Privacy Policy
Effective date: March 24, 2026 · Last updated: March 24, 2026
This Privacy Policy describes how LOCALIZE AI LLC (“l6e,” “l6e ai,” “we,” “us,” or “our”) collects, uses, and protects your information when you use the l6e website at l6e.ai, the l6e dashboard at app.l6e.ai, the l6e API at api.l6e.ai, and the l6e MCP server software (collectively, the “Service”).
By using the Service, you agree to the practices described in this Privacy Policy.
1. Information We Collect
1.1 Account Information
When you create an account via GitHub OAuth, we receive and store:
- Your GitHub display name
- Your GitHub email address (used as your account identifier)
- Your GitHub avatar URL
We do not receive or store your GitHub password or access tokens beyond the initial authentication flow.
1.2 Session Metadata (Cloud Sync)
When cloud sync is enabled, the l6e MCP server sends session metadata to l6e Cloud:
| Data | Collected | Notes |
|---|---|---|
| Session ID and timestamps | Yes | When the session started and ended |
| Model and client identifiers | Yes | Which LLM model and MCP client were used |
| Per-call token estimates | Yes | Estimates your agent provides at each checkpoint |
| Per-call gate decisions | Yes | allow, reroute, halt for each call |
| Total estimated cost | Yes | Accumulated estimated spend for the session |
| Task summaries | Configurable | Short labels synced by default. Set L6E_SEND_TASK_SUMMARIES=false to omit. |
| Prompts and completions | Never | l6e never sees or stores prompt content |
| Source code | Never | l6e has no access to your codebase |
| LLM responses | Never | l6e does not intercept LLM API calls |
Cloud sync is opt-in — it requires you to set L6E_CLOUD_SYNC=1 and provide an API key. Without cloud sync, all session data stays on your local machine.
1.3 Billing Import Data
If you use the reconciliation feature, you may upload billing CSV files from your LLM provider. These files contain usage and cost data from your provider account. We store this data to compute calibration factors and match sessions against actual costs.
1.4 API Keys
We store a cryptographic hash and a short prefix of each API key you create. We do not store the raw API key — it is shown to you once at creation and cannot be retrieved.
1.5 Profile and Preferences
We store your display name and preference settings, including notification preferences and your community calibration opt-in status.
1.6 Usage and Analytics
We use Plausible Analytics on l6e.ai for privacy-friendly, cookie-free website analytics. Plausible does not use cookies, does not collect personal data, and is compliant with GDPR, CCPA, and PECR.
2. Information We Never Collect
This is as important as what we do collect:
- Prompts and completions — l6e never receives, transmits, stores, or has access to the content of your AI conversations.
- Source code — l6e has no mechanism to access your codebase, files, or repositories.
- LLM provider credentials — l6e does not store or interact with your Anthropic, OpenAI, Google, or other provider API keys.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service — enforce budget gates, display run history, compute calibration factors, perform reconciliation.
- Improve accuracy — use your billing imports to compute your personal calibration factor.
- Communicate with you — respond to support inquiries, send service-related notices.
- Maintain and improve the Service — monitor performance, fix bugs, develop new features.
- Community calibration — if you opt in, contribute anonymized aggregate model multipliers to improve calibration for all users. No session content, cost data, task summaries, or personally identifiable information is shared.
4. Data Sharing and Disclosure
We do not sell your personal information. We share information only in these circumstances:
- Service providers — We use Supabase for authentication and database services, and Plausible for website analytics. These providers process data on our behalf under contractual obligations.
- Community calibration — If you opt in, anonymized calibration multipliers (not personal data) are aggregated to improve calibration for all users.
- Legal requirements — We may disclose information if required by law, subpoena, or legal process.
- Business transfers — In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
5. Data Security
We implement reasonable technical and organizational measures to protect your data:
- API keys are stored as cryptographic hashes — raw keys are never persisted.
- All data in transit is encrypted via TLS.
- Database access is restricted by row-level security policies.
- Authentication uses industry-standard OAuth 2.0 via Supabase Auth.
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Data Retention and Deletion
- Session data is retained for as long as your account is active.
- Billing import data is retained for as long as your account is active or until you delete it.
- Account deletion permanently removes all associated data: your profile, API keys, run history, billing imports, reconciliation records, and calibration data. Account deletion is available in Settings and is irreversible.
After account deletion, we may retain anonymized, aggregated data that cannot be linked back to you (such as community calibration factors computed before deletion).
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate personal information.
- Delete your personal information (see Section 6).
- Export your data — run history and session data are accessible via the l6e API.
- Opt out of community calibration at any time via Settings.
- Withdraw consent for cloud sync by removing
L6E_CLOUD_SYNCfrom your configuration.
To exercise these rights, contact us at hello@l6e.ai or use the controls in the dashboard at app.l6e.ai.
7.1 California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request deletion of your personal information, and to not be discriminated against for exercising your rights. We do not sell personal information.
7.2 European Residents (GDPR)
If you are located in the European Economic Area, our legal basis for processing your personal information is:
- Contract performance — processing necessary to provide the Service you requested.
- Legitimate interests — improving Service accuracy and security.
- Consent — community calibration and optional task summary sync.
You have the right to lodge a complaint with your local data protection authority.
8. Children’s Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children. If we learn we have collected information from a child under 13, we will delete it promptly.
9. International Data Transfers
l6e is operated from the United States. If you use the Service from outside the United States, your information may be transferred to and processed in the United States. By using the Service, you consent to this transfer.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, for significant changes, provide notice via the dashboard or email.
11. Contact
If you have questions about this Privacy Policy, contact us at:
LOCALIZE AI LLC
Email: hello@l6e.ai
GitHub: github.com/l6e-ai