Skip to content
LikelyAILikelyAI

Privacy policy

Last updated 12 August 2026

Draft pending legal review. This document describes how the service is built and intended to operate. It has not been reviewed by counsel, and items marked to be confirmed are unresolved. Do not treat it as a final agreement.

The short version

We keep as little as possible. Content you submit for analysis is deleted on a short retention window, one hour by default. We never use it to train our models. What we do keep is the structured result, the metadata needed to explain and reproduce it, and the billing record.

This section is a summary for orientation. The sections below are the operative detail.

Who we are

The service is operated by LikelyAI, legal entity name (to be confirmed), registered at registered address (to be confirmed). For privacy questions, contact privacy contact address (to be confirmed).

What we collect

  • Account identity. You sign in with GitHub or Google. We receive your name, email address, and avatar from that provider. We never receive or store a password, because there is no password to store.
  • Organisation and billing data. Organisation name, plan, members and their roles, and the billing identifiers created by our payment processor.
  • Content submitted for analysis. The text, image, or audio you send to the detection endpoint, held temporarily while it is analysed.
  • Detection results and metadata. The probability, confidence, classification, individual signals, model and calibration versions, and properties of the input relevant to interpreting the result such as length, dimensions, duration, or encoding.
  • Usage records. One immutable ledger entry per billable operation, recording the organisation, the detection, the modality, the credits charged, and the pricing version applied.
  • Technical logs. Request timing, status, and correlation identifiers. Logs never contain submitted content or a full API key.

Retention of submitted content

Content you submit is stored in object storage only for as long as the analysis needs it, then deleted. The default window is one hour and it is configurable for your organisation.

Two things outlive the content, and it is worth being explicit about them. The structured result stays available in your dashboard and through the API, because a detection you cannot look up again is not useful. The usage ledger entry stays because it is the billing record. If you delete a detection, the result is removed and the ledger entry remains.

Neither of those contains your content. Input properties are derived measurements, never an excerpt large enough to reconstruct what you sent.

We do not train on your content

Content you submit is not used to train, fine-tune, or evaluate our models. This is the default and there is no setting that changes it. If that ever changes it would require your explicit, separate, opt-in consent, and this document would be updated before it did.

Why we process it

  • To provide the service you asked for, which is analysing the content you send.
  • To authenticate you and secure your account and API keys.
  • To meter usage and bill you accurately.
  • To keep the service reliable, and to investigate abuse and misuse.
  • To meet legal and accounting obligations, which is why billing records are kept longer.

The legal basis under GDPR and the applicable retention period for each of these is still being determined with counsel (to be confirmed).

Who else processes it

We use a small number of subprocessors. Billing runs through Stripe, which receives the identifiers and amounts needed to charge you but not your submitted content. Hosting and object storage are provided by hosting and storage providers (to be confirmed). The processing location and the full subprocessor list are to be published here (to be confirmed).

We do not sell your data, and we do not share it for advertising.

How we protect it

  • Content is encrypted in transit.
  • API keys are stored as a secure hash, never in plaintext. A key is shown in full exactly once, at creation, and cannot be retrieved afterwards.
  • Submitted content and full API keys never appear in logs.
  • Access to production systems is limited and audited.

Your rights

Depending on where you live you may have the right to access, correct, export, or delete your personal data, to object to processing, and to complain to a supervisory authority. You can delete detections and revoke API keys yourself from the dashboard. For anything else, contact privacy contact address (to be confirmed).

One limit is worth stating plainly: we cannot return content you submitted, because after the retention window it no longer exists.

Changes

If we change this policy in a way that materially affects how we handle your data, we will say so before the change takes effect rather than after. The date at the top always reflects the current version.

See also the terms of service.