LEGAL
Privacy policy
Last updated: August 20, 2026
The privacy of your data (and it is your data, not ours) is a big deal to us. This policy sets out what we collect, why we collect it, who receives it, how long we keep it, and what you can do about it. We never sell your data: never have, never will.
Who we are
Lattney is operated by HiWork LLC, a company registered in the United States. You can reach us about anything in this policy at help@lattney.com.
This policy covers the Lattney application at app.lattney.com, our marketing website at lattney.com, and our help center.
The two roles we play
Lattney holds two different kinds of data, and our responsibility is different for each. The distinction decides who you should ask when you want something done.
Your account, your billing details, and how you use the product. We are the controller. We decide what happens to it, and this policy describes it.
The contacts, notes, tasks, files and messages you put into your CRM. We are the processor. Our customer decides what happens to it. We hold it and act on their instructions.
If you are a contact in somebody's Lattney account, or you filled in a form on a Lattney share link, we did not choose to collect your data and we cannot decide what happens to it. The business that holds the record is responsible for it, and your request should go to them. Write to help@lattney.com if you cannot work out who that is and we will point you to them.
What we collect, why, and on what basis
Your account
Your name and email address, and optionally your company, job title, time zone and theme. To create and run your account, and to address you correctly. Legal basis: performance of our contract with you.
Your password, stored in a hash we cannot reverse. To sign you in. Legal basis: performance of our contract with you.
If you sign in with Google: your Google account identifier and the profile picture URL Google returns. To sign you in without a password. Legal basis: performance of our contract with you.
Your account membership, role and permissions. To control what you can reach and do. Legal basis: performance of our contract with you.
Email addresses you invite to your account. To send the invitation. Legal basis: performance of our contract with you.
API tokens and connected applications, with the secret stored only as a hash. To let you use the API and connect other tools. Legal basis: performance of our contract with you.
Your name, email address and either a password or a Google account are required to open an account. Without them we cannot provide the service. Everything else in your profile is optional.
Signing in, and security
A sign-in session record holding your IP address, browser user agent and the time you were last active. To keep you signed in, and to let us investigate suspicious access. Legal basis: our legitimate interest in securing accounts, and performance of our contract with you.
An activity log of who changed what in an account, including the IP address and user agent of the person who made the change. To show account owners what happened in their account, and to support investigations. Legal basis: our legitimate interest, and our customers' legitimate interest in overseeing their own account.
Billing
Your billing name and email address, your Stripe customer and subscription identifiers, and the amount, refunded amount and currency of each charge. To charge you, run your subscription, and answer billing questions. Legal basis: performance of our contract with you.
Your payment method type, and the card brand, last four digits and expiry month and year that Stripe returns to us. To show you which card is on file, and to help when a payment fails. Legal basis: performance of our contract with you.
Billing records kept after an account closes. For accounting and tax. Legal basis: compliance with a legal obligation, and our legitimate interest in defending claims.
Card numbers never reach our servers. Your card details go directly to Stripe, our payment processor. What we store is what Stripe hands back to us: the card brand, the last four digits, and the expiry month and year, alongside the amount and currency of each charge. Stripe is also the merchant of record on your purchase, which means it sells to you for that transaction, sends you receipts and invoices directly, and decides its own purposes for the data that involves.
Email we send you
Password resets, account invitations and workflow share links. The service does not work without them. Legal basis: performance of our contract with you.
Daily and weekly task digests, if you leave them switched on. To summarize your day or week. Legal basis: performance of our contract with you.
Product tips and news, if you leave marketing emails switched on. To tell you about the product. Legal basis: our legitimate interest in marketing our own product to our own users.
Every one of these is a switch in Preferences.
Product analytics
We use PostHog to understand how the product is used, so we can prioritize what to build and find what is broken. PostHog receives this data in the United States, and our legal basis is our legitimate interest in understanding and improving our own product.
For a signed-in user we send your user identifier and email address, so your activity is grouped into one profile, plus a page view for each page you open. Those page views carry the page address and the IP address and user agent that reach PostHog with any request.
PostHog keeps events and profiles for 30 days.
We set no analytics cookies. PostHog runs in cookieless mode on every page of the application, the public share pages and the help center. It writes no cookie, no local storage entry and no session storage entry on your device.
Cookieless is not the same as anonymous. For a signed-in user we still send your user identifier and email address, so PostHog holds a profile that is you.
