Legal

Privacy

What Lemma collects, what it never collects, who else can see it, and how to change your mind — in plain language, because you should be able to read it.

Effective August 16, 2026deepak@lemma.work

The short version

We collect what it takes to run Lemma: who you are, what your workspace holds, and how the product gets used.

We never sell it, never advertise against it, and never feed what you build into analytics.

Run Lemma on your own machine or your own server and almost none of this happens at all.

Straight answers

Do you sell my data?

No.

Not to advertisers, not to data brokers, not to anyone. Lemma is paid for by the people who use it.

Do you train models on my work?

No.

We do not train models on anything in your workspace, and we buy model capacity under business terms that do not let providers train on what we send them.

Does my workspace ever leave Lemma?

When an agent runs.

Agents are language models we do not host. What an agent needs to answer you goes to a model provider and comes back as a reply. Section 05 is the whole of it.

Can Lemma staff read my pods?

Almost never.

Only for support you have asked for, a security or abuse investigation, or a legal obligation. Access is limited to the people who need it and it is logged. Never to browse.

Am I tracked across the web?

No.

No ad networks, no third-party trackers, no session recording, no screen capture. One analytics tool, on servers in the EU, that never sees inside your workspace.

Can I change my mind?

Any time.

Analytics has a switch further down this page and it works in both directions. Turning it off removes what was stored in this browser.

Your setting

Analytics in this browser

Checking what this browser is set to.

01

Who we are

Lemma is made by Folks and Machines, Inc., a Delaware corporation ("we", "us"). This policy covers the Lemma website, the hosted product, the desktop app, our APIs, and the support conversations around them. It is meant to be read — if a line here is unclear or seems to contradict what the product actually does, that is a bug, and deepak@lemma.work is where to report it.

02

What we collect

Four kinds of information, and it is worth knowing which is which, because they are used for very different things.

  • Your account. Your name, email address, organization, how you signed in, and your preferences. You hand us this in order to have an account.

  • What you build. The pods, tables, records, files, agents, workflows, and connections you create. We store it because storing it is the product. We do not read it for any other purpose.

  • How the product gets used. Which screens are opened, which actions succeed or fail, and the technical details every browser sends: device and browser type, IP address, the rough region that IP implies, timestamps.

  • Payments. Which plan you are on and what you have been billed. Card numbers go straight to our payment processor and are never held by us.

  • What you tell us. Emails, bug reports, feedback, survey answers, and anything else you send our way.

03

What we never collect

This section matters more than the one above it, so it gets to be its own section rather than a caveat inside one.

  • The contents of your workspace, for analytics. Records, files, prompts, and agent conversations are left out where events are created, not filtered out afterwards — the difference being that a filter is one mistake away from failing and an omission is not.

  • The names of things you make. A pod called "Q3 layoffs" reaches our analytics as an identifier and nothing else.

  • Your screen or your session. No session replay, and no autocapture — the feature that quietly scrapes the text off a page into event properties — because Lemma renders your business data and that is the fastest way to put it somewhere it does not belong.

  • Identifiers in page addresses. A URL is reduced to its route pattern before it leaves your browser, so the id of the pod you were looking at is not carried out with the pageview.

  • Anything bought from a data broker. We do not enrich, append, or buy information about you, and there is no advertising profile to build because we do not advertise against you.

04

How we use it

Six purposes. If we ever want to use your information for something that is not on this list, we will come back and change the list first.

  • Run the product: sign you in, keep your session, store your work, and make the workspace do what it says on the tin.

  • Take payment: process purchases, manage subscriptions, send receipts, and sort out billing questions.

  • Keep it standing: watch performance, chase bugs, investigate abuse, and stop people getting into accounts that are not theirs.

  • Make it better: understand which parts are used, which parts are abandoned, and what to build next.

  • Talk to you: service notices, security alerts, policy changes, and answers to things you asked.

  • Meet obligations: comply with the law and enforce our terms when we have to.

05

Language models

Lemma runs on large language models and we do not run those ourselves. This is the one place your workspace content routinely leaves our systems, so it is spelled out rather than folded into a list about vendors.

  • When an agent runs, the parts of your workspace it needs in order to answer — your instructions, the records and files in scope, the conversation so far — are sent to a model provider, which sends a reply back. Nothing else goes with it.

  • We contract with those providers on business terms that do not permit training on what we send. We do not train models on your workspace either, and we have no plans that would require us to.

  • Connectors work the same way pointing outwards. Connect Lemma to another service, or ask an agent to send something somewhere, and data moves — on that service's terms as well as ours.

