Privacy notice
Accillion AS · Last updated 2 July 2026
The short version. Lippa's core workspace is hosted on EU infrastructure by default. Some features, including selected model providers and video generation, may process data outside the EEA and are identified in the product or in this notice. We do not use your content to train Lippa models, we do not sell your data, and we use provider API terms and settings designed so that your Lippa content is not used to train third-party models. You can export your workspace data and delete your account, subject to limited retention for security, abuse prevention, accounting, backups and legal obligations. We collect what Lippa needs to run, protect and improve the service.
1. Who is responsible
Accillion AS, a company registered in Norway, is the data controller for Lippa and for this website. Contact: hello@lippa.ai. The Norwegian Data Protection Authority (Datatilsynet) is our supervisory authority.
Our role. For individual users, Accillion AS is generally the controller for account, product, security, billing-support, safety and analytics processing. For future organisation workspaces, we may act as processor for workspace content under a separate data processing agreement, while remaining controller for account administration, billing, security, abuse prevention and legal compliance. If you publish a generated website or shared content, you are responsible for what you publish; Lippa remains responsible for operating the hosting, security and notice-and-action processes. Business customers that need a data processing agreement can request one at hello@lippa.ai.
2. What we collect
- Account data: email address, password hash or Google sign-in identifier, plan and settings.
- Your content: conversations, uploaded files, memory items, artifacts, generated media, and imports you choose to bring in via the browser extension.
- Device and technical data: IP address, device and browser information, session identifiers, security logs, crash and error reports, and approximate location derived from IP where needed for security, fraud prevention, localisation or compliance.
- AI routing and safety metadata: selected model and provider, request timestamps, token and credit usage, safety classifications, blocked requests, abuse reports, moderation decisions, and content hashes (fingerprints) of reported or blocked material.
- Publishing data: shared links, generated websites, custom domains, page assets, public URLs and publication settings.
- Age and eligibility data: age confirmations and feature-access status where required for media generation or other restricted features.
- Billing data: payments are processed by Stripe. We never see or store your full card details.
- Correspondence: support and contact emails, and mailing-list signups (email plus the interests you tick).
The browser extension only imports content from supported services or pages when you enable it and choose to connect or capture that content. It does not continuously upload your browsing history, we do not use it to read unrelated browsing activity, and we do not sell extension data.
3. How your content is processed by AI models
- When you send a message, upload a file, generate media, review a document or use another AI feature, the prompt, files and relevant context are sent to the model provider selected by you or by Lippa's Auto routing, solely to produce the requested response. That is processing on your instruction, not training.
- We do not use your content to train Lippa models. For third-party providers, we use API terms, settings and contractual arrangements designed so that prompts, files, context and outputs submitted through Lippa are processed only to provide the requested feature and are not used to train the provider's models. If a feature or integration ever carries different terms, we disclose that where you enable it.
- Your memory layer is stored in Lippa, on EU infrastructure, and is never shared between accounts. Memory items are only sent to a provider when they are selected as relevant context for your own request.
- Some model providers may process data outside the EEA; the model picker identifies each model's provider. Video generation currently uses Google's Veo and may be processed in the United States; this is shown at the point of use and is optional per request. Finished clips are stored in your Lippa library on EU infrastructure.
- We may use automated systems to scan prompts, uploads, generated media, shared links and public pages for security, abuse, child-safety, non-consensual-imagery, fraud, malware, impersonation and other prohibited-content risks. Flagged items may be reviewed by trained staff where necessary. We do not generally monitor private workspace content, but we may review content when it is reported, flagged, required by law, necessary for security, or needed to enforce our terms. Where content is reported or blocked for a safety reason, we may generate and retain a hash (a fingerprint) of that content and use it to detect and prevent re-submission of the same material, and, for the most serious categories, to support reporting to the relevant authorities.
4. Why we process, and on what legal basis
- Running the service you signed up for, including AI processing, storage and sync (contract, GDPR art. 6(1)(b)).
