Privacy Policy
Last updated: September 16, 2026
Lit Association ("Lit," "we," "us") provides the litprotocol.com website and the hosted Lit services described in our Terms of Service, including crypto infrastructure, confidential compute, and Agent Keychain. This Policy explains how we handle personal data in those services. We do not sell your data. That includes personal data, customer content, and de-identified datasets.
Personal data is information that identifies, relates to, or can reasonably be linked to a person. Encryption, a wallet address, or an agent identifier does not automatically make information anonymous. This Policy does not govern independent operators, third-party applications, model providers, or services merely because they use Lit software or connect to Lit.
Contact Lit Association at support@litprotocol.com with privacy questions or requests. This Policy explains our practices; accepting terms or visiting a website does not substitute for consent where law requires it.
1. Our role
Lit is generally the controller of personal data used to run its own website, manage customer relationships, authenticate accounts, bill customers, prevent abuse, and meet legal obligations. This means we determine the purposes and means of that processing.
For personal data in a customer’s application, dataset, or workload, Lit may act as a processor or service provider on that customer’s instructions. The applicable customer agreement and data processing agreement govern that processing. The customer remains responsible for its notices, lawful instructions, and relationship with its users. Contact that customer first about data it controls; we will assist as required by our agreement and applicable law. A technical ability to verify execution does not change these legal roles by itself.
2. Information we handle
The categories depend on which service you use. We obtain information from you, your organization or authorized agents, connected services and identity providers you select, our service providers, and your interactions with the Services.
Account, identity, and contact information
This may include your name, email address, organization, correspondence, account identifiers, public wallet addresses, public keys, passkey credential identifiers, and identity-provider authentication claims. If you sign in with a provider such as Google, we receive the information needed for that sign-in and the permissions you authorize. Provider and browser or device recovery services have their own privacy practices. Do not send private identity keys to support.
Credentials, permissions, and service metadata
For Keychain and related services, we handle encrypted credential records and metadata needed to locate and authorize their use. Metadata can include credential names, agent public keys, owner identifiers, permission records, expiration, versions, and timestamps. Encryption of a secret’s value does not mean that all associated metadata is encrypted or hidden from the service.
Keychain encrypts credential values in the browser before storage. Authorized operations use confidential hardware to check access and either use a credential for a supported operation or encrypt it for delivery to an approved client. A local client can then decrypt it. The actual exposure depends on the operation, the client, the provider, and your configuration; it is not a promise that a credential can never leave confidential hardware.
Application and AI content
We process code, deployment configuration, prompts, inputs, datasets, model artifacts, results, and other content you submit or authorize the Services to process, to the extent required for the service you select. Confidential workloads can process plaintext inside the protected runtime. Application behavior determines what is returned, retained, logged, or sent to permitted destinations.
A request to train or fine-tune a model authorizes that requested workload. It does not give Lit permission to sell your content or use it for unrelated purposes. Do not put credentials, personal datasets, or other sensitive content into ordinary support messages or sales forms when a secure deployment or support process is needed.
Transactions and public records
Wallet addresses, transaction identifiers, public contract state, permission changes, and software approval records may be visible on a blockchain. Their visibility and retention follow the relevant network. We may read those records to verify permissions, operate the Services, investigate abuse, or support you. Public identifiers may become identifiable when linked with other information.
Billing information
We handle plan selections, billing contact details, subscription status, payment-provider customer identifiers, invoices, and payment status. Payment details entered in hosted Stripe checkout or its billing portal go to Stripe. Lit receives the billing information needed to administer the purchase rather than a copy of the full payment-card number from that hosted checkout. A credential you deliberately store for a connected payment service is separate from paying for a Lit subscription.
Technical and usage information
Requests can expose IP addresses, browser and device information, referring pages, timestamps, requested endpoints, usage, errors, and security events to the systems handling them. Operational records can include identifiers needed for authentication, billing, abuse prevention, and troubleshooting. Confidential execution does not mean the entire service operates without metadata or logs.
3. How we use information
We use the relevant information to:
- Provide requested functionality, authenticate users and agents, enforce permissions, process workloads, and return results.
- Maintain accounts, process payments, administer subscriptions, and communicate about purchases or service changes.
- Secure and maintain the Services, investigate incidents and fraud, enforce appropriate limits, and troubleshoot problems.
- Respond to support requests, inquiries, privacy requests, and legal notices.
- Understand website and product usage and improve reliability and usability, consistent with the purposes for which the information was collected.
- Send product information and marketing communications where permitted, with consent where required and a way to unsubscribe.
- Meet legal obligations, respond to lawful requests, resolve disputes, and protect legal rights.
