LYNOTE PRIVACY POLICY
DRAFT — FOR LEGAL REVIEW ONLY. THIS IS NOT LEGAL ADVICE. This document is a working draft prepared for internal and counsel review. It has not been finalized, adopted, or published, and it does not constitute legal advice. Values shown in 【brackets】 are placeholders to be confirmed before publication.
Entity: Lynote ("Lynote," "we," "us," or "our")
Contact: support@lynote.ai
Governing Law: State of Delaware, United States (see Section 8, Dispute Resolution)
Effective Date: [Effective Date: to be set on publication]
Last Updated: 【Last Updated: to be set on publication】
Scope of this Policy. This single Privacy Policy governs both of Lynote's product lines under one shared user account:
- (A) the Consumer App — the Lynote AI learning assistant and media/summarization tools offered to individual end users ("Consumer App"); and
- (B) the Lynote AI API and Developer Console — our paid, developer-facing text API (comprising the AI Detector and the AI Humanizer, where both input and output are plain text) together with the web-based developer console used to manage keys, usage, plans, and billing ("API" and "Console").
We refer to the Consumer App and the API/Console collectively as the "Services." A single Lynote account may be used to access either or both product lines. Where a provision applies only to one product line, we say so expressly; otherwise, provisions apply to the Services generally.
Introduction. Lynote is committed to handling data with care while providing AI-learning assistance, media processing tools, and developer API services. This Policy explains what information we collect, how we use and share it, how long we keep it, and the rights and choices available to you. By using the Services, you acknowledge the practices described in this Policy. Your use of the Services is also governed by our Terms of Service and, for API and enterprise customers, any applicable Data Processing Agreement ("DPA").
1. Information We Collect
We collect the following categories of information across the Services.
1.1 Information You Provide to Us (Account and Support — All Users)
The following items apply to all users across both product lines under the single shared account:
- Account Information — name, email address, and password (or equivalent credentials). This account is shared across both product lines.
- Support Communications — the content of messages, requests, and other information you send when you contact support@lynote.ai.
1.2 Information You Provide to Us (Consumer App)
- User Content — content you submit to the AI learning assistant and knowledge base, including text, documents (for example, PDFs), and links you submit for analysis, summarization, or interaction.
1.3 Information You Provide to Us (API and Console)
For users of the paid API and developer Console, we additionally collect:
- Submitted Text (API Input) — the plain-text content you (or your application) send to the API for detection or humanization. This is processed to produce Output and is subject to the strict retention limits in Section 5.3.
- Output — the plain-text results returned by the API (for example, detection estimates or humanized text). Output retention is addressed in Section 5.3.
- API Keys — the credentials issued to authenticate your API requests.
- Billing and Credit Data — your subscription plan, credit balances and consumption, credit-pack purchases, invoices, and related transaction metadata. Payment is handled by a third-party payment processor; we do not store full payment card numbers.
1.4 Information Collected Automatically
- Log and Usage Data (Consumer App) — IP address, browser type, device identifiers, and interaction metrics generated as you use the Consumer App.
- API Usage-Log Metadata (API and Console) — for each API request, we record metadata such as timestamp, endpoint called, language, request status, credits consumed, and requests-per-minute (RPM) and concurrency counters used for rate-limiting and abuse prevention. By default, API usage logs contain metadata only and do not include the request body (your Submitted Text) or Output.
- Cookies and Similar Technologies — see Section 1.6.
1.5 Information Processed for Media Tools (Consumer App)
For the Consumer App's media tools, we process URLs and media files solely upon your request. We use commercially reasonable efforts to queue such data for deletion immediately after the processing session ends.
1.6 Cookies and Authentication
- Consumer App / Website — uses cookies for session management and functionality. You can refuse cookies through your browser settings, although some features may degrade.
- API Endpoints — authenticate using Bearer-token (API key) credentials. API calls themselves do not rely on cookies.
- Developer Console (web) — may use necessary cookies for authentication and session management.
2. How We Use Your Information
We use the information we collect to:
- provide, operate, and maintain the Services;
- process User Content and Submitted Text to generate AI insights, summaries, interactions, detection estimates, and humanized text at your request;
- authenticate accounts and API keys, meter and bill credit usage, and enforce plan limits, rate limits, and concurrency budgets;
- detect, prevent, and respond to unauthorized use, fraud, and abuse, and to secure the Services;
- respond to your support requests; and
- enforce our Terms of Service and comply with applicable law.
2.1 Training — Unified Red Line
We do not use your content to train our AI models by default.
- We do not use your User Content (Consumer App content) or your API Submitted Text or Output to train our AI models by default.
- We use such content to train our models only with your explicit, opt-in consent. Training is OFF BY DEFAULT for enterprise and API usage. You may withdraw your consent at any time; withdrawal applies going forward.
- We may use aggregated, anonymized usage statistics (for example, request volumes and error rates) to operate, secure, and analyze the Services — but not to train our AI models unless you have opted in.
