Who is responsible.
Thinkery AG, Holzmoosrütisteig 1b, c/o Yves Gugger, 8820 Wädenswil, Switzerland (CHE-257.640.994), is responsible for the processing described in this policy. Contact hello@leanctx.com about privacy, access or deletion requests.
This policy covers leanctx.com and explains relevant data flows in LeanCTX. When you operate the software for your organisation, you are responsible for the sources, permissions, recipients and retention you configure. Your AI host, model provider and connected services have their own privacy terms.
When you visit the website.
Our website, API and email services are hosted in Switzerland. Your browser sends technical connection data when requesting pages and assets, including an IP address, requested URL and browser information. Website infrastructure uses this data to deliver pages, diagnose failures and protect the service.
Fonts and site assets are served with the website. Documentation search uses Pagefind: its index is downloaded and searched in your browser. Search queries are not submitted to a hosted search provider.
Some pages request public community statistics or release information from LeanCTX services. As with other network requests, the destination receives technical connection information. Clicking an external link takes you to a separate service.
Cookies, storage and analytics.
Essential browser storage remembers settings such as your colour theme and cookie choice. Account pages use browser storage for your account session. These purposes are separate from optional analytics.
We operate PostHog on our own server for optional website analytics. Its browser script loads only after you accept analytics; declining leaves it unloaded. You can withdraw your choice using . Analytics permission expires after 12 months; recorded refusals remain in effect until changed.
Analytics processes page visits, predefined link and install-button clicks, scroll milestones, active reading-time milestones, broad technical error categories, browser/device information and pseudonymous identifiers stored in cookies or local storage. Error messages, stack traces and form contents are not collected by this instrumentation. Reading time excludes hidden pages and stops accumulating after 30 seconds without interaction. Session recordings require an additional, separate choice. These recordings reconstruct interactions on public pages; input values and page text are masked before transmission. We exclude account, sign-in, checkout and other sensitive routes. Network bodies, headers and console messages are not recorded. We do not use this integration for advertising.
With analytics consent, we collect the referring website or domain, limited UTM campaign tags, and your approximate country or continent. Our self-hosted server uses the request IP briefly for this location lookup, then discards it before event storage; analytics does not retain an exact location. We record clicks on approved public-page links, not form text. The internal exclusion preference lasts until cleared or for up to 12 months; an analytics QA marker lasts one browser session, and these operator controls are not visitor analytics.
We also derive hourly request counts from existing server access logs, grouped by public page, response status, broad browser/device class and source category. Those aggregate counters contain no IP addresses or visitor identifiers and are not counts of unique people. They are retained for 90 days in the aggregate source store and displayed separately from consented browser analytics.
New analytics is sent to our PostHog installation rather than PostHog Cloud. Data previously collected with consent by PostHog EU was processed in Frankfurt, Germany; see PostHog's privacy policy for that provider's practices. Withdrawing consent stops future browser collection; it does not itself delete data already collected. Contact us for a data request.
When you run LeanCTX locally.
The local runtime reads and shapes sources within its configured access boundaries. It can store configuration, cached content, search indices, knowledge, session state, logs and recovery artifacts on your machine. Those artifacts can contain source content or sensitive information; protect access to the machine and manage their retention.
Local processing does not mean that all subsequent use stays on your device. In context-only mode, LeanCTX returns prepared information to your connected host, which decides how to use it. When you route model or tool execution through the Engine, the configured provider or service receives the permitted request data. External sources, remote endpoints, organizational deployments and exports have their own data flows, access rules and retention settings.
The runtime can check for updates over the network. In the reviewed implementation, this can be disabled with update_check_disabled = true or LEAN_CTX_NO_UPDATE_CHECK=1. The destination still receives ordinary connection data when a check is made.
Runtime telemetry is controlled separately from website analytics. From version 3.11.0 it is on by default; earlier versions sent nothing unless you opted in. Setup asks whether to keep it on and stores your answer. Installations that declined before 3.11.0 see a one-time notice on their first interactive command. CI jobs never collect or send telemetry.
Telemetry is sent as cumulative daily totals, several times a day, to api.leanctx.com. It contains a random installation identifier that is not derived from your machine or account; the LeanCTX version, operating system, CPU architecture and install channel; the AI client family and setup profile; for each built-in tool, the daily number of calls, failures and latency buckets; session counts and uptime, error categories and version upgrades; and aggregate autopilot, sync and plan counts. It never contains prompts, code, file contents, file names, paths, commands, tool arguments or secrets, and it is not combined with website analytics or account data.
