1. Information We Collect
We collect several different types of information for various purposes to provide and improve our Platform:
- Account Data: Email address, username, and profile information provided during registration via Clerk authentication.
- Usage Data: Browser type, browser version, pages visited, time spent on pages, and device identifiers collected through standard web protocols.
- Local Storage: Theme preferences, UI state, and cached session metadata stored locally in your browser. AI credit balances are not stored in local storage β they are stored server-side in our Supabase credit ledger.
- Conversations & Project Memory: Messages sent to AI agents, conversation history, project context, and agent memories are durably stored in our Supabase database. Conversations are linked to your account and projects, and persist across sessions.
- AI Credit Ledger: Your AI credit balance, transaction history (grants, spending, purchases), and billing records are stored server-side in our Supabase credit ledger.
- Uploaded Media & Attachments: Files, images, audio, and other media you upload or generate are stored in Cloudflare R2 object storage and linked to your account.
- Voice Data:When you use voice features in Studio, your microphone audio is streamed to Inworld AI for speech-to-text transcription. The transcribed text is processed through the canonical Studio conversation. Generated responses may be sent to Inworld's dedicated TTS service for audio playback.
- Camera & Screen Sharing: When you use camera preview or screen sharing features in Studio, camera output and screen content are processed locally in your browser and may be shared within your active session. These features require explicit browser permission prompts.
- GitHub Connection Data: When you connect a GitHub repository, we store repository references, branch information, and deployment metadata to enable project synchronization and terminal workspace provisioning.
2. How We Use Your Information
LiTTree LabStudios uses the collected data for:
- Providing and maintaining the Platform functionality.
- Authenticating users and securing accounts via Clerk.
- Processing subscriptions, AI credit grants, and marketplace transactions via Stripe.
- Routing AI requests to appropriate model providers based on task type, model availability, and user configuration.
- Storing conversation history, project memory, and agent context to provide continuity across sessions.
- Provisioning terminal workspaces and synchronizing GitHub repositories.
- Analyzing usage patterns to improve the Platform.
- Communicating updates, security alerts, and service notifications.
3. AI Model Provider Routing
Your AI conversations and generation requests are processed through multiple model providers depending on the task type, model availability, and your configuration. Providers include:
- Google Gemini: Primary LLM and image generation (free tier).
- OpenRouter: Fallback LLM routing with multiple models (DeepSeek, Mistral, Llama, Qwen, Trinity).
- Groq: Fast inference and audio transcription (Whisper).
- OpenAI: Premium LLM and media generation (BYOK β Bring Your Own Key).
- Anthropic: Premium LLM (BYOK).
- Together: FLUX image generation.
- Fal: Image generation.
- MiniMax: 3D generation (Space model).
- Alibaba: Image and video generation.
- Recraft: Vector and logo image generation.
- Cloudflare: Image generation.
- ElevenLabs: Music and audio generation.
- Inworld AI: Voice speech-to-text and text-to-speech.
Each provider processes data according to its own privacy policy. Your conversation content and generation requests are transmitted to these providers via encrypted connections. We do not expose API credentials to the browser.
4. Data Storage & Security
We use industry-standard security measures including encryption in transit (TLS/SSL) and secure authentication. Your data is stored as follows:
- Authentication data: Managed by Clerk (SOC 2 compliant).
- Database: Supabase (PostgreSQL) stores user accounts, conversations, project memory, AI credit ledger, subscriptions, and marketplace data.
- File storage: Cloudflare R2 stores uploaded and generated media (images, audio, video, assets).
- Payment data: Processed by Stripe. We do not store full card numbers β Stripe handles PCI-compliant payment data.
- Code & terminal workspaces: Provisioned on Railway infrastructure with per-user isolation.
No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
5. Third-Party Services
We use the following third-party services:
- Clerk: Authentication and user management.
- Supabase: Database, conversations, project memory, and AI credit ledger.
- Stripe: Payment processing for subscriptions and marketplace transactions.
- Cloudflare R2: Object storage for media and assets.
- Vercel: Hosting and deployment infrastructure.
- Railway: Terminal workspace provisioning and voice proxy.
- GitHub: Repository connections for project synchronization.
- Inworld AI: Voice speech-to-text and text-to-speech.
- AI Model Providers: Google Gemini, OpenRouter, Groq, OpenAI, Anthropic, Together, Fal, MiniMax, Alibaba, Recraft, Cloudflare, ElevenLabs β as described in Section 3.
6. Cookies & Local Storage
We use minimal cookies and browser storage:
- Authentication cookies: Set by Clerk to maintain your signed-in session.
- Local storage: Theme preferences, UI state, and cached session metadata. AI credit balances are fetched from the server, not stored locally.
- Analytics: Vercel Analytics may collect basic usage metrics (page views, performance). No cross-site tracking or advertising cookies are used.
You can instruct your browser to refuse all cookies. Note that this may affect Platform functionality, particularly authentication.
7. Data Retention
- Conversations & project memory: Retained for the lifetime of your account unless you delete them.
- AI credit ledger: Transaction history is retained for billing and audit purposes.
- Uploaded media: Retained until you delete the associated project or asset.
- Voice data: Audio streams are processed in real-time by Inworld AI for transcription and TTS. We do not store raw audio recordings unless explicitly saved as part of a project.
- Audit events: Security and operational audit logs are retained for 90 days, then automatically purged. IP addresses and user agents are only recorded for security-critical events (errors, rate limiting, denied approvals, deployments) β routine events do not capture IP or device information.
- Rate limit data: IP-based rate limit counters are purged after 1 hour. These are used solely for abuse prevention and do not constitute a tracking record.
- Account data: Retained while your account is active. You may request deletion at any time.
8. Your Data Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your personal data.
- Object to or restrict processing of your data.
- Export your data in a portable format.
- Disconnect GitHub repositories and revoke access.
- Delete conversations and project memory.
To exercise these rights, contact us at support@litlabs.net. We will respond to your request within 30 days, as required by GDPR Article 12. For complex requests, we may extend this by up to 60 additional days and will inform you of the extension within the first 30 days.
You can also export your data directly from Settings β Privacy & Security without contacting us, or delete your data via the same page.
9. Data Subject Access Requests (DSAR)
If you wish to access, correct, export, or delete your personal data, you can:
- Self-service: Use the Export and Delete buttons in Settings β Privacy & Security. These actions take effect immediately on our database.
- Email request:Email support@litlabs.net with the subject line βData Requestβ. Include your account email so we can verify your identity.
We will verify your identity before processing any request. We respond to all valid requests within 30 days.
10. Data Breach Response
In the event of a personal data breach, we will:
- Assess the breach within 24 hours of discovery to determine its scope and severity.
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
- Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).
- Document the breach, its effects, and the remedial action taken.
To report a suspected breach, email support@litlabs.net immediately.
11. User Controls
- Voice: Microphone access requires explicit browser permission and can be revoked at any time in your browser settings.
- Camera: Camera preview requires explicit browser permission and is only active when you open the camera tool in Studio.
- Screen sharing: Screen share requires explicit browser permission and is only active during an active share session.
- GitHub: You can disconnect repositories at any time from your Studio settings.
- AI providers (BYOK): When you provide your own API keys (OpenAI, Anthropic), those keys are stored encrypted and used only for your requests.
12. Children's Privacy
Our Platform does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us.
13. Security Limitations
While we use industry-standard security practices, no platform is perfectly secure. AI model providers may retain conversation data according to their own policies. We recommend not sharing sensitive personal information, trade secrets, or credentials in AI conversations.
14. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
15. Contact Us
If you have any questions about this Privacy Policy, please contact us at support@litlabs.net.