1. Introduction & Data Controller
This Privacy Policy explains how Lioma ("we", "us", "our") collects, uses, and protects your personal data when you use our AI-powered automation application.
Data Controller:
Lioma e.U.
Radetzkystraße 10
9020 Klagenfurt am Wörthersee, Austria
Email: privacy@lioma.eu
We are committed to protecting your privacy and processing your data in compliance with the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and the California Consumer Privacy Act (CCPA/CPRA).
Data Protection Officer: We are not required to appoint a Data Protection Officer under Article 37 GDPR. For all data protection queries, please contact privacy@lioma.eu.
2. Data We Collect
A. Account Information
- Email address, name, phone number, timezone
- Authentication credentials (securely hashed passwords, passkeys)
- OAuth identifiers (if you sign in with Google or GitHub)
- Language and notification preferences
B. Conversation & Automation Data
- Conversation transcripts with our AI assistant
- Goals, reflection entries, and other content you create
- Energy level data (productivity readiness indicator)
- AI-generated summaries and insights
- Voice data (processed in real-time for transcription, not permanently stored)
C. Usage & Behavioral Data
- Check-in preferences and schedules
- Feature usage patterns (collected only if you enable analytics)
- Session duration and engagement metrics (collected only if you enable analytics)
D. Payment Information
- Subscription plan and billing status
- Stripe customer and subscription identifiers (web purchases)
- RevenueCat anonymous user ID and entitlement status (mobile app purchases)
- Note: Your payment card details are processed directly by Stripe, Apple, or Google and never touch our servers
E. Technical Data
- IP address (in server logs)
- Browser type and device information
- Push notification endpoints (if enabled)
- Authentication tokens
F. Calendar Data (Optional)
- If you connect Google or Microsoft Calendar: we read your event titles and times
- We use event titles to suggest smarter focus times (e.g., "after your standup" or "before that client call")
- We can create focus time events in your calendar when you explicitly request it
- Calendar data is not permanently stored - we query it in real-time when needed
- Your calendar data is never shared with third parties
G. AI Assistant Data (If Enabled)
- Task execution logs and activity history
- Emails sent on your behalf (content and metadata)
- Browser session recordings (URLs visited, actions taken)
- Connected service credentials (stored encrypted)
- Workspace files created by the assistant
- Confirmation decisions (approved/rejected actions)
3. Prospects & Third-Party Contacts
This section explains how we handle personal data about people who are not Lioma users: the business contacts ("prospects") that our customers reach through Lioma's outreach features, and the professional contacts our customers store in Lioma. These outreach features are provided for business use only (see our Terms and our Data Processing Agreement).
Our Two Roles
- Processor for customer outreach: When a customer runs outreach, that customer is the data controller and Lioma acts as their processor. The customer decides whom to contact and why; we source, prepare, send, and track outreach on their documented instructions under a Data Processing Agreement. Business customers are responsible for having a lawful basis to contact each prospect and for honouring objections.
- Controller for our prospect-research database: To provide the service efficiently, we maintain a central store of business-contact and publicly available professional information that may be used across customers. Because we determine the purpose and means of that database, Lioma acts as controller for it.
Categories of Data
Business name, business email address, employer, job title, city and country, LinkedIn profile URL, publicly available professional information, and a short AI-generated research summary used to tailor outreach. For outreach a customer sends, we also process the message content (in text or, where used, AI-generated voice), delivery status, any reply, and the prospect's interactions with the personalised landing page created for them. The personalised landing page uses only first-party, privacy-friendly analytics (such as page visits) and does not set advertising or cross-site tracking cookies. We process business/professional-context data only and do not knowingly collect special categories of data (Art. 9 GDPR) about prospects.
Sources
- Our customers
- B2B contact-data providers (currently Apollo)
- Publicly accessible sources (company websites, public professional profiles, business registers and imprints)
- Address-validation providers
Legal Basis
We rely on our and our customers' legitimate interests (Art. 6(1)(f) GDPR) in initiating and conducting business-to-business relationships and outreach. We have weighed these interests against the interests and rights of the data subjects and limited the processing to a professional context, business-relevant information, frequency caps, and an easy opt-out.
