Last updated: September 20, 2026· 2026.09
Information pursuant to Art. 13 and 14 GDPR. We process as little personal data as possible and use no analytics or advertising tracking services.
The controller is Alexander Leonhartsberger-Schrott, Dörferstrasse 26c, 6065 Thaur, Österreich ("Lithify", lithify.ai). Privacy enquiries: hello@kofel.io.
Lithify is operated as an invitation-only beta. For accounts we process your email address and an optional display name; sign-in happens via one-time login links or through your organisation's single sign-on (OpenID Connect). We further process technical session data (e.g. IP address, browser identification) for security and abuse prevention. Legal basis: Art. 6(1)(b) GDPR (performance of the usage agreement) and Art. 6(1)(f) GDPR (security of the service).
Data that you or your integrations feed into a workspace — feedback items, briefs, emails, attachments, customer and project data — is processed by us on your behalf: you are the controller, we are the processor. The basis is the Data Processing Agreement (DPA), concluded with your acceptance of these terms. Categories and safeguards are set out in its annexes, including the sub-processor list.
Operators of a workspace can publish intake forms (also embeddable on their own websites) and dedicated feedback addresses. If you submit feedback this way, we process the content you provide (message, optional email address for follow-ups, attachments), and — for submissions from mobile apps — technical device information (device model, OS and app version, locale, optional diagnostic logs). Purpose: processing your feedback on behalf of the workspace operator. Legal basis: Art. 6(1)(a) GDPR (your consent, given by submitting) and Art. 6(1)(b) GDPR in relation to the operator. The short-form notice for submitters is available at Submitter Notice.
Workspaces can connect feedback inboxes (IMAP) and error-tracking services (e.g. Sentry). For connected sources we process the received messages and events (sender, subject, content, attachments, user identifiers contained therein such as email addresses and usernames) on behalf of the workspace operator. Access credentials are stored encrypted.
Lithify uses AI providers (large language models) to triage and refine feedback, answer questions and draft changes. AI providers are configured per workspace; where a workspace uses its own provider and API key ("bring your own key"), processing at that provider takes place under the operator's direction and responsibility. Content sent to AI providers may include briefs, feedback texts, emails and workspace context. All AI invocations are logged (including input and output) for traceability. Legal basis: Art. 6(1)(b) GDPR (contractual performance for the workspace operator); details and safeguards in the DPA and the sub-processor list.
Uploaded attachments are stored in access-controlled object storage; download links are short-lived and signed. Storage location and provider are listed in the sub-processor list.
If you enable notifications, we process the technical data required for delivery (push subscription endpoint, public keys, user agent). Delivery to browsers on Google Chrome routes through Google's push service. Legal basis: Art. 6(1)(b) GDPR (requested feature).
This website loads all fonts and assets from our own servers — no requests to Google Fonts or other third-party CDNs. Public forms are protected against automated submissions with Cloudflare Turnstile; in doing so, Cloudflare, Inc. (USA) processes technical data of your request. Legal basis: Art. 6(1)(f) GDPR (abuse prevention).
The service is operated at Hetzner Online GmbH, Falkenstein, Deutschland (EU). A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider.
Recipients of personal data are the service providers named in the sub-processor list (hosting, bot protection, error tracking where enabled, object storage, email delivery, AI providers where not customer-designated).
Where service providers based outside the EU process personal data (in particular providers based in the United States), the transfer takes place only on one of the following bases:
The current overview of providers and the safeguards applied is available in the sub-processor list.
Account data is stored for as long as the account exists; after deletion it is removed in accordance with the DPA. Workspace content is retained for as long as the workspace exists, subject to the operator's deletion settings. Audit and AI logs are retained for the duration necessary for traceability of automated decisions, and deleted thereafter. Log data is kept for short periods only.
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object (Art. 21). Consents may be withdrawn at any time without giving reasons. To exercise these rights, a simple message to hello@kofel.io suffices; we respond within one month.
If you believe that the processing of your personal data infringes the GDPR, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is in particular the Österreichische Datenschutzbehörde, Wickenburggasse 8, 1080 Wien (https://www.dsb.at).
We adapt this privacy policy when processing changes. Changes are published on this page with an updated date; in the case of material changes we additionally notify account holders in the application.
Version 2026.09 — Terms of Use — Imprint