Skip to main content
AIRIN
PricingSign in

LemonLime policy evolution

Before/after stance changes across captured policy versions, with exact citations. If no before/after delta is available yet, AIRIN shows the latest citation-backed stance events instead.

Diffs
0
Improved
0
Worsened
0
Changed
0
No before/after stance delta is available for this filter yet. Latest citation-backed stance events are shown below.
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

We have written this Policy to be as clear as we can. Because the language has to be precise, we summarize the most important points here. The full Policy below controls in case of any conflict. Our role: We are a B2B service provider. For most personal information we process about Customers’ end users and contacts, we act as a “processor” or “service provider” on behalf of our Customer, who decides what data goes into the Services and why. What we collect: Account, billing, and contact information from Customers; data Customers submit to the Services; data automatically generated when you use the Site or Services; and information from third-party sources, vendors, and AI model providers we work with. How we use it: To operate, secure, support, and improve the Services; to bill Customers; to communicate with you; to comply with law; and, in de-identified or aggregated form, to develop and improve our products. Sharing: With service providers and subprocessors (including third-party AI model providers and hosting providers), with Customers (where you are an end user), in connection with corporate transactions, and where required by law. We do not sell your personal information for monetary consideration. Some sharing for advertising or analytics may qualify as a “sale” or “share” under California law; you can opt out as described below. AI: We use third-party AI and machine-learning models to provide the Services.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

We have written this Policy to be as clear as we can. Because the language has to be precise, we summarize the most important points here. The full Policy below controls in case of any conflict. Our role: We are a B2B service provider. For most personal information we process about Customers’ end users and contacts, we act as a “processor” or “service provider” on behalf of our Customer, who decides what data goes into the Services and why. What we collect: Account, billing, and contact information from Customers; data Customers submit to the Services; data automatically generated when you use the Site or Services; and information from third-party sources, vendors, and AI model providers we work with. How we use it: To operate, secure, support, and improve the Services; to bill Customers; to communicate with you; to comply with law; and, in de-identified or aggregated form, to develop and improve our products. Sharing: With service providers and subprocessors (including third-party AI model providers and hosting providers), with Customers (where you are an end user), in connection with corporate transactions, and where required by law. We do not sell your personal information for monetary consideration. Some sharing for advertising or analytics may qualify as a “sale” or “share” under California law; you can opt out as described below. AI: We use third-party AI and machine-learning models to provide the Services.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

This Policy describes our processing of personal information in three main contexts: (a) when LemonLime is the “controller” or “business” — that is, when we determine the purposes and means of processing — for example, when you visit the Site, contact us, sign up for marketing communications, apply for a job, or are an authorized representative of a Customer; (b) when LemonLime acts as a “processor” or “service provider” — that is, when we process personal information on behalf of, and under the instructions of, a Customer (for example, end-user data submitted to the Services by Customer); and (c) when we receive personal information from third-party sources or partners as described in this Policy.
Open citation
Jul 20, 2026prompt ownershipmedium

data sharing

Latest stance: third party or vendor sharing

When you use the Site or the Services, we (and our service providers) automatically collect certain information about your device and how you interact with the Site and the Services, including: Device and connection data such as IP address, device type, operating system, browser type, mobile network information, time zone, language, and unique device identifiers. Usage and log data such as the pages or features you visit, the time and duration of your activities, the URL of the page that referred you to the Site, error and diagnostic logs, the actions you take in the Services, the prompts you submit, and the responses you receive. Cookies and similar technologies, as described in Section 5.
Open citation
Jul 20, 2026commercial usemedium

