Privacy Policy

Last updated: August 2026

At Lona, our philosophy is simple: Your data belongs to you. Not us. We don't use your information for advertising, and we never sell it to anyone. This page explains exactly what that means in practice — what Lona touches, what it doesn't, and where your information actually lives.

1. Two Ways to Run Lona

Lona ships two ways, and it changes who's actually handling your data. Self-hosted (Community Edition): you run Lona on your own machine or server with your own Telegram bot, your own Notion integration, and your own AI provider key — Texsenss never sees, stores, or has access to any of it. Managed Hosting: Texsenss runs your instance for you, which means Texsenss — not just the software — is handling data on your behalf, as described below. Either way, the underlying data flow (what reaches Notion, your AI provider, and Telegram) is the same; only who operates the server changes.

2. Data Storage

Lona is a bridge, not a warehouse. Every capture, idea, and task is stored directly in your own Notion workspace. Lona does not maintain a permanent database of your personal notes or life organization.

3. Messaging via Telegram

You talk to Lona through Telegram, so every message reaches us by way of Telegram's own servers first — that's true for any Telegram bot, not just ours. Telegram's bot conversations use its regular chats rather than its end-to-end-encrypted Secret Chats, which aren't available to bots on any account, so your message content is held on Telegram's side under Telegram's own privacy policy. If you'd rather not keep particularly sensitive material sitting in that chat history, you can clear your conversation with the bot at any time from within Telegram.

4. AI Processing

To turn a message into a structured to-do, event, or reflection, its text is sent to an AI provider — Anthropic (Claude), Groq, or Google Gemini, depending on how your instance is configured. On self-hosted Lona, that's your own API key talking directly to your chosen provider; Texsenss is never in that loop. On Managed Hosting, it's either your own key (BYO plan) or a Texsenss-provided shared key (Shared plan) — on the shared plan, we track token counts and estimated cost per user to enforce a fair-use monthly cap, never the content of your messages, only the numbers.

5. Voice Processing

Audio recordings sent to Lona are transcribed to text in real-time using a locally-run speech-to-text model — your audio is never sent to a third-party transcription service. Once transcription is complete, the audio file is immediately deleted from our temporary processing cache. We do not store your voice recordings.

6. Google Calendar

If you connect Google Calendar, Lona requests permission to view and manage events on the specific calendar you authorize — so it can create, update, and cancel events for the to-dos and events you capture, and read your calendar to keep synced items accurate. We request no Google scope beyond Calendar: not Gmail, Drive, Contacts, or anything else. Calendar data is never used for advertising, never sold, and never used to train any AI model. Lona's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke this access at any time from your Google account settings.

7. What We Don't Log

Our application logs record operational metadata only — message type, confidence scores, timestamps, error states. The actual text of your captures, check-ins, and messages is never written to our logs.

8. Data Retention & Deletion

Your Notion data lives in your own workspace, under your control, indefinitely — edit or delete anything, anytime, from within Notion itself. If you leave Managed Hosting, your server-side configuration (API keys, calendar tokens, local logs) is permanently deleted; your Notion workspace is untouched, since it's yours. Usage-tracking data (Section 4) is kept only for the current and prior billing month.

9. Security

We use per-user API keys and OAuth tokens scoped to your own accounts, and we never write credentials into logs. No method of transmission or storage is 100% secure, but we take reasonable steps appropriate to a service of our scale to protect your information.

10. Integrations & Revoking Access

We use OAuth to connect to your Notion and Google Calendar. We only request the permissions necessary to read and write the specific "atoms" you create. You can revoke these permissions at any time through your account settings in Notion or Google.

11. Communications

We only collect the minimum information required for your application to Lona. This information is used solely for the purpose of onboarding and communicating with you about your account.

12. Children's Privacy

Lona is not directed at children under 13, and we do not knowingly collect information from anyone under 13.

13. Website Analytics

Separately from the Lona bot described above, this website (lona.texsenss.com) collects anonymous, first-party usage analytics — pageviews, which buttons get clicked, download counts, and similar aggregate behavior — so we can see what's working and what isn't. Events are tied to a random identifier stored in your browser, not to your name or email; even if you later join the waitlist or download the Community Edition, the two aren't linked. We don't store your IP address, don't use any third-party analytics vendor, and don't sell or share this data with anyone. Analytics events are kept for up to 12 months, after which they're automatically deleted. Our hosting provider, Vercel, separately collects basic pageview data as part of serving the site — see Vercel's privacy policy for that.

14. Changes to This Policy

We may update this policy as Lona's features change. Material changes will be reflected by an updated "Last updated" date above.

15. Contact Us

Questions about this policy or your data? Reach us at lona@texsenss.com.