Privacy Policy
Effective Date: 14 JULY 2026
1. Introduction
This Privacy Policy explains how Lythe Inc. and its applicable affiliates, including Lythe Pte. Ltd. (collectively and as applicable, "Lythe," "we," "us," or "our"), collect, use, disclose, store, and protect personal data in connection with Lythe's products, websites, applications, public demos, simulation tools, integrations, documentation, and related services, including Fraser Simulation Studio (collectively, the "Services").
Fraser Simulation Studio is Lythe's AI-powered simulation and automated evaluation product for testing websites, product flows, visual experiences, and Android applications using AI personas and subagents. Lythe Inc. operates Lythe's self-serve websites, dashboards, public demos, documentation, and related online Services worldwide. Lythe Pte. Ltd., Lythe's Singapore subsidiary, may separately provide contracted Services only where it is expressly identified as the responsible entity in an applicable Order Form, customer agreement, Terms of Service, or other written agreement.
The Services may be used to create, configure, test, evaluate, and improve AI personas, subagents, simulations, automated evaluation workflows, and related outputs. Simulation tools may generate AI persona feedback, product critiques, evaluation reports, simulated user reactions, messaging analysis, and product research outputs. This Privacy Policy is intended to help users, customers, End Users, research subjects, and business partners understand how personal data may be handled in connection with the Services.
2. Scope of This Policy
This Policy applies to personal data we process in connection with the Services, including information collected through our websites, product dashboards, public demos, customer support, sales interactions, events, simulation workflows, and product evaluation tools.
Lythe Inc. is responsible for personal data processed in connection with Lythe's self-serve websites, dashboards, related online Services, Fraser Simulation Studio, and public demos that it operates worldwide. Where Lythe Pte. Ltd. separately provides contracted Services, Lythe Pte. Ltd. will be responsible for the relevant processing to the extent identified in the applicable Order Form, customer agreement, Terms of Service, or other written agreement.
When we process personal data on behalf of a business customer under a written agreement, the applicable Lythe entity may act as a service provider, data processor, or data intermediary, depending on the applicable law and the relevant processing activity. In those cases, the customer is generally responsible for providing required notices, obtaining required consents, establishing lawful bases, and instructing Lythe on how to process personal data, subject to Lythe's own obligations under applicable law. Our Data Processing Addendum or customer agreement may further govern that processing.
This Policy does not apply to third-party websites, applications, products, or services that are not controlled by Lythe, even if they link to or integrate with the Services. Submitting a third-party website, URL, screenshot, prototype, or product flow for analysis through Fraser Simulation Studio does not make Lythe responsible for that third-party service.
3. Information We Collect
3.1 Account and Business Contact Information
- Name, company name, role, email address, phone number, billing contact, and account credentials.
- Information provided during onboarding, sales calls, demos, pilot programs, customer support, enterprise procurement, and product waitlists.
- Communications with us, including messages, support tickets, feedback, surveys, demo requests, application forms, and meeting notes.
3.2 Customer Content, Agent Configuration, and Simulation Configuration
- Prompts, scripts, instructions, knowledge base content, agent names, AI persona configurations, simulation settings, evaluation criteria, workflows, tools, API configurations, and business rules submitted to the Services.
- CRM, calendar, helpdesk, messaging, payment, analytics, data warehouse, product analytics, design tool, or other integration data that customers connect to Lythe services.
- Files, records, datasets, screenshots, websites, URLs, prototypes, landing pages, product flows, Android application packages (APK files), research notes, customer feedback, user personas, or other materials uploaded for agent testing, simulation, evaluation, personalization, or deployment.
3.3 Voice, Call, and Conversation Data Used for Persona Generation
- Customer-provided call audio, call recordings, transcripts, summaries, notes, conversation metadata, speaker identifiers, timestamps, call duration, call outcomes, and related interaction records.
- Conversation analysis outputs, including topics, intents, sentiment or tone indicators, recurring pain points, feature requests, objections, product feedback, and persona-generation signals.
- This information may be used to generate, configure, evaluate, and improve AI personas, simulations, product evaluation workflows, and related outputs for the customer's own use. Lythe does not provide outbound calling, voice agent deployment, telemarketing, robocalling, call routing, or automated phone agent services unless expressly agreed in a written agreement.
3.4 Simulation, AI Persona, and Product Evaluation Data
- Simulation inputs, AI persona prompts, persona profiles, product concepts, feature descriptions, user flows, messaging, positioning, onboarding flows, product screenshots, landing pages, prototypes, and related evaluation materials.
