Legal
Effective date: to be set at launch — this policy is not yet in effect. The version shown here is under legal review and subject to change before go-live.
What we collect, why, who we share it with, and how to ask us to delete it — including how Git and MCP integrations are secured.
The short version: we collect what's needed to run hosting — account and billing information (via Stripe), server logs, and, if you connect one, GitHub and MCP integration data. GitHub App credentials are encrypted at rest; MCP tokens we issue are hashed and shown to you only once. We don't sell personal information, and we don't run advertising trackers. Our infrastructure runs primarily on servers we operate ourselves rather than a general-purpose cloud vendor.
This Privacy Policy explains how personal information is collected, used, disclosed, retained, and protected in connection with lemonadehost.com, the Lemonade Host account dashboard, hosting platform, support channels, deployment tools, APIs, GitHub integration, MCP server, optional add-ons, and related services (collectively, the "Service").
Until a successor entity is identified in an updated version of this Policy, Analytix Media is the current legal operator of the Lemonade Host service and is the controller or business responsible for personal information used for Lemonade Host account administration, billing, security, support, and operations. Lemonade Host is a separate product and brand. Analytix Media is identified solely because it is temporarily acting as the legal operator before the Lemonade Host business is transferred to a dedicated entity.
For personal information contained in or collected through a customer's hosted website and processed only on that customer's instructions, the customer generally acts as the controller or business and Lemonade Host generally acts as a processor, service provider, or contractor. Section 12 explains this distinction.
Questions or privacy requests may be sent to [email protected].
We collect the information reasonably needed to provide and secure a hosting service, process payments, connect authorized repositories and deployment tools, respond to support requests, comply with law, and prevent abuse.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not run third-party advertising trackers. We may use essential cookies or similar technologies for login, session, fraud prevention, preferences, and security.
The Service is hosted primarily on infrastructure owned or controlled by the current Operator. We use third parties for functions such as payments, content delivery and security, GitHub connections, transactional email, error monitoring, optional backup storage, and potentially AI-assisted support.
No method of collection, transmission, or storage is completely secure. You should not upload secrets or regulated data unless the Service and your plan are expressly designed for that use.
Before paid accounts are available, the waitlist may collect:
The waitlist email address is used to send the launch notification and related essential delivery or suppression processing. It is not automatically enrolled in an ongoing marketing newsletter unless the person separately opts in.
Depending on how you use the Service, we may collect the following categories.
Authentication may use magic links, one-time codes, passkeys, passwords, GitHub or another OAuth provider, or other methods we make available. We may process:
We do not receive your GitHub password. If password authentication is offered, passwords should be stored using an industry-standard one-way hashing method rather than in readable form.
Stripe processes payment-card information. Stripe may collect card details, billing address, tax information, and fraud-prevention data directly. Lemonade Host generally receives and stores:
We do not intentionally store full payment-card numbers or card security codes on our own servers.
We store and serve the files and content you deploy, which may include HTML, CSS, JavaScript, images, fonts, text, code, configuration, and other site assets. Optional features may also process form submissions, structured data, messages, or other information that a customer chooses to collect through a Site.
Customer Content may contain personal information about the customer, website visitors, employees, contractors, clients, or other people. Customers control what they upload and are responsible for having a lawful basis and providing required notices.
We do not routinely read Customer Content for marketing purposes. We may access or automatically analyze it as reasonably necessary to provide the Service, troubleshoot at the customer's request, detect malware or abuse, enforce policies, protect security, comply with law, or restore data.
Our systems and Cloudflare may automatically process:
Logs may relate to visitors of lemonadehost.com, account users, API or MCP clients, and visitors to customer Sites.
For deployments and integrations, we may process:
We may show a raw MCP or API token only once when it is created. After that, a properly implemented hashed token cannot be retrieved by us and must be replaced if lost.
We collect information you provide in support tickets, emails, chat, feedback, abuse reports, privacy requests, legal notices, and other communications. This may include contact details, account information, screenshots, files, diagnostic data, and the contents of the message.
Do not send passwords, full card numbers, private keys, raw access tokens, repository secrets, or unnecessary sensitive information in an ordinary support message.
We may collect and preserve information associated with suspected phishing, malware, fraud, infringement, spam, attacks, policy violations, sanctions, legal requests, ownership disputes, and investigations. This may include reports from third parties, evidence, copies of content, logs, correspondence, decisions, and appeal records.
No advertising analytics are intended at launch. We may later use a privacy-focused or self-hosted analytics tool, such as Umami, to understand aggregate use of our own marketing and documentation pages. Before activating a tool that materially changes our practices, we will update this Policy and provide any consent mechanism required by law.