This Section 2.1 supersedes any earlier or contrary language about using anonymized, de-identified, or aggregated content to develop or train our AI models.
3. Data Controller and Processor Roles
Because the Services span both a consumer product and a developer API, our role under data-protection law depends on the data at issue:
- API Submitted Text and its Output — for these, the customer is the controller and Lynote acts as a processor. We process this content only on the customer's instructions, only to provide the API service, and never for our own purposes.
- Consumer User Content — for content submitted through the Consumer App, Lynote is the controller.
- Account identity, API keys, usage-log metadata, and billing data — for these, Lynote is the controller, across both product lines.
Where Lynote acts as a processor, the applicable DPA (where one is in place) governs and, in case of conflict regarding processor obligations, prevails over this Policy.
4. How We Share Your Information
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising. We disclose information only in the limited circumstances below.
4.1 Service Providers and Processing Partners (by category)
We engage trusted third-party providers to perform functions on our behalf. In this public Policy we identify them only by category, not by name:
- AI content-processing providers (for detection and humanization processing),
- cloud hosting providers (for infrastructure and hosting),
- payment providers (a third-party payment processor; we do not store full card numbers), and
- email/communication providers (for account, transactional, and support messages).
We require these providers by contract to process data only on our instructions and to maintain appropriate security and confidentiality safeguards.
Named sub-processor list. Enterprise and API customers may obtain a named list of sub-processors under a DPA upon request. The named list is provided only through the DPA and does not appear in this public document. For API processing, we will provide advance notice of sub-processor changes and, where we deprecate a sub-processor relied upon for the API, a 【90-day】 deprecation notice where reasonably practicable, so that customers may object or transition.
4.2 Legal and Compliance Reasons
We may disclose information where we believe in good faith that doing so is necessary to comply with applicable law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Lynote, our users, or the public.
4.3 External Platforms
Where the Services interact with external platforms at your direction, those platforms' own terms and privacy policies apply to their independent handling of your data. This provision addresses only user-directed external platforms acting on their own behalf; it does not limit, waive, or disclaim Lynote's own obligations with respect to data for which Lynote is the controller or processor under this Policy.
5. Data Security and Retention
5.1 Security
We maintain commercially reasonable administrative and technical measures designed to protect information, including:
- API key (Bearer-token) authentication for API access;
- account isolation and rate/concurrency limits to separate customers and constrain abuse; and
- log minimization — API usage logs retain metadata only and, by default, exclude request bodies and Output.
No system or method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
5.2 Breach Notification
- When Lynote is the controller (for example, account, API-key, usage-metadata, and billing data), we will notify the competent supervisory authority within 72 hours of becoming aware of a personal-data breach where required, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
- When Lynote is a processor (for API Submitted Text), we will notify the affected customer without undue delay after becoming aware of a breach, so the customer (as controller) can meet its own obligations.
5.3 Retention and Deletion
We retain information only as long as necessary for the purposes described in this Policy, then delete or de-identify it. The following retention rules apply:
| Data category | Retention |
|---|---|
| API Submitted Text (API input) | Deleted within 24 hours after processing. This 24-hour period is a firm maximum (stricter than the Consumer App); see the residual-copy note below, which does not extend it. |
| API Output | Not retained by default beyond what is necessary to return the result to you; deleted on the same 24-hour firm ceiling as the corresponding API Submitted Text. Output is customer-controlled processor data. |
| API usage logs | Metadata only, no request body content or Output by default; kept only as necessary for security and compliance. |
| Consumer User Content / AI interaction history | Retained as long as necessary to provide the Services; deleted on request. |
| Account and billing data | Retained 30 days after account termination, unless applicable law requires a longer period. |
| Billing / transaction records | Retained as required by applicable law (for example, tax and accounting obligations). |
Upon a valid deletion request, we will queue the relevant data for deletion. For Consumer App data, residual copies may remain in caches, logs, or backups for a commercially reasonable period before being overwritten or purged. For API Submitted Text and API Output, the 24-hour deletion ceiling above is firm: any residual copies in transient caches or backups are purged or overwritten on their ordinary short backup-rotation cycle and are never retained beyond a tightly bounded period, and this residual-copy language does not extend API Submitted Text or API Output retention beyond the 24-hour ceiling for any live or accessible copy.
6. Your Data Rights and Choices
Depending on your jurisdiction (for example, the EEA, UK, or certain U.S. states), you may have rights to access, rectify (correct), erase (delete), restrict, object to, and port your personal information, and to withdraw consent where processing is based on consent.
- How to exercise. Submit requests to support@lynote.ai. We may need to verify your identity before acting.
- Response times. We aim to respond within approximately one month under the GDPR/UK GDPR and within approximately 45 days under the CCPA/CPRA, subject to any extensions permitted by applicable law.