Retention
We keep prospect records only as long as they remain useful for the service and automatically delete records that have been inactive for 12 months. Where a person opts out, we retain the minimum information necessary to continue honouring that opt-out (suppression), and nothing more.
Recipients
To deliver outreach, prospect data may be shared with our postal provider (Pingen), address-validation providers, the relevant messaging channel (for example LinkedIn or our email provider), and our EU hosting provider (AWS, Frankfurt).
Your Rights If You Are a Prospect
You have the right to access, rectification, restriction, erasure, and data portability, and an unconditional right to object to direct marketing at any time (Art. 21(2) GDPR). To exercise these rights, email privacy@lioma.eu or use the "remove me" link on the landing page or letter you received. An objection or erasure removes you from our prospect database and suppresses future contact across the entire Lioma platform. You may also contact the customer who reached out to you; we will assist them as their processor.
Source of Your Data (Art. 14 GDPR)
Where we did not obtain your data from you directly, we obtained it from the sources listed above. This notice, together with the notice provided at the point of contact, satisfies our information obligations under Article 14 GDPR.
4. How We Use Your Data & Legal Basis
Under the General Data Protection Regulation (GDPR), we must have a valid legal basis for each processing activity. The table below provides a comprehensive overview of what data we process, for what purposes, and our legal justification under Article 6(1) GDPR.
Legal Bases We Rely On
- Art. 6(1)(a) GDPR - Consent: You have given clear consent to process your personal data for a specific purpose.
- Art. 6(1)(b) GDPR - Contract: Processing is necessary for the performance of a contract with you, or to take steps at your request before entering into a contract.
- Art. 6(1)(c) GDPR - Legal Obligation: Processing is necessary to comply with a legal obligation to which we are subject.
- Art. 6(1)(f) GDPR - Legitimate Interests: Processing is necessary for legitimate interests pursued by us, except where overridden by your interests or fundamental rights.
Detailed Data Processing Overview
| Data Category |
Specific Data |
Processing Purpose(s) |
Legal Basis |
| Account Information | Email address | Account creation, authentication, password reset, transactional communications | Art. 6(1)(b) - Contract |
| Account Information | Email address | Marketing communications, weekly summaries, reminders | Art. 6(1)(a) - Consent |
| Account Information | Name, timezone, language preference | Personalization, displaying correct times, service delivery | Art. 6(1)(b) - Contract |
| Phone Number | Phone number | SMS/WhatsApp/Signal check-in reminders, voice call check-ins | Art. 6(1)(b) - Contract |
| Phone Number | Phone number | Enabling the SMS/WhatsApp/Signal/voice channel (requires explicit opt-in) | Art. 6(1)(a) - Consent |
| Authentication Data | Hashed password, passkeys, OAuth identifiers | Secure authentication, account access | Art. 6(1)(b) - Contract |
| Authentication Data | Magic link tokens, 2FA secrets | Passwordless login, enhanced account security | Art. 6(1)(b) - Contract |
| Conversation Content | Conversation transcripts with AI assistant | Providing AI automation service, generating personalized responses, displaying history | Art. 6(1)(b) - Contract |
| Conversation Content | AI-generated summaries and insights | Pattern detection, personalized automation recommendations | Art. 6(1)(b) - Contract |
| Reflections & Journaling | Reflection entries, energy level data | Journaling feature, productivity tracking, AI-powered pattern analysis | Art. 6(1)(b) - Contract |
| Reflections & Journaling | Photos attached to reflection entries | Enriching reflection entries, displaying your content back to you | Art. 6(1)(b) - Contract |
| Goals & Progress | Daily goals, goal completion status | Goal tracking feature, progress visualization, AI context | Art. 6(1)(b) - Contract |
| Gamification | Stamps, streaks, ranks, letters, patterns | Achievement system, motivation features, progress tracking | Art. 6(1)(b) - Contract |
| Voice Data | Voice audio (real-time, not stored) | Real-time transcription for voice conversation feature | Art. 6(1)(a) - Consent + Art. 6(1)(b) - Contract |
