Privacy policy

Last updated: September 2026

This policy explains what data Liteo holds, why, and how we handle it.

Data we collect

Liteo holds your account details, including your name and email address. It also holds the CRM data you enter, such as contacts, businesses, deals, tasks, notes, and files.

We don’t sell your personal data or use it for targeted advertising. We share data with service providers and connected services when needed to run Liteo.

Meta Lead Ads

A workspace admin can connect Meta Lead Ads and select Facebook Pages and Instant Forms. Liteo receives the Meta account ID, granted permissions, selected Page details, form questions, and submissions from those forms.

Submissions can include names, email addresses, phone numbers, job titles, and other answers requested by the form. Liteo uses mapped answers to create contacts or fill empty fields on matching contacts in the connected workspace.

Liteo stores lead, Page, and form IDs for delivery and duplicate protection. You choose whether lead, Page, form, campaign, ad set, and ad IDs also appear in contact fields.

Convex stores encrypted Meta access tokens, connection settings, delivery records, and imported contacts. Vercel handles the sign-in callback. Meta data is used to run the integration, not for advertising or sale.

Disconnecting Meta in Liteo stops new lead delivery and removes stored connection credentials and form settings. Existing contacts and delivery history remain. You can also revoke Liteo's access in Meta's Business Integrations settings.

Delete Meta data

Delete imported contacts in Liteo when you no longer need them. To request removal of Meta connection details, delivery history, or other imported data, email hello@liteo.io.

Include your workspace name, account email, and the data you want removed. Do not send passwords or access tokens. We'll verify your authority to make the request and confirm its outcome by email.

Email

Liteo holds mail you send through Liteo. It also holds mail you choose to log by uploading it, adding your logging address as a recipient, or forwarding it there.

Liteo doesn’t read or sync Gmail. Outlook users can separately choose to enable the Outlook sync beta. If they do, Liteo starts with new Inbox and Sent Items mail from that connection date and doesn’t import older mail.

Outlook sync checks sender and recipient details first. It reads a body only when an address exactly matches an existing CRM contact, and skips messages covered by the user’s never-log rules or exchanged only between workspace members. Synced bodies are stored as text without attachments.

Shared mail is visible to members of its workspace. Mail you mark private stays visible only to you unless you share it.

If you leave, Liteo schedules your private mail and temporary export copies for deletion. Shared mail stays with the workspace.

Connecting a mailbox

If you connect Gmail or Outlook for sending, Liteo asks for send-only mail access. It also asks for the basic account permissions needed to maintain that connection.

Outlook sync is a separate opt-in connection with a separate encrypted token and Microsoft’s delegated Mail.Read permission. Liteo doesn’t request Mail.ReadWrite, application-wide mailbox access, or shared-mailbox access.

You can disconnect in settings after any pending sends finish. You can revoke access directly with Google or Microsoft at any time.

Once Liteo starts a disconnect, sending stops immediately.

With Gmail, Liteo asks Google to revoke access and deletes the local token after revocation succeeds. If revocation fails, Liteo keeps sending disabled and retries.

With Outlook, Liteo deletes its local token and shows you how to remove access in Microsoft My Apps.

Disabling Outlook sync doesn’t disable sending. You can choose to keep email already synced or remove messages created by sync.

Liteo’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

AI assistants you connect

A workspace member can connect an AI assistant, such as Claude, ChatGPT, Codex, or Cursor, through Liteo’s MCP server. The member signs in to Liteo and approves the connection for one workspace.

The assistant can read and change the CRM data that member can. It gets only what each of its requests returns, such as the results of a search. What the assistant’s provider does with that data is covered by the provider’s own privacy policy.

Liteo doesn’t receive or store your conversation with the assistant. It receives only what the assistant sends to run a request, such as a search term or the fields of a new contact.

For each connection, Liteo stores the app’s name, where it returns after sign-in, and who approved it. It also stores the workspace and when the connection was created and last used. Sign-in tokens are stored only in a form Liteo can check but can’t read back. A hashed IP address is kept with each app registration to limit abuse.

Sign-in codes expire after 5 minutes. Access tokens expire after 1 hour and refresh tokens after 30 days, and expired ones are deleted. When an assistant marks a change as safe to retry, Liteo keeps the result for 24 hours so a retry doesn’t create a duplicate. An app registration is deleted after 24 hours if it never connects, or after 30 days without use.

Members can see and disconnect their connected apps in Settings, under Integrations, then For developers. Admins see every connection in the workspace. Disconnecting stops access right away, and a connection also ends when its member leaves the workspace.

Records the assistant created stay in Liteo. The record of a disconnected app stays too, and its tokens are deleted once they expire.

How long we keep it

Most CRM records don’t expire automatically. Unlinked logged mail is scheduled for deletion once it is 30 days old.

Email added by Outlook sync is scheduled for deletion after 365 days unless you choose to keep it when disabling sync.

Temporary self-service export files are scheduled for deletion once they are 7 days old.

Services we use

Liteo uses Convex for its database and Clerk for sign-in and workspace invitations. Vercel hosts the service, and Stripe handles payments.

Resend handles transactional email and mail sent to a Liteo logging address.

The public Liteo website also loads Google Tag Manager.

If you connect a mailbox, Google or Microsoft handles the connection and sending data. If you separately enable Outlook sync, Microsoft also handles the mailbox data Liteo requests under the limits described above.

When a business has no uploaded logo, Liteo may send its website domain to Google’s favicon service to display its public icon.

Your rights

You can request account deletion in settings. If self-service deletion isn’t available, email hello@liteo.io.

Closing an account disables access and schedules its private mail and temporary export copies for deletion. Shared mail stays with the workspace.

Liteo retains some account details, mailbox connection records, and the deletion request after closure. These records don’t currently have an automatic deletion schedule.

Active workspace admins can download a self-service JSON export of core CRM records and email they are permitted to see. For a complete copy request, or if self-service export is unavailable, email hello@liteo.io.

We don’t read your CRM data or your email for support. If you ask us to look at something, we’ll check with you first.

Contact

Questions about privacy? Email hello@liteo.io.