Updated September 30, 2026
Privacy and security
Lapidia reads the text field you're writing in so it can rewrite it. An app that does that needs to say exactly what it reads, where it sends it and what it keeps. That's what this page does.
In short
- Your text isn't stored. The service passes your request to the AI model and keeps neither the request nor the answer. The model provider doesn't store the content either: it stays in memory only while the answer is generated.
- Never reads passwords or logs your typing. It reads only the field you asked for help with, at the moment you asked, on Mac and Windows. Password fields are never read, and nothing you type outside that request is recorded or sent.
- No one trains AI on your text. Neither Lapidia nor the model provider uses what you write to train models.
- Encrypted and under your control. Everything travels over HTTPS. Your history and prompt library stay on your computer, with secrets masked, and the result only goes into the field when you accept it.
What the app reads
Only when you trigger an improvement (shortcut, orb or floating button), the app reads:
- the text in the focused field, or the selected text;
- on Mac, up to 12,000 characters of the visible content of the source app's window, as context;
- the app's name and, in browsers, the tab's title and address, to tell whether it's a chat app.
Password fields are never read. On Mac, the app doesn't capture keystrokes: detecting a pause in your typing counts characters through the macOS Accessibility API and doesn't know what was typed. On Windows, the app reads the field by selecting and copying the text (the clipboard is restored right afterward), and pause detection counts key presses without storing or sending which keys they were. Windows doesn't allow copying from password fields.
Where it goes
The text that was read and the context are sent to the Lapidia service, which passes them to the AI model and returns the answer. The model (DeepSeek V4.1 Flash, open-weight) runs on Fireworks AI, in the United States, which doesn't record the content of the calls: it stays in memory only while the answer is generated. The service does not store the text of the request or the answer. For up to 30 days, it logs only: an identifier for your account (or the hash of the legacy license code), the task, the model used, the token count, the latency and the HTTP status.
Neither Lapidia nor Fireworks uses your text to train models. Fireworks logs only technical metadata, such as the token count.
What stays on your computer
- Prompt library: every prompt you accept, with secrets (keys, tokens) masked before saving. Can be turned off and cleared in Settings.
- History: per session, a short title for the draft, mode, model, tokens and outcome. Never the full text.
- Feedback: whether each suggestion was accepted, edited or discarded. Labels only.
- Account session (or the legacy license code): in a file private to your user (permission 600). On the service, only its hash exists.
- Local log: sizes and labels, never content.
Your account and payments
- Account: we keep your email, your plan, your billing cycle dates and how many improvements you've used. The sign-in code and the session are stored only as hashes; no one can read them back.
- Payment: handled by Stripe. Your card details go straight to Stripe; Lapidia never sees or stores them. On the Lapidia side, only the Stripe customer ID and subscription ID are kept.
- Emails: we send the sign-in code, confirmations (such as the one for a withdrawal) and notices about the service, such as a price change or a change to these terms. We don't sell or hand over your email.
- How long: for as long as the account exists. Expired sign-in codes and old sessions are deleted automatically. Payment records may be kept for as long as tax law requires.
Updates
When it opens, the app checks a version file on our server. That check sends the installed version and the operating system, nothing more.
Your rights (LGPD)
Under the LGPD (Brazil's General Data Protection Law), you can ask to access, correct, port or delete your data, and to know who it has been shared with (Stripe, Meta, Google and the service providers named above). Write to suporte@lapidia.com and include the email address on your account; we reply within 15 days. What the app keeps on your computer you can delete in Settings or by removing the app's data folder.
Data controller: Jhony Silva Souza (Sophisti Tecnologia), CNPJ (Brazilian company registration number) 32.276.663/0001-20, Rua Kiyoshi Enomoto, 158, Ap. 16B, Torre 2, São José dos Campos – SP, CEP 12235-831, Brazil.
