Privacy Policy — Lynto Labs

    Last updated: 2026-05-05

    1. Data Controller

    Lynto Labs (Cyprus) is the data controller. Contact: [email protected].

    2. Data We Collect

    We collect the following categories of personal data:

    • Account data: name, email, hashed password, authentication provider ID
    • Usage data: conversation history, uploaded files (retained during your session or as configured), AI credit usage
    • Technical data: IP address, browser type, device info, access timestamps
    • Payment data: processed by third-party providers; we store only transaction references

    3. Legal Basis for Processing (GDPR)

    • Performance of contract: providing the Service you subscribed to
    • Legitimate interest: security, fraud prevention, analytics
    • Consent: marketing communications (opt-in)
    • Legal obligation: tax, regulatory compliance

    4. How We Use Your Data

    To provide, maintain, and improve the Service; to process payments; to communicate with you about your account; to detect abuse; to comply with legal obligations.

    We do not use your conversations or uploaded files to train AI models.

    5. Data Sharing

    We share data only with: AI model providers (conversation content, processed under data processing agreements); payment processors; hosting/infrastructure providers; law enforcement when legally required.

    6. International Transfers

    Data may be transferred outside the EEA/Russia. We use Standard Contractual Clauses (SCCs) and ensure adequate safeguards per GDPR and Federal Law No. 152-FZ.

    7. Data Retention

    Account data is retained while your account is active and for 30 days after deletion. Conversation history is retained per your workspace settings. Payment records are kept for 7 years per tax law.

    8. Your Rights

    Under GDPR, CCPA, and Federal Law No. 152-FZ, you have the right to: access your data; rectify inaccuracies; erase your data; restrict or object to processing; data portability; withdraw consent. Submit requests to [email protected]. We respond within 30 days.

    9. Security

    We use encryption in transit (TLS 1.3) and at rest (AES-256), access controls, regular audits, and incident response procedures.

    10. Children

    The Service is not intended for users under 16. We do not knowingly collect data from minors.

    11. Changes

    We will notify you of material changes via email or in-app notice at least 14 days before they take effect.

    12. Contact

    Data protection inquiries: [email protected].