Features Pricing FAQ About Sign In
Legal

Privacy Policy

How Legate Studio collects, uses, and protects your information. We've written this to be readable, not impenetrable.

1. Who We Are

Legate Studio is operated by O-Live Dev LLC. When we say "we," "us," or "our" in this policy, we mean O-Live Dev LLC and the Legate Studio service at legate.studio. If you have questions, reach us at hello@legate.studio.

2. What We Collect

2.1 Account Information (from GitHub OAuth)

When you sign in with GitHub, we receive your GitHub username, display name, and avatar URL from GitHub's API. We use this to create and identify your account. We do not receive your GitHub password, email address (unless it's public on your GitHub profile), or access to any of your repositories.

2.2 Your Knowledge Base Content

Notes, categories, voice recordings (during processing), transcriptions, embeddings, graph data, and any other content you create in Legate Studio. This is stored in your per-user SQLite database on Fly.io infrastructure. Your content is private by default; you choose to publish specific notes.

2.3 Profile Information

Display name, bio, and accent color you set for your public profile. This information is publicly visible if you create a public profile.

2.4 Billing Information

If you subscribe to a paid plan, billing is handled entirely by Stripe. We store a Stripe customer ID and your subscription status. We do not store your credit card number, CVV, or any sensitive payment details — those live only in Stripe's systems, which are PCI-DSS compliant.

2.5 Usage Analytics

We use Plausible Analytics to understand how the product is used. Plausible collects aggregate, non-identifiable data: pageviews, country-level location, referrer, browser type. No cookies are set. No user profiles are built. No data is shared with advertisers. For details, see Plausible's privacy policy.

2.6 Server Logs

Our hosting infrastructure (Fly.io) generates standard access logs including IP addresses, request timestamps, and response codes. These logs are used for debugging and security purposes and are retained for a limited period per Fly.io's standard policies.

3. How We Use Your Information

  • To operate the service — storing and retrieving your knowledge base, processing Motifs through AI pipelines, running search and graph features.
  • To authenticate you — verifying your identity via GitHub OAuth on each session.
  • To process payments — creating and managing your subscription via Stripe.
  • To display your public profile — if you've enabled one, showing your published notes and profile information to visitors.
  • To improve the product — using aggregate Plausible analytics to understand which features are used and where friction exists.

We do not use your content to train AI models. We do not sell your data. We do not share your personal information with advertisers.

4. AI Processing and Third Parties

To power transcription, categorization, and semantic search, your content is sent to Google's Gemini API for processing. On the BYOK plan, this happens using your own API key under your own Google agreement. On the Managed plan, it happens under our Google API agreement.

Google processes your content as part of providing the API service. We do not control Google's data handling practices — review Google's AI terms for details. We select Google because they offer data processing agreements and commit to not training on API inputs by default.

Third parties we share data with:

  • Stripe — payment processing. They receive your payment information and billing address.
  • Google (Gemini API) — AI processing. They receive content from your notes during processing.
  • GitHub — authentication. They confirm your identity when you log in.
  • Fly.io — hosting infrastructure. Your data is stored on their servers.
  • Plausible — analytics. They receive anonymous pageview data.

5. Data Retention

Your account and knowledge base are retained as long as your account is active. If you delete your account, your per-user database is deleted. We retain billing records as required by law (typically 7 years). Server logs are retained for a limited period per our hosting provider's policies.

6. Your Rights

You have the right to:

  • Access your data — download your knowledge base database directly from account settings.
  • Delete your data — delete your account and all associated data from account settings.
  • Correct your information — update your profile from account settings.
  • Data portability — your knowledge base is a standard SQLite file, downloadable at any time.

If you are in the European Economic Area (EEA), you have additional rights under GDPR. Contact us at hello@legate.studio to exercise any of these rights.

7. Cookies

We use a single session cookie to keep you logged in. This is a functional cookie required for the service to work — it contains a session identifier, not personal information. We do not use advertising cookies, tracking pixels, or third-party cookies of any kind. Plausible Analytics does not use cookies.

8. Children's Privacy

Legate Studio is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe we have inadvertently collected such information, contact us at hello@legate.studio.

9. Changes to This Policy

We may update this policy as the product evolves. We will update the "last updated" date at the top of this page when we make changes. For significant changes, we will notify active users via email or in-app notification.

10. Contact

Questions about this privacy policy? Email us at hello@legate.studio.