← Back to Lipsius

Privacy Policy

Last updated: 16 September 2026

1. Who we are

Lipsius (“we”, “us”, “our”) is an AI-powered strategic intelligence service for founders, operated by Wessel Vinke (sole proprietor and data controller). We are based in Oxford, United Kingdom.

Our website is lipsius.io and our dashboard is at app.lipsius.io.

For questions about this policy, data subject requests, or privacy concerns, contact us at privacy@lipsius.io.

2. What data we collect

Account data

When you sign up, we collect your name and email address. If you upgrade to a paid plan, payment card details will be processed directly by Stripe and will never be stored on our servers.

Telegram identity

If you choose to connect Telegram, you provide your Telegram ID in the dashboard. This is used solely to authenticate your messaging access and route messages to your personal agent.

Messaging data

Messages you send to your Lipsius agent via Telegram or the dashboard chat are processed by our AI system to generate responses. Message history is stored in your private workspace on our servers.

Workspace data

Your agent generates reports, research, briefs, and other files in your workspace. You may also edit files and provide business information (company details, goals, market data). This data is stored in your private workspace directory, isolated from other customers.

Connected services

If you choose to connect third-party services (such as Gmail, Google Calendar, Stripe, Notion, GitHub, Linear, or Slack), we store OAuth tokens or API keys necessary to access those services on your behalf. We access only the data needed to perform the actions you or your agent request. Connecting a service is entirely optional and based on your explicit consent.

Website analytics

Our marketing website uses the Meta (Facebook) Pixel for conversion tracking. This collects browsing data including pages visited, referral source, device information, and identifiers that may be linked to your Facebook or Instagram account. We obtain your consent before activating this tracking. Use Cookie settings at the bottom of this site to change your choice. Rejecting analytics does not prevent signup. The dashboard also records product and operational events needed to understand service use and failures.

Waitlist submissions

If you join our waitlist, we collect your email address and optionally your name, company, and role. This data is used only to contact you about Lipsius.

3. How we use your data

  • Provide the service: Process your messages, generate research and reports, execute actions on your behalf through connected services.
  • Authenticate access: Verify your identity for dashboard login and messaging channels.
  • Process payments: Manage billing through Stripe if you choose a paid plan.
  • Send notifications: Deliver email digests, alerts, and service communications you have opted into.
  • Improve the service: Analyse aggregate usage patterns (e.g., which features are used most) to improve the product. We do not use your business data, message content, or workspace content for this purpose.

4. AI processing

Your messages and workspace data are processed by third-party AI model providers to generate agent responses, research, and reports. This processing is necessary to provide the core service. The current runtime uses OpenAI through a subscription connection and a private relay. See Section 10 for international processing.

Lipsius does not operate a model-training pipeline. Provider processing, retention and training treatment depend on the applicable account settings and provider terms; we do not promise zero retention or a separate no-training contract here. Contact us before providing information that requires specific processing terms.

When your agent performs web research, it searches publicly available information on the internet. Search queries can be derived from your task and workspace context; avoid including personal or confidential information that is unnecessary for the research.

Automated decision-making

Your Lipsius agent uses AI to generate recommendations, research, and draft communications. These AI-generated outputs are advisory — the agent does not make decisions with legal or similarly significant effects on you. External actions use the permissions you set. This may include standing permission for a defined audience, limit or publishing action rather than a separate confirmation every time. Support replies require founder review before sending.

5. Data sharing and third parties

We do not sell, rent, or trade your personal data. We share data with the following third parties in the course of providing the service:

Data processors (acting on our instructions)

  • OpenAI — model processing through the current subscription connection. Relevant task context is sent to produce responses and tool decisions. (privacy policy)
  • Pipedream and Browserbase — connected-app and browser execution when those capabilities are used. Task data needed for that operation may be processed by the selected provider.
  • Hetzner (Germany) — server hosting. (privacy policy)
  • Cloudflare (United States) — CDN and DNS. (privacy policy)
  • Resend (United States) — email delivery for digest emails. (privacy policy)

Independent controllers (operating under their own privacy policies)

  • Stripe (United States) — payment processing. When you make a payment, Stripe processes your card details as an independent controller. (privacy policy)
  • Telegram (United Arab Emirates) — if you use Telegram, messages are transmitted through Telegram’s Bot API. Telegram is an independent controller. (privacy policy)

Web search

Research tools send search queries derived from your task to web-search providers. Pages and search results may be read to answer your question; do not supply unnecessary sensitive information in a research request.

