Legal
Privacy policy
How we handle personal data on the ls.bot website and the hosted Lightspeed platform. Last updated 29 August 2026.
1. Who is responsible
The controller for personal data processed through the ls.bot website and the hosted Lightspeed platform is:
Smart Computer AGhello@smartcomputer.company
This policy follows the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies to you, it also provides the information required under that regulation.
2. The website
The website is a static site. It sets no cookies, uses no analytics or tracking, and loads no fonts, scripts or media from third parties.
When you visit, our web server records technical access data — your IP address, the time of the request, the address requested, the referring page and your browser's user-agent string — in server logs. We use these logs only to keep the site running securely and to diagnose problems, based on our legitimate interest in operating the site. Logs are kept for a limited period, typically no longer than 30 days.
If you contact us by email, we process the data you send us in order to answer you. We keep correspondence as long as needed for that purpose and for any legal retention duties.
3. The hosted platform
The platform is open by invitation only. When you use it, we process the following categories of data:
- Account and invitation data. When you sign in with GitHub we receive your GitHub user ID, username, display name, email address and avatar. We also keep a record of who invited you and when.
- Your content. Instructions, prompts, files, repositories, messages and any other data you or your agents submit or connect, and the output your agents produce.
- Connections and credentials. Access tokens and grants for the channels and integrations you connect (for example GitHub repositories, Telegram or MCP servers). We store them only to perform the connections you set up.
- Execution and audit data. Workflow histories, agent transcripts, logs and audit trails that the platform records so that agent runs are durable, reproducible and reviewable.
- Technical data. IP addresses, timestamps and request logs, as for the website.
Purposes and legal bases. We process this data to provide and operate the platform for you (performance of a contract), to keep it secure and prevent abuse (legitimate interest), to communicate with you about your account and the early-access programme (contract and legitimate interest), and to meet legal obligations. We do not use your content to train AI models, and we do not sell personal data.
4. Who receives data
We share personal data only with providers we need in order to run the services, and only to the extent required:
- Hosting. The website and the platform run on servers we rent from Hetzner Online GmbH. Platform data, including databases, object storage and backups, is stored there.
- AI model providers. To generate agent responses, the platform sends the relevant parts of your content — prompts, context and tool results — to third-party model providers, currently OpenRouter, OpenAI and Anthropic. They process that data under their own terms and privacy policies.
- Identity provider. GitHub, for sign-in.
- Services you connect. Repositories, channels and integrations you connect exchange data with the platform according to your configuration and their own terms.
Some of these providers are located outside Switzerland and the EU/EEA, in particular in the United States. Where we transfer personal data to such countries, we rely on the safeguards recognised under Swiss and EU law, such as standard contractual clauses, or on an adequacy decision or certification such as the Swiss-U.S. Data Privacy Framework where the recipient is covered.
5. How long we keep data
- Account data and your content: for as long as your account exists. After you delete your account or we close it, we delete this data within 30 days, except where we must keep it for legal reasons.
- Backups: platform backups rotate on a fixed schedule; data deleted from the platform disappears from backups as they rotate.
- Server logs: typically no longer than 30 days.
- End of early access: we may reset the platform when the early-access phase ends. We will inform account holders in advance and, where reasonably possible, offer a way to export their data first.
6. Security
Data is transmitted over encrypted connections (TLS). Platform workloads run tenant-isolated, access to production systems is restricted to the people who operate them, and agent runs are recorded so that their actions can be audited. No system is completely secure; if you believe your data has been compromised, contact us immediately.
7. Your rights
Under the FADP and, where applicable, the GDPR, you can ask us for access to the personal data we hold about you, for rectification or erasure, to restrict or object to processing, and to receive data you provided in a portable format. Where processing is based on consent, you can withdraw it at any time. To exercise these rights, write to hello@smartcomputer.company. You also have the right to complain to a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or the data protection authority of your EU/EEA country.
8. Changes
We will update this policy as the services evolve and publish the current version here with its date.
9. Contact
Privacy questions and requests: hello@smartcomputer.company. Company details are in the imprint.