For customer-controlled workload content, these purposes are limited by the customer’s instructions, applicable agreements, and law. A general interest in improving a product does not authorize unrelated use of a customer’s confidential payloads. We do not disclose personal data to third parties for their own direct marketing.
4. When information is disclosed
Service providers. We use providers for hosting and confidential-computing infrastructure, storage, authentication, payments, communications, analytics, support, and security. They receive information needed for the relevant function, subject to applicable contractual and legal requirements. Providers do not necessarily have access to every category, and infrastructure hosting does not itself imply access to protected runtime memory. Some providers, such as payment or identity providers, also process information for their own legally defined purposes under their notices.
Your instructions and integrations. We send information to agents, applications, model providers, accounts, MCP tools, and other destinations you or your application authorize. Those recipients can see and retain what they receive. Allowing a destination is different from reviewing the contents sent to it. An external model does not become confidential merely because the calling application runs inside Lit.
Your organization. Administrators and authorized users may receive account information, permissions, usage, or content according to the product’s access model. Confirm your organization’s policies when using an organization-managed account.
Legal and safety purposes. We may disclose information where required by law or where legally permitted and reasonably necessary to investigate abuse, protect people or systems, establish or defend claims, or enforce agreements. Legal process does not give us a technical ability to decrypt data or recover keys we cannot otherwise access.
Business changes. A merger, reorganization, or transfer of the relevant business may involve transferring records to a successor, subject to applicable law and continuing privacy obligations. This is not permission to sell customer datasets as a product. We will provide notice or obtain consent where required.
Public information. Information intentionally published on a blockchain or other public channel can be copied and used by others. We cannot control those independent copies.
We may create aggregate or de-identified information to understand and improve the Services. We take reasonable steps to prevent re-identification and do not attempt it except as permitted by law to test de-identification. We do not sell this information.
5. Cookies, browser storage, and website analytics
Services may use cookies or local storage for sessions, security, user preferences, and client configuration. Keychain uses session cookies for authenticated access. Some client identity material and configuration are held on the device; protect that device and review what you export or synchronize.
The litprotocol.com website uses Plausible Analytics for aggregate website measurement. Its standard script does not use analytics cookies or persistent cross-site identifiers. It processes request information, including IP address and browser information, to produce statistics about page visits, referrals, device types, and approximate location. See Plausible’s data policy for its handling and retention. This does not describe the separate operational logs of hosting providers or connected applications.
The litprotocol.com website does not use cross-context behavioral advertising. A linked service or external form may use different technologies; its privacy information applies when you visit it. Where consent is legally required for optional technologies, it must be obtained before those technologies are used.
You can manage browser storage through browser settings, although blocking essential storage may prevent sign-in or other requested features. Global Privacy Control and other legally recognized opt-out signals are treated according to applicable law; there is no sale of your data to opt out of. Such signals do not disable the processing needed to provide a service you request. An older browser "Do Not Track" setting is distinct from those legally recognized signals.
6. Security, retention, and deletion
We use safeguards appropriate to the data and service, including encryption and access controls where applicable. Confidential hardware and attestation are parts of this approach, not a guarantee against every vulnerability or disclosure. Clients, identity providers, software dependencies, administrators of your own systems, and authorized recipients remain relevant to security. Once plaintext is delivered to a recipient, revoking access cannot retrieve it.
We retain information for the time needed for the relevant purpose and legal obligations:
- Account and permission records: while needed to provide access, honor authorized operations, manage the relationship, and handle reasonable security or dispute needs.
- Stored content and encrypted credentials: according to product controls, customer instructions, contractual commitments, and applicable law. Subscription cancellation alone does not delete a Keychain account or its stored credentials.
- Billing and transaction records: for accounting, tax, fraud-prevention, and other required recordkeeping periods.
- Support and operational records: for the period reasonably needed to resolve issues, maintain security, and handle legal obligations or disputes.
- Backups: until they expire or are removed through the applicable backup process, with restricted use rather than an assurance of immediate removal from every copy.
The duration varies by purpose and service; contact us for the retention information applicable to your account or deployment. Where information is no longer needed, we delete or de-identify it as applicable. Required preservation, security investigations, and legal claims may justify retaining limited records. We do not promise that deleting an account erases blockchain history, third-party copies, or credentials already delivered to an agent. Those limits do not remove our duty to handle lawful deletion requests for data under our control.
Maintain your own recoverable backups where appropriate. Exported encrypted backups, agent identity files, and originals retained with a provider may be outside Lit’s control.
7. International processing
Our providers and users operate internationally, and information may be processed outside your country, including in the United States. The processing location depends on the service and deployment. This Policy does not promise a single hosting country or data residency. Contact us before submitting data subject to specific location requirements.
