Legal
Privacy
Last updated 1 September 2026
The short version
Your AI worker runs on a private server that belongs to your account alone. Your files, your messages and the accounts you connect stay inside that space. We do not sell your data, we do not share it with advertisers, and we do not use it to train AI models.
One thing we want to say plainly rather than bury: to answer you, your worker sends the relevant part of a conversation to an AI model provider. That is how the thinking happens. What we send, who we send it to, and what they may do with it is set out under Sending your data to an AI model below.
Who we are
Lionox is a service provided by Lionox LLC, 650 James St, Lakewood, NJ 08701. We provide personal AI workers, each on its own private server. Lionox LLC is the company responsible for the information described on this page.
Lionox is an independent service and is not affiliated with WhatsApp, Meta, Google, or any messaging platform. You can reach us at support@lionox.io, or by post at the address above.
What we collect
- Account details — your email address and the password you set, so you can sign in.
- Billing details — handled by our payment processor. We store the plan you are on, your credit balance and the status of your subscription. We do not store your card number.
- Service data — the conversations you have with your worker, the files it works with, the notes and skills it builds up, and the data it reads from accounts you have connected. This lives on your private server.
- Connected account credentials — the access tokens that let your worker act in the apps you connected. Held so it can do what you asked, and nothing else.
- Basic operational information — sign-in times, error reports, and records of what your worker did, so we can keep the service running and you can see its history.
We do not ask for special categories of data. But your email, calendar and files may contain sensitive information — health appointments, financial details, whatever happens to be in your inbox. We treat everything your worker touches as confidential, and we do not go looking through it.
Sending your data to an AI model
Your worker cannot think on its own. When you ask it something, it sends the parts of the conversation needed to answer — which may include the content of an email, a calendar entry or a file — to the AI model provider you have selected, and receives the answer back.
We want to separate two things here, because a lot of privacy policies blur them: what we do, and what the model provider you picked does.
What we do.
- We do not read your data. Nobody at Lionox goes through your messages, your email or your files. The exceptions are narrow and the usual ones: if you specifically ask us to look at something, if we have to investigate a security problem or abuse, or if the law requires it.
- We do not train anything on it. Lionox does not use your data to build, train, fine-tune or improve any AI model — not ours, not anyone else’s. We are not in that business, and your inbox is not our training set.
- Only what is needed goes. Your worker sends the context for the task in front of it, not your whole account.
What the model provider does is their policy, not ours. Every AI company sets its own rules on how long it keeps what you send and whether it learns from it, and those rules differ from one to the next. We are not going to pretend we control that, so here is how it actually works:
- You choose the provider, per conversation, from the model picker. The choice is yours to make and yours to change.
- We reach them through an aggregator rather than connecting to each one directly. That layer carries controls for excluding providers that train on what is sent to them, and we configure it in your favour.
- Some models run outside the United States. Where that is the case the model picker says so before you select it.
- If a provider’s terms matter to you — because of what your work involves, or who your clients are — ask us at support@lionox.io and we will tell you which provider sits behind the model you are considering and what their policy says.
Data from Google accounts is a special case with stricter rules, including a flat prohibition on using it to train AI models. That is set out under Google user data below and we hold to it.
If you would rather no third party saw any of it at all, the service supports bringing your own provider credentials, or pointing your worker at a model running on hardware you control.
That is covered on the technical page.
Google user data
If you connect Gmail, Google Calendar or Google Drive, some extra promises apply, and we set them out separately because Google requires it and because they are worth reading.
Lionox’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In practice:
- We use Google data only to provide the features you asked for — reading, sorting, drafting, scheduling and filing on your instruction.
- We do not transfer or sell it to anyone for advertising, retargeting, data brokerage, or credit and lending decisions.
- We do not use it to train or improve any general AI model.
- No person at Lionox reads your Google data, except where you have specifically asked us to look at something, where it is needed to investigate a security problem or abuse, or where the law requires it.
- You can disconnect Google at any time from your dashboard, or from your Google account permissions, which revokes our access immediately.
Connected accounts generally
When you connect an app, you sign in to that app yourself and grant the access. We hold the token needed to carry out the actions you ask for. You can disconnect any app from your dashboard at any time, which revokes that access straight away.
The connection itself is operated by Composio, the integration platform we use to reach the apps your worker works with. The sign-in you complete is with the app itself, through Composio’s verified connection, and it is Composio that holds the registered application with Google and the other providers. They act on our instructions and are bound to protect what passes through.
