Privacy Policy
Effective as of August 20, 2026.
lilco, operated by Paul Gebheim ("lilco," "we," "us" or "our") provides liluser, a service that runs autonomous agent personas against your web application and reports what an AI agent experiences. This Privacy Policy describes how lilco processes personal information that we collect through our digital or online properties or services that link to this Privacy Policy (including liluser.dev and the liluser API, collectively the "Service").
California Notice at Collection / State Privacy Rights Notice: See the State privacy rights notice section below for important information about your rights under applicable state privacy laws.
Personal information we collect
Information you provide to us
- Contact data, such as your email address, when you contact us.
- Profile data. Sign-in is via GitHub OAuth (scope
read:user); we store your GitHub ID, username (login), and avatar URL to establish and maintain your account. - Communications data based on our exchanges with you, including when you contact us by email.
- Run input data, such as the target URL, persona, goal, and optional callback URL you submit when requesting a run, and API keys you mint (stored only as hashes).
Third-party sources
- GitHub. When you sign in with GitHub, we receive your GitHub user ID, username, and avatar URL as permitted by your GitHub account settings.
Automatic data collection
We and our service providers (Cloudflare) may automatically log information about you, your computer or mobile device, and your interaction with the Service, such as:
- Device data, such as operating system, browser type, IP address, and language settings.
- Online activity data, such as pages viewed, access times, and navigation paths, collected through standard server logs.
Tracking & Other Technologies
Some of our automatic data collection is facilitated by cookies. We use only strictly necessary cookies (for authentication and sign-in security); we do not use cookies for analytics, advertising, or tracking. For details, see our Cookie Notice.
How we use your personal information
- Service delivery and operations, including to provide the Service; enable security features; establish and maintain your account; communicate with you about the Service (announcements, security alerts, support); and respond to your requests and feedback.
- Service improvement, including analyzing usage of the Service and developing new products and services.
- Compliance and protection, including to comply with applicable laws and legal process; protect our, your, or others' rights, privacy, safety, or property; enforce our terms; and prevent fraud and abuse.
- Aggregated, de-identified, or anonymized data. We may create aggregated, de-identified, or anonymized data from personal information we collect — including run trajectories — and use and share it for our lawful business purposes, including building and improving model evaluations, benchmarks, and readiness statistics. We remove information that makes the data identifiable to you and we will not attempt to reidentify any such data. App-identifying publication is never done without your explicit opt-in.
Retention
We retain personal information to fulfill the purposes for which we collected it, including satisfying legal, accounting, or reporting requirements. Concretely:
- Authentication sessions: 30 days (stored as hashed tokens).
- API keys: retained until revoked or rotated (stored only as hashes).
- Per-run artifacts (episode records, traces, findings, reports, screenshots): 90 days. Artifacts in object storage are automatically deleted after 90 days by a storage lifecycle rule; episode metadata is marked for 90-day retention (
retain_untilon each episode row), with purge enforcement rolling out. - Run records (target URL, persona, goal, outcomes, cost): retained until you request deletion or close your account.
- Persona inboxes (
@reallybadidea.comaddresses) and their contents are our own infrastructure, not customer data.
When we no longer require personal information, we delete or anonymize it. You may request deletion of your run artifacts and rows by emailing hello@lilco.dev; anonymized aggregates already published cannot be recalled (they cannot be traced back to your app).
How we share your personal information
- Service providers that help us operate the Service, including Cloudflare (hosting, storage, server logs), GitHub (authentication), and the model providers that power agent runs.
- Professional advisors, such as lawyers, auditors, bankers and insurers, in the course of the professional services they render to us.
- Authorities and others, where we believe in good faith it is necessary or appropriate for the compliance and protection purposes described above.
- Business transferees, in connection with an actual or prospective merger, acquisition, financing, or sale of all or part of our business or assets.
We do not sell your personal information, and we do not share it with third-party advertising partners.
Your choices
- Access or update your information. Account information comes from your GitHub profile; update it there, or contact us.
- Communications. We do not send marketing emails — we do not hold your email address. Service communications are delivered via notices posted on the Site.
- Cookies. See our Cookie Notice.
- Delete your account or runs. Email hello@lilco.dev and we will delete your account and the run artifacts and rows you identify.
- Do Not Track. Some browsers can send "Do Not Track" signals. We currently do not respond to them; note that we do not track you across sites in any case.
- Declining to provide information. If you do not provide information required to sign in, you cannot use account features of the Service.
Other sites and services
The Service may contain links to third-party websites and services, and runs you request necessarily interact with third-party applications you designate. We do not control and are not responsible for third-party sites or services. We encourage you to read their privacy policies.
Security
We employ technical and organizational safeguards designed to protect the personal information we collect. However, security risk is inherent in all internet technologies and we cannot guarantee the security of your personal information.
