Legal · Privacy
What we collect, and what we don't.
Last updated June 2026. Plain-language summary first; the precise terms follow.
At a glance
- Account, audit, and integration data — no marketing trackers.
- Stored in Canada Central (Supabase, Montreal).
- No analytics SDKs. No selling data. Ever.
- PIPEDA compliant; Quebec Law 25 rights honoured.
The short version.
- limena collects your account info (email, name, workspace), the URLs you scan, and the scan results.
- We do not sell, rent, or share your data with third parties beyond what's required to run the service (Supabase, Vercel, Render).
- Your data lives in Canada (Supabase's Canada Central region). Scan workers run in US East — only the URL and scan output transit there.
- You can export or delete your workspace at any time.
- limena is compliant with PIPEDA (Canada's federal privacy law). Quebec Law 25 considerations are noted below.
What we collect.
Account data
- Email address (required for sign-in via Google / Microsoft OAuth)
- Display name (optional)
- Workspace name and tier
- OAuth provider tokens (Linear, Jira, GitHub) — encrypted at rest
- LLM provider key (Anthropic / OpenAI / Azure) — encrypted at rest, never returned to the browser
Audit data
- URLs you ask us to scan
- Scan results (findings, severity, screenshots at scan time, browser metadata)
- Annotations and user stories you write against findings
- Cadence configuration (when audits run automatically)
Operational data
- Standard server logs (IP, user agent, request paths) for security and debugging — retained 30 days
- Stripe billing data (last 4 of card, billing email, country) — handled by Stripe, we don't store full card numbers
What we don't collect.
- We don't run third-party analytics — no Google Analytics, no Mixpanel, no Segment.
- We don't use cookies for tracking. Auth cookies are session-only and first-party.
- We don't read or store the LLM responses your provider returns — only the user story text you save explicitly.
- We don't crawl pages other than the ones you ask us to scan.
Where your data lives.
Database (Supabase)
Postgres in Supabase's ca-central-1 region (Montreal). All structured account, workspace, audit, finding, annotation, and integration data sits here. Supabase carries SOC 2 Type II.
App and serverless functions (Vercel)
Static assets and edge functions served from Vercel's global CDN. Serverless functions execute in iad1 (US East) by default. We're evaluating a Canadian region for Enterprise customers. Vercel carries SOC 2 Type II and ISO 27001.
Scan worker (Render)
Playwright and axe scans run on a Render Background Worker in us-east. Only the URL of the page being scanned and the resulting scan data transit through this worker. No customer account data is ever sent to it.
How we use your data.
- To run the service you signed up for — accounts, audits, integrations, billing.
- To send transactional emails (sign-in, audit ready, regression detected). No marketing emails unless you opt in.
- To respond to support tickets and investigate incidents. See Operator access below for what this means in practice.
- To comply with legal obligations if we receive a valid request from Canadian law enforcement.
Operator access to your data.
limena's engineering team holds service-role database credentials. These credentials let our infrastructure run audits on your behalf, verify your session, and access your workspace data for support and incident response.
When we access your data:
- Responding to a support ticket you've sent us.
- Investigating an incident that may have affected your workspace (worker crash, database outage, suspicious-activity check).
- Billing reconciliation when our records don't match Stripe's.
- Valid legal requests from Canadian law enforcement.
What we don't do:
- Browse customer data out of curiosity, product research, or sales prep.
- Train language models on your audits, page content, screenshots, or findings.
- Share, sell, or rent your data to anyone outside limena.
If you have questions or concerns about how we've handled your workspace data, email ryan@shortux.com and we'll respond.
Your rights.
Under PIPEDA you have the right to:
- Access the data we hold about you — request it from ryan@shortux.com
- Correct inaccurate data — most account fields are editable in Settings
- Delete your account and data — also from Settings, or by emailing us
- Withdraw consent — by deleting your account
- File a complaint with the Office of the Privacy Commissioner of Canada
Quebec residents have additional rights under Law 25, including the right to data portability and the right to be informed of automated decision-making. limena does not use your data for automated decisions affecting you.
Data retention.
- Workspace data: retained for the life of your subscription.
- After cancellation: 30-day read-only grace period, then deletion of all customer data within 90 days.
- Server logs: 30 days.
- Stripe billing records: retained per Stripe's policies and Canadian tax law (typically 6 years).
Security.
- HTTPS-only for all traffic.
- OAuth tokens and LLM keys encrypted at rest using Supabase's pgsodium.
- Row-level security in the database — workspace members can only see their workspace's data.
- No customer payment data stored on limena infrastructure.
Sub-processors.
- Supabase — database and auth (Canada Central)
- Vercel — app hosting and serverless
- Render — scan worker
- Stripe — billing (when active)
- Anthropic / OpenAI / Azure OpenAI — only when you bring your own key. We don't have a contractual relationship with these providers on your behalf.
The full list with what each one processes, regions, and notification policy lives at limena.app/sub-processors. Customers on paid plans can subscribe to material-change notifications via legal@limena.app.
When you use limena from Claude.
limena offers an optional integration with Claude (Anthropic's AI assistant) via the Model Context Protocol — you can install limena as a Claude Code plugin or add it as a custom connector in claude.ai. When you choose to use it, the contents of API responses we send to Claude — including client names, audit URLs, finding details, and any text fields in your workspace that the tool call returns — transit Anthropic's infrastructure under Anthropic's terms. That's a separate processor relationship between you and Anthropic; limena passes data through during the time you're actively using Claude with us.
If a specific client engagement isn't compatible with Anthropic transit (sensitive industries, contractual restrictions), you have three options: (1) don't enable the Claude integration on that workspace, (2) mint a read-only OAuth token so Claude can never write or delete, or (3) use limena's worker-scheduled audits and the CI integration — both run server-to-server with no AI tool calls.
The Claude integration runs in your Claude session — it never executes on your or your client's website, collects no end-user data, and has no presence on a deployed page. It is not, in any sense, an "accessibility overlay."
Changes to this policy.
Material changes will be communicated by email and posted here with a new "last updated" date. Continued use after a change constitutes acceptance.
Contact.
Questions, requests, or complaints: ryan@shortux.com. Postal mail: limena, c/o Short UX, Ottawa, Ontario, Canada.
Built calmly, hosted in Canada.
The plumbing stays out of the way. The findings get fixed.