Privacy Policy

Last updated: July 21, 2026

Limato (“we”, “us”) is a Chrome extension that rewrites, translates, and explains user-selected text using AI. This policy explains what data we collect, how we use it, who it is shared with, and how long we keep it.

Limited Use disclosure. Limato’s use and transfer of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not sell your data, do not use it for advertising, and do not allow humans to read it except where required for security, legal compliance, or with your explicit consent.

1. What we collect

a) Text you select, and its surrounding context

When you trigger a rewrite, the text you selected on the current page (up to 5000 characters per request) is sent to our backend for processing.

When you select a single word or a short phrase while reading a page, the extension can offer Explain — a contextual explanation of that term. Because the meaning of a word depends on the sentence around it, Explain sends a limited amount of the surrounding text in addition to your selection: up to 600 characters immediately before and 600 characters immediately after it, taken from the same paragraph or block element. The selected term itself is limited to 200 characters in this mode.

Explain applies only to text you are reading on a page. Selections inside text fields you are writing in (comment boxes, message composers, editors) and in Google Docs always use rewrite or translation instead, and never send surrounding text you did not select. Context is used only to produce the explanation for that one request: it is not stored on our servers and is not used to train AI models.

b) Device identifier

On first use, a random UUID is generated and stored locally in your browser. It is sent with each request so we can apply daily rate limits to anonymous users. It is not linked to your identity.

c) Preferences

Your chosen tone and target language are stored locally in your browser and sent with each request. Your last choice between Explain and Translate for short selections is also stored locally.

d) Authentication data (optional)

If you choose to sign in, we use Supabase to handle authentication. We receive a JWT token containing your Supabase user ID and email. Signing in is optional and unlocks a higher daily rewrite limit.

e) Technical data

Our backend temporarily processes your IP address (via Cloudflare) to enforce rate limits and prevent abuse. IP addresses are not stored in application logs.

2. How we use your data

We do not use your data for advertising, profiling, or training AI models.

3. Third parties we share data with

We do not sell or rent your data to any third party.

3.1 Cookies and similar technologies

Our website sets the following client-side storage:

4. Data retention

5. Permissions we request

6. Your rights

You can uninstall the extension at any time to stop all data collection. If you signed in, you may request deletion of your account by emailing us at the address below. Because we do not store selected text, there is no stored content to delete on our side.

If you are located in the EEA / UK / California, you have rights under GDPR / UK GDPR / CCPA, including access, correction, deletion, and objection. To exercise these rights, contact us.

7. Children

Limato is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect data from them.

8. Changes to this policy

We may update this policy. Material changes will be announced on this page with a new “Last updated” date.

9. Contact

Questions, requests, or data-deletion inquiries: support@limato.app.