| Calendar Data | Calendar events (titles, times) | Suggesting optimal focus times, context-aware scheduling | Art. 6(1)(a) - Consent |
| AI Assistant Data | Activity logs, emails sent, browser sessions, connected services, workspace files | Automated task execution, email sending, browser automation, service integration | Art. 6(1)(b) - Contract |
| AI Assistant Data | Connected service credentials (OAuth tokens, session cookies) | Accessing third-party services on your behalf | Art. 6(1)(a) - Consent |
| Check-in Data | Reminder schedules, check-in responses | Delivering scheduled reminders, recording progress | Art. 6(1)(b) - Contract |
| Subscription & Payment | Subscription status, Stripe/RevenueCat IDs | Determining feature access, payment processing | Art. 6(1)(b) - Contract |
| Subscription & Payment | Payment history, invoices | Tax compliance, accounting records, dispute resolution | Art. 6(1)(c) - Legal Obligation |
| Technical Data | Push notification endpoints | Delivering push notifications for reminders and updates | Art. 6(1)(b) - Contract |
| Technical Data | IP address, browser/device info | Security monitoring, fraud prevention, abuse detection | Art. 6(1)(f) - Legitimate Interests |
| Analytics Data | Feature usage, session data, page views | Service improvement, understanding user needs, fixing bugs | Art. 6(1)(a) - Consent (opt-in, off by default) |
| Consent Records | Consent timestamps, consent method, IP at time of consent | Demonstrating GDPR compliance, audit trail | Art. 6(1)(c) - Legal Obligation |
| Server Logs | Request logs, error logs | Debugging, security monitoring, service reliability | Art. 6(1)(f) - Legitimate Interests |
Legitimate Interests Assessment
Where we rely on legitimate interests (Art. 6(1)(f) GDPR), we have conducted a balancing test to ensure our interests do not override your fundamental rights. Our legitimate interests include:
- Security: Protecting our service and users from fraud, abuse, and unauthorized access. This is essential for maintaining trust and service integrity.
- Debugging: Identifying and resolving technical issues to ensure service reliability.
You have the right to object to processing based on legitimate interests. Contact privacy@lioma.eu to exercise this right.
Special Categories of Data
We do not intentionally collect special categories of personal data as defined in Article 9 GDPR (racial or ethnic origin, political opinions, religious beliefs, health data, etc.).
Energy Level Data: Lioma allows you to log your "energy level" as a productivity readiness indicator. This is explicitly not health data. Energy level is a subjective productivity metric (similar to "how focused do you feel?" or "how ready are you to tackle your goals?") - not a medical, diagnostic, or mental health measurement. We do not use this data to infer health conditions, provide health recommendations, or for any medical purpose.
5. Third-Party Service Providers
We work with trusted third-party providers to deliver our service. All providers are bound by data processing agreements and appropriate safeguards.
Infrastructure & Hosting
- Amazon Web Services (AWS): Application hosting on ECS Fargate and database on RDS PostgreSQL (EU region - Frankfurt, eu-central-1)
- AWS EC2: Cloud servers for AI assistant workers (EU region - Frankfurt, eu-central-1)
- AWS S3: Cloud storage for generated images and media files (EU region - Frankfurt)
- AWS CloudFront: Content delivery network for the web application (EU edge locations)
- Cloudflare: DNS, CDN, and network security for our domains (receives request metadata such as IP address)
Authentication (optional)
- Google OAuth: Sign-in (receives email, name, profile picture)
- Apple Sign-In: Sign-in (receives email, name - may be anonymized by Apple)
- Microsoft/Entra ID: Sign-in (receives email, name)
- GitHub OAuth: Sign-in (receives email, name, username)
AI & Voice Processing
- AWS Bedrock: Primary AI model hosting and inference via the Bedrock Converse API (receives conversation context for text and anonymized scene descriptions for image generation; processed in the EU region - Frankfurt, eu-central-1, with US - us-east-1 failover for availability)
- Anthropic: AI model provider used as a fallback only (receives conversation context for generating responses via the Anthropic API when Bedrock is unavailable)
