Privacy

What this site collects, and why.

A plain description of what happens to information you give us here, who is responsible for it, and what you can ask of us. It covers this website only — the laibrary product is governed by your organization's agreement with us.

Who is responsible

The controller of the personal data described in this notice is laibrary Inc., a Delaware corporation with its registered office at 8 The Green #10215, Dover, DE 19901, USA (“laibrary”, “we”, “us”). Questions about this notice or about your data go to info@laibrary.ai.

When you use the contact form

We store what you type, which is:

  • your first and last name;
  • your work email address;
  • optionally your phone number, organization, job title, country, industry and the countries you operate in, if you fill those in;
  • the fact that you ticked the consent box, and the IP address the submission came from.

The IP address is kept with the submission so that abuse of the form can be traced and rate limits enforced. We use the rest to reply to you. We do not sell it, and we do not add you to a mailing list.

When you use “Ask Dewey”

Dewey is the website's assistant. The question you type is sent to our server and passed to Anthropic, which generates the answer from a fixed set of published facts about laibrary. Dewey is separate from the Guardian Agent inside the product and has no access to any customer's data. Do not put confidential information into it — it is a public tool answering questions about laibrary, not a support channel with any agreement attached.

We keep the questions people ask, together with the answer given, so we can see what visitors want to know and improve the tool. These records are not linked to your IP address or to any account — they are only the question and the answer.

Browser extension

Some organizations that use laibrary install our laibrary Shadow AI browser extension on their employees’ managed browsers. It is deployed by that organization’s administrator, not by us, and it reports only to that organization’s own laibrary tenant. This section describes exactly what it does.

What leaves the browser, for a visit to a site on the vendor list:

  • the hostname of the AI-vendor site (for example claude.ai);
  • which vendor on the list it matched;
  • the time of the visit;
  • a work email address, only if the employee typed one into the extension’s options or their administrator set one by policy — otherwise nothing that identifies the person.

What never leaves the browser:

  • page content, anything typed, form data or keystrokes;
  • the path or query string of any URL;
  • cookies or sign-in state;
  • any site that is not on the vendor list — the extension asks the browser for access to the listed AI-vendor hosts and to laibrary itself, and nothing else.

The vendor list is public and identical for every organization: it is served at /api/v1/shadow-ai/extension-catalogue and the extension refreshes it daily. Reports are signed with a key that belongs to the employer’s tenant; the employer’s administrator can rotate that key at any time, which stops every installed copy from reporting until it is reconfigured. The package the Chrome Web Store serves is the complete, unminified source, and the same package with its checksum is available to customers on request, so an organization’s security team can read exactly what it deploys.

How long an organization keeps these reports, and the lawful basis for monitoring, are matters between the employee and their employer under that organization’s own policies.

Cookies and similar technologies

This site runs no third-party analytics, no advertising tags and no tracking pixels, and the marketing pages set no cookies at all — which is why there is no consent banner: there is nothing to consent to.

What the site does store, all first-party and all functional: signing in to the product — which lives on its own host, app.laibrary.ai — stores a session token in your browser, which is what keeps you logged in; and the pages may keep small conveniences (such as a dismissed prompt) in your browser’s local storage, which never leaves your device and is never used to identify or track you. Clearing your browser’s site data removes all of it, with no effect beyond being signed out.

If we ever introduce analytics or any non-essential cookies, this section will change first and a consent choice will appear before anything is set.

This cookies statement is subject to change pending legal review.

Where it is held, and who processes it for us

Submissions and Dewey questions are stored in our own database on infrastructure we operate, rather than in a third-party marketing platform. That infrastructure is hosted in Germany, in the EU — the provider is Hetzner. A small number of providers process data for us, each under written data-processing terms and only for the purpose stated:

  • Hetzner Online GmbH (Germany) — hosts the servers and database where submissions and Dewey questions are stored.
  • Resend, Inc. (United States) — delivers the emails that carry your contact-form details to us and the acknowledgement back to you.
  • Anthropic, PBC (United States) — generates Dewey’s answers from the question you type and a fixed set of published facts about laibrary; it does not receive your name or contact details.
  • Functional Software, Inc. (Sentry) — receives technical error reports from our servers so we can fix faults. Those reports are configured to exclude personal data, request contents and IP addresses.
  • Calendly — “Book a call” takes you to Calendly’s own site; anything you enter there is governed by Calendly’s privacy notice, not this one.

