1. Purpose of this Notice
This Notice explains what information a Litmous installation may communicate to SYMBIOGENESIS PRIVATE LIMITED, which communications are necessary for connected product operation, which are optional, and how optional reporting is controlled.
It forms part of the Litmous Privacy Policy and should be read with that Policy.
2. Essential connected-service information
When a Litmous installation uses connected Litmous services, the following information may be processed for release delivery, authentication, compatibility, security and basic service operation:
| Category | Examples | Purpose |
|---|---|---|
| Installation identity | Random installation UUID and authentication credential | Recognise and authenticate the installation |
| Platform information | Operating platform, architecture and OS version | Compatibility and release support |
| Version information | Application, Core and component versions | Compatibility, update and support analysis |
| Service timestamps | First seen and last seen | Operation and security of connected services |
| Download information | Release, request identifier, timestamp, user agent, referrer and application-level HMAC-derived IP value | Release delivery, security and approximate download analysis |
The installation UUID is randomly generated. Litmous does not require the computer's MAC address, motherboard serial, storage serial or another hardware fingerprint as its installation identifier.
3. Diagnostics — optional
If the user grants the diagnostics scope, Litmous may submit diagnostic information such as:
- health status;
- CPU utilisation;
- memory usage or configured memory limit;
- available disk/storage capacity;
- error information; and
- related technical state needed to diagnose operation.
Diagnostic health payloads are not accepted by the Litmous reporting service unless the latest diagnostics consent for that installation is granted.
4. Product analytics — optional
If the user grants the product_analytics scope, a Litmous release may submit product-level usage events or measurements intended to understand how features operate and where product improvement is needed.
Product analytics does not, by itself, authorise transmission of conversation text. Conversation content is governed separately by the conversation_reporting scope.
5. Conversation reporting — optional and separate
Conversation reporting is disabled unless the user has granted the conversation_reporting scope under the current applicable policy.
When enabled, a report may include:
- a random request UUID;
- the user's query;
- the Litmous response;
- the outcome, such as completed, partial, unsupported or failed;
- whether retained knowledge was used;
- limited knowledge identifiers or provenance references;
- Litmous and component versions;
- performance information; and
- the reporting time.
Each accepted conversation report is linked to the specific consent record under which it was received.
6. Feedback — optional
If a feedback function is offered and the user grants the feedback scope, Litmous may transmit the feedback deliberately submitted by the user and the limited associated context identified by that feature.
7. Consent records
Consent is recorded separately for:
- diagnostics;
- product analytics;
- conversation reporting; and
- feedback.
A consent record includes the installation, scope, whether consent was granted or withdrawn, policy version, source of the decision and time of the decision.
A new consent decision does not erase an earlier one. Historical records are retained where reasonably necessary to establish which consent applied to previous processing.
8. Withdrawal
A user may withdraw an optional consent through the controls provided by the Litmous application when those controls are available.
After withdrawal, subsequent information requiring that scope should not be sent. The Litmous server also checks the applicable consent for protected reporting categories such as conversation reporting and diagnostics.
Withdrawal does not retroactively invalidate processing that was lawful before withdrawal.
9. Authentication and identifiers
When an installation first registers, the service may issue a random client credential. The usable credential is returned to that installation and should be protected locally.
The server stores a cryptographic hash of that credential rather than storing the usable token itself.
The random installation UUID is intended to identify the Litmous installation and is not intended to function as a hardware fingerprint.
10. What Litmous does not automatically transmit
Merely opening, reading, indexing, understanding or using a local source does not by itself authorise transmission of that source to Symbiogenesis.
In particular, Litmous does not treat local books, documents, knowledge bases or source files as telemetry merely because those materials contributed to an answer.
Where knowledge provenance is included in an authorised conversation report, the reporting design is intended to use limited references or identifiers rather than the original source content.
11. Retention and deletion
Telemetry and reporting information is retained only for as long as reasonably necessary for its operational, security, quality, consent-accountability, dispute or legal purpose.
The relevant retention period depends on the category and the continuing need for the information. Information may be deleted, aggregated or anonymised when its purpose ends, subject to legal and security requirements.
12. Contact
Questions or privacy requests concerning Litmous telemetry may be sent to: noreply@litmous.com.