Privacy Policy
Last updated: 2026-09-09 · Version 2
This notice covers LogiShell websites, account services and clients. Operator details: LogiShell LTD is the proposed company name in England and Wales. Company registration is in progress; the registered number and office address appear here as soon as Companies House issues them. For privacy questions and rights requests, contact hello@logishell.com.
1. Our role
We act as controller for account administration, website enquiries, service security, billing and our own product operations. Where an organisation directs how personal data in its workspace is processed, it may be the controller and LogiShell may act as its processor. Contact your workspace administrator for those instructions and contact us to discuss a data processing agreement before entrusting data that requires one. This notice is not a signed data processing agreement.
2. Information and sources
| Information | Source and purpose |
|---|---|
| Account details | Email, name, avatar, identity-provider identifiers and connected wallet addresses supplied by you or your chosen sign-in provider; used to authenticate and manage your account |
| Workspace content | Files, graphs, messages, prompts, outputs, attachments and related metadata that you upload, sync, share or submit for processing |
| Connected resources | Device identifiers, presence, permissions, integration configuration and credentials needed for features you enable |
| Operational records | IP address, browser/client information, timestamps, request and security records needed to deliver and protect the Service |
| Usage and billing | Model/resource usage, charges, transaction references, invoices and payment status needed for billing, limits and accounting |
| Communications | Support requests, feedback, and the email address and preferences you submit for product updates |
| Optional telemetry | Allowlisted diagnostic and feature-use events when you enable the corresponding setting; these event fields exclude file, prompt and terminal contents |
Local resources are not all automatically uploaded merely because you install a client. What leaves a device depends on the sync, assistant, sharing and execution features you use. Do not put secrets or unrelated personal data in feedback or support messages. Network requests may carry technical identifiers even when a telemetry event contains no content; “content-free” does not mean every part of processing is anonymous.
3. Purposes and legal bases
Where UK GDPR or EU GDPR applies, we rely on:
- Contract: creating and operating accounts, carrying out requested processing, delivering paid services and responding to service requests.
- Legitimate interests: protecting accounts and infrastructure, preventing abuse, maintaining reliability, handling business enquiries and establishing or defending claims. We consider the impact on individuals; you can object to processing on this basis.
- Legal obligations: accounting, tax, valid legal demands and other applicable duties.
- Consent: optional diagnostics, optional product analytics, and product-update emails you request. These choices are separate from accepting the Terms. Refusing or withdrawing them does not prevent core service use.
Optional diagnostics and analytics start off for new choices in every region. Change them in Settings → Privacy. Withdrawal affects future consent-based processing and does not invalidate earlier lawful processing. Essential security and billing records continue on their separate legal bases. Ask us to stop product-update emails at hello@logishell.com; accepting the Terms alone does not subscribe you.
4. Who receives information
We disclose information only as needed for the relevant purpose:
- Infrastructure providers, including Cloudflare, deliver hosting, edge services, storage, network security, transactional email and real-time communications used by the Service.
- The AI provider selected for your request, such as Anthropic, OpenAI or Google, receives the prompts, context and attachments submitted to that model. Local models and user-configured endpoints have different processing paths. Review the provider and endpoint before sending confidential data; provider retention and policies depend on that provider and your account arrangement.
- Identity providers such as Google or GitHub process sign-in requests when you choose them. Connected services and plugins receive information within the access you grant.
- Payment providers identified at checkout process payment information where paid features are offered. Wallet connections and public networks receive information needed for the wallet functions you use.
- Workspace members, administrators and link recipients receive information you share with them. Publicly published information can be copied by others.
- Authorised support personnel, professional advisers and authorities may receive information where necessary for support, compliance, security or legal claims. In a business reorganisation, information may transfer subject to applicable data-protection requirements.
We do not sell personal data or use advertising trackers on the landing page. The list above describes recipients by function; it is not a representation that every optional integration is a contracted subprocessor. Business customers can request details of the providers and contractual arrangements relevant to their deployment at hello@logishell.com.
5. International processing
Infrastructure and external providers may process data outside your country, including in the United States. The applicable locations depend on the feature and provider selected. Where regulated transfers require safeguards, the relevant transfer must be covered by an applicable adequacy decision or contractual safeguards such as EU Standard Contractual Clauses and the UK Addendum or IDTA. Contact hello@logishell.com for the safeguards and a copy of relevant information for your deployment. This notice does not itself establish a transfer agreement or promise that data remains in a single country.
6. Storage, encryption and security
Access controls and encryption protect information, but no system can guarantee absolute security. Workspace access restrictions are different from end-to-end encryption. Only features explicitly identified as client-side encrypted provide that specific property. We may still process associated ownership, size, timestamps and access metadata. We cannot recover encryption keys we do not hold. Once you decrypt content and send it to a provider or recipient, their processing applies.
Keep credentials and recovery methods secure. Contact hello@logishell.com about a suspected security issue. Do not send passwords or recovery phrases in a report.
7. Retention and deletion
We keep personal data only as needed for its purpose and applicable obligations. Retention depends on the record and feature:
| Category | Retention criteria |
|---|---|
| Account and hosted content | While your account or requested workspace storage is active; following a deletion request, subject to shared-workspace obligations, recovery copies and legal exceptions |
| Security and operational records | For the period needed to investigate incidents, prevent abuse and maintain reliability; longer where a specific incident or legal claim requires preservation |
| Optional telemetry and consent records | Telemetry for the relevant diagnostic or measurement purpose; consent and withdrawal records as needed to demonstrate and honour your choice |
| Billing and accounting | For applicable statutory accounting/tax periods and resolution of payment disputes |
| Support and updates | Until the enquiry is resolved or subscription withdrawn, with limited records where needed to honour opt-outs or resolve disputes |
| Device storage | Until expiry, replacement or removal by you as explained in the Cookie Policy |
A deletion request is not a promise that every system or backup is erased instantly. We will explain any lawful retention exception and applicable timing when handling your request. Local copies on your devices and copies retained by independent recipients require separate removal. Public blockchain records, if you use those functions, cannot be erased by us.
8. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, object to legitimate-interest processing, and withdraw consent. Email hello@logishell.com from your account address where possible, stating what you need. We may request proportionate verification and clarification. We normally respond within one month under UK/EU GDPR; if a lawful extension applies, we will explain it within that period. Requests are normally free.
You may complain to the UK Information Commissioner or your local data-protection authority, including in the EEA. You do not need to contact us first. For organisational content, we may refer the request to the controller and assist them. We cannot export readable content where we possess only ciphertext and no decryption key.
9. Cookies and similar technologies
Read our Cookie Policy for session/security cookies, browser storage, durations and controls. Optional analytics consent is separate from essential sign-in storage. Clearing browser storage does not withdraw the server-side telemetry choice for an account: change that choice in Settings → Privacy.
10. Children and automated decisions
The Service is intended for people aged 16 or older, subject to any higher local eligibility requirements. Contact us if you believe a child has provided data contrary to these requirements. The Service provides automation tools; customers are responsible for the decisions they configure and their duties to affected individuals. Contact us for information or to challenge an account restriction affecting you.
11. Changes and contact
We publish dated versions and bring material changes to account holders’ attention through the Service or other appropriate communication. A new consent-based purpose requires a new choice before that processing starts. Contact: hello@logishell.com.