Privacy Policy
What Lathe keeps about you as an account holder, why, for how long, and who else sees it. What you store inside your instance is covered by the Data Processing Agreement, under which we act on your instructions only.
1. Who is responsible
Lathe is the controller for the data described here. Contact for anything in this policy: support@lathe.live.
2. What we collect and why
- Email address. Signing in creates the account; the address is your identity and where sign-in links and service notices go. Needed to provide the service.
- Billing details. Your name, and optionally a company name, tax id, address, country and phone number, as entered on the account page. They appear on invoices and receipts. Needed for the contract and for tax law.
- Payment. Card payments are taken by our payment provider on its own page. We never see the card number; we keep the provider's token for that card, its expiry and the last four digits, so renewals can be charged and you can recognise the card. Needed to bill you monthly.
- Your instances. Names, tags, engine settings, IP allowlists, API keys (stored as hashes), webhook addresses and OAuth applications you create, and a log of what happened on the account: sign-ins, purchases, jobs, and actions taken by you, by your API keys or by us. Needed to run the service and to answer "what happened" - yours and ours.
- Technical data. Your IP address and browser details in the web server's logs, and short-lived counters keyed by IP address and by email that limit sign-in attempts, API calls and free trials. Our legitimate interest in keeping the service up and free of abuse.
- Visits and where you came from. To count visitors and see which pages lead to sign-ups we keep, per page view, a hash of your address and browser under a key that changes daily and is then discarded, so one day's visitors cannot be matched with the next's or with you; and, when you sign up, the page you first landed on, the site that sent you and any campaign tags in the address. Our legitimate interest in knowing whether the site works. No third party is involved and no cookie is set for it. On the public site and in the console we also run Umami, an open-source web analytics program, on our own server: for each page view it keeps the page, the site that sent you, your country, browser type, operating system and screen size, again under a daily hash of your address and browser; and for a few buttons the fact that they were pressed, such as which plan was chosen or that a sign-in link was asked for, never what you typed. It sets no cookie, honours your browser's Do Not Track setting, and nothing it collects leaves our servers.
- The waiting list. When we are out of machines, an email address you leave to be told when there is room, with the time you left it; dropped once you have been told or when you ask. Nothing else is sent to it.
- Support email. What you write to us, kept in our mailbox for as long as we need it to help you.
Nothing else. There is no advertising, no tracking pixel and no third-party script on any page; the one analytics script is ours and talks only to our own server. Every email we send is about your account; there is no newsletter.
3. Cookies
Four, all set by us and none for tracking: a session cookie that keeps you signed in for 30 days, a sign-in cookie that ties a sign-in code to the browser that asked for it for 15 minutes, a one-minute cookie that carries a confirmation message from one page to the next, and a cookie that remembers the style and light-or-dark mode you chose for a year, shared between this site and the console so the choice follows you. The page you arrived on is kept in the browser's own storage for the length of the tab and sent only with a sign-in request, as described above.
4. Who else sees it
The providers listed at https://lathe.live/subprocessors: Hetzner runs the machines (EU), Resend delivers our email (USA, message metadata only), and the payment provider processes card payments (Israel). Our DNS is at Cloudflare, which sees name lookups only; site traffic is not routed through it. Our support mailbox is hosted by Titan. We do not sell or share your data with anyone else, and disclose it only when the law compels us.
5. Where it is kept
Our own systems and their database run on Hetzner machines in Finland; your instance runs in the EU location you chose. Backups stay in the EU. Our staff administer the service from Israel, which benefits from an EU adequacy decision.
6. For how long
- Account, billing and event records: for the life of the account, then as long as tax and accounting law requires for the invoices they belong to.
- Instance data: deleted with the instance, after the final 7-day snapshot. Daily machine backups are kept 7 days.
- Copies of our own records: hourly, the newest two days kept, on top of the daily backups.
- Web server logs: rolled by size, a few weeks in practice, never longer than needed to investigate an incident.
- Sign-in and rate-limit counters: minutes to a day, then gone.
7. Your rights
You can see and change your billing details on the account page at any time. You can export your instance data yourself: you have full access to every engine, and the API lists everything about the account. To get a copy of what we hold about you, to have it corrected, or to close the account and have it deleted, email support@lathe.live from the account's address; delete your instances first, and we keep only what invoicing law obliges us to. If you are in the EU or UK you may also complain to your data-protection authority.
8. Changes
We announce material changes by email to every account, 30 days before they take effect, as the terms promise.
Last updated 6 September 2026.