Privacy Policy
Last updated: 2026-07-16
1. Who we are and how to reach us
Lessly is operated by Apliteni OÜ, a private limited company registered in Estonia (registry code 14296961, Tornimäe tn 3 // 5 // 7, Tallinn, Estonia).
For all privacy-related questions, requests, or complaints, contact us at privacy@lessly.com. We aim to respond within 30 days.
We do not have a designated Data Protection Officer (DPO). For GDPR inquiries, privacy@lessly.com reaches the person responsible directly.
2. What data we collect and why
We collect only what we need for each stage of the product.
While you are on the waitlist (current)
Analytics are currently cookieless. When the waitlist form activates, cookie-based analytics will replace cookieless tracking — at that point the legal basis switches to Consent.
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address | To notify you when Lessly launches and to send a confirmation email | Consent (you submitted the form) |
| Page view and interaction events (cookieless) | To understand which parts of the landing page drive sign-ups and improve the experience | Legitimate interest (product analytics) |
| Page view and interaction events (via analytics cookie, when active) | Same purpose — cookie-based analytics activated alongside the waitlist form | Consent (you may withdraw at any time by emailing privacy@lessly.com) |
After you create an account
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address, display name | Account identity and communication | Contract performance |
| GitHub OAuth token | Connecting your repository so Lessly can deploy your code | Contract performance |
| Workspace content (code, environment variables, secrets, databases) | Running your applications on the Lessly platform | Contract performance |
| Payment details (Stripe customer ID, last 4 digits of card) | Processing subscription payments | Contract performance |
| Audit log entries (user ID, action, timestamp) | Security, accountability, and compliance | Legitimate interest + legal obligation |
| Application and request logs | Diagnosing errors and monitoring platform health | Legitimate interest |
Signing in with Google
If you sign in with Google, we receive your name, email address, and profile picture from your Google Account via Google OAuth. We use this data only to create and secure your Lessly account and to show who is signed in. We do not request access to any other Google user data, do not share Google user data with third parties, and do not use it for advertising or to train AI/ML models. Lessly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We never access the content of customer databases. Lessly is infrastructure — your data belongs to you.
3. Legal bases for processing
We process your data on one of these grounds for each category:
- Consent — analytics cookies and optional communications. You can withdraw consent at any time by emailing privacy@lessly.com.
- Contract performance — account, workspace, and payment data are necessary to provide the service you signed up for.
- Legitimate interest — security monitoring, fraud prevention, product analytics (landing page only, no personal profiles), and service improvement. We balance these interests against your rights before relying on this basis.
- Legal obligation — retaining audit logs as required by applicable law.
4. Who we share your data with
We use the following sub-processors. Each has a Data Processing Agreement (DPA) in place and is assessed for GDPR compliance.
| Vendor | Role | Data processed | Region | Transfer safeguard |
|---|---|---|---|---|
| Google Cloud Platform | Hosting, compute, databases, object storage, secrets | All customer and end-user data processed by the platform | EU (europe-west4, Netherlands) | none (EU processing) |
| GitHub (Microsoft Ireland Operations Ltd) | Source-code connector, OAuth sign-in | Account identity (name, email), OAuth tokens, repository metadata | EU / global (Microsoft Ireland contracting entity) | DPF-certified (Microsoft) |
| PostHog (EU Cloud) | Product analytics | Usage events, pseudonymous identifiers (IP not stored) | EU (eu.posthog.com, Frankfurt) | none (EU processing) |
| MailerSend | Transactional email | Recipient email address, message content | EU | none (EU processing) |
| Axiom | Logs and traces | Request metadata (IP redacted at source) | EU (eu-central-1, Frankfurt) | none (EU processing) |
| Stripe | Payment processing (activates with billing) | Payment card (last4), billing name and email, Stripe customer id | EU / US | DPF-certified + SCCs (known US exception) |
| Inngest | Workflow orchestration | Workflow event payloads (may include account identifiers) | US | SCCs (Art. 46 GDPR) |
| Anthropic PBC | LLM inference (Claude) for the natural-language analytics service — text-to-SQL and answer summarization | End-user analytics questions (free text, may contain personal data) and query result rows (operational telemetry from wired extensions) | US | SCCs (Art. 46 GDPR) |
We do not sell your personal data. We do not share it with advertisers.
