Skip to the document

Privacy policy

This policy explains what Lymi receives, why it uses it, who helps provide the service, and the choices you have.

Last updated 16 September 2026

Who is responsible

Lymi is provided by Krambertech OÜ, an Estonian private limited company. In this policy, “Lymi”, “we” and “us” refer to Krambertech OÜ. Contact us at hello@lymi.app.

Data Lymi receives

Beta access requests

If you request access, we store your email address, where on the site you made the request, and when you made it. Requesting access does not create an account.

Account and sign-in data

Google sign-in gives Lymi your name, email address, profile image if available, and identifiers needed to connect the Google account to Lymi. We also keep session records, which can include an IP address, browser information and sign-in tokens.

If you sign in with an email address and a password, we store the address and a hash of the password, never the password itself. We also store short-lived records for confirming an address and resetting a password, and counts of recent sign-in, sign-up, resend and reset attempts by address and IP address, so those requests can be rate limited.

Learning data

We store the decks and cards you create or join. A card can include a term, meaning, pronunciation, example, notes, tags, language, source, learning direction and generated audio. We also store archive state, review history, scheduling state, goals, streaks, time zone, preferences and an activity record of changes.

Review history is append-only while the account exists so the schedule and learning record stay honest. Undo creates a separate record rather than rewriting the original review.

API and connected-app data

If you create an API key, we store the key record, its name, permissions, usage counters and dates. If you connect an app through MCP, we store the app identity, the permissions you grant, consent records and access or refresh tokens. Lymi records whether a change came from you, an API key, a connected app, AI or the system.

A connected assistant may read lesson material in the conversation where you use it. Lymi does not receive that raw lesson material unless the assistant sends it in a card field such as the term, meaning, example, notes or source. The assistant provider handles the conversation under its own terms and privacy policy.

Audio, reminders and account email

When pronunciation audio is first requested, Lymi sends the card term and language to a speech provider. It stores the resulting audio so it can be reused. We do not send the rest of the card for speech generation.

If you enable review reminders, we store a push endpoint, browser-generated encryption keys, your reminder time and time zone, and delivery state. Reminder notifications contain a due-card count, not card text.

When Lymi sends an account email, Cloudflare Email Service receives the recipient address, sender, subject and message body. Cloudflare handles delivery, bounces and suppression of addresses that should not receive another message.

Service data

Our hosting provider processes request metadata, security signals, timings and error logs needed to operate and protect Lymi. Query strings are redacted from Worker logs. We avoid putting card content, email addresses, access tokens and other private content in logs.

Why we use data

  • To provide accounts, decks, cards, review scheduling, audio, reminders, account email, API access and connected apps.
  • To authenticate requests, enforce permissions, prevent abuse and investigate failures.
  • To answer support requests and act on privacy requests.
  • To manage private-beta access and email people who asked to hear when a place opens.
  • To meet legal obligations and protect the rights and safety of Lymi and its users.

Depending on the activity and applicable law, we process data to perform our agreement with you, with your consent, for legitimate interests such as security and service reliability, or to meet a legal obligation. You can withdraw optional consent, such as reminders, at any time.

Service providers and other recipients

  • Cloudflare provides the website, application, database, object storage, session storage, network protection, operational logs and transactional email delivery.
  • Google provides Google sign-in and may provide speech generation when configured as the fallback provider.
  • OpenAI may provide speech generation. A configured Cloudflare AI Gateway may relay that request.
  • Your connected apps receive only the data allowed by the permissions you approve. Disconnecting an app stops future access but does not erase data the app already received.
  • Your browser’s push service receives an encrypted reminder when you enable notifications.

These providers may process data in countries outside Estonia or the European Economic Area. Where required, we rely on the transfer safeguards made available for the relevant service.

How long we keep data

  • Beta access requests stay until you ask us to remove them or the beta list is retired.
  • Account and learning data stay while your account is active and are removed when we complete an account-deletion request, except where law requires a longer period.
  • Sessions normally expire after 30 days and may be refreshed while you remain active.
  • API keys stay until you revoke them or they expire. Connected-app tokens and consent stay until expiry, revocation, disconnection or account deletion.
  • Push subscriptions stay until you disable reminders, the push service reports the subscription expired, or the account is deleted.
  • Generated audio stays with the related card or account until it is removed under the service’s storage lifecycle.
  • Cloudflare keeps operational and email-delivery logs under the active service configuration. Lymi does not maintain a separate long-term copy of those logs.

Your choices and rights

You can edit card content and settings, archive and restore cards or decks, revoke API keys, disconnect apps, and turn reminders off in Lymi. Archive is reversible and is not deletion.

Account-wide access, export, correction and deletion are not self-service yet. Email hello@lymi.app from your account address and describe what you need. We may ask you to verify your identity before acting. We will respond as required by applicable data-protection law. You may also complain to the Estonian Data Protection Inspectorate or your local supervisory authority.

Cookies and local storage

Lymi uses an authentication cookie to keep you signed in. The public site and app also use local browser storage for preferences and offline product behavior. We do not use advertising cookies.

Security and children

We use access controls, encrypted transport and provider security controls to protect data, but no online service can guarantee absolute security. Do not share API keys, connection tokens or other credentials. Lymi is not directed to children who cannot lawfully consent to this processing.

Changes and contact

We may update this policy when Lymi or the law changes. We will update the date above and give additional notice when a change materially affects your rights. Questions and privacy requests can be sent to hello@lymi.app.