Connected services

When you connect a third-party service (Gmail, Calendar, Stripe, Notion, etc.), your agent accesses that service using the credentials you provide, solely for actions you authorise. A task you authorise may move relevant data between connected services, for example reading a message and preparing a reply. You can disconnect any service at any time via the dashboard.

6. Data storage and security

The native app stores its data on a Hetzner-hosted server in the European Union. The public website uses separate shared hosting. We implement the following security measures:

  • All connections are encrypted in transit via TLS/HTTPS.
  • Workspace data is isolated per customer — other customers cannot access your data.
  • Access to the server is restricted to authenticated, authorised personnel via SSH key authentication.
  • Connected-account tokens are encrypted in access-controlled storage outside the model-visible workspace.
  • Cloudflare provides domain DNS and may process traffic for routes configured to use its proxy.

7. Data retention

  • Active account: Your data is retained while your beta account or paid subscription is active.
  • After cancellation or deletion: Cancellation does not itself confirm erasure of all stored files, connected credentials or backups. Contact privacy@lipsius.io to request deletion and confirmation of what has been removed, including the treatment of retained backups.
  • Waitlist data: Retained until you unsubscribe or request removal.
  • Payment records: Retained as required by UK tax and accounting laws (up to 6 years).
  • Server logs: Retained for up to 90 days for security and debugging purposes.

8. Your rights

Under UK GDPR and the Data Protection Act 2018, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”).
  • Restrict processing of your data in certain circumstances.
  • Data portability — receive your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests, including profiling.
  • Withdraw consent at any time where processing is based on consent (e.g., connected services, marketing communications, analytics cookies). Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
  • Not be subject to automated decision-making with legal or similarly significant effects (see Section 4 — our AI processing is advisory, not decisional).

How to exercise your rights:

  • Email privacy@lipsius.io for access, rectification, erasure, restriction, portability, or objection requests.
  • Disconnect a connected service (Gmail, Calendar, etc.) at any time via the dashboard Integrations page.
  • Manage cookie preferences via the cookie banner on our marketing website.
  • Unsubscribe from email digests in your dashboard Settings.

We will respond to data subject requests within one calendar month. For complex requests, we may extend this by a further two months, but we will inform you within the first month and explain the reason for the delay.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

9. Legal basis for processing

We process your data under the following legal bases (UK GDPR Article 6):

Processing activityLegal basis
Account management, messaging, workspaceContract (Article 6(1)(b))
Payment processingContract (Article 6(1)(b))
Connected third-party services (Gmail, Calendar, Stripe, etc.)Consent (Article 6(1)(a))
Meta Pixel analytics cookiesConsent (Article 6(1)(a))
Waitlist and marketing communicationsConsent (Article 6(1)(a))
Aggregate usage analytics (no personal data)Legitimate interest (Article 6(1)(f))
Fraud prevention, securityLegitimate interest (Article 6(1)(f))
Tax/accounting record retentionLegal obligation (Article 6(1)(c))

10. International data transfers

The native workspace is hosted in the EU. Model, integration, payment and other providers may process data in other countries, depending on the service and account configuration. Contact privacy@lipsius.io for the applicable provider terms and transfer information before submitting data that requires a specific regional or contractual commitment.

11. Cookies

Marketing website (lipsius.io):

  • Meta Pixel: A tracking pixel for conversion analytics. This sets cookies on your device and collects browsing data including pages visited, referral source, device information, and identifiers that may be linked to your Facebook or Instagram account. This is only activated after you provide consent via our cookie consent notice. You can withdraw consent at any time or manage your preferences via Meta’s ad preferences.

Dashboard (app.lipsius.io):

  • Session cookie (__Secure-authjs.session-token): A strictly necessary authentication cookie to keep you logged in. This does not require consent under PECR as it is essential for the service to function.

12. Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the UK Information Commissioner’s Office within 72 hours. If the breach poses a high risk, we will also notify you directly without undue delay, providing details of the breach and the measures taken.

13. Children

Lipsius is a business service intended for adults. We do not knowingly collect data from individuals under the age of 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

14. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email to active subscribers at least 14 days before taking effect. The “last updated” date at the top of this page reflects the most recent revision.

15. Contact

For any privacy-related questions, data subject requests, or concerns:

Email: privacy@lipsius.io

Data controller: Wessel Vinke

Location: Oxford, United Kingdom