- Simulation outputs, including AI persona responses, product critiques, usability observations, feature recommendations, product-market-fit hypotheses, segmentation insights, evaluation scores, reports, research-preparation outputs, and related analytics.
- Research methodology information, evaluation settings, assumptions, success criteria, failure conditions, review notes, and human-feedback records associated with simulations or automated evaluations.
3.5 Usage, Device, and Technical Information
- Log data, IP address, browser type, device identifiers, operating system, pages viewed, referring URLs, session activity, API requests, latency, errors, uptime information, and feature usage.
- Product interaction information, including clicks, scrolling behavior, cursor or pointer movements, navigation paths, page transitions, feature interactions, timestamps, form interactions, and session replay data.
- Where enabled, session replay technology may record how users interact with the Services to help Lythe identify bugs, usability issues, technical problems, and product performance issues. Session replay may capture interactions with forms and input fields. Text entered into form fields is masked by default.
- Sensitive fields, including passwords, payment information, authentication credentials, API keys, security codes, and other sensitive information, are masked or excluded from session replay. Lythe does not intentionally record such information through session replay.
- Security and diagnostic data used to protect the Services, detect abuse, debug issues, prevent unauthorized website testing or scraping, and maintain system reliability.
- Cookies, pixels, local storage, SDKs, session replay technologies, and similar technologies used for authentication, analytics, security, preference management, and marketing where permitted.
3.6 Payment and Billing Information
- Billing address, invoice details, plan type, usage-based charges, subscription status, simulation pack purchases, payment status, tax information, and transaction records.
- Payment processing is handled by Stripe. Lythe does not directly collect, store, or process full payment card numbers, bank account details, or payment credentials. Stripe may process payment information, billing details, transaction data, fraud-prevention data, and related information in accordance with Stripe's own terms and privacy policy. Lythe may receive limited payment tokens, customer IDs, subscription status, invoices, transaction confirmations, payment status, and related billing records.
4. How We Use Information
We use personal information for the following purposes:
- To provide, operate, maintain, secure, and improve the Services.
- To create, configure, monitor, evaluate, and support AI personas, subagents, simulations, automated evaluators, and related workflows.
- To process customer-provided conversations, call recordings, transcripts, summaries, notes, and interaction records for persona generation, simulation, product evaluation, and customer-requested research workflows.
- To run simulations, generate AI persona responses, produce product critiques, evaluate user flows, analyze messaging, create reports, and support customer-requested product research workflows.
- To authenticate users, manage accounts, process payments, send invoices, administer plans and usage limits, and provide customer support.
- To detect, prevent, investigate, and respond to fraud, spam, abuse, unauthorized website testing, security incidents, illegal activity, and violations of our terms or policies.
- To analyze product usage, measure performance, debug technical issues, improve public demos, and develop new features.
- To comply with legal obligations, enforce agreements, resolve disputes, and protect the rights, safety, security, and interests of Lythe, our customers, End Users, research subjects, users, business contacts, and the public.
- To send administrative messages, product updates, security notices, and marketing communications where permitted by law and subject to opt-out rights.
- To understand how users navigate and interact with the Services through product analytics, interaction events, and session replay.
- To identify bugs, usability friction, navigation issues, failed workflows, technical errors, and product performance problems.
5. AI Processing, Evaluation, and Service Improvement
Lythe may process Customer Data, customer-provided call recordings, transcripts, conversation metadata, uploaded materials, product materials, simulation inputs, AI persona configurations, feedback, and evaluation results to provide, operate, secure, support, troubleshoot, and evaluate the Services in accordance with customer instructions, applicable agreements, and applicable law. This may include testing agent behavior, measuring performance, detecting failure modes, producing customer analytics, running simulations, generating evaluation reports, investigating incidents, and updating prompts, configurations, or workflows for that customer's own deployment.
Lythe does not use Customer Data, call recordings, transcripts, CRM data, lead data, product materials, research data, simulation inputs, AI persona outputs, or other personal data submitted to or generated through a customer's use of the Services to train Lythe models, shared models, general-purpose models, or models or systems used for the benefit of other customers, unless expressly agreed in a written agreement with the customer and permitted by applicable law.
Lythe does not permit third-party model or AI infrastructure providers to use Customer Data, call recordings, transcripts, research data, simulation inputs, AI persona outputs, or other personal data processed through the Services to train their models.
Lythe may use de-identified or aggregated information that does not identify individuals or customers to analyze service performance, security, reliability, abuse patterns, and product usage, provided that such information is handled in accordance with applicable law and applicable customer agreements.
