logo

Privacy Policy

Overview

Linity GmbH operates Lytris, a learning platform used by universities and their members.

This Privacy Policy explains which personal data we process when you use our website https://www.lytris.com and the Lytris application, for what purposes, and on what legal basis.

Lytris is not a brochure website. It stores user accounts, course materials, uploaded documents, coursework submissions, grades, and chat conversations, and it uses AI models to process them. This policy describes that processing.

1. Controller

The controller within the meaning of article 4(7) GDPR is Linity GmbH, Bildungscampus 1, 74076 Heilbronn, Germany.

Managing directors: Johannes Zimmer, Julian Bühlmaier.

Email: hello@linity.one.

2. Scope of This Policy

This policy covers our website https://www.lytris.com and the Lytris application, including all course, exercise, and workspace features.

Our platform contains links to external services (for example Discord and our feedback board). We have no control over how those providers process your data. Please consult their own privacy notices before providing data to them.

3. What Data We Process, Why, and on What Legal Basis

a) Server log data. When you access our platform we process your IP address, date and time of the request, the page requested, HTTP status code, volume of data transferred, referring website, browser type and version, operating system, and language settings. Purpose: technical operation, stability, and security of the platform. Legal basis: article 6(1)(f) GDPR; our legitimate interest is the secure and uninterrupted operation of the platform.

b) User account. To register and sign you in we process your name, email address, username, profile picture, the identifier of your single sign-on provider where applicable, your role (student or lecturer), your language setting, and your course memberships. Purpose: providing your user account. Legal basis: article 6(1)(b) GDPR (performance of a contract).

c) Content you provide. Uploaded documents, lecture materials, coursework submissions, audio and video recordings, voice dictation, and your inputs in the AI workspace, including private messages to other users of the same course. Where you submit coursework, this also includes identifiers contained in the document itself, such as your name, email address, and registration number. Purpose: providing the learning features you use. Legal basis: article 6(1)(b) GDPR.

d) Grades and feedback. Points awarded, written feedback, assessment criteria, and any objection you raise against a grade. Purpose: performing the assessment features that your institution and you use. Legal basis: article 6(1)(b) GDPR.

e) Payment data. Subscription status, invoice data, and transaction identifiers. Legal basis: article 6(1)(b) GDPR; for the retention of accounting records additionally article 6(1)(c) GDPR in conjunction with commercial and tax law retention obligations.

f) Error and performance data. In the event of technical faults we record diagnostic data such as the error message, the page involved, browser information, and your user identifier. Legal basis: article 6(1)(f) GDPR; our legitimate interest is identifying and fixing faults.

g) Usage analysis. Events describing which pages and features are used, linked to your user identifier, plus your email address and username. Legal basis: article 6(1)(f) GDPR; our legitimate interest is understanding and improving how the platform is used. You may object at any time (see section 10).

h) Contacting us. If you write to us we process your details in order to respond. Legal basis: article 6(1)(b) GDPR for contract-related enquiries, otherwise article 6(1)(f) GDPR.

4. AI Features and Automated Assessment

Lytris uses AI models to provide its core features. The following content is transmitted to the AI providers named in section 5 and processed there on our behalf: your chat inputs and the resulting responses, uploaded documents and lecture materials, audio and video recordings for transcription, and coursework submissions including handwritten work.

For coursework submissions, the model is instructed to read identifying details contained in the document, such as name, email address, and registration number, so that a submission can be matched to the correct person.

Assessment. Where your course uses the assessment features, an AI model produces a proposed score and written feedback for a submission.

In the hand-in mode, that proposal is not visible to you until the lecturer releases it. The lecturer can amend or replace the score and the feedback.

In the immediate-feedback mode and for check-in questions, the assessment is generated and shown to you directly without prior review by a lecturer.

These scores do not by themselves determine whether you pass or fail, and Lytris does not issue credits, certificates, rankings, or comparisons against other participants.

Regardless of the mode, you always have the right to obtain human intervention: contact your lecturer or write to us at hello@linity.one to have an assessment reviewed by a person, to state your point of view, and to contest the result.

We do not use your data to train the AI models of the providers named in section 5.

5. Recipients and Processors

We use the following service providers. Except where stated otherwise, they act as processors within the meaning of article 28 GDPR and process your data only on our documented instructions.

Convex, Inc. (United States), our database and backend runtime. Processes all application data listed in section 3. Processing location: European Union.

Clerk, Inc. (United States), authentication, account management, and transactional email. Processes email address, name, username, profile picture, session and device data, and IP address.

Google Cloud EMEA Ltd. (Ireland), hosting, file storage, and the Vertex AI models used for chat, document processing, transcription, and assessment. Our compute infrastructure runs in the europe-west3 (Frankfurt) region. Processes the content described in sections 3 and 4.

Mistral AI SAS (France), text recognition in uploaded documents. Receives access to the uploaded document for the duration of processing.

PostHog, usage analysis and quality assurance for AI features. Processes usage events, your email address and username, and the content of AI interactions including uploaded document text. Processing takes place on servers in the European Union.