A random installation identifier can count as pseudonymous personal data. We use it only to count installations and how they use LeanCTX over time, and we delete telemetry records after 90 days. Show the exact payload with lean-ctx telemetry show. Turn telemetry off with lean-ctx telemetry off, DO_NOT_TRACK=1 or LEAN_CTX_TELEMETRY=off. Delete the records stored for your installation with lean-ctx telemetry delete-remote.
We process runtime telemetry under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the GDPR. It serves our legitimate interest in knowing how many installations actively use LeanCTX, which features and AI clients they rely on and where the software fails, so that we can maintain and improve it (Art. 6(1)(f) GDPR). We limit it to pseudonymous daily counts, do not use it to identify or profile individual people, store it on our servers in Switzerland and do not sell it or share it with third parties for their own purposes. You can object at any time (Art. 30 FADP, Art. 21 GDPR) by turning telemetry off, which stops all further sending, and lean-ctx telemetry delete-remote erases the records already stored.
Browser extensions, SDK applications and other integrations have different scopes. Review their version-specific permissions and configuration in the security documentation. We do not describe every integration as entirely offline or promise that filters detect every sensitive value.
Accounts, contact and payments.
If you create or use an account, the service processes information needed to authenticate you and operate it, such as your email address, credentials, account identifiers and the service data you choose to submit. Availability and data flows depend on the service and agreement you use; a local installation does not require an account.
When you email us, we use your address and message to respond and keep a record of the enquiry. Please include only information needed to resolve it. Avoid sending secrets or private source files unless a suitable transfer method has been agreed.
Payments use the checkout provider shown before payment. Records of existing voluntary contributions are also handled through the payment provider. Stripe processes payment details under its privacy policy. We may receive customer, transaction and billing records needed to administer the payment; card details are handled by the payment provider.
If you explicitly publish a recap, the selected information becomes public. It can identify you even where the underlying statistics are aggregate. Check the preview and sharing settings before publication.
Recipients and international processing.
Relevant recipients include our infrastructure and email providers, payment providers when used, and services you explicitly connect or visit. We operate the current PostHog analytics installation ourselves. Access may also be necessary for legal obligations or the protection of rights.
Earlier PostHog EU analytics was processed in Germany. External providers such as GitHub and Stripe operate internationally; consult their privacy notices for their locations and transfer arrangements. The privacy terms and data-processing arrangements for any separately agreed hosted service form part of that service's documentation.
Contact us for information about the recipients and international processing applicable to your enquiry or service.
Retention and your rights.
We retain personal data for the purpose for which it was collected and where required for legal, accounting, security or dispute-resolution obligations. Different categories have different retention needs; withdrawing analytics consent does not remove statutory billing records.
You control the data stored by your local installation and the retention of the services you configure. Removing the application alone should not be treated as proof that every local artifact, backup or external copy has been erased.
Subject to applicable law, you can request access to your personal data, correction, deletion, restriction or an available portable copy, and object to processing or withdraw consent. We may need to verify your identity and explain any applicable exception. Write to hello@leanctx.com; do not post personal data in a public issue.
You can also contact the Swiss Federal Data Protection and Information Commissioner or another competent data-protection authority. Where the GDPR applies, its corresponding rights and requirements also apply.
Policy updates.
We update this policy when relevant processing changes and show the revision date above. A hosted service may provide additional notices for its particular processing. Contact us if you need clarification about a version or a specific data flow.
Cookieless statistics and your objection.
For public website request statistics, we log only published page paths without query strings, response status and broad source, device and browser categories. The new statistical log contains no IP addresses, full user agents, cookies or full referrers. PostHog receives hourly aggregate counters, without visitor identifiers or fingerprints. These numbers count requests, not unique people.
You can disable server statistics in Cookie settings. Essential only also disables them for future requests. We store only the necessary refusal preference lctx_statistics=off in a cookie. Existing refusals are transferred on the next page visit; its initial request may already have been counted before that transfer. Do Not Track and Global Privacy Control are respected. Necessary security processing remains separate.
We also analyse daily totals of created accounts, email verifications and created checkout sessions. The database aggregates these before transfer; names, emails, customer identifiers and payment data are not sent to PostHog. Totals cover all access channels and may include test accounts. A checkout session is not a purchase. Reports use the last 90 days and do not link accounts to website visitors. Browser click paths and masked recordings still require the choices described above.
Let’s make it clear.
If you have a question about this document, we’re one email away.
hello@leanctx.com