Legal
Privacy Policy
Version 1.0 · Effective 26 September 2026
This policy explains what LIME collects, why, how long we keep it, and the rights and controls you have. Every statement matches how the service actually behaves today.
Who we are
LIME is a passport system for AI agents. The service is operated by a Singapore-registered company; production infrastructure is hosted in the United States (Los Angeles).
Privacy requests, access, deletion, export, objections and appeals: [email protected]. Security and breach reports: [email protected].
A named privacy owner (DPO equivalent) has not been appointed yet — that is an operator action being completed in DOC-02, and no name is invented here. Until then, [email protected] reaches the team for every privacy matter. The registered postal address and EU/UK Article 27 representatives are being added by DOC-02.
What we collect
Account: email address, password hash (never the password), account status and verification timestamp.
Security and anti-fraud: last login time, last login IP address and browser or device details; session records keep hashed IP and user-agent values, not raw ones. Used for new-device alerts, lockouts and abuse defence.
Product: your display name, biography and avatar, and the same for your agents.
Integrations: site display name and domain, site login requests (including the webhook URL a site asks us to call), agent binding redirect URIs, and token hashes — never the tokens themselves.
Email delivery: queued transactional email content, notification preferences stored as hashes, and an email suppression list stored only as an email hash for hard-bounced addresses.
Verification challenges: one-time codes are stored hashed. When you change your email, the pending new address is the only plaintext item in the challenge row and is deleted when the code is used or after 15 minutes.
Audit records: security and legal audit events. Audit metadata carries no PII and tamper protection is enforced in the database. We also keep a non-reversible aggregate of portal visits — no individual profiles.
We do not collect age or date of birth, government identifiers, precise geolocation, health data, card data or advertising identifiers.
Why we use your data
Contract: creating and operating your account, authenticating you, providing agents, sites and bindings, and delivering transactional email you ask for.
Legitimate interests: security and anti-fraud (login alerts, abuse and rate-limit defence, account recovery), keeping audit and backup integrity, and aggregate non-identifying visit statistics. Data is minimised, hashed or aggregated where possible and used only for these purposes.
Legal obligation: security audit records, hashed deletion evidence, the email suppression list required for deliverability and CAN-SPAM, and breach-notification duties.
No automated decision-making, no profiling, no cross-context behavioural advertising. Marketing email is not sent in this wave; every current message is transactional or security-related and cannot be unsubscribed, though it is still rate-limited and bounce-tracked. Adding a marketing purpose later requires prior opt-in and a working opt-out first.
How long we keep data
Account, product and session data: for the life of your account. Sessions expire on their TTL and by inactivity (7 days by default, configurable) and are purged with a short grace window.
Site login requests and binding requests: 30 days after reaching a terminal state (configurable 7–365 days).
Processed transactional email: 30 days after processing (configurable 7–365 days).
Registration and verification: email codes expire after 15 minutes; idempotency records are kept 24 hours for retry safety.
Aggregate visit statistics: 35-day TTL, non-reversible by design.
Security audit events: 365 days by default (configurable 90–3650 days), append-only. Deletion tombstones (hashes only): 365 days.
Email suppression hashes: 2 years; these hashes survive account deletion because deliverability and CAN-SPAM obligations outlive the account.
Deletion, backups and restores
Deleting your account removes data from the live systems in one cascade: account, agents, sessions, sites and integrations, login and binding requests, queued email, avatars and files, preferences and challenges. Only irreversible hashes and tombstones remain, plus the suppression hash above.
Encrypted backups may retain a deleted account for a bounded window: PostgreSQL point-in-time recovery up to 35 days; the host-local archive 7 days; Redis/restic objects in Cloudflare R2 for up to about 6 months (daily 7, weekly 4, monthly 6).
Hosteons VM snapshots are operator-managed; the exact window is under investigation and is assumed to be no longer than 35 days until recorded.
Backups are encrypted, unreachable through any API and readable only by the operator restore process. A restore never brings a deleted account back: every restore replays the deletion ledger and completes deletions before the service accepts traffic.
Your rights
Delete your account: Settings → Account → Danger zone → Delete account. This requires your password, typing DELETE and a one-time code sent to your email. Deletion is irreversible and there is no grace period.
Export your data: Download my data produces a machine-readable JSON file (schema version 1, capped at 5 MB, once per day) with your profile, agents, sites, session metadata and your own site login requests — never tokens, hashes, passwords or other users' rows.
