li-quid

Privacy Policy

Last updated: 7 October 2026

This policy explains what personal data Li-quid at li-quid.app ("Li-quid", "the service") processes, why, and what your rights are. Li-quid is a project management and time tracking tool used by the LI Solutions team and by the people it invites.

Who is responsible

The service is operated by LI Solutions OÜ, a company registered in Estonia ("we", "us"). We are the controller of the personal data described here.

If you were invited to a workspace run by another organisation, such as a client, that organisation decides what goes into its workspace. We process that workspace's content on its behalf, and you can also contact that organisation about it.

For anything in this policy, including requests about your data, contact us through the form at li.solutions/contact-us.

What we process

Account data. Your name, email address, password (stored only as a secure hash), role and workspace memberships, and when you last signed in. If you sign in with Google, we also store your Google account ID and the email address of that Google account.

Content you create. Issues, comments, documents, attachments, time entries and anything else you or your colleagues enter in a workspace.

Team and time off data. If your workspace uses the Team section: job title, department, manager, start date, country (for public holidays), birthday (day and month only, and you can hide it), vacation allowances, and leave requests with their dates, type (such as vacation, day off or sick leave) and an optional note. We don't ask for medical reasons; please don't put them in the note.

Emails. The service emails you about your account (invitations, sign-in links and password resets) and about things that need you: an @mention, with a short plain-text quote of the comment, an issue assigned to you, an agent waiting for your answer, a time off request you may approve (with the requester's note) and the decision on your own request. Mentions, assignments and agents' questions are emailed only if you haven't seen them in the service within a few minutes; status changes and other updates are never emailed. Emails carry no attachments. We keep a record of each email (address, type, the references needed to build it, and whether it was delivered) for 30 days. You can turn off each kind of notification email in Settings → Account → Email or with the unsubscribe link in every one of them; account emails can't be turned off.

Data from Google. When you choose Sign in with Google, Google shares your name, email address, Google account ID and whether Google has verified the address. We do not store Google access tokens or your Google profile photo from sign-in. When a workspace admin imports people from their Google Workspace directory, we receive each person's name, email address, job title, department, manager and photo, and, if the admin maps them, birthday, start date and country.

Technical data. Your IP address and your browser's user agent. Both are recorded with each sign-in session and in our web server logs, and the IP address is used to limit sign-in attempts. When something breaks, an error report is sent to our own error tracking server. These reports contain technical details and can include your user ID and browser; request bodies, cookies, IP addresses and query strings are removed from them.

Cookies

We use only cookies that the service needs to work: a session cookie that keeps you signed in, short-lived cookies that protect the Sign in with Google flow and an admin's Google Workspace connection, a short-lived cookie that lets an instance administrator return to their own account, and a cookie that remembers how you like the issue panel laid out. We do not use analytics, advertising or third-party tracking cookies.

Why we process it and on what legal basis

  • To provide the service to you and your workspace, including sign-in, collaboration, notification emails, time tracking and reports: performance of a contract (GDPR Art. 6(1)(b)), or our and your organisation's legitimate interest in running the tool your team uses (Art. 6(1)(f)).
  • To manage work time, time off and holidays for members of our team: the employment or service contract (Art. 6(1)(b)) and legal obligations (Art. 6(1)(c)). Where sick leave is recorded, we process it to meet employment obligations (Art. 9(2)(b)).
  • To keep the service secure, prevent abuse and fix errors: our legitimate interest (Art. 6(1)(f)).

Who receives the data

We do not sell personal data or use it for advertising. Inside the service, other members of your workspace see content according to their roles. Our instance administrators can sign in as you for up to an hour at a time, to check what you can see or to help you; each time is recorded in the administrative log, and they can't change your sign-in details while doing so. We use these service providers:

  • Hetzner Online GmbH hosts the servers, in Germany.
  • Cloudflare, Inc. provides DNS and the network in front of the service, and processes IP addresses and requests to deliver and protect it. On the sign-in, password reset and contact forms it also runs Turnstile, a check that tells people from bots: your browser loads it from Cloudflare, which looks at technical signals from the browser and your IP address. Turnstile sets no cookies.
  • Google delivers the service's emails, and so processes each email's recipient address and content. Otherwise it is involved only when you use Sign in with Google, or when a workspace admin connects Google Workspace.

When a workspace admin imports public holidays, the service asks a public holiday service for a country and a year. No personal data is sent.

Workspace admins can also connect optional integrations: webhooks for AI agents, external error trackers, and the built-in coding agent, which works with Anthropic's API and GitHub. These are off unless an admin turns them on. When they are on, the data they need, such as the content of the issues they work on, is shared with those services.

Transfers outside the EU

Our servers and backups are in the EU. Cloudflare and Google may process data outside the European Economic Area. Where they do, the transfer is covered by the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

How long we keep it

  • Account data, including the IP address and browser recorded with your sign-in sessions: for as long as your account exists. We delete an account when you ask us to.
  • Workspace content: for as long as the workspace exists. When a workspace is deleted, its content leaves the live system right away.
  • A log of administrative actions, such as who changed roles or removed members, keeps the names and email addresses of the people involved for accountability, also after their accounts are deleted.
  • Backups: nightly backups are kept for 14 days. Backups made before software upgrades may be kept longer, until we remove them.
  • Web server logs: about two weeks.
  • Records of sent emails: 30 days.

Security

The service is only available over encrypted connections. Passwords are stored as hashes, stored secrets such as integration keys are encrypted, access to the servers is restricted, and backups are checked after they are written.

Your rights

Under the GDPR you can ask us for access to your personal data, and for its correction, deletion, restriction, or a copy in a portable format. You can also object to processing based on legitimate interests. Send your request through li.solutions/contact-us. We will answer within one month.

You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or to the data protection authority where you live or work.

Children

The service is not intended for anyone under 16.

Changes

We will update this page when our practices change and change the date at the top. For significant changes we will let you know in the service or through your organisation.