We also strip search text out of the page addresses we send. Our list pages put your search term in the address bar, and a contact link can carry a company name, so both are replaced with a placeholder before the address leaves your browser.
You can object. In Preferences, switch off Product analytics. From then on your browser sends nothing further to PostHog, and we stop identifying you. The change takes effect when the page next loads, so another tab you already have open keeps sending until you reload it. Objecting stops what happens next. It does not withdraw what PostHog already holds, which ages out under the 30 day retention above.
Visitors to public share pages and to our help center are not identified and are not sent to PostHog by name, and nothing is stored on their device. Those pages carry a link to this policy but no analytics switch, because there is no account to attach a preference to.
Errors and application logs
We use an error monitoring provider to catch errors and keep the application running. It receives our application log stream as well as error reports, which means log lines that can carry identifiers and, occasionally, personal data. Our legal basis is our legitimate interest in operating a reliable service. Logs and errors are kept for 30 days. The provider, and the country it processes in, are named on our sub-processor list.
When you write to us
Mail you send to help@lattney.com sits in our support inbox, with your address and whatever you put in the message, so we have the history the next time you write. Our legal basis is our legitimate interest in supporting our own users. We keep support mail for 24 months.
If you exercise a privacy right, we log the request, what we checked, and what we did, because we have to be able to show we handled it. Our legal basis for that log is compliance with a legal obligation. It is kept for 24 months.
Our marketing website
lattney.com is a separate website from the application, and it behaves differently.
We set no cookie until you accept one. A Google Ads tag loads on every page of lattney.com, and a banner asks on your first visit. Decline and the tag stores nothing. Accept and it sets Google advertising cookies, which tell us which ads bring people to us. Our legal basis for them is your consent.
Our website host separately receives the requests your browser makes, including your IP address. Our legal basis for that is our legitimate interest in running the site.
We do not upload your email address, hashed or otherwise, to any advertising network.
You can change your mind. Cookie Settings in the footer reopens the banner. Declining there deletes the advertising cookies already on your device. You can also delete them in your browser, and control ad personalization in your Google account settings. None of this affects the application at app.lattney.com, which sets no advertising cookies at all.
The CRM content our customers put in
We hold whatever a customer puts into their account: contacts and their addresses, phone numbers and email addresses, notes, comments, tasks, custom fields, uploaded files, imported and exported files, mail sent and received through the product, and the answers contacts give on public share links.
We are the processor for all of it. We do not decide what goes in and we do not use it for our own purposes. Nobody at HiWork LLC reads it except when a customer asks us to help with a support case, or when diagnosing a fault surfaces it in an error report or a log line.
How long we keep things
Your account, profile and CRM content. For as long as the account exists. Deleted when you delete it, with no waiting period.
Sign-in sessions. 90 days after last activity, and no more than 365 days after sign-in.
Account activity log. 24 months.
Invitations. 30 days after they are accepted or declined.
Exported files. 7 days. Imported files. 30 days.
Raw inbound email. 30 days after it is processed.
Product analytics at PostHog. 30 days.
Errors and application logs. 30 days.
Support mail, and privacy request records. 24 months.
Billing records. Kept after the account closes, for accounting and tax. Stripe keeps its own records under its own retention.
Backups. Copies of deleted data persist in our database backups until those backups cycle out.
Who receives your data
We publish the full list, with what each vendor does, where it processes data, and in what capacity, at https://app.lattney.com/sub-processors. It is kept current, and we give 30 days' notice before a new vendor starts processing your data.
Beyond that list, we share data in four situations.
You connect something. If you connect a third party service, or use an API token or the MCP endpoint, data goes where you send it. See below.
We are legally compelled. We respond to government requests for user data only when compelled by valid legal process. Our policy is to notify you first unless we are legally prohibited from doing so.
A tax authority audits us. We share the minimum needed, such as billing addresses and tax exemption information.
We are acquired or merge. We do not plan on it, but if it happens we will tell you well before any personal information transfers or becomes subject to a different privacy policy.
Programmatic access: the API and the MCP endpoint
Lattney has a JSON API and an MCP endpoint, both reachable with a token you create. They are a genuine route by which the personal data in an account leaves it.
If you connect Lattney to an AI assistant over MCP, that assistant and its model provider can read the contacts, notes and tasks the token's permissions allow, and can create and change them. We cannot see where that data goes once it leaves us, and we have no relationship with whoever receives it. You choose the connection, and you are responsible for it. Tokens are listed and can be revoked in your account settings.
