Privacy Policy
Lochless is provided by Synoptic Data Ltd. (company no. 517379954), an Israeli company ("Lochless," "we," "us"). Contact: support@lochless.io. This policy explains how we handle personal data through lochless.io, console.lochless.io, api.lochless.io and the MCP server (the "Service").
1. Our role
For the text and metadata you send through the API, the queries you run, and the results and answers returned ("Customer Content"), you decide why and how it is processed. We act as your processor or service provider, under the data processing terms in section 9 of our Terms. For sign-in, billing, usage, support and website data, we are the controller.
2. Data we collect
- Sign-in data: name, email address and profile identifiers from your Google sign-in, received through our authentication provider, plus session and security identifiers.
- Customer Content: the documents, ids, timestamps and metadata you send, the queries you run and the results and answers returned. It may include personal data about others, which you control.
- Usage and billing data: API key identifiers (never the key itself in readable form), request counts, tokens scanned, spend, balance, purchases, rate-limit events and billing status. Payment card details are collected by our merchant of record, not by us.
- Technical data: IP address, browser and device information, timestamps, logs and diagnostics. We use only the cookies needed for sign-in and security. We do not use advertising or analytics cookies.
- Communications: support requests, limit-increase requests and other messages you send us.
You do not have to give us personal data, but we need your sign-in data to provide the Service.
3. How we use data
| Purpose | Legal basis |
|---|---|
| Provide the Service: index and search Customer Content and answer your queries. | Performing our contract with you. For Customer Content, your instructions as controller. |
| Meter usage, enforce limits and spend caps, and bill. | Performing our contract with you. |
| Keep the Service secure and prevent abuse, such as duplicate workspaces. | Our legitimate interests. |
| Send service messages and provide support. | Performing our contract with you, and our legitimate interests. |
| Improve the Service using usage and technical data. We never use one customer's content to improve the Service for another. | Our legitimate interests. |
| Keep tax and accounting records and comply with law. | Legal obligation. |
We do not make decisions about you based only on automated processing that have legal or similarly significant effects on you.
4. Customer Content stays in your workspace
- Customer Content is used only to serve your workspace.
- The Service may learn from your workspace's own queries and documents, to improve results for your workspace. What it learns serves only your workspace and is never used for any other customer. You can ask us to turn this off at any time, and to delete what it has learned.
- We do not use Customer Content to train, tune or evaluate models or settings for anyone else.
- Our staff access Customer Content only to provide the Service to you, to fix problems, to keep the Service secure, or when the law requires.
- We do not sell personal data or Customer Content, or share it for advertising.
5. AI processing
The Service uses AI models to index and search text and to write cited answers. Where an AI service provider runs a model for us, we send it only what that function needs. Some providers process data under their own terms. Ask us for the named list of AI providers and those terms.
6. Who we share data with
We use service providers (subprocessors) in these categories:
| Category | Purpose |
|---|---|
| Cloud infrastructure | Hosting, storage, databases, networking, logs and backups. |
| AI model providers | Indexing, search and answer generation for your queries. |
| Authentication | Sign-in and identity. |
| Usage metering and billing | Metering usage and sending it for invoicing. |
| Email and support | Service communications and support. |
| Monitoring and alerting | Error alerts and internal team communication. |
A list of named subprocessors is available on request to support@lochless.io.
Checkout, payment details, invoices and tax are handled by our merchant of record, Polar. When we approve your access request, we give it your email address and workspace id so it can set up billing and any later purchases. It processes checkout and payment data as an independent controller under its own privacy policy, shown at checkout.
We may also disclose information to professional advisers, or to authorities when reasonably necessary to comply with law, protect rights or investigate abuse. In a merger, acquisition, financing or sale, information may transfer to a successor, subject to applicable law.
7. Retention and deletion
- Documents stay in your index until you delete them through the API or ask us to delete your workspace.
- Deleting a document removes it from your index. It leaves search results once the deletion is processed.
- Query history: we keep your queries, the results and answers returned, and copies made from them. This history can include text from documents you later delete. We delete it automatically after 90 days, and copies in backups are removed within a further 7 days. After that, the only records we keep of each call are billing and usage records, with no query or document text.
- On request, we delete your workspace's query history and what the Service has learned from it, or delete your whole workspace with all its content and sign-in data, within 30 days. Email support@lochless.io from the address you sign in with. We verify the request first. Copies in backups are removed within a further 7 days. We keep what billing records must hold.
- Records of each call (the query, timing and status) are kept for 30 days.
- Operational logs, which can include parts of queries, are generally kept for 30 days.
- We keep sign-in data until your workspace is deleted, or until 24 months pass with no use of your account, whichever comes first.
- We keep support emails for 24 months.
- We keep access requests and limit-increase requests for 24 months.
- We keep billing and usage records as long as needed for tax, accounting and legal purposes, generally up to 7 years.
8. Security
We use reasonable safeguards, including access controls, workspace isolation, encryption in transit and at rest, API keys stored only in hashed form, logging and monitoring. A SOC 2 audit is in progress. No system is completely secure, so we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the authorities as the law requires.
9. International transfers
We are based in Israel. We store Customer Content in the United States, and our service providers may process data in the United States and other countries. The European Commission and the UK recognize Israel as providing adequate protection. For transfers to countries without that status, we use safeguards the law accepts, such as the European Commission's standard contractual clauses.
10. Your rights
- Depending on where you live, you may have rights to access, correct, delete, restrict, object to or port your personal data, and to withdraw consent. Contact support@lochless.io. We answer within one month, or sooner where the law requires.
- If your data is part of a customer's Customer Content, we will refer your request to that customer, who controls it.
- California residents may have the right to know, delete and correct personal information. We do not sell or share personal information, and we will not treat you differently for using your rights. You may use an authorized agent.
- You may also complain to your local data protection authority, or in Israel to the Privacy Protection Authority.
11. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect their personal data.
12. Changes
We may update this policy. We will post the new version here with a new effective date, and tell you by email or in the console before a material change takes effect.
13. Contact
Synoptic Data Ltd., Israel. Company no. 517379954.
support@lochless.io