data sharing

Latest stance: third party or vendor sharing

We share personal information with the following categories of recipients: Service providers and subprocessors. We share personal information with vendors and contractors that perform services on our behalf, including cloud hosting and infrastructure providers, third-party AI model providers (such as foundation-model and large-language-model vendors), vector and traditional database providers, observability and analytics providers, payment processors, customer-relationship-management providers, communications providers, security and fraud-prevention vendors, and professional advisors. These providers are bound by contractual obligations to use personal information only as necessary to provide services to us and to protect it appropriately. Customers. Where you are an end user, contact, employee, or lead of a Customer, we share personal information with that Customer as part of providing the Services. Affiliates. We may share personal information with our parent, subsidiaries, and other corporate affiliates, who will use it consistent with this Policy. Business partners. We may share personal information with resellers, integrators, technology partners, and other business partners where you have requested an integration or where doing so is necessary to provide the Services. Legal and compliance recipients. We may share personal information with law-enforcement, regulatory, or other governmental authorities, courts, and other parties as required by law, subpoena, court order, or other legal process; to enforce our agreements; to protect our rights, property, or safety, or those of our Customers or others; and to investigate or prevent illegal activity, fraud, or violations of our policies.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

Corporate transactions. If LemonLime is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of services to another provider, personal information may be shared, sold, or transferred as part of that transaction. With your direction or consent. We may share personal information for other purposes with your consent or at your direction. De-identified or aggregated data. We may share de-identified or aggregated information that cannot reasonably be used to identify you with third parties for any lawful purpose.
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

Security, monitoring, and observability: Oneleet (compliance and security monitoring); Vercel (deployment + edge observability); Sentry (application error tracking, with personal information redacted where feasible). Source code and CI/CD: GitHub (source code, issue tracking, deployment pipelines). Each subprocessor is bound by contract to use personal information only on our documented instructions, to maintain appropriate security measures, and to assist us in meeting our obligations to Customers and individuals. For a current comprehensive list, or to request prior notice of subprocessor changes, contact [email protected] .
Open citation
Jul 20, 2026traininghigh

data sharing

Latest stance: sale or sell

When a Customer or end user authorizes the Services to connect to Google Workspace — including Gmail, Google Drive, or Google Calendar — LemonLime requests OAuth access only to the scopes required to deliver the feature the user enabled, and uses the data received from those APIs only for the purpose the user authorized. LemonLime’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements. Specifically, LemonLime does not: transfer or sell Google user data to third parties such as advertising platforms, data brokers, or any information resellers; transfer, sell, or use Google user data for serving ads, including retargeting, personalized, or interest-based advertising; transfer, sell, or use Google user data to determine creditworthiness or for lending purposes; and transfer, sell, or use Google user data to create, train, or improve any generalized or non-personalized AI or machine-learning model. Where a user has explicitly enabled a feature that uses Google data to train or fine-tune a model scoped to that user, the resulting model is isolated to that user and is not used to serve other users. Scopes we request and why. The specific scopes requested are presented to you in Google’s OAuth consent screen at the time you authorize the integration. The features those scopes power, and the data we store as a result, are documented at the point of authorization and again in our in-product integration settings.
Open citation
Jul 20, 2026trainingmedium

data sharing

Latest stance: third party or vendor sharing

When a Customer or end user authorizes the Services to connect to Google Workspace — including Gmail, Google Drive, or Google Calendar — LemonLime requests OAuth access only to the scopes required to deliver the feature the user enabled, and uses the data received from those APIs only for the purpose the user authorized. LemonLime’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements. Specifically, LemonLime does not: transfer or sell Google user data to third parties such as advertising platforms, data brokers, or any information resellers; transfer, sell, or use Google user data for serving ads, including retargeting, personalized, or interest-based advertising; transfer, sell, or use Google user data to determine creditworthiness or for lending purposes; and transfer, sell, or use Google user data to create, train, or improve any generalized or non-personalized AI or machine-learning model. Where a user has explicitly enabled a feature that uses Google data to train or fine-tune a model scoped to that user, the resulting model is isolated to that user and is not used to serve other users. Scopes we request and why. The specific scopes requested are presented to you in Google’s OAuth consent screen at the time you authorize the integration. The features those scopes power, and the data we store as a result, are documented at the point of authorization and again in our in-product integration settings.
Open citation
Jul 20, 2026traininghigh