Customers are responsible for ensuring that any personal data they submit to or make available through the Services, including call recordings, transcripts, lead data, CRM records, contact lists, research data, product materials, screenshots, URLs, prototypes, customer feedback, and uploaded files, is collected, used, and disclosed to Lythe lawfully.
6. Simulation, Bug Testing, and Synthetic Research Disclosure
Fraser Simulation Studio may enable customers to use subagents, AI personas, simulations, visual evaluations, and bug-testing workflows to analyze websites, landing pages, product flows, screenshots, prototypes, and Android application packages (APK files). These features may be used to battle-test website bugs, evaluate user flows, generate visual simulations from URLs, identify interface issues, and produce synthetic product feedback or evaluation reports.
Customers may only use Fraser Simulation Studio, subagents, simulations, visual evaluations, and bug-testing workflows on websites, applications, APK files, product flows, or digital assets that they own, operate, control, or are expressly authorized to test. Customers must not use the Services to test, scrape, monitor, access, or analyze third-party websites, applications, systems, or content without proper authorization.
Customers are responsible for ensuring that all URLs, screenshots, APK files, product materials, customer data, and other materials submitted to the Services are lawful, authorized, and appropriate for the intended use. Customers must verify that their use of the Services does not violate any applicable laws, third-party terms of service, contractual restrictions, intellectual property rights, privacy rights, or security requirements.
Simulation outputs, AI persona responses, visual evaluations, bug-testing results, product critiques, and synthetic feedback are generated for product evaluation and research-support purposes. Customers are responsible for ensuring that these outputs are not presented as real user interactions, real customer interviews, verified vulnerability reports, statistically valid survey results, or guaranteed market truth unless independently validated through appropriate methods.
Customers must not upload malicious, unlawful, unauthorized, or third-party APK files. Lythe may scan, restrict, reject, or remove uploaded files where necessary to protect the Services, users, or third parties.
8. Subprocessors and Third-Party Services
We may use third-party subprocessors to host, store, transmit, analyze, or otherwise process personal information as part of the Services. These may include cloud infrastructure providers, transcription providers, analytics providers, support tools, payment processors, product analytics tools, AI infrastructure providers, and other operational providers. For example, we may rely on cloud and hosting platforms such as Amazon Web Services (AWS), Microsoft Azure, Vercel, Google Cloud Platform, and Cloudflare to provide infrastructure.
We use PostHog for product analytics, feature usage measurement, event analytics, debugging, and, where enabled, session replay. PostHog may process information such as device and browser information, identifiers, page activity, navigation paths, feature usage, interaction events, and session replay data in accordance with Lythe's instructions, applicable agreements, and applicable law.
We use Stripe for payment processing, billing, subscription management, invoicing, fraud prevention, and related payment operations.
Where required, Lythe will maintain a list of subprocessors or service providers and provide notice of material changes in accordance with the applicable customer agreement or Data Processing Addendum.
9. Data Retention
We retain personal information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, prevent fraud and abuse, honor opt-outs and suppression requests, and support legitimate business purposes.
Retention periods may vary depending on the type of information, customer configuration, legal requirements, product settings, provider settings, and contractual commitments. For example, customer-provided call recordings, transcripts, conversation summaries, workflow logs, simulation inputs, AI persona outputs, evaluation reports, uploaded materials, APK files, screenshots, product analytics events, session replay recordings, support records, billing records, security logs, and consent records may have different retention periods. Session replay recordings and associated analytics data are retained according to Lythe's configured retention settings and are deleted or anonymized when no longer reasonably necessary for the purposes described in this Policy.
Customers may be able to configure retention settings for certain call recordings, transcripts, logs, agent data, simulation data, uploaded materials, or reports. Deletion requests may be subject to technical limitations, backup retention, legal holds, fraud-prevention needs, security requirements, or obligations under customer agreements.
Where Lythe processes personal data on behalf of a customer under a Data Processing Addendum or customer agreement, deletion, return, retention, and backup handling may be further governed by that agreement.
10. Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, disclosure, alteration, and destruction. These safeguards may include access controls, encryption, logging, monitoring, authentication, vulnerability management, vendor review, and incident response procedures.
No system is completely secure. Customers are responsible for maintaining the confidentiality of account credentials, configuring access permissions appropriately, limiting access to workspaces and integrations, and promptly notifying us of suspected unauthorized access or security incidents.