- AssemblyAI (optional): Speech-to-text transcription (receives voice audio)
- Inworld (optional): Text-to-speech synthesis (receives response text)
Communications
- Brevo: Email delivery (receives email address, message content)
- Twilio (optional): SMS and voice calls (receives phone number, message content)
- WhatsApp (self-hosted bridge) (optional): WhatsApp messaging via a self-hosted bridge (WhatsApp Web-based) running on our own EU-based infrastructure. Messages still transit WhatsApp/Meta servers and are end-to-end encrypted by WhatsApp (receives phone number, message content)
- Signal (via signal-cli-rest-api) (optional): Signal messaging (receives phone number, message content). Hosted on our own EU-based infrastructure
- Apple Push Notification Service (APNs) (optional): iOS push notifications (receives device token, notification content)
- Firebase Cloud Messaging (FCM) (optional): Android push notifications (receives device token, notification content)
Calendar Integrations (optional)
- Google Calendar API: Calendar read/write access (receives event titles, times, availability - see Section 18 for details)
- Microsoft Graph: Calendar integration for Microsoft/Outlook calendars (receives event titles, times, availability)
Prospecting & Outreach (business use)
- Apollo: B2B contact-data provider used to source business prospects (receives search criteria; provides business-contact data)
- Pingen: Postal delivery of physical letters (receives recipient name, business address, and letter content)
- Loqate: Postal address validation (receives address data)
- Google Places / Maps: Business address resolution (receives business name and location queries)
- Tavily, Brave, Jina: Web research to prepare outreach (receive search queries and public web content)
- Composio: Integration layer for connecting third-party tools you authorise
- LinkedIn: Delivery of LinkedIn outreach from your own connected LinkedIn account, which you authorise us to act through on your behalf
Payments
- Stripe: Web payment processing (PCI-DSS Level 1 compliant)
- Apple App Store: In-app purchases on iOS (processed by Apple)
- Google Play: In-app purchases on Android (processed by Google)
- RevenueCat: Subscription management for mobile apps (receives anonymous user ID, purchase receipts, subscription status)
Analytics
We collect usage analytics only if you turn on analytics in Settings, which is off by default (processed with your consent under Art. 6(1)(a) GDPR, recorded when you opt in). This data is stored in our own database within the European Union and is not shared with third-party analytics providers. We do not use advertising or cross-site tracking analytics (such as Google Analytics). You can turn analytics off at any time in Settings.
Monitoring & Observability
- Sentry: Error tracking and performance monitoring (receives error reports, user context for debugging)
- Logtail (Better Stack): Centralized log management (receives application logs, request metadata)
Security
- Have I Been Pwned: Password breach checking (receives only partial password hash prefixes via k-anonymity protocol - your password is never transmitted)
6. Voice & AI Data Processing
Lioma uses AI to provide personalized automation. Here's how your voice and conversation data is processed:
How Voice Conversations Work
- Your voice is streamed to AssemblyAI for real-time transcription
- The transcription is sent to Claude AI to generate a response
- The response text is converted to speech via Inworld
- The full conversation transcript is saved to your account
Important Information
- Raw audio is NOT permanently stored: it's processed in real-time only
- Transcripts ARE stored in your account history (you can delete them)
- AI responses are generated, not pre-written or human-reviewed
- No automated decisions with legal effects: AI provides suggestions only
- You control your data: delete conversation history anytime in Settings
No Biometric Data Collection
We do NOT create, store, or use voiceprints or any biometric identifiers derived from your voice. Voice audio is processed solely for real-time transcription and is not used for speaker identification, authentication, or any biometric purpose. Your voice characteristics are never analyzed, stored, or compared for identification purposes.
7. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), primarily the United States, where our service providers operate.