  • If you run Lemma yourself, the provider is your choice, including a model running on hardware you own. Nothing in the product requires ours.

06

Product analytics

On Lemma Cloud we measure how the product gets used so we can tell what is working. It is handled by PostHog, acting for us, on servers in the European Union. It is the smallest version of this we could build and still learn anything.

  • What goes in. That something happened and roughly where — a pod created, an agent run finished, a workflow completed — with the identifiers of the account, organization, and pod involved, and coarse buckets such as how long it took.

  • What stays out. Everything in "What we never collect" above. It is held there by an allowlist that drops any field not explicitly named, rather than by a list of forbidden fields, and by tests that try to smuggle a prompt and an email address through and fail if either survives.

  • Before you answer. Nothing is written to your device. That first visit is measured in memory and disappears when you close the tab, which is why the question can wait until you have had a look around.

  • After you answer. Saying yes stores one identifier in this browser so your visits join up. Saying no leaves nothing behind and keeps every visit unlinked. Either way we ask once and remember the answer.

07

Who else sees it

We do not sell your information. It reaches other hands in five situations, and this is all five of them.

  • Vendors who help us run Lemma. Hosting, databases, email delivery, payments, error monitoring, analytics, model providers. Each one may use what it receives only to do that job for us, and no other.

  • Your own administrators. If you use Lemma through an organization, its admins can see and manage the account and workspace information their team holds. Your employer's Lemma is your employer's — worth knowing before you keep something personal in it.

  • Services you connect. A connector you set up, or a message you ask an agent to send, moves data outwards on purpose. That is the feature working.

  • Courts and law enforcement. When we are legally required, or when it is genuinely necessary to stop someone being harmed. We will tell you when a request touches your data unless we are legally barred from doing so.

  • An acquirer. If the company is ever sold, merged, or financed against, information can move as part of that. The policy travels with it, and you would hear from us before anything about it changed.

08

Where it lives, and how long

Lemma Cloud runs on infrastructure in the European Union, and our analytics processor is in the European Union too. We are a US company, so some information reaches the United States — for support, billing, and engineering — under the standard contractual clauses and equivalent safeguards. We keep information while your account is live and while we still need it: to run the service, settle a bill, meet a legal obligation, or resolve a dispute. Delete something in Lemma and it leaves the live product straight away; copies can sit in encrypted backups for a limited window before they age out. Everything is encrypted in transit and at rest, access is scoped to the people who need it, and no one can promise perfect security — so we will not.

09

What you can do

  • Switch analytics off, or back on, using the control on this page. Turning it off removes the identifier stored in this browser rather than merely stopping it being updated.

  • Get a copy of your information, correct it, or ask us to delete it — from workspace settings, or by writing to deepak@lemma.work. The EU, the UK, and California give people these rights by law; we extend them to everyone, because sorting users by passport is a strange way to run a company.

  • Unsubscribe from anything we send that is not about your account or your bill. The link is at the bottom of every one of those emails.

  • Disconnect a connector, or delete what you have built, subject to what your team's permissions allow.

  • Complain. To us first, we would hope — and if that goes nowhere, to your local data protection authority, which you are entitled to do without asking us.

10

Running Lemma yourself

Lemma is open source and the whole thing runs on your own machine or your own server. When it does, most of this policy stops applying, because we mostly stop being involved. A local-first product that quietly phones home would have lost something it could not buy back, so the reporting is deliberately close to nothing.

  • A self-hosted server sends one anonymous heartbeat: a random instance identifier, the version, and a bucketed count of pods. No pod identifiers, no names, no content. It can be switched off.

  • Lemma Desktop in local mode sends install health only — whether the runtime installed and how long it took — against a random install identifier, so we hear about a broken installer from the installer rather than from a GitHub issue three weeks later. It can be switched off.

  • Product analytics does not run on either one. There is no key configured to run it with, and the code path that would send it is not merely disabled but absent.

  • Your data stays on your hardware, and the model provider is yours to pick.

11

Children

Lemma is built for work and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to us and we will delete it.

12

When this changes

We will update this page as the product changes. The effective date at the top moves whenever it does, and for anything material — a new purpose, a new category of recipient, anything that would change a reasonable person's mind — we will tell you in the product or by email before it takes effect, rather than quietly reissuing the page and hoping.

13

Contact

Lemma is a product of Folks and Machines, Inc. Privacy questions, data requests, and complaints all go to deepak@lemma.work, and a person reads them.