Privacy Policy
1. Who we are and what this policy covers
TheGather, Inc., a Delaware corporation with its registered address at 2810 North Church Street, Wilmington, DE 19802, United States (“we”, “us”, “our”), operates Lymeno. This policy applies to:
- the website at lymeno.com;
- the console at console.lymeno.com;
- the Lymeno API; and
- the databases you create with Lymeno (together, the “Service”).
Two roles. For your account, sign-in, workspace, billing, and usage information, we decide why and how personal information is processed, and we are its controller. The data you store in your databases, including their backups and archives (“Customer Data”), belongs to you. We process Customer Data only to provide the Service on your instructions, and we act as your processor (or “service provider”). Our handling of Customer Data is governed by our Terms of Service, and by a data processing addendum if you need one (email support@lymeno.com to request it). If Customer Data contains personal information about other people, you are responsible for having a lawful basis to store it.
If you believe your personal information is stored in a database run by one of our customers, please read that customer’s privacy notice and contact them directly. We will help our customers respond to such requests.
2. Summary
- Website: no cookies, no analytics, and no advertising or tracking scripts.
- Console: only cookies that are necessary to sign you in. See the Cookie Policy.
- What we collect: your name and email address; sign-in credentials (stored as hashes, public keys, or encrypted values); session and security records, including IP addresses; workspace, audit, and billing records; and operational data about your databases.
- What we do not do: we do not sell or rent personal information, we do not use it for advertising, we do not use your data to train AI models, and we do not make automated decisions with legal or similarly significant effects.
- Who processes it for us: Cloudflare (hosting and email delivery), Stripe (payments), and cloud infrastructure providers (our application database, and your databases in the regions you choose).
- Where: our application database is in the United States. Customer Data stays in the region you choose.
- Your rights: you can update most account details in the console. For anything else, email support@lymeno.com. We respond within 30 days.
3. What we collect and why
| Category | Information | Purpose | Retention |
|---|---|---|---|
| Website visits | IP address, browser information, and the page requested, processed by our hosting provider when it serves a page. We do not set cookies or run analytics on the website. | Deliver the website and protect it from abuse | Our hosting provider’s standard log retention |
| Account | Name, email address, whether your email is verified, and your sign-in settings | Create and identify your account, and contact you about the Service | While your account exists, and deleted within 30 days after you close it |
| Sign-in credentials | Password (stored only as a hash), passkey public keys and device names, two-factor authentication secret, and backup codes (stored encrypted) | Verify that it is you when you sign in | While your account exists, or until you remove the credential |
| Email verification | Your email address and a 6-digit code | Confirm that you own the email address | The code expires after 10 minutes |
| Sessions and security | IP address, browser user agent, and session timestamps; your IP address is also used to limit repeated sign-in attempts | Keep you signed in, detect suspicious activity, and prevent abuse | A session expires 7 days after you last use it |
| Workspaces and invitations | Workspace name, members and their roles, and the email address of each person invited | Let teams share access to databases | While the workspace exists, and deleted within 30 days after it is closed; invitations expire after 7 days |
| Audit log | Who made each change (a person or an API token), what changed, when, and the IP address of the request | Let you review activity in your workspace, and investigate security issues | While the workspace exists |
| API tokens | Token name, a hash of the token, its access level and expiration, and when it was last used | Authenticate requests to the API | Until the token is revoked or expires |
| Billing | Name and email address of the workspace owner, which we share with Stripe; card brand, last four digits, and expiration date; credit balance and billing events. Stripe collects your full card details, billing address, and tax ID directly. We do not store full card numbers. | Charge for the Service, issue invoices, and send billing notices | As long as needed for accounting, tax, and legal requirements |
| Database operations | Resource metrics, query statistics (which may include the text of normalized SQL statements), and PostgreSQL and connection pooler logs (which may include parts of your queries and error messages) | Show monitoring in the console, troubleshoot, and operate the Service | Metrics and query statistics: 7 days. Logs: 3 days |
| Customer Data | The contents of your databases, their backups, and archives | Provide the Service | Until you delete the database. Backups follow the retention you set (1–30 days). Archives of suspended on-demand databases are kept for 30 days. We do not access the contents of your databases except to provide the Service, at your request, or when required by law |
| Support | The content of emails you send us | Answer your questions | As long as needed to resolve your request |
Information about other people. When you invite someone to a workspace, you confirm that you are authorized to give us their email address for that purpose.
