Privacy Notice
Last updated: May 13, 2026.
1. Who we are
limen is operated by Jacob Thomson ("we", "us"). For the personal data we collect from limen users, Jacob Thomson acts as the data controller. You can reach us at legal@limen.earth.
2. Personal data we collect
- Account data — email address, hashed password (or OAuth identifier), display name.
- Authentication data — session tokens, sign-in timestamps, IP address used at sign-in.
- Content you create — areas of interest, incidents, notes, and routes you save.
- Support communications — messages you send us and our replies.
- Usage and device data — pages viewed, features used, browser type, device type, approximate location derived from IP, error logs.
- Payment data — handled directly by Paddle; we receive only the customer ID, subscription status, plan, and billing period (no card numbers).
3. Why we use it (purposes & legal bases)
- Provide the service — create your account, store your content, render maps and feeds. Legal basis: performance of the contract with you.
- Security and fraud prevention — detect abuse, rate-limit, and protect upstream providers. Legal basis: legitimate interest.
- Customer support — respond to your requests. Legal basis: performance of the contract / legitimate interest.
- Product improvement — aggregate, anonymized usage analytics. Legal basis: legitimate interest.
- Legal compliance — tax, accounting, responding to lawful requests. Legal basis: legal obligation.
- Marketing — only where you have opted in. Legal basis: consent (which you can withdraw at any time).
4. Who we share data with
We share personal data only with the categories of recipients below:
- Merchant of Record (Paddle) — for sale of subscriptions, payment processing, subscription management, tax compliance, and invoicing.
- Hosting and infrastructure providers — for application hosting, database storage, and content delivery.
- Map and data providers — Mapbox, OpenStreetMap, USGS, NASA FIRMS, NOAA, adsb.lol, AISStream, CelesTrak, TomTom — to render the basemap and feeds you request.
- Authentication provider — for sign-in, session management, and (if you choose) Google OAuth.
- Analytics providers — for aggregated, privacy-respecting product analytics.
- Professional advisers — accountants and lawyers, where reasonably required.
- Authorities — where required by law or to protect our rights.
We do not sell your personal data and we do not run third-party advertising trackers.
5. International transfers
Some of our service providers are located outside the UK and the EEA. Where personal data is transferred internationally we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. Retention
We keep account and content data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 90 days, except where we are required to keep records for legal, accounting, or fraud-prevention reasons (for example, transaction records retained for the period required by tax law). Server logs are retained for up to 30 days.
7. Your rights
Subject to local law, you have the right to access, rectify, erase, restrict, or port your personal data, to object to processing based on legitimate interest, and to withdraw any consent you have given. Where GDPR or UK GDPR applies you also have the right to lodge a complaint with your supervisory authority. We aim to respond to requests within one month.
To exercise any of these rights, email legal@limen.earth.
8. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, encrypted storage at rest, scoped access controls, and row-level security on the application database. No system is perfectly secure, so we cannot guarantee absolute security.
9. Cookies and similar technologies
limen uses only the cookies and local storage strictly necessary to keep you signed in, remember your preferences (such as map layers and theme), and protect against abuse. We do not use advertising or cross-site tracking cookies. You can clear cookies via your browser settings; doing so will sign you out.
10. Changes to this notice
We may update this notice from time to time. Material changes will be communicated via email or an in-app notice before they take effect.
11. Contact
Privacy questions or requests? Email legal@limen.earth.