Where your data is stored
HiWork LLC is a United States company, and the application, its database, our file storage, our backups and our mail all run in the United States. If you are outside the United States, using Lattney means your data is stored there. Where a provider processes somewhere else, our sub-processor list says where.
For the CRM content you put into Lattney, you are the one who decides to send it to us, and if your own data protection law requires a safeguard for that transfer, the mechanism is the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two where you are a controller and Module Three where you are yourself a processor for your own clients, with the UK International Data Transfer Addendum. They are annexed to our Data Processing Addendum at https://app.lattney.com/dpa, which applies to your account automatically. You do not need to ask for them.
Cookies
In the application at app.lattney.com: two cookies, both necessary for the application to work. One holds your sign-in credential, the other carries short-lived state between pages, such as the confirmation message shown after you save something. No analytics cookie, no advertising cookie, no third party cookie.
On public share pages and the help center: nothing.
On our marketing website at lattney.com: nothing, unless you accept Google advertising cookies. Described above.
What happens when you delete something
There is no trash and no recovery window. When you delete a record in Lattney it is gone at once. We cannot get it back for you.
Deleting your user account, or deleting an account you own, is immediate in the same way. Four things are worth knowing before you do it.
Billing records survive. We keep billing name, email address, charges and card metadata after deletion, for accounting and tax.
Email delivery records survive. Records of messages the service sent survive with their links to you cleared.
Content you wrote in someone else's account stays with that account. Notes, tasks and comments you authored remain, with your name unlinked from them.
Analytics take up to 30 days to age out. We do not delete your PostHog profile by hand. It expires under the 30 day retention.
Backups cycle out on their own schedule, so copies can persist in a backup after they are gone from the live system.
Your rights
You have the following rights over the personal data we hold about you as controller. Where we hold data as a processor for one of our customers, the same rights apply, but you exercise them against that customer and not against us.
Access. Ask what we hold and get a copy. Email help@lattney.com.
Correction. Most of your profile is editable in the app. For anything the interface does not reach, email us.
Erasure. Delete your user account in Preferences, or your whole account in Account Settings. Or email us. Note what survives, above.
Portability. Ask for your data in a machine-readable format. Contacts can also be exported from the app at any time.
Restriction. Ask us to stop using data while a dispute over it is resolved.
Objection. Switch off Product analytics in Preferences. For anything else, email us and we will answer on the merits.
Withdrawing consent. Where we rely on your consent, you can withdraw it at any time, without affecting what we did before you did.
Complaint. See below.
We answer within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you why before the first month is up. We do not charge a fee. If you send an authorized agent, we need written consent from the account holder before we act.
We will not charge you a different price, give you a worse service, or treat you differently because you exercised any of these rights.
Complaints
If you are unhappy with how we have handled your data, write to help@lattney.com first, because that is usually the fastest way to fix it. You do not have to.
In the United Kingdom, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint.
In the European Union, you can complain to the supervisory authority of the member state where you live, where you work, or where the problem happened. The list is at edpb.europa.eu/about-edpb/about-edpb/members.
Elsewhere, you can complain to your local data protection or consumer protection authority, where one exists.
Automated decision-making
Lattney makes no decision about you by automated means, and does no profiling that produces legal or similarly significant effects.
Artificial intelligence
Lattney does not send your data to any AI provider.
The one exception is entirely in your hands: if you connect Lattney to an AI assistant using the MCP endpoint, you are sending your data to that assistant. That is described above.
How we secure your data
Encryption in transit. Every connection to Lattney is forced over TLS.
Password storage. Passwords are stored only as one-way hashes.
Token storage. API token secrets are stored only as hashes and cannot be recovered, by us or by anyone.
Authorization. Every API action runs a permission check, and every database query is scoped to a single account.
File access. Uploaded files are private and reached only through signed, expiring URLs.
Secrets. Credentials are held in encrypted configuration, never in our source code.
Filtering. Passwords, tokens and CRM field values are filtered out of our logs and error reports.
Automated scanning. Security scanners run on every change before it can ship.
No system is perfectly secure, and we would rather tell you what we do than promise you what nobody can.
Google sign-in
If you sign in with Google, we request only your email address and basic profile. Lattney's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use it to sign you in and to fill in your name and profile picture, and for nothing else.
Changes to this policy
We update this policy when what we do changes, and when we find something in it that is no longer accurate. The date at the top always reflects the last change. Where a change is significant we will tell you rather than relying on you noticing.
Questions
Email help@lattney.com. A person reads it.