Privacy Policy
Last updated: August 14, 2026
This Privacy Policy explains how [LINIORA LEGAL ENTITY NAME — to be added once incorporated]("Liniora," "we," "us," or "our") collects, uses, discloses, and protects information when you use our website and our engineering management platform (together, the "Service"). It applies to visitors, account holders, and members of organizations that use the Service (collectively, "you").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service. This policy should be read together with our Terms of Service and our Cookie Policy.
1. Who this policy applies to
Liniora is a business-to-business SaaS product. Most of the personal data we process belongs to the employees, contractors, and collaborators of the organizations ("Customers") that sign up for the Service. If your employer or organization has added you as a member, your organization's administrator controls your access, and their agreement with us (and their own internal privacy notices) may also apply to you.
2. Information we collect
a. Account and profile information
When you create an account, we collect your name, email address, and, if you sign in with GitHub or Google, the basic profile information those providers share with us (such as your name, email, and avatar). If you sign in with an emailed one-time code, we store the email address and a hashed verification code. We also store organization details you provide, such as your company name and team structure.
b. Content you create ("Customer Data")
The Service is built to store and organize your team's work. This includes work items and tickets, comments and discussion threads, review requests and review findings, testing instructions, attachments and screenshots, meeting notes, knowledge base articles, and any other content your organization creates inside Liniora. We process this content to provide the Service to you; we do not review it except as needed for support, security, or as described in this policy.
c. Integration data
If you or your organization connect a third-party tool, we access only the data needed to power the feature you enabled, using the permissions you grant during that provider's authorization flow:
- GitHub / GitLab — repository metadata, branches, commits, and pull request status, to power branch automation and codebase indexing.
- Jira / Asana — issues and project data, to import and migrate your existing tasks.
- Slack — messages and threads in the channels where Liniora is installed and mentioned, to post notifications and to create or update tickets from a thread when you ask it to.
- Google Workspace — calendar and Google Meet access, to schedule and link review meetings.
You (or your organization's administrator) can disconnect any integration at any time from your organization's settings, which revokes our access going forward.
d. Billing information
Subscription payments are handled by Paddle.com Market Limited("Paddle"), which acts as the merchant of record for paid plans. We do not receive or store your full card number. We receive limited billing information from Paddle, such as your subscription plan, billing status, and transaction history, so we can manage your account. Paddle's own privacy policy governs the payment information you provide directly to them.
e. Log and device information
Like most web services, we automatically collect technical information when you use the Service, such as IP address, browser type, device information, pages viewed, and timestamps. We use this for security, debugging, and to keep you signed in — see our Cookie Policy for the specific cookies we set.
f. Communications
If you contact us for support or sales, we collect the information you send us (such as your email and the content of your message) to respond to you.
3. How we use AI features
Liniora offers AI-assisted features, including semantic codebase indexing, ticket drafting, meeting summarization, and Slack thread analysis. To provide these features, relevant Customer Data (for example, a ticket description, a meeting transcript, or a Slack thread) is sent to OpenAI, our AI sub-processor, to generate a response. This is done under OpenAI's API business terms, under which API inputs and outputs are not used to train OpenAI's general-purpose models. AI-generated content (summaries, drafts, suggestions) may be inaccurate and should be reviewed by a human before you rely on it.
4. Legal basis for processing (EEA/UK users)
Where the GDPR or UK GDPR applies, we process personal data on the following legal bases: performance of a contract (providing the Service you or your organization signed up for), legitimate interests (such as securing the Service and improving it), compliance with legal obligations, and, where required, your consent.
5. How we share information
We do not sell your personal information. We share information only with the following categories of recipients, and only as needed to run the Service:
| Sub-processor | Purpose |
|---|---|
| Paddle.com Market Limited | Payment processing, billing, and tax collection (merchant of record) |
| OpenAI, L.L.C. | AI-generated summaries, drafts, and semantic search |
| Cloud infrastructure and object storage providers | Hosting the application, database, and file attachments |
| GitHub, GitLab, Jira, Asana, Slack, Google | Only for organizations that connect the corresponding integration |
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets, subject to the confidentiality obligations described in this policy.
6. Data retention
We retain Customer Data for as long as your organization's account is active, and for a reasonable period afterward to allow for account recovery, as required by law, or to resolve disputes. Your organization's administrator can request deletion of the organization's account and associated data by contacting us.
7. International data transfers
We and our sub-processors may transfer and process personal data in countries outside your own, including the United States. Where required, we rely on appropriate safeguards for these transfers, such as the European Commission's Standard Contractual Clauses.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to lodge a complaint with your local data protection authority. If you are a California resident, you have the right to know what personal information we collect and to request its deletion; we do not sell or share personal information for cross-context behavioral advertising.
Because most personal data in the Service is entered by your organization, requests about your data are often best directed to your organization's administrator. You can also contact us directly at privacy@liniora.com and we will respond within the time required by applicable law.
9. Security
We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, and regular review of our systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children's privacy
The Service is intended for business use by adults. It is not directed to individuals under 16, and we do not knowingly collect personal data from children.
11. Cookies
We use a small number of cookies and browser storage items to keep you signed in and remember your preferences. We do not currently use third-party analytics or advertising cookies. See our Cookie Policy for details.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify account administrators by email or through the Service before the changes take effect. The "Last updated" date above reflects the most recent revision.
13. Contact us
Questions about this policy or your data can be sent to privacy@liniora.com.