Privacy Policy
Last updated: July 2026
1. Controller
The controller responsible for data processing on this website is:
Dr. Changkun Ou
Munich, Germany
Email: contact@latere.ai
2. What Data We Collect
We collect the minimum data necessary to operate Latere, including the latere.ai website, the latere CLI, and the Latere products: Wallfacer, Topos, Cella, Lux, Lectio, Drive, and Latere Identity:
- Server logs — Your IP address, browser type, request metadata, and pages visited are temporarily logged for security and operational purposes. These logs are deleted automatically after 7 days unless longer retention is required to investigate abuse or security incidents.
- Contact data — If you email us, we store your email address and message content to respond to your inquiry.
- Account and identity data — If you sign in, we process your email address, name where provided, federated login identifiers, organization membership, roles, consent records, session metadata, invitation status, and token metadata needed for OAuth/OIDC flows.
- CLI data — The latere CLI stores its login token on your own machine by default. When the CLI talks to Latere services, we process the authentication, authorization, and command metadata needed to fulfill the request.
- Cella data — If you use Cella, we process sandbox names, lifecycle state, command requests, command output and logs, file import/export payloads, workspace data, selected images, non-secret environment variables, credential-catalog keys, resource usage, audit events, and billing-relevant usage metrics.
- Wallfacer data — Wallfacer is primarily a local product. By default, local workspaces, prompts, credentials, logs, and model-provider configuration stay on your machine. If you connect Wallfacer to Latere cloud features, Latere Identity, Cella, or another hosted service, the data needed for that connected feature is processed by the relevant service.
- Topos data — If you use Topos, we process agent-run metadata, task and session records, policy configuration, approval decisions, and audit events needed to supervise and govern agent activity in your organization.
- Lux data — If you use Lux, we process virtual-key metadata, routing configuration, budget and quota state, and request metadata (model, token counts, latency, status) needed to route requests to model providers and enforce your policies. Prompt and completion contents pass through to the model provider you selected; we retain them only where you enable logging features that require it.
- Lectio data — If you use Lectio, we process the documents you submit for extraction, the structured data produced from them, and job metadata. Documents and outputs are retained according to your workspace settings and deleted on your instruction.
- Drive data — If you use Drive, we store the files you and your agents upload or create, file metadata, sharing and permission records, and version history, for as long as you keep them in your Drive.
- Billing data — If you use paid features, we process customer, subscription, plan, invoice, payment-method metadata, and metered usage records. Card numbers are handled by Stripe; Latere does not store full card numbers.
We do not use your code, prompts, files, command output, or project data to train models. We do not sell your personal data.
3. Legal Basis for Processing (Art. 6 GDPR)
- Art. 6(1)(b) — Processing necessary for the performance of a contract (e.g., providing our services to you).
- Art. 6(1)(f) — Processing based on our legitimate interest in operating and securing our website and services.
- Art. 6(1)(a) — Where applicable, processing based on your consent, which you may withdraw at any time.
- Art. 6(1)(c) — Processing necessary to comply with legal obligations, including accounting, tax, and security obligations.
4. Data Recipients
We do not sell your data. Your data may be shared with:
- Hosting and infrastructure providers — We use infrastructure providers to host websites, APIs, databases, storage, logs, and observability systems.
- Identity providers — If you sign in with a third-party provider such as Google, GitHub, or X, that provider processes the login according to its own terms and privacy policy.
- Email providers — We use email delivery providers for login codes, invitations, and service messages.
- Payment providers — Stripe processes payment details, billing portal sessions, subscriptions, and invoices where paid features are used.
- LLM and developer-service providers — If you configure or use features that call third-party LLMs or source-control providers, relevant prompts, code, files, outputs, or scoped credentials may be sent to those providers as necessary to provide the feature. Local Wallfacer usage communicates from your own machine unless you connect it to Latere cloud services.
If data is transferred outside the EU/EEA, we rely on appropriate safeguards under Art. 46 GDPR where required, such as Standard Contractual Clauses.
5. Cookies and Local Storage
The public latere.ai website does not use third-party analytics cookies or tracking. It stores your display preferences in your own browser: a first-party latere-lang cookie (kept for up to one year) so pages render in your chosen language, and local storage entries for your language and theme choice. These hold no personal data beyond the preference itself and are never shared with third parties. Authenticated areas may additionally use strictly necessary cookies, local storage, or similar browser storage for login sessions, CSRF protection, preferences, and security. These are required for the service to work.
6. Data Retention
- Server logs: 7 days
- Contact emails: until your inquiry is resolved, then deleted within 6 months unless a longer retention is legally required
- Account data: for the duration of your account; deleted within 30 days of account closure
- Cella sandbox and workspace data: retained according to the sandbox tier, user deletion, auto-delete deadline, workspace policy, or contract terms
- Command logs, audit events, and usage records: retained as needed for security, debugging, abuse prevention, billing, and legal obligations
- Billing records: retained for the legally required accounting and tax retention period
7. Your Rights (Art. 15–21 GDPR)
You have the right to:
- Access (Art. 15) — Request a copy of the personal data we hold about you.
- Rectification (Art. 16) — Request correction of inaccurate data.
- Erasure (Art. 17) — Request deletion of your personal data ("right to be forgotten").
- Restriction (Art. 18) — Request restriction of processing.
- Data portability (Art. 20) — Request your data in a structured, machine-readable format.
- Objection (Art. 21) — Object to processing based on legitimate interests.
- Withdraw consent (Art. 7(3)) — Where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email contact@latere.ai. We will respond within 30 days.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority for Bavaria is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
9. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. Material changes will be communicated via email where possible.
10. Contact
For any questions about this privacy policy or your data, contact us at contact@latere.ai.