data sharing

Latest stance: sale or sell

When a Customer or end user authorizes the Services to connect to a Slack workspace, LemonLime requests OAuth scopes only as required to deliver the feature the user enabled, clearly describes the scope use in our App Directory listing, and uses Slack data exclusively for the purpose the user authorized. Real-time access; no persistent storage of Slack content. Consistent with the Slack API Terms of Service, LemonLime accesses Slack content in real time to answer a user’s request at the moment it is made, and does not create persistent copies, archives, indexes, or long-term data stores of Slack messages, files, or other Slack content. Any handling or caching of Slack content is limited to what is essential for the immediate operation of the requested feature, is minimized, and is deleted promptly once the request is served. This treatment is specific to Slack; other connected sources may, with the Customer’s authorization, be indexed as described in Section 6.9. With respect to data received from the Slack API, LemonLime: does not use Slack data to train any large language model, foundation model, or other AI or machine-learning model — under any circumstances, on any tier; does not create persistent copies, archives, indexes, or long-term stores of Slack content, and does not bulk-export Slack data; does not rent, sell, share, or otherwise transfer Slack data to any third party except (a) to subprocessors strictly required to deliver the feature the user enabled and (b) where required by law; does not use Slack data for advertising, retargeting, interest-based targeting, or to contact users for marketing purposes; does not combine Slack data with external data sources for purposes unrelated to the authorized feature; and does not use one organization’s Slack
Open citation
Jul 20, 2026trainingmedium

data sharing

Latest stance: third party or vendor sharing

When a Customer or end user authorizes the Services to connect to a Slack workspace, LemonLime requests OAuth scopes only as required to deliver the feature the user enabled, clearly describes the scope use in our App Directory listing, and uses Slack data exclusively for the purpose the user authorized. Real-time access; no persistent storage of Slack content. Consistent with the Slack API Terms of Service, LemonLime accesses Slack content in real time to answer a user’s request at the moment it is made, and does not create persistent copies, archives, indexes, or long-term data stores of Slack messages, files, or other Slack content. Any handling or caching of Slack content is limited to what is essential for the immediate operation of the requested feature, is minimized, and is deleted promptly once the request is served. This treatment is specific to Slack; other connected sources may, with the Customer’s authorization, be indexed as described in Section 6.9. With respect to data received from the Slack API, LemonLime: does not use Slack data to train any large language model, foundation model, or other AI or machine-learning model — under any circumstances, on any tier; does not create persistent copies, archives, indexes, or long-term stores of Slack content, and does not bulk-export Slack data; does not rent, sell, share, or otherwise transfer Slack data to any third party except (a) to subprocessors strictly required to deliver the feature the user enabled and (b) where required by law; does not use Slack data for advertising, retargeting, interest-based targeting, or to contact users for marketing purposes; does not combine Slack data with external data sources for purposes unrelated to the authorized feature; and does not use one organization’s Slack
Open citation
Jul 20, 2026traininghigh

data sharing

Latest stance: sale or sell

Where a Customer or end user authorizes LemonLime to connect to another third-party tool (for example, HubSpot, Salesforce, Notion, GitHub, Linear, Stripe, or a custom system the Customer operates), the same general commitments apply: we request only the scopes required to deliver the authorized feature, we do not use that data to train generalized AI or machine-learning models, we do not sell or share that data for advertising, and we delete data from our active systems when the integration is uninstalled or the underlying account is deleted. Specific scope use, retention, and deletion behavior is documented in our in-product integration settings at the point of authorization.
Open citation
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

We do not sell personal information for monetary consideration. Like many businesses, however, we use third-party advertising and analytics Cookies on the Site, which may constitute a “sale” or “sharing” of personal information for cross-context behavioral advertising under the CCPA. California residents may opt out of these activities by using the “Do Not Sell or Share My Personal Information” link or cookie-preferences tool on the Site, by emailing us at [email protected] , or by sending a Global Privacy Control (GPC) signal in a supported browser. We do not knowingly sell or share for cross-context behavioral advertising the personal information of consumers under the age of sixteen (16).
Open citation
Jul 20, 2026privacymedium

data sharing

Latest stance: third party or vendor sharing

California Civil Code Section 1798.83 entitles California residents to request information about the disclosure of certain categories of personal information to third parties for their direct-marketing purposes. We do not share personal information with third parties for their own direct-marketing purposes. To make such a request, contact us at [email protected] .
Open citation
Jul 20, 2026retentionhigh

