Legal
Privacy Policy
Last updated
This Privacy Policy explains how ZetaMinusOne LLC, a Puerto Rico limited liability company (“Lattis”, “we”, “us”, or “our”), handles information in connection with the Lattis desktop application, the web application at app.getlattis.ai, and the website at getlattis.ai (together, the “Services”).
By using the Services, you agree to the collection and use of information as described in this policy.
Information we collect
- Account information. When you sign in, we collect your name, email address, and authentication identifiers.
- Usage telemetry. We collect telemetry about how you use the Services, limited to what is needed to provide the features in the tool itself.
- Session traces. While you are signed in, the desktop app uploads a full record of each agent session: the system prompts, your prompts, the model’s responses, the tool calls the agent made and their results, and the project, branch, and model names. We store these traces in Amazon S3. See Telemetry in the desktop app and Data retention.
- Error and diagnostic data. We use Sentry to collect error and diagnostic data so we can detect and fix problems.
- Content you provide. The desktop app runs on your own machine. Model credentials you supply stay on your machine. Code and prompts stay under your control, except where you direct the Services to transmit them and where they appear in a session trace.
Telemetry in the desktop app
The desktop app records usage telemetry on your machine. It sends that telemetry to us only while you are signed in to a Lattis account, or when you give a headless daemon a Lattis API key. Signing out stops it. The telemetry is limited to what is needed to provide the features in the tool.
Under the same conditions, the app also uploads a session trace for each agent session. A session trace is the full content of the session: system prompts, your prompts, the model’s responses, and the tool calls the agent made with their results. These can include source code and any other text the agent read or wrote. The app sends each trace directly to our Amazon S3 storage, and the usage and cost summary of the session to our backend. An organization admin can turn trace capture off for the whole organization by setting its trace retention to 0 days. That also deletes the traces stored before the change.
Released builds of the desktop app also send error and crash reports to Sentry. These reports do not depend on sign-in.
Both are on by default, and you can turn both off. Set "telemetry_enabled": false
in the app’s config.json file (in the Lattis data directory). Usage telemetry
and session traces then stay on your machine, even while you are signed in, and
no crash reports are sent.
Model providers
When you connect a model provider with your own credentials, your requests and credentials are sent directly to that provider, under its terms. Lattis does not route this traffic through us and does not add a per-token markup.
When you use a Lattis-hosted model (for example lattis-turbo, or a vendor model
through a Team plan) while signed in, your prompts and the model’s responses pass
through the Lattis backend. The backend forwards them to an upstream inference
provider, Pump or OpenRouter, which serves the model on our account. We keep
usage metadata for each request: the user and organization, the model, token
counts, and cost. We use it to apply usage limits and to bill your organization.
How we use information
- To provide, maintain, and improve the Services.
- To authenticate users and secure accounts.
- To report usage and cost back to you and your organization.
- To communicate with you about updates, security, and support.
- To comply with legal obligations.
How we share information
We share information with the service providers who help us run the Services:
- Amazon Web Services (AWS) — hosting and infrastructure.
- Neon — database.
- Sentry — error and diagnostic tracking.
- Resend — transactional email.
- Stripe — payment processing.
- Pump and OpenRouter — inference for Lattis-hosted models.
We do not sell your personal information. We may disclose information where required by law, or as part of a merger, acquisition, or sale of assets.
Data retention
We keep session traces for 90 days by default. An organization admin can set a different period, from 0 to 365 days. At 0, we capture no traces for the organization. When a trace reaches the end of its period, we delete it.
We keep usage and cost summaries for each session and request, without the session content, for as long as the account exists. They support usage limits, billing, and the usage history we report to you and your organization.
If you ask us to delete your account, we delete your associated personal information and keep none of it, except where the law requires otherwise.
Your choices and requests
You can ask us to access or delete your personal information by emailing privacy@zetaminusone.com. To stop the desktop app from sending telemetry and crash reports, see Telemetry in the desktop app.
Security
We use reasonable technical and organizational measures to protect information. No method of transmission or storage is completely secure.
Children’s privacy
The Services are not directed to children under the age required by applicable law, and we do not knowingly collect their personal information.
International data transfers
We process and store information in the United States, for example through AWS. If you access the Services from outside the United States, you consent to this transfer.
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent change.
Contact us
Questions about this policy can be sent to privacy@zetaminusone.com, or by mail to ZetaMinusOne LLC, Puerto Rico.