Safeguards we use:
- EU-US Data Privacy Framework (DPF) for certified providers
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Supplementary technical measures (encryption in transit and at rest)
- Data Processing Agreements (DPAs) with all processors
Provider-Specific Transfer Mechanisms
| Provider |
Purpose |
Processing Location |
Transfer Mechanism |
| AWS Bedrock | Primary AI inference, responses and image generation | EU (Frankfurt) primary, US (us-east-1) failover | EU-primary; US failover under DPF + SCCs |
| Apollo | B2B prospect data source | US | SCCs |
| Anthropic | Fallback AI model provider (Claude) | US | SCCs |
| AssemblyAI | Speech-to-text | US | DPF certified |
| Inworld | Text-to-speech | US | SCCs |
| AWS (ECS, RDS, S3, CloudFront) | Application hosting, database & storage | EU (Frankfurt) | No transfer (EU-based) |
| AWS EC2 | AI assistant cloud servers | EU (Frankfurt) | No transfer (EU-based) |
| Stripe | Payment processing | EU/US | DPF + SCCs |
| Twilio | SMS/Voice calls | US | DPF + SCCs |
| Brevo | Email delivery | EU (France) | EU-based |
Other sub-processors listed in Section 5 may process limited data outside the EEA; where they do, we rely on Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
8. Data Retention & Deletion
We retain your data only as long as necessary:
| Data Category |
Retention Period |
| Account data (email, name) | Until account deletion (then anonymized) |
| Conversation transcripts | Until you delete them or delete account |
| Reflection entries & goals | Until you delete them or delete account |
| Stamps & patterns | Until account deletion |
| Payment/subscription records | 7 years (legal/tax requirement) |
| Magic login tokens | 24 hours |
| Voice recordings | Not stored (real-time processing only) |
| Server logs | 90 days |
| Database backups | 30 days (rolling) |
| AI assistant activity logs | Until account deletion |
| Connected service credentials | Until you disconnect the service or delete account |
| Browser session data | Persists for the duration of the task execution, then automatically cleaned up |
| Prospect research data (business contacts) | Deleted after 12 months of inactivity, or on opt-out / erasure |
| Suppression / opt-out list | Retained as long as needed to honour the opt-out |
Account Deletion Process
When you delete your account, the following happens immediately:
- Permanently deleted: Goals, reflection entries, conversations, letters, stamps, patterns, calendar integrations, check-in schedules, and passkeys
- Anonymized: Your user record is kept but anonymized (email becomes anonymous, name becomes "Deleted User", password cleared) for accounting purposes
- Retained: Subscription record with payment provider IDs (required for tax/accounting compliance for 7 years)
- Canceled: Any active subscription is automatically canceled
To delete your account, you must confirm via email for security. For detailed instructions, see our account deletion guide.
Deleting Individual Data
You can delete specific data without deleting your entire account:
- Reflection entries: Tap on an entry in Reflections, then tap the delete icon
- Check-in reminders: Go to Check-ins and tap the trash icon next to any reminder
- Bulk deletion: Contact privacy@lioma.eu to delete all reflection entries, goals, or conversation history while keeping your account
Third-Party Data Retention
When you delete your account, we instruct our service providers to delete your data. However, some providers may retain data according to their own policies:
- Stripe/RevenueCat: Payment records retained for their legal compliance requirements
- AI providers (AWS Bedrock): May retain conversation data per their data retention policies (typically 30 days for abuse monitoring)
- Communication providers (Twilio, Brevo): Message logs retained per their policies
9. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right of Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Correct inaccurate or incomplete data
- Right to Erasure (Art. 17): Delete your account and all data ("right to be forgotten")
- Right to Restriction (Art. 18): Limit how we process your data
- Right to Data Portability (Art. 20): Export your data in a structured, commonly used, machine-readable format (JSON)
- Right to Object (Art. 21): Object to processing based on legitimate interest
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
How to Exercise Your Rights
- Email: privacy@lioma.eu
- In-app: Settings → Delete Account
- Response time: Within 30 days
Supervisory Authority
You have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Vienna, Austria
dsb@dsb.gv.at
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
Categories of Personal Information Collected
- Identifiers: Name, email, phone number, IP address
- Commercial information: Subscription and payment history
- Internet activity: Usage data, conversation history
- Audio information: Voice processed for transcription (not stored)
- Inferences: AI-generated insights, productivity patterns
Your CCPA Rights
- Right to Know: Request disclosure of data we've collected
- Right to Delete: Request deletion of your data
- Right to Correct: Request correction of inaccurate data
- Right to Opt-Out: We do NOT sell your personal information
- Right to Non-Discrimination: No penalty for exercising your rights
"Do Not Sell My Personal Information"
Lioma does not sell your personal information. We do not share your data for cross-context behavioral advertising. Your data is only shared with service providers necessary to operate our service.
How to Exercise CCPA Rights
Email: privacy@lioma.eu
Response time: Within 45 days
Verification: We verify requests via email confirmation to your registered account.
