Privacy Policy
Last updated: May 2026
lema (“we”, “our”, “us”) is in Phase 0 — currently accessible only to a small group of invited operators. This policy describes how we collect and use information when you use lema.sh or related services.
What we collect
We collect information you provide directly: your email address and profile information when you sign in via WorkOS, and the decisions, events, and workspace content you create.
When you connect a GitHub repository, lema reads its contents — architecture decision records, pull requests, issues, and commit history — to build and keep your decision graph current. We access only the repositories you authorize, and only to produce the decisions, rationale, and citations lema serves back to you.
We collect limited usage data — pages visited, actions taken — to understand how the product is being used and where to improve it.
How we use it
We use your information to operate the service, authenticate your session, and send you product updates if you've opted in. We do not sell your data.
Data storage
Data is stored on Google Cloud (us-central1). We apply reasonable security controls. During Phase 0, the product is not GDPR or SOC 2 certified — those certifications are targeted for Phase 2.
AI processing
lema uses Google Vertex AI (Gemini models) to produce its core output: it reads source material to extract structured decisions and claims, generates the embeddings that power search, and synthesizes the cited answers you see. This content is processed under Google Cloud's data-processing terms and is not used to train Google's foundation models.
On the public /try demo, your questions are sent to that model to answer over the public open-source decision graphs we host — no account, and nothing you type is stored against an identity.
Third-party services and subprocessors
We rely on the following third-party subprocessors to run lema. Each processes only the data needed for its function, under its own terms:
- WorkOS — authentication and sign-in.
- Google Cloud, including Vertex AI — hosting, storage, and the AI inference described above (us-central1).
- Stripe — payment processing for paid plans. We do not store your full card details.
- Resend — transactional email, such as sign-in and repository-import notifications.
- GitHub— repository access when you connect a repo, to read the content described under “What we collect.”
We do not sell your data and do not currently use advertising or analytics third parties.
Your rights
You may request deletion of your account and data at any time by emailing [email protected]. We will fulfill deletion requests within 30 days.
Changes
We will update this policy as the product grows. Material changes will be communicated via email to active users.
Questions? Email [email protected].