Last updated: May 10, 2026
Limato (“we”, “us”) is a Chrome extension that rewrites user-selected text using AI. This policy explains what data we collect, how we use it, who it is shared with, and how long we keep it.
Limited Use disclosure. Limato’s use and transfer of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not sell your data, do not use it for advertising, and do not allow humans to read it except where required for security, legal compliance, or with your explicit consent.
When you trigger a rewrite, the text you selected on the current page (up to 5000 characters per request) is sent to our backend for processing.
On first use, a random UUID is generated and stored locally in your browser. It is sent with each request so we can apply daily rate limits to anonymous users. It is not linked to your identity.
Your chosen tone and target language are stored locally in your browser and sent with each request.
If you choose to sign in, we use Supabase to handle authentication. We receive a JWT token containing your Supabase user ID and email. Signing in is optional and unlocks a higher daily rewrite limit.
Our backend temporarily processes your IP address (via Cloudflare) to enforce rate limits and prevent abuse. IP addresses are not stored in application logs.
We do not use your data for advertising, profiling, or training AI models.
localStorage and a
first-party cookie. In the browser extension we collect anonymous
usage events (e.g. popup opened, rewrite completed) keyed by a
local device ID. IP addresses are processed transiently for
geolocation and discarded by PostHog. We use PostHog under a Data
Processing Agreement; data is stored in the EU. Legal basis on the
website: consent (you can accept or reject via the cookie banner).
Legal basis in the extension: legitimate interest (product
improvement) — disclosed at install via the Chrome Web Store
listing. You can opt out at any time by clicking "Reject" in the
cookie banner, clearing browser storage, or contacting us.
We do not sell or rent your data to any third party.
Our website sets the following client-side storage:
limato_consent_v1
(localStorage) — remembers your cookie banner choice.
No consent required.
localStorage and a
first-party cookie under the ph_* prefix. Loaded only
after you click "Accept" on the cookie banner.
activeTab — to read the text you selected on the current
page.
storage — to save your preferences and device ID
locally.
identity — to support sign-in via Supabase OAuth (only
used if you sign in).
You can uninstall the extension at any time to stop all data collection. If you signed in, you may request deletion of your account by emailing us at the address below. Because we do not store selected text, there is no stored content to delete on our side.
If you are located in the EEA / UK / California, you have rights under GDPR / UK GDPR / CCPA, including access, correction, deletion, and objection. To exercise these rights, contact us.
Limato is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect data from them.
We may update this policy. Material changes will be announced on this page with a new “Last updated” date.
Questions, requests, or data-deletion inquiries: [email protected].