Privacy Policy
Last updated on 7 August 2026
Who is responsible, and how can you reach us?
The controller for the processing of personal data on lytris.com and in the Lytris application is:
- Controller
- Linity GmbH, Heilbronn, Germany
- Represented by
- Johannes Zimmer and Julian Bühlmaier, Managing Directors
- Commercial register
- Heilbronn Local Court, HRB 795872
- VAT identification number
- DE368689127
- Contact
- hello@lytris.com
Our Data Protection Officer
We have appointed an external Data Protection Officer and notified the supervisory authority. You may contact them directly and in confidence about anything concerning your data (Art. 38(4) GDPR). They are bound to secrecy, including towards us.
- Data Protection Officer
- Dr. Kilian Schmidt, Kertos GmbH
- Address
- Brienner Str. 41, 80333 Munich, Germany
- Phone
- +49 151 525 797 93
Competent supervisory authority
State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany. You may lodge a complaint there at any time (Art. 77 GDPR) without contacting us first.
Who does this policy apply to?
There are two ways to use Lytris, and which one applies decides who is responsible for which data. Please read the part that applies to you.
Private account
You sign up yourself, without a university. You either use Lytris free of charge with a daily message allowance, or on a paid subscription with a higher allowance. For everything that happens in such an account we are the controller under the GDPR, and this policy describes it in full.
Access through your university
You join a course through an invitation link from your university. Your account and the general features are still governed by this policy. For the teaching itself, however, something else applies:
If you use Lytris through your university, we process course content, submissions and assessments solely on its behalf, under a contract pursuant to Art. 28 GDPR. Your university is the controller in that respect and informs you separately. You may still exercise your rights against us; we will pass your request on.
Where data that does not come from you originates
Art. 14(2)(f) GDPR requires us to name the source. With university access we receive:
- your course membership and your role in the course, from your university or via the invitation link,
- your identity data from the sign-in process, if you sign in with a university account or a third-party provider,
- course material and assignments uploaded by teaching staff, which may mention you.
Do you have to give us this data?
Under Art. 13(2)(e) GDPR: an email address and an account are required in order to use Lytris; without them we cannot give you access or store a history. Payment data is required only if you take out a paid subscription. Everything else you enter or upload is voluntary. Not providing it puts you at no disadvantage; only the feature in question will be unavailable.
What rights do you have?
These rights are yours, without having to give a reason and free of charge. A short email is enough.
- Access (Art. 15). You learn which data we process about you and receive a copy.
- Rectification (Art. 16). We correct inaccurate data and complete incomplete data.
- Erasure (Art. 17). We delete your data unless a statutory retention obligation prevents it.
- Restriction (Art. 18). We freeze processing instead of deleting, for example while a correction is being checked.
- Data portability (Art. 20). You receive your data in a common, machine-readable format.
- Withdrawal of consent (Art. 7(3)). With effect for the future, without making the processing up to that point unlawful.
- Complaint (Art. 77). With any supervisory authority, in particular the one named above.
Right to object (Art. 21 GDPR). Where we process data on the basis of a legitimate interest, you may object at any time on grounds relating to your particular situation. This concerns our product analytics in particular. We will then stop the processing unless we demonstrate compelling legitimate grounds that override your interests.
To exercise a right, write to compliance@lytris.com or directly to our Data Protection Officer at data-privacy@kertos.io. We respond within one month (Art. 12(3) GDPR).
What data, for what purpose, on what basis, for how long?
| Data | Purpose | Legal basis | Duration |
|---|---|---|---|
| Account data: name, email address, sign-in identifier, language setting | Running your account, signing you in, communicating with you | Art. 6(1)(b) (contract) | For as long as your account exists |
| Content you enter or upload: conversations, documents, notes, workspaces | Providing the learning and AI features | Art. 6(1)(b) (contract) | Until you delete it or request its deletion |
| Usage data: areas visited, interactions, device type, browser | Keeping the service running, finding faults, improving the product | Art. 6(1)(f) (legitimate interest) | For as long as needed for the analysis, at most for the life of your account |
| Payment and invoicing data on a paid subscription | Billing and accounting | Art. 6(1)(b) and (c) (legal obligation) | Invoicing records for ten years (sec. 147 AO, sec. 257 HGB) |
| Error and operational logs, truncated IP addresses | Security, stability, abuse prevention | Art. 6(1)(f) (legitimate interest) | Short term, within the retention of our logging providers |
| Your messages to our support team | Answering your request and keeping a record of it | Art. 6(1)(b) and (f) | Until the matter is resolved, then within statutory retention periods |
[university access only] If you use Lytris through your university, course-related data is added that we process solely on its behalf. Your university is the controller for it, see Who does this policy apply to?.