data sharing

Latest stance: sale or sell

Residents of certain other U.S. states (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) may have rights under their state privacy laws similar to those described in Section 8 and Section 9, including rights to access, correct, delete, port, and opt out of certain processing of their personal information. To exercise these rights, contact us at [email protected] . We will respond within the time period required by applicable law and may verify your identity before responding. If we deny your request, you may have the right to appeal that decision; instructions for appealing will be included in our response. Nevada residents: Nevada law allows residents to opt out of the sale of certain “covered information.” We do not sell covered information as defined under Nevada law. If you have questions about our Nevada privacy practices, please contact us at [email protected] .
Open citation
Jul 20, 2026indemnity / liabilitymedium

legal burden

Latest stance: indemnity

To comply with our legal, regulatory, and contractual obligations, respond to lawful requests from public authorities, and exercise or defend legal claims. Recruiting. To evaluate your application for employment, contact you about open positions, and (with your consent) keep your application on file for future opportunities. Corporate transactions. To facilitate due diligence and consummate any merger, acquisition, financing, restructuring, sale of assets, or similar transaction.
Open citation
Jul 20, 2026traininglow

model training

Latest stance: no training claim

LemonLime does not train our own models on identifiable Customer Data. Whether a third-party model provider may use data routed to it is governed by that provider’s own terms; where they offer a no-training setting, we generally configure our integration to use it. See Section 6.2. Your rights: Depending on where you live, you may have rights to access, correct, delete, port, or limit our use of your personal information. See Section 8.
Open citation
Jul 20, 2026traininglow

model training

Latest stance: no training claim

LemonLime does not train, fine-tune, or improve our own (or any shared or foundational) AI or machine-learning models on Customer Data — in identifiable, de-identified, or aggregated form. We do not share Customer Data in identifiable form between Customers. When Customer Data is routed to a third-party AI provider to generate a response (for example, OpenAI, Anthropic, Google, Meta, xAI, Perplexity, or Microsoft), whether that provider may use the data to train or improve its own models is governed by that provider’s own terms and default configuration, not by LemonLime. Where a provider offers a no-training setting, enterprise API tier, or zero-retention option, we generally configure our integration to use it. Customers are responsible for reviewing the terms of any specific model they direct LemonLime to route Customer Data through, and may restrict which models we route their data to through in-product settings. A Customer may also explicitly opt in to a feature that involves training a model on that Customer’s own data for that Customer’s own use (for example, a Customer-specific fine-tune or retrieval embedding). When a Customer does so, the resulting model artifacts are isolated to that Customer’s tenancy and are not used to serve other Customers.
Open citation
Jul 20, 2026traininglow

model training

Latest stance: no training claim

We may use de-identified, aggregated, or anonymized data derived from Customer Data and from your use of the Services to operate, secure, troubleshoot, analyze, and improve the Services. We do not use Customer Data — in identifiable, de-identified, or aggregated form — to train, fine-tune, or improve our own (or any shared or foundational) AI or machine-learning models. Where required by law or by our contract with a Customer, we will provide a means to opt out of certain forms of service-improvement processing. Customers can contact us at the email addresses below to discuss available options.
Open citation
Jul 20, 2026trainingmedium

model training

Latest stance: training with opt out

We may use de-identified, aggregated, or anonymized data derived from Customer Data and from your use of the Services to operate, secure, troubleshoot, analyze, and improve the Services. We do not use Customer Data — in identifiable, de-identified, or aggregated form — to train, fine-tune, or improve our own (or any shared or foundational) AI or machine-learning models. Where required by law or by our contract with a Customer, we will provide a means to opt out of certain forms of service-improvement processing. Customers can contact us at the email addresses below to discuss available options.
Open citation
Jul 20, 2026trainingmedium

