Privacy Policy

Last updated: August 6, 2026

This policy explains what personal data Treezy Technologies Inc. ("litwindow", "we", "us") collects when you use litwindow.ai (the "Service"), why we collect it, where it is stored, who processes it, and what rights you have. We are the data controller for the personal data described here.

The short version: we collect the minimum needed to run your service and bill you. We never store your AI provider API keys. The work your agents produce stays on your dedicated machine. Platform data lives in the European Union. We do not sell personal data and we do not run advertising trackers.

1. Data we collect

Account data. When you sign in with Google we receive your email address, display name, and a stable account identifier. We use this to create and secure your account. We do not receive or store your Google password.

Billing data. Payments are processed by Stripe, Inc. Your card details go directly to Stripe and never touch our systems. We store your Stripe customer identifier, subscription status, plan, and invoice history references so the dashboard can show your billing state.

Instance and telemetry data. To operate your dedicated machine we store: your chosen subdomain, plan, machine identifiers and IP address, provisioning status and event history, heartbeat timestamps, disk and CPU utilisation, the state of each service container, backup timestamps, and whether the instance has completed first-owner setup.

API keys. Keys you submit for AI providers are transmitted over TLS directly to your dedicated machine and stored only there. Our platform retains a truncated SHA-256 fingerprint of each key (16 hex characters) so the dashboard can show which keys are configured. A fingerprint cannot be reversed into the key.

Agent content. Prompts, outputs, files, and databases created by your agents remain on your dedicated machine. We do not read, index, analyse, or train on this content. Platform operators access a machine only to deliver support you have requested or to investigate a security incident, and such access is disclosed to you.

Logs you view. When you open service logs in the dashboard, log lines stream from your machine to your browser through a short-lived authenticated channel. The platform does not retain them.

Support communications. If you email hello@litwindow.ai we keep the correspondence so we can help you and improve the Service.

Website data. The public website and dashboard use only the cookies and local storage needed for sign-in sessions. We do not use third party analytics or advertising cookies.

2. Why we process it (legal bases)

We process account, billing, instance, and telemetry data to perform our contract with you (GDPR Art. 6(1)(b)): creating your account, provisioning and monitoring your machine, and billing you. We process security logs and abuse signals under our legitimate interest in protecting the Service and other customers (Art. 6(1)(f)). We process tax and accounting records to comply with legal obligations (Art. 6(1)(c)). Where we ever rely on consent, we will ask for it explicitly and you can withdraw it at any time.

3. Where data lives

Your dedicated machine runs in Hetzner data centers in Germany or Finland. Platform data is stored in Google Cloud (Firestore, europe-west multi-region) in the EU. DNS and TLS termination are provided by Cloudflare, whose global network routes traffic to your machine. Backups created by your instance are stored on the instance itself.

4. Processors we use

We share personal data only with the processors needed to run the Service: Stripe, Inc. (payment processing, USA, under Standard Contractual Clauses and its own certifications); Google Cloud / Firebase (platform hosting, authentication, EU data residency for stored data); Hetzner Online GmbH (dedicated machines, Germany and Finland); and Cloudflare, Inc. (DNS, TLS, and traffic routing). Each processes data only under contract and only for the purposes described here. We will update this list if our processors change.

5. International transfers

Stored platform data and your machine stay in the EU. Some processors (Stripe, Cloudflare, Google) are US companies and may process limited operational data outside the EU; such transfers rely on the EU-US Data Privacy Framework or Standard Contractual Clauses.

6. Retention

Account data is kept while your account exists. Instance telemetry and event history are kept for the life of the instance and deleted within 30 days after deprovisioning. When an instance is deprovisioned, its machine and disks are deleted at Hetzner immediately and are not recoverable. Billing and tax records are retained as long as law requires (typically 7 years). Support correspondence is kept for up to 2 years after the last contact.

7. Security

All connections use TLS. Tenant machines sit behind default-deny firewalls with only web and SSH ports open. Commands from the platform to your machine are cryptographically signed and verified on the machine. Agent tokens are stored only as hashes. API keys follow the push-only custody model described above. Access to production systems is limited to the operator and protected by hardware-backed authentication.

8. Your rights

Subject to applicable law, you can: access the personal data we hold about you; ask us to correct or delete it; receive a copy in a portable format; object to or restrict certain processing; and withdraw consent where processing is based on consent. Email hello@litwindow.ai and we will respond within 30 days. If you are in the EU or UK you may also lodge a complaint with your local supervisory authority. If you are a California resident, the rights above cover the access, deletion, and non-discrimination rights of the CCPA; we do not sell or share personal information as those terms are defined there.

9. Children

The Service is not directed at children under 18 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

10. Changes

If we make material changes to this policy we will notify you by email or in the dashboard before they take effect. The "Last updated" date at the top reflects the current version.

Contact

Treezy Technologies Inc. · hello@litwindow.ai