Your data has lineage, not a product.
EFFECTIVE DATE · July 1, 2026
v1.0We log what we collect. We stop there. No advertising, no data sales, no cross-site tracking.
§ 01 · DATA WE COLLECT
Data We Collect
LIAW collects only what is necessary to operate the market data infrastructure. There are three categories.
Account Data
When you create an account, we collect your email address and the name you provide. If you sign in via a third-party OAuth provider, we receive only the email and display name that provider shares. Passwords, when used, are hashed with bcrypt and never stored in plaintext.
API Usage Data
Every authenticated API request is logged with: timestamp, endpoint path, asset symbols queried, HTTP status code, response latency, and your API key identifier (not the key secret). These logs power your usage dashboard, credit accounting, and rate-limit enforcement. We do not log request payloads or response bodies.
Device & Connection Data
We record your IP address and user-agent string on authentication events (sign-in, token issue, password reset) and on security anomaly detection. We do not record IP on routine API calls.
§ 02 · HOW WE USE YOUR DATA
How We Use Your Data
We use collected data to operate LIAW — nothing else. Specifically:
- Service delivery. Your API key, account record, and credit balance are required to authenticate requests and enforce plan limits.
- Usage reporting. Request logs are aggregated to produce the usage graphs in your dashboard. These aggregates are visible only to you and to LIAW staff for support.
- Billing. Credit consumption data is passed to our payment processor (Polar) to calculate invoices. See § 04 for third-party detail.
- Security. Connection metadata is used to detect credential-stuffing attempts, flag anomalous access patterns, and respond to incidents.
- Infrastructure improvement. Aggregate, anonymized latency and error-rate distributions guide capacity planning. No individual query patterns are analyzed for product decisions without explicit consent.
We do not use your data for advertising, behavioral profiling, or sale to third parties. We do not build cross-service tracking profiles.
§ 03 · DATA RETENTION
Data Retention
Retention periods are set to the minimum required for the stated purpose.
| Data Type | Retention |
|---|---|
| API request logs | 90 days, then permanently deleted |
| Account record | Duration of account + 30 days post-deletion |
| Authentication events | 12 months |
| Billing records | 7 years (statutory requirement) |
| Aggregate usage stats | Indefinite — anonymized, not linked to you |
When you delete your account, we initiate permanent deletion of your account record and API logs within 30 days. Billing records are retained for the statutory period regardless of account status.
§ 04 · THIRD PARTIES
Third Parties
LIAW engages a small set of infrastructure providers. We do not sell, license, or share personal data with any advertiser, data broker, or analytics vendor.
Polar — Payment Processing
Subscription billing and invoice management. Polar receives your email and plan data to generate invoices. Payment card data is handled exclusively by Polar and their downstream processor; LIAW never sees raw card numbers. Polar's privacy policy is at polar.sh/legal/privacy.
Neon — Database Hosting
Serverless Postgres hosting for the LIAW application database. Data resides in EU-West regions. Neon does not have access to your data beyond what is necessary for managed hosting.
OVH — Infrastructure Hosting
VPS and object storage for the ingestion plane, API servers, and backup artifacts. OVH processes data under its own DPA.
We require all subprocessors to maintain appropriate technical and organizational measures. If a subprocessor changes materially, this policy will be updated before the change takes effect.
§ 06 · YOUR RIGHTS
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. LIAW honors these requests regardless of legal obligation.
Access
Request a copy of the personal data we hold about you, including your API usage logs.
Rectification
Correct inaccurate account data. Email and name can be updated directly in account settings.
Erasure
Delete your account and associated data. Initiate this from account settings or by contacting us.
Portability
Contact us to request an export of your API usage logs in CSV or JSON format.
Restriction
Request that we stop processing your data for purposes other than service delivery.
Objection
Object to processing where we rely on legitimate interest. We will assess and respond within 30 days.
To exercise any right, contact us at the address in § 07. We will respond within 30 days. Identity verification may be required before we act on a request.
If you are located in the European Economic Area, you have the right to lodge a complaint with your local supervisory authority. If you are in California, you have rights under the CCPA including the right to know, delete, and opt-out of sale (we do not sell data).
§ 07 · CONTACT
Contact
Questions, requests, or concerns about this policy or your data should be directed to:
LIAW · Privacy
legal@liaw.devMaterial changes are communicated via email at least 14 days before they take effect.
Response time: 30 days or less.
This policy was last updated on July 1, 2026. Material changes will be communicated via the email address on your account at least 14 days before they take effect.
This policy is subject to revision.