model training

Latest stance: training with opt out

We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to provide the Services, comply with our legal, accounting, tax, or reporting obligations, resolve disputes, enforce our agreements, and operate our business. Specific retention periods depend on the type of information and the context in which it was collected, and may include: for active accounts and Customer Data, the duration of the Customer relationship plus a reasonable period afterward (typically not exceeding ninety (90) days unless retention is required by law or our contract with the Customer); for billing and tax records, the period required by applicable accounting and tax laws; for sales and marketing data, until you opt out or until the data is no longer reasonably useful for those purposes; for support communications, the period necessary to resolve the matter and to maintain a record for quality, training, and audit purposes; for security, audit, and legal-claim purposes, the period necessary to investigate and resolve issues, and to satisfy applicable statutes of limitation; and for recruiting data, the duration of the recruiting process plus, where you consent, a reasonable additional period for future opportunities. When personal information is no longer required, we delete it or de-identify it, except that we may retain de-identified or aggregated information indefinitely.
Open citation
Jul 20, 2026traininghigh

model training

Latest stance: training permitted

When a Customer or end user authorizes the Services to connect to Google Workspace — including Gmail, Google Drive, or Google Calendar — LemonLime requests OAuth access only to the scopes required to deliver the feature the user enabled, and uses the data received from those APIs only for the purpose the user authorized. LemonLime’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements. Specifically, LemonLime does not: transfer or sell Google user data to third parties such as advertising platforms, data brokers, or any information resellers; transfer, sell, or use Google user data for serving ads, including retargeting, personalized, or interest-based advertising; transfer, sell, or use Google user data to determine creditworthiness or for lending purposes; and transfer, sell, or use Google user data to create, train, or improve any generalized or non-personalized AI or machine-learning model. Where a user has explicitly enabled a feature that uses Google data to train or fine-tune a model scoped to that user, the resulting model is isolated to that user and is not used to serve other users. Scopes we request and why. The specific scopes requested are presented to you in Google’s OAuth consent screen at the time you authorize the integration. The features those scopes power, and the data we store as a result, are documented at the point of authorization and again in our in-product integration settings.
Open citation
Jul 20, 2026traininglow

model training

Latest stance: no training claim

When a Customer or end user authorizes the Services to connect to a Slack workspace, LemonLime requests OAuth scopes only as required to deliver the feature the user enabled, clearly describes the scope use in our App Directory listing, and uses Slack data exclusively for the purpose the user authorized. Real-time access; no persistent storage of Slack content. Consistent with the Slack API Terms of Service, LemonLime accesses Slack content in real time to answer a user’s request at the moment it is made, and does not create persistent copies, archives, indexes, or long-term data stores of Slack messages, files, or other Slack content. Any handling or caching of Slack content is limited to what is essential for the immediate operation of the requested feature, is minimized, and is deleted promptly once the request is served. This treatment is specific to Slack; other connected sources may, with the Customer’s authorization, be indexed as described in Section 6.9. With respect to data received from the Slack API, LemonLime: does not use Slack data to train any large language model, foundation model, or other AI or machine-learning model — under any circumstances, on any tier; does not create persistent copies, archives, indexes, or long-term stores of Slack content, and does not bulk-export Slack data; does not rent, sell, share, or otherwise transfer Slack data to any third party except (a) to subprocessors strictly required to deliver the feature the user enabled and (b) where required by law; does not use Slack data for advertising, retargeting, interest-based targeting, or to contact users for marketing purposes; does not combine Slack data with external data sources for purposes unrelated to the authorized feature; and does not use one organization’s Slack
Open citation
Jul 20, 2026traininglow

model training

Latest stance: no training claim

Where a Customer or end user authorizes LemonLime to connect to another third-party tool (for example, HubSpot, Salesforce, Notion, GitHub, Linear, Stripe, or a custom system the Customer operates), the same general commitments apply: we request only the scopes required to deliver the authorized feature, we do not use that data to train generalized AI or machine-learning models, we do not sell or share that data for advertising, and we delete data from our active systems when the integration is uninstalled or the underlying account is deleted. Specific scope use, retention, and deletion behavior is documented in our in-product integration settings at the point of authorization.
Open citation

Generated from live stance events. Informational only, not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.