Business Prospect Data
Where we process the personal information of California residents as business prospects, they have the same rights described above, including the rights to know, delete, and correct. We do not sell prospect data. To exercise these rights or to be removed, email privacy@lioma.eu or use the removal link in the message you received.
11. Cookies & Browser Storage
We use localStorage for essential functions:
- Authentication token (to keep you logged in)
- Language preference
- Voice mute setting
Analytics
We collect usage analytics only if you turn on analytics in Settings, which is off by default (processed with your consent under Art. 6(1)(a) GDPR). This data is stored in our own database within the European Union and is not shared with third-party analytics providers. You can turn analytics off at any time in Settings.
We do NOT use:
- Google Analytics or similar advertising analytics
- Advertising cookies or trackers
- Cross-site tracking pixels
Other third-party cookies: May be set by Stripe (during checkout) or Google (during OAuth sign-in). These are subject to their respective privacy policies.
12. Children's Privacy
- Lioma is not intended for users under 16 years of age
- We do not knowingly collect personal data from children under 16
- If we discover we have collected data from a child under 16, we will delete it promptly
- Parents or guardians may contact us at privacy@lioma.eu
13. Payment Processing
Web Payments (Stripe)
- Payments are processed securely by Stripe, a PCI-DSS Level 1 certified processor
- We never see or store your full credit card number
- We only receive: transaction confirmations and subscription status
- Stripe's privacy policy: stripe.com/privacy
Mobile App Purchases (Apple & Google)
- In-app purchases on iOS are processed by Apple through the App Store
- In-app purchases on Android are processed by Google through Google Play
- We use RevenueCat to manage subscriptions across platforms
- RevenueCat receives: anonymous user ID, purchase receipts, and subscription status
- We never see your payment method details for in-app purchases
- RevenueCat's privacy policy: revenuecat.com/privacy
- Apple's privacy policy: apple.com/legal/privacy
- Google's privacy policy: policies.google.com/privacy
14. Communication Services
Notification Categories
We send different types of notifications, each with its own consent requirements:
- Transactional: Account-related messages (welcome emails, password resets, purchase confirmations). Sent to all users as necessary for service operation.
- Check-in Reminders: Messages you schedule yourself (daily goal reminders, reflection prompts). Controlled by channel toggles in Settings.
- Achievement Celebrations: Notifications about your progress (streaks, rank-ups, letter unlocks). Can be disabled in Settings.
- Marketing & Nudges: Weekly digests, inactivity nudges, quarterly vision reminders. Requires explicit opt-in at signup or in Settings.
SMS is only used for check-in reminders you schedule - never for marketing or promotional content.
Email (via Brevo)
- Used for: Magic links, password resets, check-in reminders, achievement celebrations, and (if opted-in) marketing digests
- You can manage email preferences in Settings
SMS (via Twilio)
- Used for: Check-in reminders only (if you opt in)
- We do not send marketing or promotional SMS
- Standard messaging rates may apply from your carrier
- Text STOP to opt out at any time
WhatsApp (self-hosted bridge)
- Used for: Check-in reminders and notification messages (if you opt in)
- We operate our own self-hosted WhatsApp bridge (WhatsApp Web-based) on EU-based infrastructure. We do not use an official WhatsApp Business API relationship with Meta
- When you opt in, messages are sent to and from your phone number over WhatsApp. As with any WhatsApp message, the content transits WhatsApp/Meta servers
- Message content is end-to-end encrypted by WhatsApp
- You can opt out at any time by replying STOP or updating your preferences in Settings
- We do not use WhatsApp data for advertising purposes
- Meta's WhatsApp privacy policy also applies to messages that transit WhatsApp: whatsapp.com/legal/privacy-policy
Signal (Self-Hosted)
- Used for: Check-in reminders and notification messages (if you opt in)
- We operate our own Signal bridge on EU-based infrastructure using the open-source signal-cli-rest-api
- When you opt in, your phone number is used to send Signal messages
- Message content is end-to-end encrypted by Signal
- You can opt out at any time by updating your preferences in Settings
- No data is shared with third parties for Signal messaging
Voice Calls (via Twilio)
- Used for: Voice check-ins (if you opt in)
- You control when and how often we call
Push Notifications
- Browser and native app push notifications
- Used for: check-in reminders, achievement celebrations, and (if opted-in) nudges
- Achievement and marketing notifications respect your Settings preferences
- Disable anytime in Settings or your device/browser preferences
Consent History
We maintain an immutable audit trail of all your consent decisions (when you opt in or out of marketing communications). This record includes the timestamp, method of consent, and IP address for compliance purposes. You can view your consent history in Settings.
15. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit: TLS 1.3 for all connections
- Encryption at rest: Database encryption, encrypted OAuth tokens
- Access controls: Role-based access, authentication requirements
- Secure development: Regular security reviews, dependency updates
- Password security: Bcrypt hashing, never stored in plain text
No system is 100% secure. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.
16. AI Assistant Infrastructure Security
Lioma's personal assistant is powered by a custom AI agent infrastructure built by the Lioma team. We deliberately chose not to use third-party or open-source AI agent frameworks, because they introduce security risks that are difficult to mitigate in a managed service: public skill marketplaces that allow untrusted third-party code, broad system access that expands the attack surface, and credential handling patterns that expose API keys to the AI model itself.
By building our own infrastructure, we control every layer of the stack and can enforce security guarantees that are not possible with general-purpose agent frameworks.
Isolated Environment
Every Lioma user receives a dedicated, isolated environment for their personal AI assistant. Your assistant runs under its own operating-system account with its own files, configuration, and credentials, isolated from other users at the operating-system layer, so no other user's assistant can access your personal workspace, files, or credentials. When you use outreach features, messages are sent from the accounts you connect (for example, your own LinkedIn account, which you authorise us to act through on your behalf), not from shared accounts.
No Third-Party Code
Unlike agent frameworks that support public plugin or skill marketplaces, Lioma Runtime has no mechanism for third-party code installation. Every capability your assistant has was authored, reviewed, and deployed by the Lioma team. This eliminates the supply chain risks that have affected open-source agent ecosystems.
Credential Isolation
Open-source agent frameworks typically place API keys and authentication tokens directly in the agent's configuration, where the AI model can see them. This creates a risk that prompt injection or malicious web content could trick the agent into revealing those credentials.
Lioma Runtime uses a proxy architecture instead. When your assistant needs to access an external service, the request routes through the Lioma backend, which injects authentication server-side. Your assistant never sees raw API keys or tokens. This applies to search services, language model access, and your own API keys if you have chosen to bring your own.
Minimal Attack Surface
Lioma Runtime is purpose-built for Lioma's use case. It does not include features common in general-purpose agent frameworks that widen the attack surface:
- No plugin marketplace: No mechanism for untrusted code to run on your instance.
- Sandboxed browser: Your assistant browses the web through an isolated headless browser with no access to your local machine or desktop.
- No direct credential access: All authentication is proxied through the Lioma backend.
- Restricted shell access: All commands executed by your assistant are security-screened and limited to pre-approved operations within your isolated environment.
Security Patching
Because we own the full stack, we can patch vulnerabilities without waiting for upstream releases. We continuously monitor our infrastructure and deploy security fixes promptly.
What Your Assistant Can Access
Your assistant has access to:
- Your conversations within Lioma
- Your goals, vision, and reflection entries
- Websites you ask it to visit
- Files in your personal workspace
- Your calendar (if connected)
Your assistant does not have access to:
- Other users' data or environments
- Raw API keys or authentication tokens
- Your email inbox (unless you have explicitly connected the email service)
- The Lioma backend infrastructure
Data Collected Through AI Assistant Actions
When your AI assistant performs automated tasks, we collect and store the following additional data:
- Activity logs: Records of tools used, tasks performed, and estimated time saved
- Email records: Metadata (recipients, subjects, timestamps) and content of emails sent through the assistant
- Browser session data: URLs visited, actions taken, and cookies stored during browser automation sessions. Browser sessions are isolated per user and automatically expire
- Connected service tokens: OAuth tokens or session cookies for services you connect. These are stored encrypted and isolated in your personal environment
- Workspace files: Files your assistant creates or manages in your personal workspace
- Confirmation history: Records of actions requiring your approval and your approval/rejection decisions
All AI assistant data is subject to the same retention, deletion, and export policies described in Section 8 of this Privacy Policy. When you delete your account, all AI assistant data, including connected service credentials, workspace files, and activity logs, is permanently deleted.
17. Automated Decision-Making
- Our AI provides suggestions, insights, and automation
- These are recommendations only, not binding decisions
- There is no automated decision-making with legal or similarly significant effects on you
- You always control your goals, actions, and data
AI System Transparency (EU AI Act)
In accordance with Regulation (EU) 2024/1689 (the EU AI Act):
- Our AI system generates personalized responses using large language models (currently AWS Bedrock). These responses are generated automatically without human review
- Lioma's AI features are classified as limited-risk AI systems. We comply with the transparency obligations set out in Article 50 of the EU AI Act
- All AI interactions with our AI assistants are clearly identified as AI-powered. You are interacting with artificial intelligence, not humans
- AI-generated content (reflection narratives, illustrations, emails sent by the AI assistant) is identified as AI-generated both visibly and through machine-readable markers where technically feasible
- Sentiment analysis within conversations is text-based only. We do not use biometric data, facial recognition, or physiological signals for emotion recognition
- You may use Lioma without engaging with AI features. Core functionality (manual goal tracking, reflection entries) works without AI interaction
18. Google Sign-In & Calendar Integration
Google Sign-In
When you sign in with Google, we receive your name, email address, and profile picture to create or access your account. We do not access any other Google data.
Google Calendar Integration
If you connect Google Calendar:
- Reading: We read your event titles and times to suggest smarter focus times (e.g., "after your standup" or "before that client call")
- Creating: When you ask Lioma to schedule focus time, we create events directly in your calendar
- We use calendar access only to suggest optimal focus times and schedule sessions you request
- We do NOT store calendar data permanently - it's queried in real-time
- Your calendar data is never shared with third parties
- Disconnect anytime in Settings
Google API Limited Use Disclosure
Lioma's use of Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements:
- We use Google data only for purposes described in this policy
- We do not use Google data for advertising
- We do not allow humans to read Google data without explicit consent
- We do not transfer Google data except as necessary for the service
- The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google Workspace data to create, train, or improve generalized AI or machine learning models.
19. Data Breach Response
We maintain a documented incident response plan to handle potential data breaches in compliance with GDPR Article 33/34 and applicable US state laws.
Our Commitment
- Detection: We monitor our systems for unauthorized access, data exfiltration, and security anomalies
- Assessment: Upon detecting a potential breach, we immediately assess the scope, affected data, and risk to individuals
- Authority notification: If a breach is likely to result in risk to individuals, we will notify the Austrian Data Protection Authority (DSB) within 72 hours as required by GDPR
- User notification: If a breach is likely to result in high risk to your rights and freedoms, we will notify affected users without undue delay
- US state requirements: For US users, we comply with applicable state breach notification laws (e.g., California, Colorado, Virginia) which may have varying notification timelines
What We Will Tell You
In the event of a breach affecting your data, our notification will include:
- Nature of the breach and categories of data affected
- Likely consequences of the breach
- Measures we have taken or propose to take
- Contact point for further information
- Recommendations for protecting yourself
20. Record of Processing Activities
In accordance with GDPR Article 30, we maintain a comprehensive Record of Processing Activities (ROPA) that documents:
- All categories of personal data we process
- Purposes of each processing activity
- Legal basis for each processing activity
- Categories of data subjects and recipients
- International transfers and safeguards
- Retention periods for each data category
- Technical and organizational security measures
This internal document is available for inspection by the Austrian Data Protection Authority (DSB) upon request. If you wish to understand how your specific data is processed, please contact privacy@lioma.eu.
21. Changes to This Policy
- We may update this policy to reflect changes in our practices or legal requirements
- Material changes will be communicated via email and/or in-app notification
- The "Last updated" date at the top indicates the most recent revision
- Continued use after changes constitutes acceptance of the updated policy
- Previous versions are available upon request
22. Contact Us
Data Controller:
Lioma e.U.
Radetzkystraße 10
9020 Klagenfurt am Wörthersee, Austria
Privacy inquiries: privacy@lioma.eu
General inquiries: info@lioma.eu
Data Protection Authority:
Österreichische Datenschutzbehörde (DSB)
Barichgasse 40-42, 1030 Vienna, Austria
www.dsb.gv.at