Privacy Policy
Last updated: January 31, 2026
1. Introduction
Lotte ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI assistant application and related services (collectively, the "Service").
Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, and payment information when you create an account or subscribe to our Service.
- Communications: Information you provide when contacting us for support or feedback.
2.2 Information Processed Locally
Lotte is designed with a privacy-first architecture. The following data is processed locally on your device and is never transmitted to or stored on our servers:
- Email content and metadata from connected email accounts
- Calendar events and scheduling information
- CRM data and contact information
- Documents and files you process with Lotte
- Conversation history with Lotte
2.3 Information Transmitted to AI Providers
To provide AI-powered features, certain data may be sent to third-party AI providers (such as Anthropic) for processing:
- Text prompts and queries you submit to Lotte
- Context necessary to generate responses (e.g., email content being summarized)
This data is transmitted via encrypted connections and is subject to the AI provider's privacy policy. We do not retain copies of this data on our servers.
2.4 Website Visitor Identification
We use Midbound Inc.'s person-based marketing platform to identify companies and individuals visiting our website for lead generation and business development purposes. This service may collect:
- Identifiers: IP address and device identifiers
- Internet Activity: Browser type, pages visited, and browsing behavior on our site
- Geolocation Data: General location based on IP address
- Professional Information: Publicly available business contact information associated with your organization
- Inferences: Information about your potential interests based on browsing activity
Midbound Inc. acts as our service provider/processor for website visitor identification and operates under contractual limitations on their use of this data. To opt out of Midbound's visitor identification, visit midbound.ai/optout.
2.5 Automatically Collected Information
- Usage Data: Anonymous usage statistics, feature usage patterns, and error logs to improve the Service.
- Device Information: Operating system, application version, and general device characteristics.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and send related information
- Send technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Monitor and analyze trends, usage, and activities
- Detect, investigate, and prevent fraudulent transactions and abuse
4. Data Storage and Security
4.1 Local Data
Your emails, CRM data, and other sensitive information are stored locally on your device. We do not have access to this data and cannot retrieve it.
4.2 Account Data
Account information and subscription data are stored on secure servers with industry-standard encryption.
4.3 Security Measures
We implement appropriate technical and organizational measures to protect your information, including:
- End-to-end encryption for all API communications
- Local encryption of sensitive data at rest
- Regular security audits and updates
- Access controls and authentication requirements
5. Data Sharing and Disclosure
We do not sell your personal information. We may share information in the following circumstances:
- Service Providers: With third-party vendors who perform services on our behalf (e.g., payment processing, AI providers)
- Legal Requirements: If required by law or in response to valid legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you have given us permission to share
6. Third-Party Services
The Service integrates with third-party services including:
- Anthropic (Claude): For AI processing - Privacy Policy
- Google (Gmail, Calendar): For email and calendar integration
- Affinity CRM: For CRM integration
- WhatsApp: For messaging interface
- Midbound Inc.: For website visitor identification - Privacy Policy | Opt Out
Your use of these integrations is subject to each provider's respective privacy policies.
7. Your Rights and Choices
You have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information
- Data Portability: Request a copy of your data in a portable format
- Opt-Out: Opt out of marketing communications at any time
To exercise these rights, contact us at privacy@getlotte.ai.
7.1 State-Specific Privacy Rights
If you are a resident of California, Colorado, Connecticut, Utah, or Virginia, you have additional rights under your state's privacy laws:
- Right to Opt-Out of Sale/Sharing: You may opt out of the "sale" or "sharing" of your personal information for targeted advertising purposes. Our use of website visitor identification services may constitute a "sale" or "share" under certain state laws.
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To opt out of website visitor identification and targeted advertising, visit midbound.ai/optout. For all other privacy requests, contact privacy@getlotte.ai.
8. Data Retention
We retain your account information for as long as your account is active or as needed to provide you services. Local data remains on your device under your control. Upon account deletion, we will delete or anonymize your personal information within 30 days, unless retention is required by law.
9. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18.
10. International Data Transfers
If you are located outside the United States, please note that we process data in the United States. By using the Service, you consent to the transfer of your information to the United States.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Material changes will be communicated via email or in-app notification.
12. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: privacy@getlotte.ai