Skip to content

Privacy Policy

Last updated on 7 August 2026

Who is responsible, and how can you reach us?

The controller for the processing of personal data on lytris.com and in the Lytris application is:

Controller
Linity GmbH, Heilbronn, Germany
Represented by
Johannes Zimmer and Julian Bühlmaier, Managing Directors
Commercial register
Heilbronn Local Court, HRB 795872
VAT identification number
DE368689127

Our Data Protection Officer

We have appointed an external Data Protection Officer and notified the supervisory authority. You may contact them directly and in confidence about anything concerning your data (Art. 38(4) GDPR). They are bound to secrecy, including towards us.

Data Protection Officer
Dr. Kilian Schmidt, Kertos GmbH
Address
Brienner Str. 41, 80333 Munich, Germany
Phone
+49 151 525 797 93

Competent supervisory authority

State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany. You may lodge a complaint there at any time (Art. 77 GDPR) without contacting us first.

Who does this policy apply to?

There are two ways to use Lytris, and which one applies decides who is responsible for which data. Please read the part that applies to you.

Private account

You sign up yourself, without a university. You either use Lytris free of charge with a daily message allowance, or on a paid subscription with a higher allowance. For everything that happens in such an account we are the controller under the GDPR, and this policy describes it in full.

Access through your university

You join a course through an invitation link from your university. Your account and the general features are still governed by this policy. For the teaching itself, however, something else applies:

If you use Lytris through your university, we process course content, submissions and assessments solely on its behalf, under a contract pursuant to Art. 28 GDPR. Your university is the controller in that respect and informs you separately. You may still exercise your rights against us; we will pass your request on.

Where data that does not come from you originates

Art. 14(2)(f) GDPR requires us to name the source. With university access we receive:

  • your course membership and your role in the course, from your university or via the invitation link,
  • your identity data from the sign-in process, if you sign in with a university account or a third-party provider,
  • course material and assignments uploaded by teaching staff, which may mention you.

Do you have to give us this data?

Under Art. 13(2)(e) GDPR: an email address and an account are required in order to use Lytris; without them we cannot give you access or store a history. Payment data is required only if you take out a paid subscription. Everything else you enter or upload is voluntary. Not providing it puts you at no disadvantage; only the feature in question will be unavailable.

What rights do you have?

These rights are yours, without having to give a reason and free of charge. A short email is enough.

  • Access (Art. 15). You learn which data we process about you and receive a copy.
  • Rectification (Art. 16). We correct inaccurate data and complete incomplete data.
  • Erasure (Art. 17). We delete your data unless a statutory retention obligation prevents it.
  • Restriction (Art. 18). We freeze processing instead of deleting, for example while a correction is being checked.
  • Data portability (Art. 20). You receive your data in a common, machine-readable format.
  • Withdrawal of consent (Art. 7(3)). With effect for the future, without making the processing up to that point unlawful.
  • Complaint (Art. 77). With any supervisory authority, in particular the one named above.

Right to object (Art. 21 GDPR). Where we process data on the basis of a legitimate interest, you may object at any time on grounds relating to your particular situation. This concerns our product analytics in particular. We will then stop the processing unless we demonstrate compelling legitimate grounds that override your interests.

To exercise a right, write to compliance@lytris.com or directly to our Data Protection Officer at data-privacy@kertos.io. We respond within one month (Art. 12(3) GDPR).

What data, for what purpose, on what basis, for how long?

DataPurposeLegal basisDuration
Account data: name, email address, sign-in identifier, language settingRunning your account, signing you in, communicating with youArt. 6(1)(b) (contract)For as long as your account exists
Content you enter or upload: conversations, documents, notes, workspacesProviding the learning and AI featuresArt. 6(1)(b) (contract)Until you delete it or request its deletion
Usage data: areas visited, interactions, device type, browserKeeping the service running, finding faults, improving the productArt. 6(1)(f) (legitimate interest)For as long as needed for the analysis, at most for the life of your account
Payment and invoicing data on a paid subscriptionBilling and accountingArt. 6(1)(b) and (c) (legal obligation)Invoicing records for ten years (sec. 147 AO, sec. 257 HGB)
Error and operational logs, truncated IP addressesSecurity, stability, abuse preventionArt. 6(1)(f) (legitimate interest)Short term, within the retention of our logging providers
Your messages to our support teamAnswering your request and keeping a record of itArt. 6(1)(b) and (f)Until the matter is resolved, then within statutory retention periods

[university access only] If you use Lytris through your university, course-related data is added that we process solely on its behalf. Your university is the controller for it, see Who does this policy apply to?.

Where we state a criterion instead of a fixed period, that is deliberate: Art. 13(2)(a) GDPR expressly allows criteria, and we will not promise you a deadline our systems do not keep.

