Levirge products (Search, Brain) are operated by **React IoT** from Western
Australia. This page matches the [terms of service](/terms) and, like them,
is a working draft pending legal review — what it states holds today.
Questions — [talk to us](/contact). Last updated: 2026-08-09.

## What we collect

- **Account data** — when you sign in with Google or Microsoft we receive
  your name and email from that provider; we don't see or store passwords.
  Per-user tokens are stored as hashes only, never the raw credential.
- **Customer Data** — what your workspace sends to the Services: Search
  queries and fetched pages, and the knowledge, entities, skills and
  handoffs your agents and users put into Brain.
- **Activity records** — every search and read is recorded in your
  workspace: URL, outcome, timestamp. Recorded *for* you, not about you —
  it exists so you can show what an answer was based on.
- **Contact form** — name, email, topic, message and your follow-up
  consent, sent to us by email. A hidden anti-bot field drops automated
  submissions silently.
- **This website** — uses Google Analytics to understand aggregate page
  usage (pages viewed, rough geography — not who you are). The only other
  third-party request the site makes is Google Fonts.

## Ownership and use

Customer Data is yours ([terms §9](/terms)). We use it only to operate the
Services for your workspace — storing, indexing, and serving it to the
agents and users you authorise. We don't sell it, train on it for other
customers, or claim any commercialisation rights.

## Where model calls go

Two lanes, one runtime switch. **Private mode** runs every model call —
categorisation, summarisation, chat — on LLMs Levirge hosts on its own
infrastructure; no cloud model provider is in the path. **Hosted mode**
sends model calls to cloud LLM providers, for speed. Embeddings and
reranking run on Levirge infrastructure in both modes. Whichever lane is
active, your workspace's data is tenant-isolated, and personal Vaults are
private to their owner, enforced fail-closed.

## Retention and deletion

- Pages read by Search stay available for **24 hours** (the cache window),
  then expire. The activity record stays with your workspace.
- Brain knowledge stays until you change or delete it — and exports out at
  any time. Brain's ingestion runs a secret-redaction gate so credentials
  and keys aren't persisted into the knowledge base.
- On termination: **30 days** to export, then Customer Data is deleted
  from the Services, except records we must keep by law
  ([terms §18](/terms)).

## Subprocessors

Kept deliberately short: our hosting infrastructure providers; **Brevo**
(contact-form email delivery); **Google** (Analytics on this website, Fonts,
and sign-in) and **Microsoft** (sign-in); and — only when your workspace uses hosted mode — the cloud LLM
providers serving that lane. Ask us for the current list and hosting
regions.

## Your rights

Workspace admins can see usage by user, issue and revoke tokens, and
export knowledge. For access, correction, deletion, or anything this page
doesn't answer, [contact us](/contact) — we'll respond promptly, and we'll
notify affected workspaces without undue delay if a breach touches their
data.

## Legal requests and changes

We disclose data only as required by law, and where lawful we'll tell you
first. Changes to this page follow the same 30-day notice as the terms.
