Section 01
Data We Collect
We collect the following categories of data when you use Lyralink:
- Account details such as username and email address
- Authentication and security data including login attempts, 2FA status, and device session metadata
- Chat content and saved conversation history when you use account-based sync
- Operational diagnostics such as IP address, browser/app user agent, and abuse-prevention logs
- Billing status and subscription information needed to provide paid service tiers
- Support communications when you open a support ticket or contact us
- Usage data including feature interactions, API call counts, and plan utilization
Section 02
How We Use Your Data
- To operate the Lyralink service and deliver AI responses
- To secure accounts, detect abuse, and investigate incidents
- To manage plans, support requests, and compliance obligations
- To improve reliability, performance, and product quality
- To communicate service updates, account notices, and security alerts
- To enforce these policies and any applicable legal requirements
We do not use your data for targeted advertising or behavioral profiling for ad purposes.
Section 03
Cookies & Local Storage
Lyralink uses session cookies to maintain authenticated sessions. We do not use third-party tracking cookies or advertising cookies.
- Session cookies — required for login and account state; expire when your session ends or you log out
- Preference cookies — store non-sensitive UI state (e.g. dev mode flag) for authenticated users only
- Local storage — used by the web app to cache interface state client-side; not sent to our servers
Essential session cookies cannot be disabled without breaking authentication. You can clear cookies and local storage at any time through your browser settings.
Section 04
Third-Party Processing
To operate the service, we share limited data with trusted third parties:
- AI providers (Groq / Meta) — prompt content and request metadata are sent to generate AI responses. Do not include sensitive personal information in prompts.
- Payment processors (PayPal) — payment and subscription records. We do not store full card numbers.
- Hosting & infrastructure — server, CDN, and database providers operating under data processing agreements.
We do not sell, rent, or trade personal information to third parties for their own marketing purposes.
Section 05
Operator Data Responsibilities
Lyralink offers an Operator Program that allows approved businesses to deploy AI products under their own brand using Lyralink infrastructure. When you operate a Lyralink-powered product:
- You are responsible for your own end-user privacy disclosures and data practices
- Client account data generated through your operator deployment is subject to this policy as well as your own obligations
- You must not use the platform to collect data in ways that violate applicable privacy law
- Operator earnings, client counts, and payout records are retained for audit and compliance purposes
Operator Note
If you run a white-label deployment, your clients interact with Lyralink infrastructure. You should provide your own privacy notice that references this policy where applicable.
Section 06
Retention & Deletion
We retain your data for as long as your account is active or as needed to provide the service. Specific retention guidelines:
- Chat history — retained while your account is active; deletable from within account settings
- Account data — retained until account deletion is processed and any hold period expires
- Security & audit logs — retained for up to 12 months for fraud prevention and incident response
- Billing records — retained for up to 7 years where required by financial regulations
- Support tickets — retained for up to 3 years for quality and compliance purposes
You can request deletion of chat history or your full account from within the account area or by contacting support. Certain records may be retained beyond deletion where legally required.
Section 07
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Deletion — request deletion of your account and associated personal data
- Portability — request your data in a structured, machine-readable format where feasible
- Objection — object to certain processing activities where applicable law permits
- Restriction — request that we restrict processing of your data in certain circumstances
To exercise any of these rights, contact us at support@lyralinkai.com. We will respond within 30 days. Identity verification may be required before processing requests.
Section 08
Children's Privacy
Lyralink is not directed to children under 13. We do not knowingly collect personal data from children under 13. Users between 13 and 17 must have parental or guardian consent as described in our Terms of Service.
If we learn that we have collected data from a child under 13 without parental consent, we will delete that data promptly. If you believe a child under 13 has created an account, contact us at support@lyralinkai.com.
Section 09
International Transfers
Lyralink is operated from the United States. If you access the service from outside the US, your data may be transferred to and processed in the United States or other countries where our infrastructure providers operate.
We rely on infrastructure and AI providers that operate internationally. By using Lyralink, you consent to this transfer. We take steps to ensure that such transfers are handled in accordance with applicable data protection law.
Section 10
Security
We use HTTPS, session controls, rate limiting, two-factor authentication, and verification safeguards to protect account access. Sensitive credentials are hashed and never stored in plaintext.
No system can guarantee absolute security. In the event of a breach affecting your data, we will notify affected users as required by applicable law.
You are responsible for maintaining the security of your account credentials. Do not share your password or 2FA recovery codes.
Section 11
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised effective date. Where appropriate, we will notify users via email or in-app notice.
Continued use of Lyralink after policy changes constitutes acceptance of the updated policy.
This policy applies to lyralinkai.com and Lyralink-branded products operated by LyralinkAI. It does not apply to third-party websites or services we may link to.