Transfers subject to European, UK, or Swiss restrictions require an applicable lawful mechanism, such as an adequacy decision or appropriate contractual safeguards with the required supplementary protections. The applicable arrangement must be established for the transfer; merely accepting this Policy does not execute standard contractual clauses or waive transfer protections. Contact support@litprotocol.com for the locations and safeguards relevant to your service and to request a copy of applicable contractual safeguards, subject to necessary redactions.
8. Your choices and privacy rights
Depending on your location and applicable law, you may have rights to access or obtain a copy of your personal data, correct inaccuracies, request deletion, restrict or object to processing, obtain portability, withdraw consent, and opt out of certain uses or disclosures. These rights are subject to applicable exceptions and may differ when Lit processes data on a customer’s behalf.
Send a request to support@litprotocol.com with "Privacy request" in the subject. We may need proportionate information to verify identity or an authorized representative’s authority. We will not ask you to disclose a private key or secret credential to make a privacy request. We use verification information for the request and related security purposes. We respond within the period required by applicable law and explain an applicable refusal, extension, or fee. Requests are ordinarily free, and we will not discriminate against you for exercising protected rights.
You can unsubscribe from marketing messages through their unsubscribe option or by contacting us. Necessary account, security, billing, and legal communications may continue. Withdrawal of consent applies prospectively and does not invalidate earlier lawful processing. To appeal a denied request where that right applies, reply with "Privacy appeal." You may also contact the relevant privacy regulator.
California and other U.S. state notices
Where applicable state privacy law covers our processing, the categories in Section 2 describe the personal information collected, and Sections 3–4 describe the purposes and recipients. Categories can include identifiers, account and commercial information, internet or network activity, approximate location, customer communications, and customer-submitted information. Login credentials and certain submitted content may be sensitive personal information. We use sensitive information as needed to provide requested services, maintain security, and meet legal obligations, rather than to infer personal characteristics for advertising.
We do not sell personal information. Where applicable, you also have rights to opt out of sharing for cross-context behavioral advertising or other targeted advertising, and to limit certain uses of sensitive personal information. The website analytics described above are not cross-context behavioral advertising. We do not knowingly sell or share the personal information of people under 16 for such advertising. Applicable rights may also cover correction, access, deletion, portability, authorized agents, and certain profiling or automated decisions. Contact us using the process above; customers remain responsible for decisions made by their own applications.
European, UK, and Swiss notices
Where the GDPR, UK GDPR, or Swiss data protection law applies, Lit Association is the controller for the purposes described in Section 1. Our legal bases, where required, are:
- Contract: account management, requested service delivery, billing, and service communications needed to perform our agreement or take steps you request before entering one.
- Legitimate interests: proportionate security, fraud prevention, operational troubleshooting, business communications, website measurement, and legal claims, after considering the effects on your rights. For an organization’s account, some contact processing rests on legitimate interests rather than a contract with the individual contact.
- Consent: optional processing for which consent is required, such as certain marketing or optional tracking. Consent can be withdrawn.
- Legal obligation: required financial records, lawful legal requests, and other mandatory duties.
Data submitted under a customer’s instructions is processed under the applicable customer arrangement. Providing information necessary for a requested service is optional, but the service may not work without it. We do not make decisions about you with legal or similarly significant effects based solely on automated processing as part of the website analytics described here. A customer’s AI application may involve different processing, for which the customer must provide its own notice and safeguards.
You may object to processing based on legitimate interests, and you may object to direct marketing at any time. GDPR requests generally receive a response within one month; permitted extensions and exceptions apply, and we will explain them. You can complain to your local supervisory authority, including the UK Information Commissioner, the Swiss FDPIC, or an EEA supervisory authority.
Our appointed EU privacy representative is Dr. Axel Freiherr von dem Bussche, Taylor Wessing Partnerschaftsgesellschaft mbB, Hanseatic Trade Center, Am Sandtorkai 41, 20457 Hamburg, Germany; A.Bussche@taylorwessing.com. You may also direct requests to Lit Association at support@litprotocol.com.
9. Children
The Services are intended for adults, not children. We do not knowingly collect personal data directly from children under 16 through account signup. If you believe a child has provided such information, contact us so we can investigate and take the steps required by law. Customers must independently comply with child-privacy requirements for their applications and must not submit children’s data requiring a separate arrangement without that arrangement.
10. Changes and contact
We update this Policy when practices or legal requirements change and identify the revision date above. We will give notice of material changes through an appropriate channel and obtain consent where required before materially different processing. Changes do not retroactively authorize uses that were inconsistent with the notice and permissions applicable when data was collected.
For privacy questions, security concerns, requests, or information about the applicable customer processing arrangement, contact Lit Association at support@litprotocol.com.