This Privacy Policy explains what personal information E&EL Global Inc. ("we", "us", "our") collects when you use Lili (at hey-lili.com and the Lili desktop application), how we use and share it, and the rights you have. E&EL Global Inc. is the data controller for that information. By using Lili you acknowledge this Policy; where the law requires consent, we ask for it separately.
When you sign up we collect your first and last name and email address. Your password is stored only as a salted cryptographic hash — we never see or store it in readable form. If you sign in with Google, we receive basic profile information and your email address from Google so we can create and identify your account.
While Lili's Google integration is going through Google's verification process, if you sign up with a Gmail or Google Workspace address we may add that email to the authorized-testers list on Lili's Google OAuth consent screen, which is what allows your Google sign-in and Gmail/Calendar connections to work in that state. That list is held by Google in the project's OAuth configuration. If you delete your account or ask us to remove you, we will remove your address from it.
The Free tier has no E&EL billing — you pay your AI provider directly under your own account, and we do not process payments or receive your card details for it. If you take an Enterprise or other paid offering under a separate agreement, payments run through our payment processor (Stripe), which holds the billing data; we would then receive a customer identifier, plan code, and limited card metadata (brand, last four digits) — never full card numbers.
To operate your licence we hold a licence identifier and a device-activation record. Any usage records we keep are content-free — a model identifier, token counts, and timestamps — and do not contain the content of your conversations. (On the Free tier there is no plan or credit balance; you use your own provider key.)
On the Free tier, your prompts and the model's responses go directly from your device to your chosen AI provider using your own key — they do not pass through E&EL's servers, and we do not receive, store, or process them. Your relationship for that content is with your provider, under the key and terms you have with them. Before a request is sent, Lili applies on-device redaction to reduce the personal data it contains (best-effort — see section 1e).
Some optional features do send content off your device, to us and/or a third party, when you choose to use them: the optional meeting bot (meeting audio/transcript is processed by a third-party capture provider and transits our servers to reach you — the default on-device capture instead keeps it on your machine); an enabled messaging channel such as Slack (message content is relayed through our servers); and web search (your query is sent to a third-party search provider). Content handled by these features is treated as described in this Policy.
To help you see when sensitive data may be leaving your device, Lili can record metadata about your requests — for example a severity level, a short code for the type of sensitive data detected (such as an email address, phone number, or API key), the category of tool used, counts, and timestamps. This record does not contain the text of your prompts or the assistant's responses. We keep this activity metadata for no more than 90 days; you can view it in the Privacy Activity area of the accounts portal.
Wake-word detection runs on your device; the audio is not sent anywhere for that step. Speech-to-text may use your operating system's built-in speech service, which sends audio to that service's provider. We do not retain a copy of the audio.
If you connect a service such as Google (for Gmail or Calendar), access tokens are stored in your device's operating-system keychain — not on our servers. Lili uses those tokens locally to carry out your requests. Your AI-provider key is handled the same way: it is stored in your device's secure credential store and is never sent to or stored on our servers (the accounts portal only ever sees whether a key is configured and its last four characters).
We collect IP address, application version, and server logs, and a device-key fingerprint used to detect a licence being shared across multiple devices.
The accounts portal uses strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. We do not run analytics or advertising cookies, and we do not use cookies to track you across other websites.
We use personal information to:
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases under the GDPR / UK GDPR are:
We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising. We disclose it only to the service providers / processors below, who may use it only to provide their service to us:
| Provider | What they do |
|---|---|
| Google (OAuth) | "Continue with Google" sign-in; Gmail/Calendar connections you choose to make |
| Recall.ai | Third-party meeting-capture provider — only if you use the optional meeting bot |
| Brave | Web-search provider — only when you run a search |
| SendGrid (Twilio) | Transactional email delivery |
| Cloudflare | Network delivery and edge security |
| Google Cloud Platform, Hostinger | Cloud hosting and infrastructure |
| Stripe | Payment processing — Enterprise / paid offerings only (not the Free tier) |
Your AI provider is not our sub-processor. On the Free tier you send your prompts directly to the AI provider you chose, under your own key — we do not transmit that content to them, so they process it for you under your own agreement with them, not on our behalf. Review your provider's own privacy terms for how they handle it. We may disclose information where required by law or legal process, or to protect the rights, safety, and security of our users, the public, or us, and in connection with a merger, acquisition, or sale of assets (with notice as required by law).
We are based in the United States, and our providers operate in the United States and other countries, so your information may be processed outside your home country. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) — or another lawful transfer mechanism. You can ask us for more detail using the contact below.
We keep account and operational data for as long as your account is active. We do not hold your Free-tier conversation content — it never reaches us (section 1d). The redaction/activity metadata in section 1e is kept for no more than 90 days, and content handled by the optional features in section 1d is kept only as long as needed to deliver that feature. If you delete your account, we delete or de-identify your account and usage data within 30 days, except where we must keep a limited record for legal, tax, or anti-abuse reasons.
You can access, correct, or delete your account information from the accounts portal at any time, or by contacting us (section 13). You may also ask us for a copy of your data, or to restrict or object to certain processing. We will not discriminate against you for exercising your rights.
If you are in these regions you have the right to: access your personal data; have inaccurate data corrected; have your data erased ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time (without affecting processing already carried out). You also have the right to lodge a complaint with your local supervisory authority. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing (see section 7).
If you are a California resident you have the right to: know the personal information we collect and how we use and disclose it; access a copy of it; correct inaccurate information; delete it; and opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information, and we have not done so in the preceding 12 months. You also have the right to limit the use of sensitive personal information — we only use the sensitive information we actually hold (such as account credentials, or content handled by an optional feature in section 1d) to provide the service you requested and for security, not to infer characteristics about you.
In the preceding 12 months we have collected these categories of personal information, used for the purposes in section 2 and disclosed to the providers in section 3:
We do not use or disclose sensitive personal information for purposes other than those permitted by the CPRA. You may exercise these rights yourself or through an authorized agent. We will not discriminate against you for exercising them.
Use the accounts portal, or email hello@hey-lili.com. To protect your data we will take reasonable steps to verify your identity (typically by confirming control of the account email) before acting on a request, and we will respond within the timeframe the applicable law requires (generally within 30–45 days). An authorized agent must provide proof of authorization.
Lili generates content using AI models at your direction; that output is not a decision we make about you. We do not use solely-automated processing to make decisions about you that produce legal or similarly significant effects. Automated anti-abuse controls may flag accounts, but enforcement that affects your access is subject to human review on request.
Lili is not directed to children. You must be at least 18 years old to use Lili, and we do not knowingly collect personal information from anyone under 18 (or under 16 in the EEA/UK). If you believe a child has provided us personal information, contact us and we will delete it.
We use sensible technical and organizational measures — encryption in transit, hashed passwords, OS-keychain storage of secrets, and access controls. No system is perfectly secure, so please use a strong, unique password and take care with highly sensitive data.
If a personal-data breach occurs that is likely to affect you, we will notify the relevant supervisory authority and affected users where and within the time the law requires.
We may update this Policy from time to time; we'll post the new version here and update the version date above. For material changes we'll give reasonable notice.
E&EL Global Inc., the data controller. Privacy questions or rights requests: hello@hey-lili.com. We'll respond within a reasonable time and within any period required by law.