personal workspace, files, or credentials. When you use outreach features, messages are sent from the accounts you connect (for example, your own LinkedIn account, which you authorise us to act through on your behalf), not from shared accounts.

No Third-Party Code

Unlike agent frameworks that support public plugin or skill marketplaces, Lioma Runtime has no mechanism for third-party code installation. Every capability your assistant has was authored, reviewed, and deployed by the Lioma team. This eliminates the supply chain risks that have affected open-source agent ecosystems.

Credential Isolation

Open-source agent frameworks typically place API keys and authentication tokens directly in the agent's configuration, where the AI model can see them. This creates a risk that prompt injection or malicious web content could trick the agent into revealing those credentials.

Lioma Runtime uses a proxy architecture instead. When your assistant needs to access an external service, the request routes through the Lioma backend, which injects authentication server-side. Your assistant never sees raw API keys or tokens. This applies to search services, language model access, and your own API keys if you have chosen to bring your own.

Minimal Attack Surface

Lioma Runtime is purpose-built for Lioma's use case. It does not include features common in general-purpose agent frameworks that widen the attack surface:

  • No plugin marketplace: No mechanism for untrusted code to run on your instance.
  • Sandboxed browser: Your assistant browses the web through an isolated headless browser with no access to your local machine or desktop.
  • No direct credential access: All authentication is proxied through the Lioma backend.
  • Restricted shell access: All commands executed by your assistant are security-screened and limited to pre-approved operations within your isolated environment.

Security Patching

Because we own the full stack, we can patch vulnerabilities without waiting for upstream releases. We continuously monitor our infrastructure and deploy security fixes promptly.

What Your Assistant Can Access

Your assistant has access to:

  • Your conversations within Lioma
  • Your goals, vision, and reflection entries
  • Websites you ask it to visit
  • Files in your personal workspace
  • Your calendar (if connected)

Your assistant does not have access to:

  • Other users' data or environments
  • Raw API keys or authentication tokens
  • Your email inbox (unless you have explicitly connected the email service)
  • The Lioma backend infrastructure

Data Collected Through AI Assistant Actions

When your AI assistant performs automated tasks, we collect and store the following additional data:

  • Activity logs: Records of tools used, tasks performed, and estimated time saved
  • Email records: Metadata (recipients, subjects, timestamps) and content of emails sent through the assistant
  • Browser session data: URLs visited, actions taken, and cookies stored during browser automation sessions. Browser sessions are isolated per user and automatically expire
  • Connected service tokens: OAuth tokens or session cookies for services you connect. These are stored encrypted and isolated in your personal environment
  • Workspace files: Files your assistant creates or manages in your personal workspace
  • Confirmation history: Records of actions requiring your approval and your approval/rejection decisions

All AI assistant data is subject to the same retention, deletion, and export policies described in Section 8 of this Privacy Policy. When you delete your account, all AI assistant data, including connected service credentials, workspace files, and activity logs, is permanently deleted.

17. Automated Decision-Making

  • Our AI provides suggestions, insights, and automation
  • These are recommendations only, not binding decisions
  • There is no automated decision-making with legal or similarly significant effects on you
  • You always control your goals, actions, and data

AI System Transparency (EU AI Act)

In accordance with Regulation (EU) 2024/1689 (the EU AI Act):

  • Our AI system generates personalized responses using large language models (currently AWS Bedrock). These responses are generated automatically without human review
  • Lioma's AI features are classified as limited-risk AI systems. We comply with the transparency obligations set out in Article 50 of the EU AI Act
  • All AI interactions with our AI assistants are clearly identified as AI-powered. You are interacting with artificial intelligence, not humans
  • AI-generated content (reflection narratives, illustrations, emails sent by the AI assistant) is identified as AI-generated both visibly and through machine-readable markers where technically feasible
  • Sentiment analysis within conversations is text-based only. We do not use biometric data, facial recognition, or physiological signals for emotion recognition
  • You may use Lioma without engaging with AI features. Core functionality (manual goal tracking, reflection entries) works without AI interaction

18. Google Sign-In & Calendar Integration

Google Sign-In

When you sign in with Google, we receive your name, email address, and profile picture to create or access your account. We do not access any other Google data.

Google Calendar Integration

If you connect Google Calendar:

  • Reading: We read your event titles and times to suggest smarter focus times (e.g., "after your standup" or "before that client call")
  • Creating: When you ask Lioma to schedule focus time, we create events directly in your calendar
  • We use calendar access only to suggest optimal focus times and schedule sessions you request
  • We do NOT store calendar data permanently - it's queried in real-time
  • Your calendar data is never shared with third parties
  • Disconnect anytime in Settings

Google API Limited Use Disclosure

Lioma's use of Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements:

  • We use Google data only for purposes described in this policy
  • We do not use Google data for advertising
  • We do not allow humans to read Google data without explicit consent
  • We do not transfer Google data except as necessary for the service
  • The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google Workspace data to create, train, or improve generalized AI or machine learning models.

19. Data Breach Response

We maintain a documented incident response plan to handle potential data breaches in compliance with GDPR Article 33/34 and applicable US state laws.

Our Commitment

  • Detection: We monitor our systems for unauthorized access, data exfiltration, and security anomalies
  • Assessment: Upon detecting a potential breach, we immediately assess the scope, affected data, and risk to individuals
  • Authority notification: If a breach is likely to result in risk to individuals, we will notify the Austrian Data Protection Authority (DSB) within 72 hours as required by GDPR
  • User notification: If a breach is likely to result in high risk to your rights and freedoms, we will notify affected users without undue delay
  • US state requirements: For US users, we comply with applicable state breach notification laws (e.g., California, Colorado, Virginia) which may have varying notification timelines

What We Will Tell You

In the event of a breach affecting your data, our notification will include:

  • Nature of the breach and categories of data affected
  • Likely consequences of the breach
  • Measures we have taken or propose to take
  • Contact point for further information
  • Recommendations for protecting yourself

20. Record of Processing Activities

In accordance with GDPR Article 30, we maintain a comprehensive Record of Processing Activities (ROPA) that documents:

  • All categories of personal data we process
  • Purposes of each processing activity
  • Legal basis for each processing activity
  • Categories of data subjects and recipients
  • International transfers and safeguards
  • Retention periods for each data category
  • Technical and organizational security measures

This internal document is available for inspection by the Austrian Data Protection Authority (DSB) upon request. If you wish to understand how your specific data is processed, please contact privacy@lioma.eu.

21. Changes to This Policy

  • We may update this policy to reflect changes in our practices or legal requirements
  • Material changes will be communicated via email and/or in-app notification
  • The "Last updated" date at the top indicates the most recent revision
  • Continued use after changes constitutes acceptance of the updated policy
  • Previous versions are available upon request

22. Contact Us

Data Controller:

Lioma e.U.

Radetzkystraße 10

9020 Klagenfurt am Wörthersee, Austria

Privacy inquiries: privacy@lioma.eu
General inquiries: info@lioma.eu

Data Protection Authority:
Österreichische Datenschutzbehörde (DSB)
Barichgasse 40-42, 1030 Vienna, Austria
www.dsb.gv.at

Lioma

One moment, laying out the stationery...