Aggregated data. We may combine and de-identify Usage Data so that it no longer identifies you or anyone else, and use it to plan capacity and improve the Service. This policy does not apply to data in that form.
Emails we send. We send service emails: verification codes, workspace invitations, and billing notices such as low credit and archive reminders. We do not send marketing emails.
Legal bases (EEA and UK). We process account, sign-in, workspace, billing, and operational data to perform our contract with you. We process security records, abuse prevention data, and the audit log based on our legitimate interest in keeping the Service secure. We keep billing records to comply with legal obligations.
4. How we share information
We share personal information only as described here.
- Service providers that process it on our behalf, under contracts that limit their use of it:
- Cloudflare, Inc. hosts the website, the console, and the API, provides DNS, and delivers our emails.
- Stripe, Inc. processes payments and manages invoices. Stripe’s handling of your payment information is governed by the Stripe Privacy Policy.
- Cloud infrastructure providers host our application database in the United States, and run your databases and store their backups and archives in the region you choose.
- Your workspace. Members of a workspace can see the workspace’s databases, members, invitations, and audit log, including the names, email addresses, and IP addresses recorded in it.
- Legal reasons. We may disclose information when required by law, or to protect the rights, property, or safety of our users, the public, or us.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. This policy will continue to apply to it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We never use or share Customer Data for marketing or advertising.
5. Where information is stored
Account, workspace, billing, and operational data is stored in our application database in the United States. The website, console, and API run on Cloudflare’s global network, so requests may be processed in a data center near you.
Customer Data is stored in the region you select when you create a database, for example cn-hangzhou (Hangzhou), ap-east-1 (Hong Kong), ap-southeast-1 (Singapore), eu-central-1 (Frankfurt), or us-east-1 (Virginia). Backups and archives stay in the same region. We do not move a database to another region unless you ask us to.
When we transfer personal information across borders, we rely on safeguards required by applicable law, such as the European Commission’s Standard Contractual Clauses.
6. How we protect information
- All connections to the website, console, API, and databases are encrypted with TLS.
- Passwords and API tokens are stored only as hashes. Two-factor backup codes are stored encrypted.
- Database passwords are generated randomly, shown once, and not stored in plain text.
- You can protect your account with passkeys or two-factor authentication.
- Changes made in your workspace are recorded in the audit log.
No method of transmission or storage is completely secure, but we work to protect your information and will notify you of a breach where the law requires it.
7. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent.
- In the console, you can update your name, change your password, manage passkeys and two-factor authentication, revoke API tokens, and delete databases.
- Customer Data is standard PostgreSQL. You can export it at any time with
pg_dump. - For everything else, including deleting your account or workspace, or receiving a copy of your account data, email support@lymeno.com from the email address on your account. We may ask you to confirm your identity. We respond within 30 days. When you close your account or workspace, we delete its data within 30 days, except records we must keep for legal, tax, or accounting purposes.
If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data protection authority.
California residents. In the past 12 months we collected the categories of information described in Section 3, for the purposes described there. We do not sell or share personal information as those terms are defined under California law. We will not discriminate against you for exercising your rights.
8. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
9. Changes to this policy
We may update this policy as the Service changes. We will post the new version on this page and update the date at the top. If a change materially affects how we handle your personal information, we will notify you by email or in the console before it takes effect.
10. Contact
TheGather, Inc.
2810 North Church Street, Wilmington, DE 19802, United States
Email: support@lymeno.com