If you delete your account

You can delete your account yourself in the settings. That removes your user account and your sign-in data. Content attached to it we delete on your request under Art. 17 GDPR; write to compliance@lytris.com for that. With university access, your university decides about course content, submissions and assessments.

How do the AI features work?

When you ask a question or upload a document, we pass the relevant content to a language model that produces the answer. We do not run these models ourselves; we obtain them from providers acting as our processors:

  • Google Cloud EMEA Limited (Ireland), Vertex AI. This covers the Gemini models as well as models from Anthropic, Qwen and Moonshot AI made available through the same service.
  • Mistral AI SAS (France). Language models that generate answers, and text recognition in uploaded documents.

Processing in the EU. For these features your content is processed in data centres within the European Union.

No training on your content. Our contracts with these providers prohibit the use of your content to train models.

Automated decisions

In a private account we make no decisions about you based solely on automated processing that produce legal effects concerning you (Art. 22 GDPR). Suggestions, explanations and hints from the AI are suggestions.

Who gets to see your data?

Within Linity, only those people have access who need it for their work. Beyond that we use service providers acting as processors on our instructions (Art. 28 GDPR). We do not sell data and do not pass it on for advertising.

Convex, Inc.
Application database. Processing in the Dublin data centre, Ireland. Privacy policy
Google Cloud EMEA Limited
Running the application, file storage and Vertex AI. Processing in the EU. Privacy policy
Mistral AI SAS
Language models that generate answers, and text recognition in uploaded documents. France. Privacy policy
Clerk, Inc.
Registration, sign-in and session management, including the subprocessors Clerk uses, among them Svix for the signed delivery of technical events. Privacy policy
PostHog
Product analytics. Processing on the provider EU infrastructure. Privacy policy
Sentry
Capturing technical errors. Processing in the EU. Privacy policy
Axiom
Operational logs. Processing in the EU. Privacy policy

Payments. Paid subscriptions are handled through Stripe. You enter your payment details directly with Stripe; we neither see nor store full card details. Stripe processes that data as its own controller to meet its own legal obligations. Stripe privacy policy

Beyond this we disclose data only where we are legally obliged to, or where it is necessary to establish or defend legal claims.

Where is your data processed?

Your content stays in the EU. The database, the file storage, the AI processing, the product analytics, the error capture and our operational logs sit in data centres within the European Union, mainly in Ireland, the Netherlands and France.

Individual providers for sign-in and payments belong to corporate groups established outside the European Union. Where personal data is transferred to a third country as a result, we rely on the European Commission Standard Contractual Clauses under Art. 46(2)(c) GDPR, supplemented by additional technical and organisational measures. You can obtain a copy of the safeguards from data-privacy@kertos.io.

Cookies and storage on your device

We set no advertising or tracking cookies. The cookies below are required for the application to work, or store a setting you made yourself (sec. 25(2) TDDDG). That is also why there is no cookie banner here.

CookiePurposeDurationSet by
__session, __client_uat, __clerk_db_jwtSign-in and session managementSession, until you sign outClerk
NEXT_LOCALERemembers your language choiceOne yearLinity
sidebar_stateRemembers whether the sidebar is openSeven daysLinity

Product analytics without a cookie

We use PostHog to measure how the application is used: the areas visited, plus clicks and form events, which also capture the label of the element you interacted with. We store nothing on your device for this; the association lasts only as long as the open window. We do not pass PostHog your name, your email address or the content of your conversations with the AI. The legal basis is Art. 6(1)(f) GDPR; you may object at any time under Art. 21 GDPR.

Storage in your browser

To keep the application responsive, it stores data in your browser that never leaves your device:

  • IndexedDB (linity-db). Your workspaces and the messages in your conversations, so they are visible immediately next time.
  • Local storage. Display settings, dismissed notices, the course you last visited and, if you arrived through a referral link, its code.

You can delete all of it at any time in your browser settings.

How do we protect your data?

We take technical and organisational measures under Art. 32 GDPR and review them regularly. In particular:

  • encryption of all connections via TLS and encryption of data at rest,
  • access limited to people who need it for their work, with two-factor authentication,
  • non-public file storage reachable only through short-lived, signed references,
  • logging of security-relevant events and a defined process for handling security incidents,
  • an information security management system and regular staff training.

No system is completely secure. If you notice a weakness, please write to hello@lytris.com.

Minimum age

Lytris is aimed at students and other adults. You may create a private account if you are at least 16 years old. If you are younger, consent or authorisation from your parent or guardian is required (Art. 8 GDPR).

If we learn that an account was created contrary to this, we delete it. Please report such cases to hello@lytris.com.

Changes to this policy

We update this policy when the application, the providers we use or the legal situation change. The version published here is the one that applies; the date of the last change is shown at the top of the page. For material changes we notify you additionally, in the application or by email.

This privacy policy is available in German and English. In case of discrepancies, the German version prevails.