Privacy Policy

Last updated: 2026-07-16

1. Who we are and how to reach us

Lessly is operated by Apliteni OÜ, a private limited company registered in Estonia (registry code 14296961, Tornimäe tn 3 // 5 // 7, Tallinn, Estonia).

For all privacy-related questions, requests, or complaints, contact us at privacy@lessly.com. We aim to respond within 30 days.

We do not have a designated Data Protection Officer (DPO). For GDPR inquiries, privacy@lessly.com reaches the person responsible directly.


2. What data we collect and why

We collect only what we need for each stage of the product.

While you are on the waitlist (current)

Analytics are currently cookieless. When the waitlist form activates, cookie-based analytics will replace cookieless tracking — at that point the legal basis switches to Consent.

DataWhy we collect itLegal basis
Email addressTo notify you when Lessly launches and to send a confirmation emailConsent (you submitted the form)
Page view and interaction events (cookieless)To understand which parts of the landing page drive sign-ups and improve the experienceLegitimate interest (product analytics)
Page view and interaction events (via analytics cookie, when active)Same purpose — cookie-based analytics activated alongside the waitlist formConsent (you may withdraw at any time by emailing privacy@lessly.com)

After you create an account

DataWhy we collect itLegal basis
Email address, display nameAccount identity and communicationContract performance
GitHub OAuth tokenConnecting your repository so Lessly can deploy your codeContract performance
Workspace content (code, environment variables, secrets, databases)Running your applications on the Lessly platformContract performance
Payment details (Stripe customer ID, last 4 digits of card)Processing subscription paymentsContract performance
Audit log entries (user ID, action, timestamp)Security, accountability, and complianceLegitimate interest + legal obligation
Application and request logsDiagnosing errors and monitoring platform healthLegitimate interest

Signing in with Google

If you sign in with Google, we receive your name, email address, and profile picture from your Google Account via Google OAuth. We use this data only to create and secure your Lessly account and to show who is signed in. We do not request access to any other Google user data, do not share Google user data with third parties, and do not use it for advertising or to train AI/ML models. Lessly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We never access the content of customer databases. Lessly is infrastructure — your data belongs to you.


We process your data on one of these grounds for each category:

  • Consent — analytics cookies and optional communications. You can withdraw consent at any time by emailing privacy@lessly.com.
  • Contract performance — account, workspace, and payment data are necessary to provide the service you signed up for.
  • Legitimate interest — security monitoring, fraud prevention, product analytics (landing page only, no personal profiles), and service improvement. We balance these interests against your rights before relying on this basis.
  • Legal obligation — retaining audit logs as required by applicable law.

4. Who we share your data with

We use the following sub-processors. Each has a Data Processing Agreement (DPA) in place and is assessed for GDPR compliance.

VendorRoleData processedRegionTransfer safeguard
Google Cloud PlatformHosting, compute, databases, object storage, secretsAll customer and end-user data processed by the platformEU (europe-west4, Netherlands)none (EU processing)
GitHub (Microsoft Ireland Operations Ltd)Source-code connector, OAuth sign-inAccount identity (name, email), OAuth tokens, repository metadataEU / global (Microsoft Ireland contracting entity)DPF-certified (Microsoft)
PostHog (EU Cloud)Product analyticsUsage events, pseudonymous identifiers (IP not stored)EU (eu.posthog.com, Frankfurt)none (EU processing)
MailerSendTransactional emailRecipient email address, message contentEUnone (EU processing)
AxiomLogs and tracesRequest metadata (IP redacted at source)EU (eu-central-1, Frankfurt)none (EU processing)
StripePayment processing (activates with billing)Payment card (last4), billing name and email, Stripe customer idEU / USDPF-certified + SCCs (known US exception)
InngestWorkflow orchestrationWorkflow event payloads (may include account identifiers)USSCCs (Art. 46 GDPR)
Anthropic PBCLLM inference (Claude) for the natural-language analytics service — text-to-SQL and answer summarizationEnd-user analytics questions (free text, may contain personal data) and query result rows (operational telemetry from wired extensions)USSCCs (Art. 46 GDPR)

We do not sell your personal data. We do not share it with advertisers.

