Privacy Policy
This Privacy Policy describes what personal data LitoAI processes, including through the staged-access LitoCode beta for Windows, why we process it, who we share it with, and what rights and controls you have.
Last updated: August 11, 2026Controller and contact
LitoAI is operated by its developer ('LitoAI', 'we'), domiciled in the Argentine Republic. For any privacy question, request, or complaint write to privacy@litochat.com: it is our privacy point of contact and the channel through which we answer access, correction, and deletion requests.
This policy covers the Android app, the web app, its chat, voice, image and video generation, memory, agent, and routine features, and LitoCode. The additional LitoCode terms explain the special risks of working with local files and commands.
Data we collect
Account: when you sign in with Google we receive your email, display name, and profile picture URL. At sign-up we ask for your date of birth to verify the minimum age. We also store your language, region, and usage preferences (response style, personality, sound, notifications, and agent or routine settings).
Content you give us: your chat messages, the files you attach (images and PDFs), image and video generation prompts, and the transcripts of your voice conversations. Memory is on by default: we store the memories LitoAI automatically curates and the ones you add manually until you turn memory off or delete them.
Generated content: the images and videos LitoAI generates for you are stored in your account so you can revisit them.
Technical data: device or session identifiers, push notification tokens, usage and quota metrics, minimized error and diagnostic metadata, and app integrity and anti-fraud signals (Play Integrity / App Check). We design operational logs to avoid chat text, attachments, prompts, and generated content. The Android app uses Firebase Analytics and Crashlytics for usage statistics and crash reports; the web version does not use analytics SDKs.
Payments: subscriptions are purchased exclusively through the Android app and processed by Google Play. We receive the purchase and subscription information needed to activate your plan, keep access synchronized between Android and the web, prevent duplicate subscriptions, and provide billing support; we never see or store your full card details.
LitoCode: when you use it, it may read files in the project folder you selected and send our providers the full contents of files the agent reads, project memory, repository paths and symbols, commands and output, your instructions, and the conversation. To request beta access, we record your country, a short description of intended use, confirmations of age and sufficient rights or authorization over the project, plan at request time, review priority, status, and the decision date. Commands run with your Windows user permissions and can reach other locations or services. Outside LitoCode, we do not access device content except what you attach or expressly authorize.
What we do NOT collect: we do not access your GPS location or contacts. Place searches use only the text of your query, not your device location. We do not sell personal data or share it for advertising; LitoAI shows no ads.
How we use your data
To provide the service (legal basis: performance of the contract): answering your messages, generating images and videos, holding voice conversations, syncing your account between mobile and web, remembering your preferences and memories, running agents and routines, and managing your plan and usage quotas.
For safety and abuse prevention (legal basis: legitimate interest): automated safety filters, fraud prevention, protection of minors, minimized error diagnostics, and infrastructure protection. Automatic safety alerts contain a category, severity, and operational source, not chat text, attachments, account email, or links to a conversation.
To comply with legal obligations (legal basis: legal obligation): responding to requests from competent authorities and keeping records required by law.
We do not use your conversations to train our own artificial intelligence models. External providers process data under their current contracts and policies; their training, retention, and control terms are described below and may differ by provider and feature.
AI processing and providers
To generate responses, LitoAI sends necessary content to artificial intelligence providers acting as processors or technical providers: OpenRouter (messages, history, attachments, and certain models), OpenAI (voice, planning and structure explanations, as well as fallback features), and fal.ai (prompts and images for video generation and image editing).
LitoCode uses OpenRouter (Qwen3-Coder model) as its default provider, which routes the request to different infrastructure companies depending on the active model rather than operating a single server of its own; we require it not to use your code to train models, but not every company it can route to guarantees zero data retention. Its fallback is the MiniMax API, operated by Nanonoble Pte. Ltd., based in Singapore, whose current policy states that data is stored in United States data centers and also offers no universal zero-retention guarantee. Planning and graph explanations use the OpenAI API with store:false, which prevents application-state storage but is not by itself the same as Zero Data Retention. LitoCode web searches send the query to Tavily.
Other service providers: Firebase / Google Cloud (authentication, database, file storage, push notifications, and analytics and crash reporting on Android), Vercel (web hosting), Tavily (receives the text of your web searches), Google Places (receives the text of your place searches), and Google Play (billing, taxes, payment methods, renewals, cancellations, and refunds for Android subscriptions).
These providers receive data only to the extent needed to deliver each feature and handle it under their own contractual and privacy commitments. We do not sell your data to them or share it for third-party advertising.
Voice and audio
In real-time voice mode, your audio is streamed live to the AI provider to hold the conversation. LitoAI does not store audio: we only keep the text transcripts of confirmed turns, and only if the conversation is not in private mode.
In voice dictation, the audio is sent solely to obtain the transcription; we keep the resulting text, not the audio.
The microphone is used exclusively when you start a voice feature. LitoAI does not record audio in the background.
