1. Overview
Litos AI ("we", "us", or "our") operates an AI-powered visual algorithmic trading platform that enables strategy creation, deployment, collaboration, and monetization. This Privacy Policy describes how we collect, use, store, protect, and share information when you use the Litos AI platform, including all services, tools, features, and connected ecosystems.
By accessing or using Litos AI, you consent to the practices described in this Privacy Policy. If you do not agree, you must not use the Platform.
We do not sell your personal data to third parties. Your trading strategies, graph structures, and performance data are your own and are not shared with advertisers or data brokers.
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically from your use of the Platform, and information from third-party services you connect to your account.
- Account registration data: name, email address, password (stored hashed)
- Profile information: display name, profile picture, bio
- Payment and billing information (processed by our payment processor; we do not store raw card data)
- Strategy content: visual graph structures, node configurations, parameter values, descriptions
- Marketplace listings: bot titles, descriptions, pricing, category, performance stats
- Forum posts, reviews, comments, and other community contributions
- Support and communications: messages you send to our support team
- Challenge participation data: enrollment records, performance submissions
- Usage data: pages visited, features accessed, session duration, interaction patterns
- Device and browser information: IP address, browser type and version, operating system, screen resolution
- Log data: server logs including request timestamps, error logs, and access records
- Authentication tokens: JWT session tokens stored in httpOnly cookies for secure session management
- AI interaction metadata: credit usage records, interaction timestamps, token consumption (not conversation content retained long-term)
- Performance data: Platform loading times, API response times, error rates
- Referral and UTM parameters: how you arrived at the Platform
- Google OAuth: when you sign in with Google, we receive your Google account email, name, and profile picture as authorized by you
- Payment processors (Stripe): transaction confirmation, billing details, fraud risk signals
- Analytics services: aggregated behavioral analytics from integrated services
3. AI & Strategy Data
The Litos AI platform involves significant interaction with our Specialized AI Agentic Framework. We want to be transparent about how AI interaction data is handled.
- Your visual graph strategy structures are stored securely and are private to your account by default
- AI conversations and interactions are used to provide the service and may be used in aggregated, anonymized form to improve our AI systems
- We do not use your private strategy content to train external AI models or share it with third-party AI providers beyond what is necessary to process your requests
- Token consumption metadata (not the content itself) is logged for billing and credit reconciliation purposes
- AI interactions consume credits which are tracked as transaction records linked to your account
- Strategy content you explicitly publish to the Marketplace is shared publicly according to your visibility settings
Your private strategy graphs and AI conversations are not visible to other users. Only content you explicitly publish becomes accessible to others.
4. Marketplace Data
The Marketplace involves sharing certain data to facilitate commercial strategy transactions.
- Published bot listings are publicly visible including: name, description, category, pricing, performance stats, and author display name
- Purchase and transaction records are stored for billing, compliance, and dispute resolution purposes
- Reviews and ratings you submit are publicly visible and attributed to your display name
- Your purchase history is private to your account and our payment processor
- Revenue payouts to strategy creators involve sharing necessary information with payment processors
- Admin review activity related to your submissions is logged internally for moderation purposes
5. How We Use Your Data
We use collected information for the following purposes:
- Creating and managing your account
- Authenticating your identity and maintaining secure sessions
- Processing transactions, subscriptions, and marketplace payments
- Delivering AI-powered features including strategy generation, auditing, and optimization
- Operating the Visual Graph Strategy Engine and storing your strategy data
- Running the Challenges ecosystem including enrollment, tracking, and reward distribution
- Improving platform features, AI model quality, and user experience
- Detecting, investigating, and preventing fraud, abuse, and security incidents
- Monitoring platform performance and resolving technical issues
- Enforcing our Terms of Service and community guidelines
- Sending transactional emails: account confirmations, purchase receipts, credit alerts
- Service notifications: important platform updates, security alerts, policy changes
- Optional marketing communications (only with your explicit consent; you may opt out at any time)
6. Data Sharing
We do not sell, rent, or trade your personal data. We share information only in the following limited circumstances:
- Service providers: we share data with trusted vendors who operate under strict confidentiality agreements, including cloud infrastructure providers, payment processors (Stripe), email delivery services, and analytics tools
- Marketplace participants: when you publish a strategy, your display name and listing details are visible to other users
- Legal compliance: we may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of Litos AI, our users, or the public
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity subject to the same privacy commitments
- With your consent: we may share data in other circumstances with your explicit approval
We never sell your personal data or trading strategy content to advertisers, data brokers, or any third party for commercial purposes.
7. Cookies & Tracking Technologies
Litos AI uses cookies and similar technologies to operate the Platform and provide a personalized experience.
- litos_jwt — httpOnly authentication cookie containing your session token. Required for secure login. Cannot be disabled.
- Session identifiers used for CSRF protection during OAuth flows
- Usage pattern tracking to understand how users interact with Platform features
- Performance monitoring to identify and resolve technical issues
- These may be disabled without affecting core functionality
You can control non-essential cookies through your browser settings. Note that disabling essential cookies will prevent you from accessing authenticated features.
8. Data Retention
We retain your data for as long as necessary to provide the Platform and fulfil the purposes outlined in this Policy, unless a longer retention period is required by law.
- Account data: retained while your account is active and for a reasonable period after closure to resolve disputes and comply with legal obligations
- Strategy and graph data: retained while your account is active; deleted upon confirmed account closure unless public listings must be preserved
- Transaction and billing records: retained for a minimum of 7 years for financial compliance
- AI interaction metadata: retained for billing reconciliation and may be retained in aggregated anonymous form for model improvement
- Log data: server logs are retained for up to 90 days for security monitoring
- Marketing preferences: retained until you withdraw consent or delete your account
9. Security
We implement industry-standard security measures to protect your data from unauthorized access, disclosure, alteration, or destruction.
- All data in transit is encrypted using TLS (HTTPS)
- Authentication tokens are stored in httpOnly, Secure cookies inaccessible to JavaScript
- Passwords are hashed using strong one-way hashing algorithms; we never store plaintext passwords
- Access to production systems and databases is restricted to authorized personnel only
- All secrets, API keys, and credentials are managed through Doppler secrets management and never committed to source code
- Our infrastructure uses role-based access control (RBAC) to limit internal data access to those who need it
- Security incidents are monitored through logging and alerting systems
No system is completely immune to security risks. If you discover a security vulnerability, please contact us responsibly at security@litos-ai.com before public disclosure.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Deletion — request deletion of your personal data (subject to legal retention obligations)
- Portability — request your data in a structured, machine-readable format
- Restriction — request that we restrict processing of your data in certain circumstances
- Objection — object to processing based on legitimate interests or for direct marketing purposes
- Consent withdrawal — where processing is based on consent, you may withdraw it at any time without affecting prior processing
To exercise any of these rights, please contact us at privacy@litos-ai.com. We will respond within 30 days. We may require identity verification before fulfilling requests.
You may also have the right to lodge a complaint with a data protection supervisory authority in your jurisdiction.
11. Children's Privacy
Litos AI is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@litos-ai.com and we will promptly delete such data.
12. International Data Transfers
Litos AI operates globally and your data may be processed and stored in countries other than your country of residence. These countries may have different data protection laws than your jurisdiction.
When we transfer personal data internationally, we ensure appropriate safeguards are in place, including relying on adequacy decisions, standard contractual clauses, or other legally recognized transfer mechanisms. By using the Platform, you acknowledge and consent to such transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, Platform features, or legal requirements. When we make significant changes, we will notify you via email or a prominent Platform notice at least 14 days before the changes take effect.
The "Last updated" date at the top of this page indicates when this Policy was last revised. Your continued use of the Platform following any updates constitutes your acceptance of the revised Policy.
14. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please contact our privacy team:
Privacy Team
privacy@litos-ai.comSecurity Vulnerabilities
security@litos-ai.com© 2026 Litos AI. All rights reserved.
Terms of Service