Privacy Policy
This policy explains how Limex handles information when you use our website, account, API, or AI-assistant connection.
Information we collect
- Account information: email address, sign-in provider identifiers, API-key metadata, and account settings. We never store the plain text of an API key after it is shown.
- Billing information: Stripe customer and transaction identifiers, payment-method status, wallet balances, charges, refunds, and ledger records. Limex does not store full card numbers.
- Research information: prompts, query parameters, selected providers, result-quality metadata, source links, and usage amounts. A query may contain company, property, professional, or other personal information supplied by you or returned by a source.
- Technical information: request times, authentication and security events, device or browser details made available in ordinary service logs, and error diagnostics.
- Contact information: messages sent to support or through our data-partner form.
How we use information
We use information to authenticate users; answer and improve research requests; choose, meter, and pay data providers; prevent fraud and abuse; provide support; maintain security and reliability; comply with law and provider contracts; and communicate about the service. We do not sell personal information or use Limex research content to train a general-purpose AI model.
Sources and recipients
Information comes from you, your connected AI client, identity provider, payment provider, and the public or licensed data sources selected for a query. We disclose only what is needed to service providers such as Clerk for authentication, Stripe for payment processing, hosting and monitoring vendors, and the data provider needed to answer a request. Source links and limited result content are returned to you and your connected AI client. We may disclose information when required by law, to protect users and the service, or in a corporate transaction subject to appropriate safeguards.
Retention
- Research query text and provider-cache payloads are retained for no more than 30 days, or less when a provider contract requires it; older usage records are retained with their query details removed.
- Expired device-connection secrets are removed after 24 hours.
- Ordinary security and application logs are retained for up to 90 days.
- Data-partner and support correspondence is retained for up to 24 months after the last interaction.
- Account information is retained while an account is active and ordinarily deleted or de-identified within 30 days after a verified deletion request, except where billing, fraud, legal, or contract records must be kept.
- Wallet, payment, tax, and transaction records may be retained for seven years.
Your choices and rights
You can review wallet and usage activity in your account, revoke API keys, and disconnect Limex in your AI client. Depending on where you live, you may request access, correction, deletion, portability, restriction, or objection, and may appeal or complain to a regulator. Email privacy@getlimex.com. We verify requests and may need to retain limited records required by law or needed to protect the service.
Security and international transfers
We use access controls, encrypted transport, hashed API keys, signed tokens, payment-provider tokenization, and provider allowlists. No system is perfectly secure. Limex and its service providers may process information in Canada, the United States, and other locations under contractual and legal safeguards appropriate to the transfer.
Children and changes
Limex is a business research service and is not directed to children under 13. We may update this policy as the service changes. Material changes will be posted here with a new effective date and, when appropriate, communicated through the service.
