Privacy Policy
Effective 15 September 2026
Lisran reads the billing and usage metadata your AI providers already hold about you, and turns it into a spend breakdown. This page sets out exactly what that means: what we store, what we deliberately never touch, and who else processes it.
The short version
- We read usage and billing metadata — token counts, model names, dates and billed cost.
- We never read your prompts or completions. The provider endpoints we call do not return them, and we do not ask for scopes that would.
- Provider API keys are encrypted at rest with AES-256-GCM and can be revoked from your dashboard at any time.
- We do not sell personal data, and we do not use your data to train machine-learning models.
What we collect
Everything Lisran stores falls into one of five buckets.
- Account details.Your email address, your company's name, and a billing email. Authentication itself is handled by our infrastructure provider; we never store your password.
- Provider API keys. Encrypted before they are written to the database, alongside the provider name, whether the key is active, and when it was last used.
- Usage and cost records. Per provider, model and day: token counts and cost, plus the team, member, customer and product labels used for attribution.
- Team directory entries. If you import a team list, the names, roles, teams and email addresses it contains — so that provider account identifiers can be shown as people rather than opaque IDs.
- Demo requests. If you ask for a demo, the email address and company you submit, along with the status and any notes we add while following up.
What we do not collect
Lisran calls its providers' organization-level usage and cost endpoints. Those endpoints return aggregate metadata — how many tokens a model consumed on a given day, and what it was billed. They do not return message content, and Lisran has no other route to it.
So we hold no prompts, no completions, no system prompts, no tool calls, no embeddings, and no files you send to your providers. There is no setting that turns this on.
How your provider keys are handled
- Keys are encrypted with AES-256-GCM before storage, using a key held only in server-side configuration and never sent to the browser.
- They are decrypted only in memory, on the server, for the duration of a sync.
- The dashboard only ever displays a masked form of a key. The full value is never returned to the browser after you save it.
- Provide read-only keys scoped to usage and billing. Lisran never needs write access, and never issues inference requests against your keys.
- Deleting a key from the dashboard removes it from our database. Revoking it at the provider takes effect immediately regardless.
Team member data
A team import contains personal data about your employees or contractors, and you remain responsible for it: for having a lawful basis to share it with us, and for telling those people that spend is attributed to them by name. Lisran processes it only to label spend within your own workspace. It is never shown to other customers, enriched, or used for any other purpose.
You can remove any team entry from the dashboard, which unlinks that person from future attribution.
Who else processes your data
Lisran runs on third-party infrastructure. Each of these processes data on our behalf, under its own terms:
- Supabase — database and authentication. Holds everything described above.
- Vercel — application hosting. Processes requests in transit and standard server logs.
- Sentry — error monitoring, when enabled. Receives error reports that can include your account identifier and technical context such as a provider or model name. We do not deliberately send usage figures or key material to it.
- Resend — transactional email: invitations, the spend alerts you switch on, and our internal demo-request notifications. Receives the recipient address and the message.
We do not sell personal data, and we do not share it with advertisers.
Retention and deletion
Account, key and spend records are kept for as long as your workspace is active, because the product's value is the history. Demo requests are kept while we are following up and for a reasonable period afterwards.
Ask us to close your workspace and we will delete your account, stored keys and spend history, except where we are required to keep records for longer. Backups age out on their own schedule.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete the personal data we hold about you, and to object to or restrict some processing. You can export your spend data as CSV from the dashboard at any time without asking us. For anything else, write to us.
Changes to this policy
If we change what we collect or who processes it, we will update this page and move the effective date at the top. Material changes will be emailed to workspace admins before they take effect.
Contact
Privacy questions, or a request about your data: [email protected].
Lisran, Inc.
See also our Terms of Service.