- API Submitted Text (processor role). Because the customer is the controller of API Submitted Text and its Output, individuals should direct data-subject requests concerning that content to the relevant customer. Lynote will assist the customer-controller in responding to such requests as required by the applicable DPA and law.
6.1 California Privacy Notice (CCPA/CPRA)
If you are a California resident, you have the rights described above as implemented under the CCPA/CPRA, including the rights to know, delete, correct, and to non-discrimination for exercising your rights. We do not sell your personal information, and we do not "share" your personal information for cross-context behavioral advertising, as those terms are defined under California law. To exercise your rights, contact support@lynote.ai.
6.2 Categories of Personal Information Collected (CCPA/CPRA)
Over the preceding 12 months, we have collected the following categories of personal information, and may retain them as described in Section 5.3:
| CCPA/CPRA category | Examples collected | Business or commercial purpose |
|---|---|---|
| Identifiers | name, email address, IP address, device identifiers, API keys | provision of the Services, authentication, security, abuse prevention |
| Personal information under Cal. Civ. Code § 1798.80(e) (customer records) | account credentials (password), billing and credit data, subscription and transaction records | account management, billing, support |
| Commercial information | subscription plan, credit balances and consumption, credit-pack purchases, invoices | billing and credit metering |
| Internet or other electronic network activity | usage-log metadata, interaction metrics, cookies | service operation, rate limiting, security and abuse prevention |
We do not use or disclose personal information for cross-context behavioral advertising, and we do not sell personal information.
6.3 Sensitive Personal Information (CPRA)
We collect the following category of sensitive personal information under the CPRA: account log-in credentials (password or equivalent). We use this sensitive personal information solely to authenticate your account and to maintain the security and integrity of the Services. We do not use or disclose sensitive personal information to infer characteristics about you, within the meaning of the CPRA.
7. International Data Transfers
Your information may be transferred to, processed, and maintained on servers located outside your country or jurisdiction, where data-protection laws may differ.
Where personal data protected by the GDPR or UK GDPR is transferred outside the EEA or the UK to a country without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum, where applicable) together with appropriate supplementary safeguards as the lawful transfer mechanism. We do not rely on bare consent as the transfer mechanism for such data, and we do not rely on any data privacy framework self-certification for these transfers. Copies of the relevant transfer mechanisms may be requested at support@lynote.ai (and, for API/enterprise customers, are addressed in the DPA).
7.1 Notice for Users in Mainland China
If the Services are offered to users located in Mainland China, our collection, processing, and cross-border transfer of your personal information are also subject to the Personal Information Protection Law of the People's Republic of China ("PIPL") and related regulations. Where applicable, we process personal information on a lawful basis, obtain separate consent where required (including for sensitive personal information and for cross-border transfers), and rely on appropriate transfer mechanisms (such as the standard contract for cross-border transfer) as required by law. You may exercise your data rights and lodge complaints with the relevant supervisory authorities in Mainland China. Our China-specific compliance measures are maintained separately and described in the applicable China-facing notice or agreement.
8. Dispute Resolution
Any dispute arising out of or relating to this Policy or the Services is subject to the mandatory, binding individual arbitration and class-action waiver set out in our Terms of Service, and is governed by the laws of the State of Delaware, as provided in the Terms. This Policy incorporates the Terms' dispute-resolution and arbitration provisions by reference.
Nothing in this Policy or in the Terms limits or excludes any right that you may have under applicable law and that cannot lawfully be waived or subjected to mandatory arbitration — including, for consumers and data subjects in the EEA and the UK, the right to lodge a complaint with a supervisory authority, to seek a judicial remedy in their country of residence, and to participate in representative or collective redress mechanisms to the extent provided by applicable law; similar mandatory local rights in other jurisdictions (including Mainland China, if the Services are offered there) are likewise preserved.
9. Billing Units, Age, and Other Notices
9.1 Billing-Units Boundary
The two product lines use independent billing units that are non-interchangeable, non-transferable, and non-carry-over between products:
- Consumer App — Learning Credits (学习币): 1 Learning Credit = 10 words.
- API — credits: 1 credit = 1 word, billed on input (for CJK text, 1 character = 1 credit).
Learning Credits and API credits are separate systems and cannot be exchanged, combined, or transferred between the Consumer App and the API.
9.2 Children and Minors
The Services are not directed to children, and we do not knowingly collect personal information from children. Consistent with our Terms of Service, the minimum age to use the Services is 13 years of age, or such higher minimum age as required by applicable law in your jurisdiction (for example, 16 in certain EEA member states). If you believe a child below the applicable minimum age has provided us personal information, contact support@lynote.ai so we can take appropriate action.
10. Changes to This Policy
We may update this Policy from time to time at our discretion. We will use commercially reasonable efforts to notify you of material changes (for example, by posting an updated version with a new effective date or by other reasonable means). Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.
11. Contact Us
If you have questions or requests regarding this Policy or your personal information, contact us at:
