Privacy
How information is handled when you visit or use lilis.
Last updated
1. Who this policy is about
lilis is operated by Particular Labs LLC, a Florida limited liability company, in the United States.
Two different groups of people appear in this policy, and their situations differ.
Businesses that use lilis are our customers. They decide what information goes into lilis and what lilis does with it.
People who contact those businesses are in a different position. If you emailed, texted or called a business that uses lilis, your message may have been processed by our service. We handle that information on behalf of that business, under its instructions. If you want your information corrected or removed, contact the business directly, because we act on its instruction and not independently.
2. Definitions
- Business
- An organization with a lilis account.
- End customer
- A person who contacts a Business through a channel connected to lilis.
- Message content
- The text and attachments of emails, text messages and call transcripts processed by the service.
- Business data
- Information a Business enters or lilis derives: contacts, records, services, locations, procedures and rules.
- Activity record
- Our permanent, append-only log of every action the service took.
- Sub-processor
- A third-party service that receives data in order for lilis to function.
3. What we collect
From a Business:
- Account and contact details for the organization and each member
- Authentication information. We use email sign-in links and passwords, and we do not store passwords in readable form
- Business data as defined above
- Configuration: connected channels, credentials for services you connect, settings and rules
- Billing and usage records
From messages processed on a Business's behalf:
- Message content, including headers, body text, attachment information and call transcripts
- Sender and recipient identifiers: email addresses and phone numbers
- Information extracted from messages by the service, such as names, dates, amounts and requests
Automatically:
- Standard technical logs: IP addresses, browser and device information, timestamps, error records
- Usage measurements for billing, including AI model usage and cost
We do not knowingly collect information from anyone under 18, and the service is not intended for them.
4. Why we process it, and on what basis
We process information to operate the service for the Business: receiving and classifying messages, extracting details, drafting responses, maintaining records, sending approved messages, keeping the activity record, measuring usage for billing, providing support, and diagnosing failures.
We also use aggregate, non-content information such as counts, timings and error rates to keep the service running and improve it. This never includes message content, contact details or anything identifying an End customer.
We do not sell information, share it for advertising, use Business data or Message content to train AI models, or use it for any purpose other than operating the service for that Business.
For Businesses, our basis is the contract between us. For End customers, we act as a processor on the Business's behalf, and the Business is responsible for having a lawful basis to process the communications it directs to us.
5. Sub-processors
We use these third parties, each receiving only what its function requires.
| Sub-processor | Purpose | Data received |
|---|---|---|
| Sub-processorOpenAI | PurposeAI model inference: reading, classifying, extracting and drafting. We do not use your business's messages to train AI models, and OpenAI's API data usage policy states that data submitted through the API is not used to train its models by default. It is also the language model on phone calls, and it turns voice messages recorded in the chat into text. | Data receivedMessage content, thread context, and the Business's own rules and procedures; what is said on a phone call, as text; voice message audio |
| Sub-processorResend | PurposeEmail delivery, email receipt on one inbound path, and delivery status reporting | Data receivedOutbound email content, inbound email content on that path, and delivery events such as bounces and complaints |
| Sub-processorTwilio | PurposeText message delivery, inbound and outbound, through the Business's own account. It also carries phone calls to and from lilis | Data receivedPhone numbers and full message content, both directions; the audio of phone calls to and from lilis |
| Sub-processorCloudflare | PurposeReceiving inbound email at the edge and routing it to lilis for processing | Data receivedThe full raw content of inbound email, including headers, body and attachment information |
| Sub-processorHostinger | PurposeApplication and database hosting | Data receivedAll stored data, because the database and the application run on this infrastructure |
| Sub-processorComposio | PurposeEmail and calendar connections. For a business that connects its Gmail or Outlook mailbox, or its Google or Outlook calendar, Composio runs that connection: Composio holds the OAuth tokens and lilis holds only the connection id, never the token itself. Email is read and sent, and free/busy times and calendar events are read and written, through Composio. Nothing reaches Composio until a business connects a mailbox or calendar. | Data receivedMailbox and calendar OAuth tokens, held by Composio and never by lilis; email message content, including the email addresses of senders and recipients; calendar event details, including the email addresses of people invited; free and busy times |
| Sub-processorLiveKit | PurposePhone calls. LiveKit connects the phone line to lilis and carries the call audio. It also passes speech recognition and language model requests on to their providers when no direct key for that provider is set. | Data receivedPhone call audio; phone numbers of the caller and the number called |