Functional Software, Inc. (Sentry), error diagnostics. Processes error messages, technical diagnostic data, and your user identifier. Session recording is disabled.

Axiom, technical logging. Processes log data including user, course, and workspace identifiers. Processing takes place in the European Union (Frankfurt).

Stripe Payments Europe, Ltd. (Ireland), payment processing. Stripe acts as a controller in its own right within the meaning of article 4(7) GDPR. Your card details are never transmitted to us. Legal basis for the transfer: article 6(1)(b) GDPR.

When you use features that embed external content, your browser retrieves that content directly from the relevant provider, which means your IP address becomes known to it. This affects YouTube (Google Ireland Limited) for embedded videos, and the jsDelivr, unpkg, and Cloudflare content delivery networks for program libraries and fonts.

Beyond this, we disclose personal data only where we are legally obliged to do so, where it is necessary to establish, exercise, or defend legal claims, or in connection with a merger, sale, or transfer of our business. Any new owner would remain bound by this policy.

We will provide a copy of the agreed safeguards for any of the above transfers on request to hello@linity.one.

6. Transfers to Third Countries

The processing of your data takes place within the European Union.

Some of the providers named in section 5 are companies established in the United States. Insofar as access from a third country cannot be ruled out in individual cases, such transfers are based on standard contractual clauses adopted by the European Commission under article 46(2)(c) GDPR, or on an adequacy decision under article 45 GDPR where one exists.

7. Retention

Account data and the content you provide are retained for as long as your account exists and are deleted after your account is closed.

Coursework submissions, grades, and feedback are retained for as long as they are needed for the course concerned and for any objection procedure.

Accounting records, in particular invoices, are retained for ten years on the basis of commercial and tax law obligations. During that period their processing is restricted to fulfilling those obligations.

Server log data, error diagnostics, and analytics data are deleted once they are no longer required for the purposes described in section 3, or upon your objection.

If you would like your data deleted sooner, please contact us using the details in section 14.

8. Access to Your Device

We store information on your device and access it.

The following are strictly necessary for the features you have requested and are therefore used without consent pursuant to section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG): the session cookie that keeps you signed in, the storage of your language and interface settings, and a local cache (IndexedDB) holding your chat history in the workspace so that it remains available to you.

We also use cookies and comparable technologies for usage analysis. You can object to this at any time (see section 10).

You can delete information stored on your device at any time through your browser settings. Doing so may mean that you have to sign in again and that interface settings are reset.

9. Your Rights

You have the following rights in relation to your personal data:

The right of access to the personal data we hold about you (article 15 GDPR).

The right to rectification of inaccurate or incomplete data (article 16 GDPR).

The right to erasure (article 17 GDPR).

The right to restriction of processing (article 18 GDPR).

The right to data portability (article 20 GDPR).

The right to object to processing based on our legitimate interests (article 21 GDPR; see section 10).

The right to withdraw your consent at any time with effect for the future, where processing is based on consent. The lawfulness of processing carried out before the withdrawal is not affected. Withdrawing consent is as simple as giving it.

The right to obtain human intervention in relation to the assessment features, to express your point of view, and to contest the result (see section 4).

The right to lodge a complaint with a supervisory authority (article 77 GDPR) if you consider that the processing of your personal data infringes the GDPR. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart. You may also contact the supervisory authority of your place of residence or work.

To exercise any of these rights, please contact us using the details in section 14.

10. Your Right to Object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where that processing is based on article 6(1)(f) GDPR. This applies in particular to server log data, error diagnostics, and usage analysis.

If you object, we will no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves to establish, exercise, or defend legal claims.

Where your data is processed for direct marketing, you may object at any time without giving reasons.

An informal message to hello@linity.one is sufficient.

11. Data Security

We take appropriate technical and organisational measures to protect your data. These include encrypted transmission, restricting access to those people who need it for their work and who are bound by confidentiality obligations, and defined procedures for handling data breaches, including notifying you and the competent supervisory authority where we are legally required to do so.

Please note that no electronic transmission or storage can be entirely secure, so we cannot give an absolute guarantee.

12. Minors

Our platform is directed at universities and their members.

Where we base processing on your consent, that consent is valid under article 8(1) GDPR only if you have reached the age of 16. For younger users, consent must be given or authorised by the holder of parental responsibility.

If we learn that an account has been created without the required consent, we will delete it. Please notify us at hello@linity.one in such a case.

13. Changes to This Privacy Policy

We update this Privacy Policy when the legal position or our processing changes. The current version is always available on this page.

If we intend to process your data for a purpose other than the one for which it was collected, we will inform you separately in advance in accordance with article 13(3) GDPR.

Where processing is based on your consent, we will obtain that consent again before making the change.

This Privacy Policy was last updated on 27 July 2026.

14. Contact

For anything concerning your personal data and data protection, including requests for access, please contact us at:

Linity GmbH, Bildungscampus 1, 74076 Heilbronn, Germany, hello@linity.one.