Please only connect accounts you are entitled to connect. If the account belongs to an employer or a client, make sure you are allowed to hand it to a tool like this.
Who else processes your data
We use other companies to run the service. They act on our instructions, under contracts that require them to protect your data and to use it only for the work we have given them. By category:
- Cloud and hosting providers — the machines your private server runs on.
- AI model providers — the thinking, as described above.
- Integration infrastructure — Composio, the layer that connects your worker to the apps you use and holds the registered application with those providers.
- Payment processing — subscriptions and credit top-ups. They handle your card details; we never see them.
- Email delivery — the messages we send you about your account.
We name the integration layer above because it is the one you interact with directly when you connect an account. For the rest we do not publish individual company names here, because the list changes and a stale list is worse than none. Ask us at support@lionox.io and we will tell you exactly who is in it at the time you ask, including where each one is located. If you are buying for a business and need that in writing before you sign up, say so and we will send it.
Some of these companies are outside the United States. Where your data crosses a border it is protected by the contract terms we have with that company.
Why we are allowed to use it
- To provide what you signed up for — running your worker, answering you, doing the jobs you asked for. Without this we have no service.
- To take your money — subscriptions, credits and refunds.
- To keep it working and safe — diagnosing faults, preventing abuse, protecting other customers.
- To meet legal obligations — tax records, lawful requests, and anything else the law requires.
- Because you asked us to — anything you specifically consent to, which you can withdraw at any time.
We do not use your service data for marketing, and we do not build profiles of you for advertising.
Decisions your worker makes on its own
Your worker acts without asking you each time for the quiet things: sorting, filing, reading, drafting. Anything consequential — spending money, sending on your behalf, anything that cannot be undone — stops and waits for you. You can tighten that so it asks before everything.
It is not used to make decisions about you. We do not use it to assess your creditworthiness, your employment, your insurance or your access to anything, and we do not let anyone else use it that way.
Where your data lives
Everything your worker touches lives on the private server assigned to your account. That server is not shared with any other customer. We build it, run it and keep it patched, which means we hold the administrative keys — no other customer has access to yours.
Keeping it secure
We protect your data with measures appropriate to how sensitive it is: your own isolated server rather than a shared one, encrypted connections, access to production systems limited to the people who need it, and credentials for connected accounts stored so that they are usable by your worker and not casually readable.
No service can promise it will never be breached, and we are not going to. What we will promise is this: if something happens that affects your data, we will tell you what happened, what it touched and what we are doing about it — without waiting to be asked, and within the time the law requires.
How long we keep it
- While you have an account — for as long as you want it.
- If you cancel — your worker is parked rather than erased. It stops running, and your files and history stay in your own space so you can come back to them. We do not delete your work because you stopped paying.
- If you ask us to delete — we remove it, as set out below.
- Billing records — kept for as long as tax and accounting law requires, whatever else you delete.
Deleting your data
Full deletion is a separate, deliberate step, because it cannot be undone. Ask us at support@lionox.io and we will permanently remove the worker, the server, the files, the conversation history, the notes it kept and the tokens for any accounts you connected. We will confirm once it is done. Billing records we are legally required to keep are the one exception.
Cookies and tracking
This marketing site sets no advertising cookies, runs no third-party analytics and does not track you across other websites. The dashboard uses the cookies it needs to keep you signed in. If that ever changes we will say so here first.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is nothing to opt out of, and we honour Global Privacy Control signals anyway.
Your rights
Wherever you live, you can ask us to: give you a copy of your data, correct it, delete it, tell you who we share it with, or stop a particular use of it. Depending on where you live you may have these rights as a matter of law — including under California, New Jersey and other state privacy laws, and under the UK and EU GDPR if you are there.
Write to support@lionox.io and we will deal with it within 45 days, or tell you why we need longer. We will not charge you and we will not treat you differently for asking. We may need to check you are who you say you are first.
If we say no, you can appeal: reply to our answer saying you want it reviewed, and someone other than the person who decided will look again and write back within 45 days. If you are still unhappy, you can complain to your state Attorney General, or to your data protection regulator if you are in the UK or EU.
Age
Lionox is for adults. You must be at least 18 to have an account, which matches the terms of service. We do not knowingly collect data from children, and if we find out we have, we will delete it. If you believe a child has given us information, tell us at support@lionox.io.
Changes to this policy
If we change anything meaningful here we will update the date at the top of this page and let account holders know by email before it takes effect. Older versions are available on request.