- Security, abuse prevention and safety review (legitimate interest, art. 6(1)(f), and legal obligation where reporting duties apply).
- Billing and accounting (contract and legal obligation).
- Mailing list and marketing emails (consent, art. 6(1)(a), withdrawable any time via the unsubscribe link). Service, security and billing notices are part of providing the service and do not require marketing consent.
- Aggregate, de-identified product analytics (legitimate interest). We do not build advertising profiles and we use no third-party ad trackers.
Where we rely on legitimate interests, those interests are operating and securing Lippa, preventing abuse and fraud, enforcing our terms, maintaining reliability, understanding aggregate feature use, and protecting users and third parties. You may object to processing based on legitimate interests; we stop unless we have compelling legitimate grounds or legal claims.
5. Where your data lives, and for how long
- Workspace data is stored and processed on EU infrastructure, with data residency in the EU as the default. Exceptions are described in section 3.
- Account and workspace content is kept while your account is active. Deleted content is removed from live systems promptly and from backups on a rolling cycle, typically within 30 to 90 days.
- Billing, invoice and accounting records are kept for the periods required by Norwegian accounting and tax law.
- Security logs are normally kept up to 12 months, longer only where needed for an investigation, fraud prevention or legal claims.
- Abuse, safety and moderation records are kept as long as needed to enforce our terms, protect users and comply with legal duties, with longer retention for severe abuse, child-safety, fraud, security or legal matters.
- Mailing-list data is kept until you unsubscribe or we delete inactive lists.
- When you close your account, you get a window to export everything; after that, your data is deleted, except the minimum we must keep for the purposes above.
6. Who we share data with
Nobody buys your data. We use processors and service providers to run Lippa:
- AI model providers (currently including OpenAI, Anthropic, Google, Mistral, DeepSeek and Zhipu), receiving only the prompts, files, context and outputs needed for your requests, under the no-training arrangements described in section 3. The current roster is always visible in the model picker;
- Google Vertex AI (Veo) for video generation, where you choose it (US, labelled at the point of use);
- Stripe for payment processing and subscription billing;
- EU-based cloud infrastructure and Cloudflare for hosting, storage, security and delivery;
- transactional email, support and mailing-list providers;
- logging and error-monitoring tools used to operate the service, without third-party advertising profiles.
Where a provider processes personal data outside the EEA, we rely on recognised transfer mechanisms, an adequacy decision or the EU standard contractual clauses, and where required we assess the transfer risk and apply supplementary technical, contractual or organisational measures. Providers based in countries without an adequacy decision are identified as such in the model picker. We disclose data to authorities only where the law requires it or where necessary to protect users or others, and we tell you when we lawfully can.
7. Cookies and local storage
This website uses only what it needs: strictly necessary cookies, and a small preference cookie that remembers your display currency on the pricing page. No advertising cookies, no cross-site tracking. The app uses functional cookies, local storage and similar technologies for your session and preferences. If we later add analytics or marketing cookies, we will ask for consent where required.
8. Your rights
Under the GDPR you can access, correct, delete and export your data, restrict or object to certain processing, object to direct marketing at any time, and withdraw consent at any time. Export and deletion are built into the product; for anything else, write to hello@lippa.ai and we respond within a month. You can also complain to Datatilsynet or your local supervisory authority.
One honest note on deletion: removing a memory item or conversation removes it from future retrieval once deletion is processed, but outputs you already exported or published may remain outside Lippa's control.
9. Children
Lippa accounts require a minimum age of 13. Image generation requires 16+, and video generation, realistic depictions of real people and public publishing of AI media require 18+. We do not knowingly allow users below the applicable age threshold to use the relevant feature. If you believe a child has created an account or used a restricted feature in breach of these rules, contact us and we will take appropriate action.
10. Changes
If this notice changes in a way that matters, we tell you in the product or by email before it takes effect. The latest version always lives at this address.
Questions about privacy: hello@lippa.ai