You may be putting unpublished work into this product, so this page is specific rather than reassuring: exactly who receives your content, exactly how long anyone keeps it, exactly what you can delete, and exactly what we haven't built yet.
We do not train any models. Your project content is not used to train ours, because we have none, and it is not used to train our providers' models either.
Two AI providers can see your content: Anthropic, which powers everything Lio reasons about, and OpenAI, which transcribes your voice input if you use it. That is the whole list — and in practice, unless you dictate, Anthropic is the only one.
We keep your data until you delete it. You can export all of it, or delete all of it, yourself, from your profile page, at any moment. You can also set a window that deletes old conversations automatically, and mark a project confidential so nothing derived from it goes to anyone but Anthropic.
There are things we have not built yet, and they are named at the bottom of this page rather than left out of it.
There is no analytics SDK anywhere in Theioptera. No Google Analytics, no PostHog, no Segment, no session replay, no advertising pixels.
What we do keep in your browser is a handful of interface preferences, and nothing else: your light/dark choice, whether your sidebar is collapsed, which briefings you have dismissed, and whether you have already seen the product tour and the changelog. The last two are stored under a key containing your email address, so that a shared computer does not show your notices to someone else. None of it is ever sent to us or to anyone else — it stays in your browser and you can clear it at any time. Separately, there is the session cookie, which is what keeps you signed in.
To answer you at all, the content of your question and the relevant parts of your project have to be sent to a language model. Here is exactly who receives what:
| Provider | What it receives | Why |
|---|---|---|
| Anthropic (Claude) | Your chat turns, project context, retrieved paper abstracts, and the text of materials you've added | All of Lio's reasoning, planning and writing |
| OpenAI | The audio you record if you use voice input — nothing else | Transcribing speech |
Under both providers' standard commercial API terms, what we send is not used to train their models, and is held only for a limited abuse-monitoring window — 30 days at the time of writing. We have not enabled any training or data-sharing option on either account.
To be plain about the limit of that: we have not yet signed a zero-retention agreement with either provider. If you put an unpublished manuscript into Lio today, its text goes to Anthropic, and it can sit in Anthropic's abuse-monitoring window for up to 30 days before it ages out. If that window matters for your work, hold the manuscript back and tell us — it is the first thing we intend to close.
An earlier version of this page also overstated OpenAI's role, and this corrects that too: OpenAI does not receive your project text. We have a paper-search index that can use OpenAI embeddings, it is switched off by default, and even when it is on it embeds only the short search phrase and the public title and abstract of published papers — never your materials, your chats or your notes. If we ever change that, it will be written here first.
Google is not one of our AI providers. Google appears only as a sign-in option. An earlier version of this page said otherwise; it was wrong, and this corrects it.
The complete list of every company that can hold or see your data — including our database host, payments and the public APIs we query — is on the Sub-processors page, linked at the bottom of this one.
When Lio looks for papers, it sends a short search phrase — derived from your question, not your project text, not your chat history, not your materials — to public scholarly APIs: OpenAlex, PubMed, Semantic Scholar, Crossref, bioRxiv, medRxiv and ClinicalTrials.gov. These requests are anonymous and carry no identifier of you or your account.
That said, a search phrase still reveals intent. "Interface propensity versus annotated ligand-binding sites" tells a log-reader roughly what you're working on, even without your name attached. We would rather say that than call the queries harmless.
If you add a material by URL, our server fetches it — the site sees a request from us, not from you.
Your data lives in a managed MongoDB database. Every connection to it is encrypted with full certificate verification, and the app itself is served only over HTTPS, so your content is encrypted in transit end to end.
We keep what you create until you delete it. There is no automatic expiry by default — a research project is meant to outlast a semester, and quietly deleting someone's work after 90 days would be the wrong default.
If you want the opposite, set a retention window on your profile: 30 days, 90 days or a year. It applies to conversations — your chats with Lio, including the ones attached to a material — and to nothing else. Your projects, materials, tasks and research graph are never touched by it. Deletion runs once a day, so it happens within a day of the cutoff rather than to the minute.
Sessions expire after 7 days. How the rest of the system is hardened — including the bugs we have found and fixed — is written up on our Security page.
Three settings, all on by your choice and none of them on by default. Each is described here by what it does and by what it does not do, because the second half is the part you actually need when deciding where to put unpublished work:
| Setting | What it does | What it does not do |
|---|---|---|
| Confidential project | Per project. Turns off literature search, overnight auto-research and voice input for it, so no search phrase, embedding or recording built from that project leaves our server. | It does not stop Anthropic seeing your chat — Anthropic is the model that answers you, and there is no local one. It does not encrypt the project or hide it from us, and it cannot recall anything sent before you turned it on. |
| Don't use my content to improve Theioptera | Per account. We stop recording feature-usage counts for you entirely. | It does not affect the daily limits on questions — those are what stop one account exhausting the shared budget, and they are not something we can let people switch off. |
| Automatic deletion of conversations | Per account. Chats older than the window you pick are deleted, once a day. | It covers conversations only, not your projects, materials, tasks or research graph. And it cannot reach what has already gone to Anthropic. |
Mark a project confidential when you create it, not after, if the topic itself is sensitive: creating a project searches for starter papers, and that search sends the topic out before you would have had a chance to change the setting.
If you're in the EU or UK, the GDPR gives you specific rights. Here is where each one actually lives in the product, rather than a promise to honour a request within thirty days:
| Right | How to use it |
|---|---|
| Access and portability | Profile → download a copy. You get every project and every associated record as JSON. |
| Erasure | Profile → delete account. Immediate, permanent, and a real delete — not a hidden flag. |
| Rectification | Edit anything you've written, in place, at any time. |
| Objection and restriction | Not yet self-serve — email us and we'll do it by hand. |
You never have to ask our permission for the first three. You also never have to ask us to prove the delete is real: the collections that export and deletion sweep are the same ones the app writes to, and that is enforced in the codebase.
Theioptera is early, and a privacy page that only lists the good parts isn't worth reading. These are the real gaps:
Three things that were on this list — a product-improvement opt-out, confidential projects, and a retention window — are now built, and are described above rather than promised here.
If any of the remaining ones blocks you from using Theioptera for real work, say so — that is the most useful thing you can tell us, and it moves them up the list.
We do not sell your data. We do not share it with advertisers. We do not use your private project content to train models, ours or anyone else's. If that ever changes, it will change with notice and a choice, not quietly in a diff.
The second item above is now a setting rather than only a promise: you can switch off product-improvement use for your account, and the server honours it.
Theioptera is operated from Germany by Yara Ismail, as an individual rather than a company. That means Yara Ismail is the data controller for everything described on this page — there is no organisation standing behind it, and it is better that you know that than that we imply otherwise.
Reach us at yaraismail2611@gmail.com for anything on this page, including a request to access, correct, export or delete your data. The full postal details are on our Impressum.
If you're in the EU or UK and think we've handled your data wrongly, you can complain to your national data protection authority. We'd rather you told us first and gave us the chance to fix it.
We'll update this page as Theioptera grows; the date above always reflects the last material change.
Privacy questions, data requests, or a DPA request from your institution: yaraismail2611@gmail.com. Security findings: email the same address with [security] in the subject — our Security page explains what to expect.