11. International Data Transfers
Lythe may process and store personal data in countries other than the country where it was originally collected, including through Lythe affiliates, service providers, and subprocessors used to provide the Services. In particular, personal data may be processed between Lythe Inc. in the United States and Lythe Pte. Ltd. in Singapore where necessary to provide, support, secure, administer, or comply with obligations relating to the Services.
These countries may have data protection laws that differ from those in the individual's jurisdiction. Where required by applicable law, Lythe will implement appropriate safeguards for cross-border transfers, such as contractual protections, data processing agreements, standard contractual clauses, transfer assessments, or other recognized transfer mechanisms.
12. Privacy Rights and Choices
Depending on the applicable law and the user's location, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of their personal information. Individuals may also have the right to withdraw consent, opt out of certain marketing communications, or lodge a complaint with a data protection authority.
If personal data is processed by Lythe on behalf of a customer, individuals should generally direct their requests to that customer. Lythe will assist customers in responding to requests as required by applicable law and applicable agreements.
Users may opt out of marketing emails by using the unsubscribe link or contacting us. Operational, billing, legal, and security messages may still be sent where necessary.
14. Regional Privacy Disclosures
14.1 Singapore PDPA
Where Singapore's Personal Data Protection Act 2012 applies, Lythe Pte. Ltd., or the applicable Lythe entity handling personal data in connection with Singapore customers or individuals, will collect, use, disclose, and transfer personal data only in accordance with applicable consent, notification, purpose limitation, protection, retention, transfer, access, correction, accountability, and data breach notification obligations.
Individuals may contact Lythe's Data Protection Contact to request access to or correction of their personal data, subject to applicable legal exceptions.
14.2 European Economic Area, United Kingdom, and Switzerland
Where the GDPR, UK GDPR, or Swiss data protection laws apply, our legal bases may include performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of vital interests. Individuals may have rights to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
14.3 California and Other U.S. State Privacy Laws
Where applicable U.S. state privacy laws apply, individuals may have rights to know, access, correct, delete, or obtain a copy of personal information, and to opt out of certain processing activities, including sale, sharing, targeted advertising, or certain profiling activities.
Lythe does not currently sell personal data for monetary consideration. However, where enabled, certain advertising or retargeting technologies may involve processing that is regulated as sale, sharing, targeted advertising, or similar activity under applicable law. Where required, Lythe will provide applicable notices, opt-out mechanisms, and recognition of opt-out preference signals, such as Global Privacy Control.
15. Children
The Services are not directed to children under 13, and Lythe does not knowingly collect personal data directly from children under 13 through its general-purpose website, public demos, product onboarding flows, or Fraser Simulation Studio.
Customers must not use the Services for workflows involving children or minors without Lythe's prior written approval and all required rights, notices, consents, safeguards, and legal authority. Where Lythe becomes aware that personal data involving children or minors has been processed in violation of this Policy or applicable law, Lythe may restrict processing, suspend the relevant workflow, require remediation, or delete data where appropriate and legally permitted.
16. Customer Responsibilities
Customers are responsible for:
- Providing legally required privacy notices to their users, leads, customers, employees, research subjects, business contacts, and other individuals.
- Obtaining required rights, notices, and consents for uploading or connecting call recordings, transcripts, customer conversations, research data, uploaded materials, APK files, URLs, screenshots, and simulation workflows.
- Ensuring that data uploaded to or made available through the Services is accurate, lawful, authorized, and appropriate for the intended use.
- Configuring agents, AI personas, simulations, scripts, integrations, permissions, retention settings, research methodology, and escalation rules responsibly.
- Responding to privacy rights requests where the customer acts as the controller or business under applicable law.
- Using the Services only in accordance with applicable law, Lythe's terms and policies, and applicable customer agreements.
17. Changes to This Policy
Lythe may update this Privacy Policy from time to time to reflect changes in the Services, data practices, subprocessors, product names, legal requirements, or business practices. Updated versions will be posted or otherwise made available to affected individuals and customers.
Unless otherwise required by applicable law or agreed in writing, material changes will apply prospectively from the effective date stated in the updated policy. Continued use of the Services after the effective date of an updated policy constitutes acceptance of the updated policy, subject to any contrary terms in a signed customer agreement.
18. Contact Us
Questions, requests, or concerns about this Privacy Policy or privacy practices relating to Lythe services may be directed to:
- U.S. parent: Lythe Inc.
- Singapore subsidiary: Lythe Pte. Ltd.
- Data Protection Contact: team@lythe.ai
- Privacy requests: team@lythe.ai
The Lythe entity responsible for a customer's use of the Services is identified in the applicable Terms of Service, Order Form, customer agreement, or other written agreement.