4a. Service providers for the Lessly website
Separate from the platform sub-processors above, our marketing website — including the waitlist form — relies on the following service providers for data collected on the site itself, where Apliteni acts as the controller and the data subjects are site visitors:
| Vendor | Role | Data processed | Region | Transfer safeguard |
|---|---|---|---|---|
| Cloudflare | Website delivery, bot protection (Turnstile), and rate limiting | Visitor IP address (received by the Turnstile bot-check); visitor IP and submitted email held briefly as rate-limit keys (one-hour expiry) | EU / global | SCCs (Art. 46 GDPR) |
| Google Workspace | Delivery of waitlist signup notifications to waitlist@lessly.com | Your signup email and the details you submit in the form | EU | SCCs (Art. 46 GDPR) |
5. Where your data is stored
All primary data storage is on Google Cloud Platform in europe-west4 (Netherlands). This region is within the EU/EEA, so no cross-border transfer mechanism is required for GCP.
Inngest runs background jobs, and our AI feature providers listed in section 4 serve inference, through US infrastructure. These transfers are covered by DPAs and Standard Contractual Clauses (SCCs) adopted by the European Commission under GDPR Article 46(2)(c), or by the provider's active EU–US Data Privacy Framework certification as listed in the table above.
All other sub-processors listed above store data in the EU, or operate under adequacy decisions, SCCs, or equivalent transfer mechanisms.
6. How long we keep your data
| Data type | Retention period | Notes |
|---|---|---|
| Waitlist email (not converted) | 6 months from sign-up | Deleted after the period ends |
| Account and workspace data | Until you delete your account, then 30 days | 30-day window lets you recover from accidental deletion |
| Application and AI request logs | 90 days | Auto-purged |
| Audit logs | 2 years | Retained under GDPR Art. 17(3)(e) — legal claims basis. Contains only user ID, action type, and timestamp; no personal content. |
| Payment records | As required by Estonian accounting law | Typically 7 years |
| Backups | 30 days | Rolling backup window |
7. Cookies and local storage
Essential items. On the Lessly website we store only what the site needs to function:
lessly_consentandlessly_consent_probe— cookies that record your cookie-consent choice and check whether it can be stored.lessly_theme— a browser local-storage preference that remembers your light or dark theme.
After you create an account, the platform additionally sets a session token and a cross-site-request-forgery (CSRF) protection token. These are strictly necessary to keep you signed in securely.
Analytics. The waitlist form is live, and our analytics remain cookieless — we do not set an analytics cookie and we do not store your IP address. If we introduce cookie-based analytics later (alongside the full product), we will update this section, name the cookie, and set it only with your consent, which you can withdraw at any time by emailing privacy@lessly.com.
We do not use advertising cookies or third-party tracking pixels.
8. Your rights under GDPR
If you are in the EU or EEA, you have the following rights:
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Ask us to correct inaccurate data |
| Erasure (Art. 17) | Ask us to delete your data. We will process the request within 30 days. Audit logs are retained for 2 years per Art. 17(3)(e). |
| Data portability (Art. 20) | Receive your data in a machine-readable format (account data and workspace metadata) |
| Objection (Art. 21) | Object to processing based on legitimate interest |
| Withdraw consent | Withdraw analytics consent at any time; this does not affect prior processing |
| Lodge a complaint | File a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee |
To exercise any right, email privacy@lessly.com with your request. We will respond within 30 days. We may ask you to verify your identity before acting.
9. Children
Lessly is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe we have data from a child, email privacy@lessly.com and we will delete it.
10. Changes to this policy
We will notify you by email if we make material changes to this policy (for example, adding a new category of data or a new sub-processor). Minor corrections or clarifications are reflected in the "last updated" date at the top of this page without separate notification.
11. Contact
Apliteni OÜ · Estonia
privacy@lessly.com