Last updated: July 18, 2026
E50 I.T., Brazil, is the data controller for information processed through Liten. Privacy, data-rights, and legal contact: legal [at] liten [dot] to.
We collect the social login provider and provider account identifier used to sign you in. Your Liten profile can also store an optional display name and optional contact email. We process destination URLs, link settings, billing references when you use paid features, support-ticket content you submit, and operational records needed to run the service. When you connect an MCP client, Liten processes the client's registered identity metadata, the scopes you approve, your consent, audit events, and idempotency records needed to operate and secure the connection. For Liten operational link analytics, we store click and public page impression events with a SHA-256 hashed IP value rather than a plain-text IP address, plus reduced device, browser, operating-system, language, referrer-host, and country metadata. Hosting, security, provider, or legally required operational logs may separately process IP addresses for operational, security, fraud-prevention, abuse-handling, or legal needs.
Your data is used to create and manage your account, provide link analytics, process billing and support requests, detect and prevent abuse, run URL safety checks, and send service-related notifications. At your request, Liten sends the connected MCP client only the account-scoped data needed to perform the operation you asked for. Liten does not receive, store, or reconstruct your complete conversation history. Liten operational link analytics are separate from Google Analytics, which measures the main public site pages. Liten Ads is first-party product content.
We do not sell your personal data. We use third-party providers and infrastructure for OAuth sign-in, Stripe billing, hosting/runtime services, cache and rate limiting, e-mail delivery, URL safety checks, support operations, access-controlled backups, and Google Analytics on the main public site pages. A connected MCP client provider is a recipient of the account-scoped data you ask Liten to send and handles that data under its own terms and privacy policy. When Google Analytics loads, your browser may connect directly to Google services under Google's own terms and privacy policies. Liten Ads does not load third-party advertising tags.
Depending on hosting and provider configuration, personal data may be processed in countries other than your own, including countries with different data-protection standards. This can happen when Liten uses external services for authentication, billing, hosting, backup storage, e-mail, URL safety checks, or site measurement. This section describes the current operational posture only and is not a final jurisdiction-specific transfer-mechanism statement.
Account data is retained while your account is active. Operational analytics events are retained for 365 days by default. MCP audit events are retained for 730 days. Disconnecting a client removes the related consent and active connection credentials; write-tool idempotency records remain until account deletion, and registered client metadata remains until that client is deleted. Link report and moderation records are retained while the related link and owner account exist, and are not subject to a separate age-based purge in the current cycle. Other operational audit, billing-webhook, and e-mail notification records have separate retention periods. Database backups are retained for up to 30 days. After account deletion, active account data is removed by the deletion flow, while residual backup copies and limited operational, billing, security, fraud-prevention, abuse-handling, or legally required records may remain until the applicable retention period expires.
Depending on your jurisdiction, including Brazil and the European Union, you may have rights to request access, correction, deletion, objection, restriction, or a copy/portability of personal data linked to you where applicable law requires it. You can disconnect an MCP client or disable MCP access in your Liten account settings, which revokes the applicable consent and active connection credentials. To exercise your rights, use legal [at] liten [dot] to or, if you are logged in, open a support ticket. Liten uses a 15-business-day response target as an operational baseline, but applicable law may require a different process or timeline.
Public user data deletion instructions are available in the User Data Deletion Instructions.
We do not store account passwords. Authentication is handled by your chosen OAuth provider. Link protection passwords are stored only as hashes. Liten operational analytics stores hashed IP values instead of plain-text IP addresses. Data is transmitted over HTTPS. No statement on this page guarantees absolute legal or technical compliance.
Privacy, data-rights, and legal contact: legal [at] liten [dot] to. Logged-in users can also open a support ticket inside the app. Controller identification used in public copy: E50 I.T., Brazil.