Legal Center
Transparency is key. Here is how we protect your data and the rules for using Lemlii.
Privacy Policy
Last Updated: August 24, 2026Introduction
Welcome to Lemlii! We are committed to protecting your privacy and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, application, and any related services (collectively, the “Service”). Please read this policy carefully. If you do not agree with its terms, please do not use Lemlii.
We may update this Privacy Policy from time to time. If we make changes, we will update the “Last Updated” date and, if changes are significant, provide notice via the Service. Continued use of Lemlii after we post an updated Privacy Policy means you accept those changes.
Information We Collect
- Personal Data: When you register for an account or interact with Lemlii, we collect personal information such as your name, email address, and (if applicable) mailing address or contact details. We may also collect payment information when you subscribe to a paid plan (handled securely via our payment processor). This personal data is necessary for creating your account, providing the Service, and communicating with you.
- Technical and Usage Data: We collect limited technical information needed to operate, secure, and understand use of Lemlii. This may include IP address, browser and device details, operating system, referring page, and interactions with the Service. We use this information to maintain security, understand performance, and improve Lemlii.
- Cookies & Similar Technologies: Lemlii uses essential cookies for functions such as authentication, security, and remembering your preferences. On our marketing website, optional analytics and advertising-measurement technologies are used only after you select “Continue.” Selecting “Reject” does not affect the core Service. Your choice is shared between lemlii.com and app.lemlii.com, remembered for up to one year, and can be changed at any time through “Cookie preferences.” If you continue, first-touch campaign details may be retained for up to 90 days.
How We Use Your Information
We use personal data for the following purposes:
- To Provide and Maintain the Service: We process your information to create and manage your account, authenticate you when you log in, and provide the features of Lemlii.
- To Personalize and Improve the Service: We may use data about how you use Lemlii to customize your experience and to develop new features or enhancements.
- For Customer Support: If you contact us for help, we will use your information to respond to and resolve your queries or issues.
- For Security and Fraud Prevention: We use information to monitor for and prevent fraudulent, unauthorized, or illegal activity on the Service.
- To Communicate with You: We will send essential communications about your account or transactions (for example, password resets, service updates, or policy changes).
- To Measure Marketing Performance (with Your Consent): If you select “Continue,” we use limited campaign and interaction information to understand which marketing efforts lead to visits, registrations, trials, and subscriptions.
- For Marketing (with Your Consent): If you have given us your consent (for example, by opting in at sign-up), we will use your email to send you newsletters, product updates, or promotional offers.
Google Calendar and Google User Data
Connecting Google Calendar is optional. If you connect it, Lemlii accesses and uses Google user data only to provide the calendar features you choose.
Data accessed
- Your Google account identifier and email address.
- Your calendar list and calendar metadata, including calendar names, descriptions, identifiers, time zones, access roles, primary-calendar status, and display colours.
- Events from calendars you select, including event identifiers, title, start and end date or time, time zone, status, location, description, visibility and availability settings, recurrence information, Google Calendar link, and technical update information used to keep events synchronized.
- OAuth access and refresh tokens, granted permissions, connection status, synchronization state, and the calendar display, privacy, and synchronization preferences you choose.
Google may include other standard calendar or event fields in its API responses. Lemlii does not use or intentionally store those additional fields.
How Lemlii uses Google user data
- Identify the connected Google account and keep it linked to the signed-in Lemlii user and active Lemlii company.
- Let you select and display Google calendars and show Google events alongside Lemlii bookings, meetings, deadlines, payments, and blackout dates.
- Provide the calendar synchronization settings you choose. Lemlii creates, updates, or deletes Google Calendar events only when you direct or configure Lemlii to do so.
- Create a dedicated Lemlii calendar and, if you choose, share it with email addresses you specify.
Storage and security
Lemlii stores Google connection information, selected calendar metadata, synchronization preferences, and synchronized event records in its database. OAuth access and refresh tokens are encrypted using AES-256-GCM before they are stored and are decrypted only by Lemlii’s server-side calendar code when needed to operate the integration. Lemlii also uses HTTPS, access controls, and other reasonable technical and organizational measures designed to protect Google user data. No system can guarantee absolute security.