We do not sell personal data, we do not share it for advertising, and no other third party receives it unless the law requires us to disclose it.

Where the EU or UK GDPR applies, our legal bases are:

  • Contact form — taking steps at your request before entering a contract (Article 6(1)(b)), and your consent, which you give by ticking the box on the form (Article 6(1)(a)). You can withdraw that consent at any time; we then stop and delete the submission.
  • IP address kept with a submission — our legitimate interest in keeping the form free of abuse (Article 6(1)(f)).
  • Dewey questions — our legitimate interest in operating and improving the website assistant (Article 6(1)(f)). Questions are not linked to you.
  • Browser extension — your employer is the controller of the reports it collects; its legal basis is set out in your employer’s own policies.
  • Legal obligations — where we must keep or disclose data to comply with the law (Article 6(1)(c)).

International transfers

laibrary Inc. is a United States company. Your contact-form details are stored in Germany, but they are read by our staff in the United States, the email that carries them to us goes through Resend in the United States, and Dewey’s answers are generated by Anthropic in the United States.

Where that means personal data protected by the EU or UK GDPR leaves the European Economic Area or the United Kingdom, we transfer it under the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), which each of the providers above offers as part of its data-processing terms, together with the safeguards described under “How we protect it” below. You can ask us at info@laibrary.ai for a copy of the transfer terms that apply.

How long we keep it

  • Contact-form submissions, including the IP address — for as long as we are dealing with your request, and for no more than 24 months after our last contact with you. If your organization becomes a customer, the details move under that agreement instead.
  • Dewey questions and answers — deleted automatically 90 days after they are asked.
  • Browser-extension reports — held in your employer’s own laibrary tenant for the retention period your employer sets; we do not keep a separate copy.
  • Emails we exchange with you — kept in our mailbox while your enquiry is open, then subject to the same 24-month limit.

You can ask us to delete a submission at any time, and we will, unless the law requires us to keep it.

How we protect it

  • Everything between your browser and our servers travels over TLS (HTTPS).
  • The disks holding our database and backups are encrypted at rest, and backups are encrypted again before they leave the server.
  • Administrative access is limited to named laibrary staff, requires multi-factor authentication, and is only possible from approved networks.
  • Inside the product, each organization’s data is isolated at the database row level, so one customer can never read another’s.
  • We keep audit logs of administrative actions and monitor our systems for faults; we run no third-party analytics or tracking on this site.

No system is perfectly secure. If we ever discover a breach that affects your personal data, we will tell you and any supervisory authority we are required to notify without undue delay.

We do not train on your data

Nothing you or your organisation puts into laibrary is used to train a model — not ours, and not a provider's. There is no training pipeline that reads customer data, and there is no setting that turns one on.

The assistant inside the product works by retrieval: it finds relevant material and passes it, with your question, to a commercial model provider to compose an answer. That is processing, not training, and it happens under an API agreement rather than a consumer one. If your organisation switches on per-tenant knowledge, the documents you upload are indexed so the assistant can retrieve from them — that indexing is scoped to your tenant, it is off unless you enable it, and turning it off stops the retrieval.

Your rights

Depending on where you live — including under the EU and UK GDPR and US state privacy laws such as those of California and Colorado — you have the right to:

  • ask for a copy of the personal data we hold about you (access);
  • have it corrected if it is wrong (rectification);
  • have it deleted (erasure);
  • restrict or object to how we use it, including any use based on our legitimate interests;
  • receive it in a portable, machine-readable form;
  • withdraw consent you have given, at any time, without affecting what was done before;
  • complain to your data-protection authority — in the EU, the supervisory authority of your member state; in the UK, the Information Commissioner’s Office.

To exercise any of these, email info@laibrary.ai. We may ask you to confirm your identity first. We answer within one month, or sooner where the law requires it, and we never treat you differently for exercising a right. We do not sell or share personal data, so there is nothing to opt out of; we do not make automated decisions about individuals.

Changes to this notice

If we change this notice we update the date at the end of the page. If a change materially affects how we use your data, we will say so prominently on this page before it takes effect.

Asking us about your data

Email [info@laibrary.ai](mailto:info@laibrary.ai) and say that your message concerns your personal data, or write to laibrary Inc., 8 The Green #10215, Dover, DE 19901, USA. You can also use the contact form — it reaches the same people.

This privacy notice is subject to change pending legal review. Last updated 21 September 2026.