4a. Service providers for the Lessly website

Separate from the platform sub-processors above, our marketing website — including the waitlist form — relies on the following service providers for data collected on the site itself, where Apliteni acts as the controller and the data subjects are site visitors:

VendorRoleData processedRegionTransfer safeguard
CloudflareWebsite delivery, bot protection (Turnstile), and rate limitingVisitor IP address (received by the Turnstile bot-check); visitor IP and submitted email held briefly as rate-limit keys (one-hour expiry)EU / globalSCCs (Art. 46 GDPR)
Google WorkspaceDelivery of waitlist signup notifications to waitlist@lessly.comYour signup email and the details you submit in the formEUSCCs (Art. 46 GDPR)

5. Where your data is stored

All primary data storage is on Google Cloud Platform in europe-west4 (Netherlands). This region is within the EU/EEA, so no cross-border transfer mechanism is required for GCP.

Inngest runs background jobs, and our AI feature providers listed in section 4 serve inference, through US infrastructure. These transfers are covered by DPAs and Standard Contractual Clauses (SCCs) adopted by the European Commission under GDPR Article 46(2)(c), or by the provider's active EU–US Data Privacy Framework certification as listed in the table above.

All other sub-processors listed above store data in the EU, or operate under adequacy decisions, SCCs, or equivalent transfer mechanisms.


6. How long we keep your data

Data typeRetention periodNotes
Waitlist email (not converted)6 months from sign-upDeleted after the period ends
Account and workspace dataUntil you delete your account, then 30 days30-day window lets you recover from accidental deletion
Application and AI request logs90 daysAuto-purged
Audit logs2 yearsRetained under GDPR Art. 17(3)(e) — legal claims basis. Contains only user ID, action type, and timestamp; no personal content.
Payment recordsAs required by Estonian accounting lawTypically 7 years
Backups30 daysRolling backup window

7. Cookies and local storage

Essential items. On the Lessly website we store only what the site needs to function:

  • lessly_consent and lessly_consent_probe — cookies that record your cookie-consent choice and check whether it can be stored.
  • lessly_theme — a browser local-storage preference that remembers your light or dark theme.

After you create an account, the platform additionally sets a session token and a cross-site-request-forgery (CSRF) protection token. These are strictly necessary to keep you signed in securely.

Analytics. The waitlist form is live, and our analytics remain cookieless — we do not set an analytics cookie and we do not store your IP address. If we introduce cookie-based analytics later (alongside the full product), we will update this section, name the cookie, and set it only with your consent, which you can withdraw at any time by emailing privacy@lessly.com.

We do not use advertising cookies or third-party tracking pixels.


8. Your rights under GDPR

If you are in the EU or EEA, you have the following rights:

RightWhat it means
Access (Art. 15)Request a copy of the personal data we hold about you
Rectification (Art. 16)Ask us to correct inaccurate data
Erasure (Art. 17)Ask us to delete your data. We will process the request within 30 days. Audit logs are retained for 2 years per Art. 17(3)(e).
Data portability (Art. 20)Receive your data in a machine-readable format (account data and workspace metadata)
Objection (Art. 21)Object to processing based on legitimate interest
Withdraw consentWithdraw analytics consent at any time; this does not affect prior processing
Lodge a complaintFile a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee

To exercise any right, email privacy@lessly.com with your request. We will respond within 30 days. We may ask you to verify your identity before acting.


9. Children

Lessly is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe we have data from a child, email privacy@lessly.com and we will delete it.


10. Changes to this policy

We will notify you by email if we make material changes to this policy (for example, adding a new category of data or a new sub-processor). Minor corrections or clarifications are reflected in the "last updated" date at the top of this page without separate notification.


11. Contact

Apliteni OÜ · Estonia
privacy@lessly.com