Sharing and transfers
Google user data may be processed by Lemlii’s infrastructure providers, including Vercel for application hosting and Supabase for database services, only as needed to operate and secure Lemlii. Lemlii does not sell Google user data or use it for targeted advertising, credit or lending decisions, or training generalized artificial-intelligence or machine-learning models.
Retention, disconnection, and deletion
Lemlii keeps OAuth credentials, selected calendar data, and synchronized event records while your Google Calendar connection is active. To disconnect, open Calendar, open Calendar settings, and choose Disconnect. Lemlii then stops synchronization, attempts to revoke the Google token, and deletes the locally stored OAuth credentials, Google calendar list, and imported Google event records even if Google is temporarily unavailable.
Disconnecting does not delete calendars or events already created in your Google account. Limited disconnected-account identifiers, integration preferences, and operational or audit records may be retained when reasonably needed for security, troubleshooting, legal, or compliance purposes. If your Lemlii account is deleted, Google connection and imported event records linked to that account are deleted, subject to any limited records Lemlii must retain for those purposes. You may request deletion of Google-derived data by emailing [email protected].
Your control and consent
You control which available Google calendars Lemlii reads and displays, which Lemlii event categories are synchronized to Google, and whether the integration remains connected. You may disconnect and withdraw access at any time. Before materially changing how it uses Google user data, Lemlii will provide notice and obtain consent for the new use.
Lemlii’s use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Lawful Bases for Processing
We only collect and process your personal data when we have a valid legal basis under the GDPR:
- Consent: We ask for consent before using optional analytics or advertising-measurement technologies and for other processing where consent is required. You may withdraw that consent at any time.
- Contractual Necessity: When you sign up and accept our Terms, a contract is formed between you and Lemlii. We process your personal data as needed to perform this contract.
- Legitimate Interests: We may process your data for purposes that are in our legitimate interests (e.g., improving our product, IT security), provided such processing does not override your rights.
- Legal Obligation: In some cases, we need to process and retain your data to comply with laws or regulations (e.g., tax records).
International Data Transfers
Lemlii is a Canadian company. If you are located in the EEA or UK, please be aware that your personal data will be transferred outside of Europe, including to Canada and the United States. Canada is recognized by the European Commission as providing an adequate level of data protection.
However, some of our data (including video content that you upload) is stored on servers located in the United States. We have implemented the European Commission’s Standard Contractual Clauses (SCCs) for data transfers with our US-based service providers to ensure GDPR-level privacy protections.
Service Providers
We use carefully selected service providers to support hosting, data storage, payments, communications, customer support, security, analytics, and advertising measurement. These providers may process only the information needed to perform services for Lemlii and are required to protect it. Optional analytics and advertising-measurement providers receive information only when the applicable consent has been given.
We use contractual and organizational safeguards appropriate to the services provided, including data-protection terms where required.
Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy. This generally means as long as you maintain an account with Lemlii. If you delete your account, we will erase or anonymize your personal information within a reasonable timeframe, barring legal retention requirements (such as tax laws).
Cookie preferences may be retained for up to one year. When optional measurement is accepted, first-touch campaign details may be retained for up to 90 days. Other records may be retained longer when required for security, contractual, financial, or legal obligations.
Data Security
Lemlii employs a variety of security measures including encryption of data in transit (SSL/TLS) and at rest, firewalls, and access controls. We limit access to personal information strictly to Lemlii personnel who need it to operate the Service.
Your Rights Under GDPR
If you are in the EEA or UK, you have the right to:
- Access your data
- Rectify inaccurate information
- Request erasure ("Right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
To exercise any of these rights, please contact us at [email protected].
Contact Us
Lemlii is headquartered in Canada. Our co-founder Lucas Bulger oversees data protection compliance.
Email: [email protected]
Address: Lemlii Inc., Guelph, Ontario, Canada.