Where we state a criterion instead of a fixed period, that is deliberate: Art. 13(2)(a) GDPR expressly allows criteria, and we will not promise you a deadline our systems do not keep.
If you delete your account
You can delete your account yourself in the settings. That removes your user account and your sign-in data. Content attached to it we delete on your request under Art. 17 GDPR; write to compliance@lytris.com for that. With university access, your university decides about course content, submissions and assessments.
How do the AI features work?
When you ask a question or upload a document, we pass the relevant content to a language model that produces the answer. We do not run these models ourselves; we obtain them from providers acting as our processors:
- Google Cloud EMEA Limited (Ireland), Vertex AI. This covers the Gemini models as well as models from Anthropic, Qwen and Moonshot AI made available through the same service.
- Mistral AI SAS (France). Language models that generate answers, and text recognition in uploaded documents.
Processing in the EU. For these features your content is processed in data centres within the European Union.
No training on your content. Our contracts with these providers prohibit the use of your content to train models.
Automated decisions
In a private account we make no decisions about you based solely on automated processing that produce legal effects concerning you (Art. 22 GDPR). Suggestions, explanations and hints from the AI are suggestions.
Who gets to see your data?
Within Linity, only those people have access who need it for their work. Beyond that we use service providers acting as processors on our instructions (Art. 28 GDPR). We do not sell data and do not pass it on for advertising.
- Convex, Inc.
- Application database. Processing in the Dublin data centre, Ireland. Privacy policy
- Google Cloud EMEA Limited
- Running the application, file storage and Vertex AI. Processing in the EU. Privacy policy
- Mistral AI SAS
- Language models that generate answers, and text recognition in uploaded documents. France. Privacy policy
- Clerk, Inc.
- Registration, sign-in and session management, including the subprocessors Clerk uses, among them Svix for the signed delivery of technical events. Privacy policy
- PostHog
- Product analytics. Processing on the provider EU infrastructure. Privacy policy
- Sentry
- Capturing technical errors. Processing in the EU. Privacy policy
- Axiom
- Operational logs. Processing in the EU. Privacy policy
Payments. Paid subscriptions are handled through Stripe. You enter your payment details directly with Stripe; we neither see nor store full card details. Stripe processes that data as its own controller to meet its own legal obligations. Stripe privacy policy
Beyond this we disclose data only where we are legally obliged to, or where it is necessary to establish or defend legal claims.
Where is your data processed?
Your content stays in the EU. The database, the file storage, the AI processing, the product analytics, the error capture and our operational logs sit in data centres within the European Union, mainly in Ireland, the Netherlands and France.
Individual providers for sign-in and payments belong to corporate groups established outside the European Union. Where personal data is transferred to a third country as a result, we rely on the European Commission Standard Contractual Clauses under Art. 46(2)(c) GDPR, supplemented by additional technical and organisational measures. You can obtain a copy of the safeguards from data-privacy@kertos.io.
How do we protect your data?
We take technical and organisational measures under Art. 32 GDPR and review them regularly. In particular:
- encryption of all connections via TLS and encryption of data at rest,
- access limited to people who need it for their work, with two-factor authentication,
- non-public file storage reachable only through short-lived, signed references,
- logging of security-relevant events and a defined process for handling security incidents,
- an information security management system and regular staff training.
No system is completely secure. If you notice a weakness, please write to hello@lytris.com.
Minimum age
Lytris is aimed at students and other adults. You may create a private account if you are at least 16 years old. If you are younger, consent or authorisation from your parent or guardian is required (Art. 8 GDPR).
If we learn that an account was created contrary to this, we delete it. Please report such cases to hello@lytris.com.
Links, embedded content and social media
Links you follow
We link to services we do not operate: our Discord community, our board for feedback and feature requests on Featurebase, and our profiles on LinkedIn and Instagram. As long as you do not click, no data flows there. Once you click, the privacy policy of that provider applies.
Content loaded when you open a feature
Some features load content from third-party servers as soon as you open them. The provider necessarily receives your IP address and details about your browser:
- YouTube. Explanatory videos in visualisations are embedded from YouTube. The provider is Google Ireland Limited.
- Libraries from content delivery networks. Running calculation examples in the browser, rendering mathematical formulas and interactive visualisations load libraries from jsDelivr and unpkg.
The legal basis is Art. 6(1)(b) and (f) GDPR: without this content the feature you opened cannot be displayed. We are working towards serving these libraries ourselves.
Changes to this policy
We update this policy when the application, the providers we use or the legal situation change. The version published here is the one that applies; the date of the last change is shown at the top of the page. For material changes we notify you additionally, in the application or by email.
This privacy policy is available in German and English. In case of discrepancies, the German version prevails.