Unsubscribe: every non-transactional email carries a one-click unsubscribe link. Transactional security mail cannot be unsubscribed by design.
Locked out? Account recovery works without a session: request a single-use code by email to reset your password or complete deletion. The answer is uniform, so it cannot be used to check whether an address exists.
Other rights: correction, restriction, objection and withdrawal of consent (no consent-based processing is active in this wave). Authorized agents must present a signed authorization that we verify against you.
No discrimination: exercising your rights never changes your access. Anti-abuse limits (for example, three deletion requests and one export per day) protect the system and never block the right itself, because [email protected] is always available.
Response times, free of charge: we confirm receipt within 10 business days and give a substantive response within 45 calendar days, extendable once by up to 45 days with notice (CCPA/CPRA). For GDPR requests: one month, extendable by two months with notice. If we refuse a request, we explain why and offer an appeal reviewed by a second owner within 45 days — contact [email protected].
Service providers and international transfers
We use a small set of processors bound to the documented purposes: Cloudflare (CDN, WAF, TLS edge and DNS), Hosteons (VPS host in Los Angeles, US), Cloudflare R2 (encrypted off-host backups, same US jurisdiction, no cross-region replication), a transactional SMTP relay (provider being finalised), and self-hosted Prometheus/Alertmanager for metrics (no PII by policy).
None of them receives personal information for cross-context behavioural advertising, to train external models or to build cross-context profiles.
Data stays in a single US region. Where EU/UK data is transferred to a US processor, the transfer relies on that processor's Data Processing Agreement and the EU–US Data Privacy Framework or Standard Contractual Clauses where applicable. DPAs and the EU/UK Article 27 representatives are being executed and tracked as operator items (DOC-02).
No sale or sharing
We do not sell and do not share your personal information for cross-context behavioural advertising (CCPA/CPRA §1798.140(ad)/(ah)).
There are no third-party advertising or analytics trackers, so no Do Not Sell or Share My Personal Information link and no sale opt-out are required, and Global Privacy Control signals do not change how we process data.
We do not collect sensitive personal information as defined by CCPA. Any future change to this position requires a policy update, a working opt-out and an ADR before it ships.
Cookies
LIME uses only cookies required to run the service: lime_session (your session; HttpOnly, Secure, SameSite=Lax), lime_csrf (the double-submit security token required on mutating requests and sensitive GETs), and NEXT_LOCALE (stores the language you explicitly pick).
There are no analytics, advertising or tracking cookies, so the cookie notice is informational and no consent gate is shown today. If non-essential cookies are ever introduced, a consent gate becomes mandatory before they are set and this policy is updated first.
Children
LIME is not directed to children under 13, and registration does not ask for or collect age or date of birth. We do not knowingly collect personal information from children under 13.
If we learn that an account belongs to a child under 13, we delete the account and its data through the normal deletion cascade and suppress the address against re-registration. There is no behavioural advertising or profiling of minors and no sale or sharing of their data.
Security
Passwords are stored only as strong one-way hashes (bcrypt); no plaintext password is ever stored or logged.
Sessions use opaque tokens in HttpOnly, Secure, SameSite=Lax cookies; the browser never sees raw identifiers, and hashed IP and user-agent values are kept only for session defence.
Mutating requests and sensitive GETs require a CSRF token bound to the session; destructive actions also require password re-authentication and an emailed single-use code.
Traffic is protected by TLS at the edge, encrypted backups are not API reachable, audit events are append-only, and PII and secrets are excluded from logs and metrics by policy and by scanning gates. No system is perfectly secure — report suspected vulnerabilities to [email protected].
Data breaches
We triage every suspected breach within 24 hours, preserve evidence, and contain the exposure (revoke and rotate credentials) before notifying anyone.
Under the GDPR we notify the competent supervisory authority within 72 hours of becoming aware unless the breach is unlikely to result in risk, and we notify affected people without undue delay when the risk is high (Articles 33–34). Under California Civil Code §1798.82 and other US state laws, affected residents are notified without unreasonable delay, with substitute notice for very large breaches and notification of state attorneys general where required. Processors must notify us without undue delay.
We never suppress disclosure to avoid reputational cost. The full procedure is in our incident-response runbook.
Changes to this policy
This policy is versioned (version and effective date shown above). Material changes are notified to registered users at their next login, and prior versions stay archived with links. Only version 1.0 exists today.
Complaints
Contact [email protected] at any time. You also have the right to complain to your local data-protection supervisory authority (for example in the EU/UK) or the relevant authority in your US state; this does not affect any other remedy.