We collect personal information from:
We may use personal information to:
We do not use Customer Content to create advertising profiles. We do not intentionally use private Customer Content to train a publicly available general-purpose AI model without a separate, clear opt-in.
Where a law requires a legal basis, we generally rely on:
When we process personal information solely on a customer's documented instructions as a processor, the customer is responsible for identifying its legal basis.
We may use cookies, local storage, session identifiers, and similar technologies that are necessary or reasonably useful for:
These technologies may be set by us or service providers such as Cloudflare, Stripe, or an authentication provider.
We do not intend to use third-party advertising cookies or pixels at launch. If we add optional analytics, advertising, or another nonessential technology, we will update disclosures and provide a consent or opt-out tool where required.
A browser's "Do Not Track" setting is not a uniform legal or technical standard. Where applicable law requires recognition of a legally valid opt-out preference signal, we will honor it for activities to which it applies. Because we do not sell or share personal information for cross-context behavioral advertising, an advertising opt-out should not be necessary for our current practices.
We disclose personal information to providers that perform services for Lemonade Host. They may process information only for permitted purposes under their contracts, instructions, and applicable law.
Confirmed or planned provider categories include:
Our primary application infrastructure and database are intended to be self-hosted on servers owned or controlled by the Operator rather than hosted by a general-purpose cloud infrastructure vendor. Standard backups may replicate to a second server owned or controlled by the Operator.
We may change providers as the Service evolves. Describing a provider by function allows us to replace it without rewriting the entire Policy, but we will update the provider name and the Last Updated date when a change materially affects privacy practices or where law requires identification.
A customer may connect an external AI coding assistant, agent, editor, script, or other tool to our MCP server or API using a scoped token. That external tool is selected, instructed, and controlled by the customer.
When the customer's tool sends a deployment command or files to Lemonade Host:
Customers should not place raw MCP tokens, secrets, personal data, or confidential content into an AI prompt unless they understand the external provider's handling of that information.
If Lemonade Host offers an AI-assisted support feature, that is different from a customer-connected deployment tool. In the support feature, we may send the support message and limited relevant account or diagnostic context to an AI provider to help generate, summarize, classify, or route a response.
Before enabling that feature, we intend to:
Users should review AI-generated support and should not rely on it as legal, security, financial, or other professional advice.
We generally determine the purposes and means of processing account, billing, security, abuse-prevention, service analytics, support, and legal-compliance information. For those activities, Lemonade Host and the Operator act as a controller or business.
When we process personal information contained in Customer Content or collected through a customer Site solely to provide hosting or an optional customer-configured feature, the customer generally determines why the information is collected and how it is used. The customer is generally the controller or business, and Lemonade Host is generally a processor, service provider, or contractor.
In that role, we process information to provide the Service, secure it, prevent abuse, follow documented customer instructions, and comply with law. We do not sell that information or use it for cross-context behavioral advertising.
Each customer is responsible for:
If a static Site uses client-side JavaScript to send information directly from a visitor's browser to a customer-selected third party, that third party may receive the data without it being stored by Lemonade Host, apart from ordinary network or security logs. The customer is responsible for disclosing and governing that transfer.
If Lemonade Host provides an upgraded feature that receives or stores form submissions or other visitor data, the feature description and any additional data-processing terms may apply.
We may disclose personal information:
We may disclose aggregated or deidentified information that cannot reasonably be linked to an individual. We will not attempt to reidentify data that applicable law requires us to maintain as deidentified.
Lemonade Host is operated from the United States, and primary systems are intended to be located in the United States. Information may therefore be transferred to and processed in the United States and other countries where providers operate.
Privacy laws in those countries may differ from the laws where you live. Where the EEA, UK, Switzerland, or another jurisdiction requires a transfer mechanism, we will use an applicable mechanism or take other required steps before making a restricted transfer, such as contractual safeguards, an adequacy framework, or another legally recognized method.
Customers that use the Service to process personal information from multiple countries are responsible for determining whether their own use requires a data processing addendum, transfer assessment, representative, local storage, or other compliance measure.
We retain personal information only for as long as reasonably necessary for the purposes described, including service delivery, security, dispute resolution, tax, accounting, legal compliance, and enforcement. Actual retention can vary based on the data, account status, backup cycles, legal holds, investigations, and technical constraints.
Our intended baseline schedule is:
Deletion from active systems does not always mean immediate deletion from immutable logs, encrypted backups, fraud systems, provider records, or records we are legally permitted or required to retain.
