Privacy Policy
1. Scope
This policy explains how ByteGap Ltd. ("ByteGap", "we", "us", the "data controller") processes personal data when you use Landivo AI, including account, editor, AI, publishing, and analytics features.
2. Data we process
We process the following categories of data:
- Account and identity data, such as user ID, email address, and basic
profile fields from authentication flows
- Preference and compliance data, such as locale preferences and recorded
consent metadata including accepted timestamp and policy version
- Project and content data, such as page metadata, generated or edited HTML,
and publishing configuration
- Uploaded assets, such as favicon and page image files
- Domain configuration data, such as custom domain values and verification
status
- AI interaction data, such as prompts, edit requests, title/language
inputs, and current page HTML used for requested AI modifications
- Product analytics data, such as screen events and click interaction fields
(for example click text, click type, click section, click destination,
click tag, and click href)
- Technical and diagnostics data, such as operational errors and service
logs required for reliability and security
- Abuse-prevention data: a one-way SHA-256 hash of the IP address making a
request, with a per-day counter, used to enforce rate limits. We keep the
hash rather than the address, and it expires after 30 days
- Illegal-content reports: the page reported, what the reporter says is wrong
with it, their email address if they choose to give one, and a hash of their
IP address. Reports can be made without an email address
3. How we use data
We process data to:
- Create and manage user accounts
- Secure access and prevent misuse
- Generate and edit page content through AI features
- Store, preview, and publish user pages
- Support custom domain setup and hosting workflows
- Measure feature usage and improve product quality
- Maintain legal records, including consent evidence
- Comply with legal obligations and enforce contractual rights
4. Legal bases
Depending on context and jurisdiction, we process data based on one or more of:
- Performance of a contract (service delivery)
- Legitimate interests (service security, reliability, and improvement)
- Consent (where legally required)
- Legal obligation (compliance and recordkeeping requirements)
5. AI processing details
When AI features are used, relevant request data is sent to our AI provider to generate output. Generation requests typically include user prompt, title, and language. Editing requests may include the full current page HTML and the requested changes. AI output is returned to the application and can be saved by the user.
6. Analytics processing details
If analytics is enabled for the environment, event data is processed for usage measurement and product analysis. Published pages may include instrumentation for page-level analytics and interaction tracking. Analytics processing can include per-page identifiers and interaction metadata to support dashboards and reporting.
7. Cookies and tracking technologies
The service and its third-party providers may use cookies, local storage, and similar technologies to:
- Maintain authentication sessions
- Store user preferences
- Collect analytics and usage data
- Support service infrastructure and security
Firebase services may set cookies for authentication and hosting. Google Analytics, if enabled, uses cookies to distinguish users and track sessions. Where required by applicable law, we obtain consent before setting non-essential cookies, and nothing non-essential loads until you have chosen.
You can change or withdraw that choice at any time, and withdrawing is as easy as giving: signed in, use Settings → Privacy; signed out, use the cookie button in the corner of the page. On a published page, the same control sits in the page's own settings button. We also honour the Global Privacy Control signal, so if your browser sends it we treat analytics as declined without asking.
8. Processors and recipients
We use infrastructure and subprocessors to provide the service, including:
- Firebase services for authentication, databases, storage, and hosting
- Google services for analytics reporting and admin operations
- Eden AI for AI generation, editing, and translation. Eden AI is an aggregator:
your prompt and the current page content are passed on to the model provider
configured for that feature, currently Anthropic, OpenAI, or Google. The
provider can be changed without an update to this policy; our subprocessor
register names the one in use.
- Sentry for error and performance monitoring, receiving diagnostic data such as
stack traces and browser user agent. It does not receive your IP address,
cookies, request headers or bodies, or AI prompts.
Two providers are named here only to be ruled out. We query the Pixabay image API from our
servers, sending a search keyword and our own API key and no data about you or your visitors;
the photos are then cached on our own storage, so Pixabay is not a processor and never sees a
visitor. DiceBear avatars are bundled into the product, so no request reaches them either.
Data may be disclosed where required by law, regulation, legal process, or to protect rights and security.
9. International transfers
Data may be processed in countries outside your own, including locations where our providers operate infrastructure. Where required, we apply transfer mechanisms and safeguards appropriate to applicable data protection law.
10. Retention
We retain data for as long as needed for service operation, account support, security, legal compliance, and dispute resolution. Retention periods vary by category:
- Account and project data are retained while your account remains active
- Consent and compliance records may be retained longer for legal evidence
- Operational logs and analytics are retained per platform and policy limits
11. Security
We use technical and organizational measures designed to protect personal data, including access controls and managed cloud security features. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12. Automated decision-making
The service does not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. AI features generate content based on your requests but do not make autonomous decisions about you.
13. Your rights
Subject to applicable law, you may request:
- Access to personal data
- Correction of inaccurate data
- Deletion of data
- Restriction or objection to processing
- Data portability
- Withdrawal of consent where processing depends on consent
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
14. Children
The service is not intended for children where parental consent is required. Do not use the service if you are below the applicable minimum age in your jurisdiction.
15. Changes to this policy
We may update this policy to reflect product, legal, or regulatory changes. If updates are material, we will provide notice through reasonable channels.
16. Contact
Data controller: ByteGap Ltd., Alexandrou Papadiamanti 1, Block B, Office 32, 6035 Larnaca, Cyprus For privacy inquiries or rights requests, contact us at contact@bytegap.com.