| Sub-processorDeepgram | PurposeSpeech recognition on phone calls. Deepgram turns what the caller says into text so lilis can respond. It receives the call audio, directly or through LiveKit. | Data receivedPhone call audio |
| Sub-processorElevenLabs | PurposeText to speech on phone calls. ElevenLabs turns the words lilis says into spoken audio. When no Deepgram key is set, it also does the speech recognition for the call. | Data receivedThe words lilis says on a phone call, as text; phone call audio, when it does the speech recognition |
| Sub-processorExpo | PurposeDelivering push notifications to a member's phone. The notification text passes through Expo on its way to the device. | Data receivedNotification title and text; the device's push token |
| Sub-processorAnthropic | PurposeAI model inference, only when lilis is set to use an Anthropic model instead of OpenAI: reading, classifying, extracting and drafting. We do not use your business's messages to train AI models. | Data receivedMessage content, thread context, and the Business's own rules and procedures, only when an Anthropic model is selected |
| Sub-processorSlack | PurposeSending notifications to a business that connects its own Slack workspace. This is the business's own choice, not a default connection. | Data receivedNotification text, only for a business that connects its own Slack workspace; it can include a customer's email address |
| Sub-processorThe business's own email provider | PurposeSending and receiving mail, for a business that connects its own mailbox instead of using the address lilis provides. | Data receivedThe full content of inbound and outbound mail in the business's own mailbox, reached through the business's own account |
| Sub-processorGlitchTip | PurposeError monitoring for the lilis servers, web workspace and mobile app. We run it ourselves; the GlitchTip company receives no data. | Data receivedError reports: error messages, stack traces and technical context, which can include part of the data being handled when the error happened |
| Sub-processorPostHog | PurposeProduct analytics for the web workspace and mobile app: which screens and actions people use, to find where they get stuck. Dormant until a project key and host are configured. Never receives message content, names, emails, or phone numbers. Every event is validated against a closed, typed schema before it can be sent. | Data receivedProduct usage events: screen and action names and counts, and opaque user and organization identifiers. No message content, names, emails or phone numbers |
Processing locations vary by sub-processor, and each publishes its own terms.
OpenAI's API data usage policy is published at https://openai.com/policies/api-data-usage-policies.
We will give Businesses notice before a new sub-processor begins processing their data, and before an existing one changes in a way that affects what it receives.
6. How long we keep information, and what deletion actually does
This section says what the system does, not what is conventional.
- The activity record is permanent. Our log of what the service did is append-only and cannot be modified or deleted, including by us and including on request.
- Contacts and records are archived, not erased. Removing one from view is reversible.
- Message content is retained. Stored message bodies are not deleted on a schedule and there is no automatic expiry.
- Credentials are retained while an account exists, encrypted. Disabling a connection does not delete them.
- Usage records are retained for billing and cannot be deleted in ordinary operation.
- Deletion is whole-organization only. On a Business's request we can delete that organization entirely, irreversibly.
- We cannot delete an individual person's information while keeping the rest. No such capability exists today.
What survives a deletion, because we will not tell anyone their data is completely gone:
- Database backups, until they expire on their own schedule
- Messages already sent, which live in recipients' mailboxes and phones
- Copies held by the sub-processors above, under their own retention terms
- Our operational and error logs
- The audit record of the deletion itself, which is deliberately preserved
7. Security
Access to production systems is limited to personnel who need it. Credentials Businesses provide are encrypted. Each organization's data is isolated at the database level, covered by the isolation tests in our release checks. Actions taken by our operators are logged.
No system is perfectly secure and we do not claim otherwise. If we become aware of a security incident affecting a Business's data, we will notify affected customers without undue delay and describe what we know, what we are doing about it, and what they should do.
8. Your choices
Businesses can view, correct and export their data through the service or by asking us, can disconnect any channel, and can request organization deletion subject to the retention section above.
End customers should contact the Business they were dealing with. To stop receiving texts, reply STOP. That is enforced automatically and immediately.
Where applicable law gives you rights over your information, we will honour them to the extent the system can. Our per-person limitation above is a real constraint and we state it rather than promise around it. Write to us and we will tell you plainly what we can and cannot do in your case.
9. International
We operate from the United States and our infrastructure is located there. The service is offered to businesses in the United States. If you are outside the United States, your information will be processed in the United States.
10. Changes
We will update this notice as the service changes. Material changes will be communicated to Businesses before taking effect, and the date at the top of this page will change.
11. Contact
Questions about privacy can be sent to admin@particularlabs.com. Particular Labs LLC, Florida, United States.