Memory and private mode
LitoAI's memory is enabled by default and stores facts about your preferences and context to personalize responses. You can view, edit, delete individual memories, or disable memory from Settings at any time. Turning it off stops new automatic memory curation and memory retrieval; it does not delete existing memories unless you delete them.
Private mode conversations are not saved to your history, do not create memories, and their attachments are discarded when the turn ends. The content is processed transiently only to generate the response and protect the service.
Privacy controls and voluntary reports
LitoAI separates ordinary operations from exceptional review. Authorized personnel do not receive a general feed of chat text or attachments. Automatic safety alerts are metadata-only and cannot be used in the admin panel to open a conversation.
If you deliberately use Report on an AI response, you submit that selected response and your report reason for review. The evidence is kept separately from the general report list and can be opened only by an authorized administrator when needed for safety, abuse, appeal, or security review. Each opening is recorded. Reporting does not turn LitoAI into a service that proactively reads every chat.
International transfers
Our servers and providers may process data in the United States, Singapore, and other jurisdictions that may not offer a level of protection equivalent to your country's. Before you use LitoCode we request separate, informed consent for these transfers under Section 12 of Argentine Law 25,326.
A consent checkbox does not replace the rights or authorization you need over third-party personal data, code, or secrets. You may use third-party projects only if you declare and have sufficient authorization to process them and share them with the declared providers. Do not use LitoCode for production uses, sensitive or regulated data, or unauthorized uses. The beta is for people aged 18 or over, and access depends on manual review; it is not activated by purchasing a subscription.
Data retention
Your LitoAI conversations, files, memories, and generated content are kept while your account is active, so you do not lose your history. You can delete individual conversations and memories at any time, and they are removed when you delete your account subject to the exceptions below.
In LitoCode, sessions, the index, project memory, snapshots, and the activity log are stored locally on your computer. Our backend does not persist LitoCode prompt or response content, but it keeps usage and cost metadata, the legal acceptance receipt, and the minimum beta access request/review data. External providers apply their own retention periods: OpenRouter has no universal zero-retention guarantee for the Qwen3-Coder model it uses by default (we only require it not to train on the content); MiniMax, the fallback, also offers no universal zero-retention guarantee; OpenAI may retain content in abuse-monitoring logs for up to 30 days unless the account has separately approved controls.
Deleting an account also removes its report metadata and voluntarily submitted report evidence from our active systems. We may retain only the minimum separate records required by applicable law, security, fraud prevention, tax requirements, or dispute resolution. Purchase records managed by Google Play remain subject to its legal and tax retention periods.
Account and data deletion
Account deletion also removes the report metadata and evidence you voluntarily submitted through Report from our active systems, together with the rest of the account data described below.
You can delete your account directly in the app: Settings → Account → Delete account. Deletion starts immediately and removes your profile, conversations, messages, memories, uploaded files, generated content, routines, agents, and your sign-in user. We may retain or de-identify minimal security, billing, and consent evidence where a legal obligation or legitimate legal interest requires it.
Deleting your cloud account does not automatically erase LitoCode data stored on your computer. You can delete sessions and snapshots in Settings and remove other local data by uninstalling the app and deleting its data folder. The local consent receipt is deliberately stored separately from preferences.
You can also request deletion by writing to privacy@litochat.com or by following the instructions at www.litochat.com/data-deletion. We process email requests within 30 days.
Your rights
Depending on your jurisdiction, you have the right to access your data, rectify it, update it, delete it, object to or restrict its processing, request its portability, and withdraw your consent. You can exercise these rights from the app or by writing to privacy@litochat.com; access is free of charge as provided by applicable law.
If you reside in Argentina: the Agency for Access to Public Information (Agencia de Acceso a la Información Pública), in its capacity as supervisory authority of Law 25,326, is competent to receive complaints and claims filed by those whose rights are affected by a breach of the applicable personal data protection rules.
If you reside in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your data protection authority. We do not sell or 'share' personal information as defined by California law; California residents can exercise their rights through the same channels.
Children
LitoAI is not directed at children under 13 and we do not allow accounts for children under 13. We ask for the date of birth at sign-up; if we detect an account belonging to a child under 13, we close it and delete its data.
Users aged 13 to 17 need permission from a parent or guardian and receive an experience with additional content restrictions. LitoCode is an exception: its staged-access beta is available only to people aged 18 or older who can legally accept its terms.
Security
We apply reasonable technical and organizational measures: encryption in transit, managed encryption at rest provided by our cloud infrastructure, per-user access rules in the database, app integrity checks (Play Integrity / App Check), restricted access to production systems, minimized operational logs, and auditable exceptional review of voluntarily reported content.
No system is infallible: we cannot guarantee absolute security, but we investigate incidents and notify where the law requires it.
Cookies and local storage
The LitoAI website only uses the storage needed to keep you signed in and remember preferences such as language. We use no advertising cookies or third-party trackers.
Changes to this policy
If we make material changes to this policy, we will give reasonable advance notice in the app or by email. The date of the latest update is shown at the top of the page.