We use administrative, technical, and physical safeguards intended to protect personal information. Depending on the feature, safeguards may include access controls, network filtering, encryption in transit, encryption at rest for retrievable credentials, one-way hashing for issued tokens, scoped permissions, secret rotation, logging, backups, and security monitoring.
GitHub App private keys and other retrievable integration secrets should be encrypted at rest. Short-lived GitHub access tokens should be generated and discarded through their normal lifecycle. MCP or API tokens issued to customers should be hashed at rest and displayed only once. Dashboard controls should allow customers to revoke GitHub connections and tokens.
No security measure is perfect. We cannot guarantee that unauthorized access, loss, alteration, disclosure, hardware failure, software defects, attacks, or other incidents will never occur. Customers remain responsible for securing their own devices, email, repositories, code, credentials, Authorized Agents, and backups.
Depending on where you live and which law applies, you may have the right to:
Submit a request to [email protected]. State the account email and the right you want to exercise. We may need to verify identity and authority before responding. Verification may include access to the account email, authentication to the account, transaction information, or other proportionate steps.
An authorized agent may submit a request where law permits, but we may require proof of authorization and direct verification with the individual.
We may deny or limit a request where permitted, including when we cannot verify identity, the information belongs to another person, deletion would impair security or legal rights, retention is legally required, or the request is manifestly unfounded, excessive, fraudulent, or outside the scope of applicable law.
We will not unlawfully discriminate against a person for exercising a privacy right.
The California Consumer Privacy Act, as amended, applies only to businesses that meet statutory criteria and to certain service providers, contractors, and recipients. Whether every CCPA obligation applies to Lemonade Host may depend on the current Operator's size, data volume, relationships, and activities.
To the extent the CCPA applies, this Policy describes the categories of personal information collected, sources, business or commercial purposes, categories of recipients, retention approach, and rights request method.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not knowingly sell or share the personal information of people under 16.
Even where a particular statutory right does not legally apply, we may choose to honor a reasonable access, correction, or deletion request when doing so is feasible, secure, and consistent with our obligations.
Where applicable, individuals in the EEA, UK, or Switzerland may have rights to access, correction, deletion, portability, restriction, objection, and withdrawal of consent, and may lodge a complaint with a competent supervisory authority.
If we rely on legitimate interests, you may request information about the balancing of those interests. If we rely on consent, withdrawal applies prospectively.
If Lemonade Host actively targets or materially expands service to these jurisdictions, additional measures may be required, including a data processing addendum, transfer terms, records of processing, a representative, or other local compliance steps. This Policy does not itself represent that every enterprise or regulated-customer requirement has been completed.
We may use automated systems to detect spam, attacks, malware, abnormal resource use, payment risk, or policy violations; prioritize support; route abuse reports; and identify technical errors.
These systems may temporarily block a request, deployment, Site, payment, or login. Where applicable law grants a right relating to a decision based solely on automated processing that has legal or similarly significant effects, you may request information or human review by contacting [email protected].
AI-assisted support may generate or suggest responses, but users should not treat those responses as professional advice. We do not intend to make employment, credit, housing, insurance, health, or similarly high-impact decisions about individuals through the Service.
The Service is not directed to children or minors. Account holders must be at least eighteen (18) years old.
We do not knowingly collect personal information directly from a person under 13 through a Lemonade Host account. If we learn that a minor created an account or submitted personal information without valid authorization, we may suspend the account and delete the information, subject to legal and security exceptions.
Customers may not use the Service to intentionally collect children's personal information unless they independently satisfy all applicable consent, notice, security, and other legal requirements and the applicable Lemonade Host feature is expressly approved for that use. The base Service is not designed for children's regulated data.
We may update this Policy as the Service, providers, features, laws, or business structure change. The Last Updated date will identify the current version.
If a change materially affects how active account information is used, we will provide notice as required by law, which may be by email, account notice, or another appropriate method. A provider-name update that does not materially change the purpose or type of processing may be made by updating the provider list and date.
If the Lemonade Host business is transferred to a dedicated entity, this Policy will be updated to identify the new controller or business and any resulting changes to governing contacts, locations, or providers.
Privacy questions and requests:
For account security, do not include passwords, full card numbers, private keys, or raw access tokens in an ordinary email.
Related
What the service includes, how billing and deployments work, and how disputes are resolved.
The limits and rules that keep a 99¢ site healthy for everyone.
The 30-day guarantee on a new site, and how billing disputes are handled.
Every plan, every interval, on one page.
Join the list and we'll email you just once — that's the only thing we use your address for.