Privacy Policy
Last updated: September 2026
For the same answers in plain words — what is on your device, what syncs, where it is stored and for how long — see Data & Security.
1. Introduction
Liminal ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our browser application and website.
2. Information We Collect
Account Information
When you create an account, we collect your email address and encrypted password. We do not store passwords in plain text.
Usage Data
We collect product usage events to improve the app: the name of the action, whether it succeeded, the app version and build, the platform and the plan. Each event carries an identifier — random until you sign in, your user id afterwards. Fields that look like a secret or an identity (passwords, tokens, cookies, sessions, API keys, device and machine ids, hostnames, serial numbers, MAC addresses, fingerprint values, IP addresses, proxy credentials, file paths, email addresses) are removed before an event is sent, and values that look like a token, an email, an IP or a path are replaced with a redaction marker. Events are sent to an EU endpoint with IP capture switched off.
Profile Data
Browsing history, saved passwords, open tabs, site data, cache and extensions of your profiles stay on your device; we never receive them. On the paid plans your catalog syncs so a second machine can pick it up: profiles with their fingerprint configuration, workspaces and folders, proxies, account cards and app settings. If you import cookies onto an account card, those cookies sync with the card and their values are encrypted before they are stored. On the free plan nothing syncs.
3. How We Use Your Information
- To provide and maintain our service
- To process your subscription and payments
- To send you important updates about our service
- To provide customer support
- To improve our product based on usage patterns
4. Data Security
All traffic between the app, this website and our API is encrypted with TLS. Account passwords are stored as bcrypt hashes and cannot be read back. Proxy passwords and imported cookie values are encrypted with AES-256-GCM before they are written to the database; the key is held by us, so that protects them against a stolen database rather than against us. Your profile folders stay on your own machine, under the protection your operating system gives them.
5. Third-Party Services
Our API, database and downloads run on DigitalOcean in Frankfurt, Germany. We use NOWPayments for crypto payments, Resend for account email, and Mixpanel (EU ingest) and Google Analytics for product and website analytics. These services have their own privacy policies governing the use of your information.
6. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data
- Opt out of marketing communications
Settings → Account in the app opens your account page, where both live: “Export my data” downloads everything we store for you as a JSON file, and “Delete account” removes the account and everything stored with it — profiles, proxies, account cards and their cookies, settings and sessions — the moment you confirm, with no grace period. Daily backups of the database are kept for about a week, after which the deletion is gone from those too.
7. Cookies
This website uses essential cookies for authentication and session management. It also loads product and website analytics — but only after you accept them in the cookie banner; until then no analytics script is loaded and nothing is written for them. We run no advertising trackers and do not share data with advertisers.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us at [email protected]