International data transfer
We are headquartered in the United States and may use service providers that operate in other countries. Your personal information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country.
Children
The Service is not intended for use by anyone under 18 years of age. If we learn we have collected personal information from a child without required consent, we will delete it as required by law.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes, we will notify you by updating the date of this Privacy Policy and posting it on the Service. Your use of the Service after the effective date of a modified Privacy Policy indicates your acknowledgment that it applies.
How to contact us
Email: hello@lilco.dev
State privacy rights notice
Except as otherwise provided, this section applies to residents of U.S. states whose privacy laws grant the rights described below (collectively the "State Privacy Laws"). Not all rights may be afforded to all users. We may not be able to process your request without sufficient detail to confirm your identity; we verify requests via GitHub sign-in on your account.
Your privacy rights. State Privacy Laws may provide some or all of: the right to information about how we collect, use, and share personal information; access to a copy of it; correction of inaccuracies; deletion; appeal of a denial; and opt-out rights. These rights are not absolute and we may decline a request as permitted by law.
- Opt-out of targeted advertising. We do not process your personal information for targeted advertising purposes.
- Opt-out of profiling/automated decision making. We do not use your personal information to engage in profiling or automated decision-making that results in significant financial, housing, education, employment, health care, criminal justice, or similarly significant impacts.
- Opt-out of sales. We do not sell your personal information within the meaning of State Privacy Laws.
- Consumers under 16. We do not have actual knowledge that we collect, sell, or share the personal information of consumers under 16 years of age.
- Sensitive Personal Information. We do not intentionally collect or process Sensitive Personal Information.
Nondiscrimination. You are entitled to exercise these rights free from discrimination as prohibited by State Privacy Laws.
Exercising your rights. Email hello@lilco.dev. We verify your identity via GitHub sign-in on your account and reserve the right to confirm your residency. Under some State Privacy Laws you may use an authorized agent; we may require proof of the agent's authority and verification of your identity.
Information practices. In the 12 months preceding the effective date of this Privacy Policy we have collected the following categories of personal information (CCPA statutory categories): identifiers (GitHub ID, username); internet or other electronic network activity information (server logs); and user content you submit (run configurations). We collect them for the business purposes described in this Privacy Policy and disclose them for business purposes only to the service providers listed above. We do not sell or share personal information for cross-context behavioral advertising. We do not attempt to reidentify deidentified information, except to test our deidentification processes.
Additional information for California residents. Under California's Shine the Light law, California residents may request information about personal information disclosed to third parties for their direct marketing purposes; we make no such disclosures. Send requests to hello@lilco.dev with "Shine the Light Request" in the subject. California users may also report complaints to the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, 1625 N. Market Blvd. Suite N112, Sacramento, CA 95834, (800) 952-5210.
Additional information for Nevada residents. Nevada residents have the right to opt out of the sale of certain personal information; we do not engage in such sales. To make a request regarding potential future sales, email hello@lilco.dev.
Notice to European users
This section applies only to individuals in the United Kingdom and the European Economic Area ("Europe"). References to "personal information" include "personal data" as defined in the GDPR.
Controller. lilco (operated by Paul Gebheim) is the controller of the processing of your personal information covered by this Privacy Policy. Contact: hello@lilco.dev. We are a U.S. operator with no establishment in Europe; if European data protection law requires us to appoint a representative or Data Protection Officer, we will update this section with their contact details.
Legal bases for processing. We process personal information: (a) as contractual necessity, to provide the Service you request (profile data, run input data, communications); (b) for our legitimate interests, including securing and improving the Service, provided your interests and fundamental rights do not override them (device data, online activity data, aggregated/anonymized reuse for model evaluation); (c) to comply with law; and (d) with your consent, where required, which you may withdraw at any time.
Your rights. European data protection laws give you the right to: access your personal information; correct inaccuracies; delete it where there is no good reason for us to continue processing it; transfer a machine-readable copy to you or a third party; restrict processing; object to processing based on legitimate interests or for direct marketing; and withdraw consent at any time. To exercise these rights, email hello@lilco.dev. We may request information to confirm your identity. If we reject a request, we will tell you why, subject to legal restrictions. If you are not satisfied, you may complain to the data protection regulator in your habitual place of residence (for the UK: the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, +44 303 123 1113).
Data processing outside Europe. We are U.S.-based; using the Service means your personal information will be processed in the U.S., which is not the subject of a GDPR adequacy decision. Where required, we rely on appropriate safeguards or a permitted derogation for such transfers. Contact us for further information on the mechanism used.
No sensitive personal information. Please do not provide sensitive personal information (e.g., government ID numbers, health, biometric, or similar data) through the Service. If you do, you consent to our processing it in accordance with this Privacy Policy; if you do not consent, do not submit it.
No automated decision-making with legal effect. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects. (Agent runs operate against third-party apps you designate; they make no decisions about you.)