Privacy is the product.

So this page can afford to be specific. Here is everything we hold, everything we refuse to hold, and everything you can make us do about it.

Who "we" is

Liir is built and operated by Siliroid LLC, in the United States, on hardware we own, not in a reseller's cloud. This policy covers liir.net and the apps it serves (mail, your page, the Vault). Data you give us lives in the United States; if you are somewhere else, it travels here. Writing to hello@liir.net reaches a person.

Cookies · exactly two, and only if you sign in

Browsing this site sets no cookies at all. Signing in sets two, both ours, both locked to liir.net over HTTPS:

__Host-liirsess: your session, a random token that signs you in. Page scripts can never read it, and the registry stores only a hash of it. It lives 30 days, or until you sign out.
__Host-liirin: the word “1”, nothing else. It lets our own pages show the signed-in header without asking the server first. It identifies nobody.

There is no cookie banner because consent rules apply to cookies that are not strictly necessary for a service you asked for. You asked to be signed in; both of these exist only to deliver that signed-in state, and no one else's cookies exist here.

Traffic, counted without you

We count visits on our own server: the page asked for, the moment, and the page that linked here. The counter never records your IP address, and cookies are stripped before a line is written: the traffic log cannot hold your session even by accident. To avoid counting you twice in one day, the server briefly mixes your connection's address with a key that lives only in memory and dies at midnight. The mixed value stays in memory too: it never reaches disk, and once the day's key is gone it cannot be tied to anyone. What disk holds is arithmetic: how many, never who. No analytics service, no pixels, nothing loaded from anyone else's servers. The examples on /hub are drawn entirely in your browser: nothing you do there is sent anywhere.

The ledger · what we actually hold, system by system

The registry: the name you claimed, the public half of your passkey (useless without the private half, which never leaves your device), and whatever facets you chose to publish, each behind the dial you set. We hold these to perform the contract you made with us: to be Liir for you.

The Vault: sealed relics. Ciphertext, its room (letter, file, cash…), its size, a random salt, and a 16-character check that proves nothing about your words. We cannot read a byte of it; the label itself is sealed. We count your relics; we cannot open one.

Mail: if you claimed a mailbox, we host your letters. Custody is its own honest page: what we hold, for how long, and who can read it while we do.

Billing: if you subscribe, Stripe, our outside payment provider, holds your card; they never tell us the number. We keep your plan, its status, and Stripe's reference IDs. For fraud prevention and its own legal duties Stripe also handles payment data as a controller in its own right, under its own privacy policy.

Invitations: a hash of each key, who minted it, who used it.

The notary: a public chain of salted fingerprints, deliberately containing no names and no content. It is built so a fingerprint cannot be tied back to a person, and we never try. If you can show us one that identifies you, the rights below apply to it like anything else.

Operations: service logs that follow one law, no IP addresses in anything persistent.

The legal bases, named

For readers in places, like the EU, where each use of data must name its legal ground: the registry, the Vault, and mail are processed to perform our contract with you. Billing is that contract plus our legal obligations (tax and accounting). Security and the service logs above are our legitimate interest in keeping the doors standing. Anything optional asks first and runs on consent, which you can take back. Recipients: the providers named on this page, no others. Retention: the “how long things live” box below. Where your data lives: the United States, as the top of this page says.

What we never hold

No passwords: none exist here. No private keys. No vault words: they never reach us; the key derived from them lives in your page for the life of a tab. No faces. No card numbers. No browsing profiles, of you or anyone. We cannot be compelled to produce what we do not hold: that is not bravery, it is inventory.

Your rights · everyone's, not just where the law insists

See it: ask, and we will show you everything we hold on your name, which is mostly ciphertext and the list above.
Take it: your relics, your mail, your facets: downloadable, yours, including on the way out. The law calls this portability; the files come in formats another service can read.
Fix it: your facets are yours to edit at will; the rest, ask.
Pause it: ask us to restrict a use of your data, or object to one, and we stop while we sort it out (restriction and objection, by their legal names).
Erase it: deleting your things yourself puts them in a 90-day rest (that window is your ransomware protection: nothing, including us, can hurry it). A formal erasure request is different: verify it is really you, and we will purge inside the legal clock: within a month, not ninety days.
Appeal it: if we refuse a request, we say why in writing, and you can appeal that refusal itself; a different set of eyes answers. Oregon residents: this is the appeal your privacy law promises, and the Oregon Department of Justice hears you if ours disappoints.
Complain: to us first, we hope (hello@liir.net), and to your local data authority always, if we disappoint you.

We answer within a month, stricter than most clocks the law sets, and we answer as people.

How long things live

Sessions: 30 days, or until you sign out; signing out deletes on the spot. Deleted relics: 90 days resting, then gone for good, on schedule. Mail: for as long as you keep the mailbox; the terms say what happens if a subscription lapses (a grace period, then frozen, never quietly deleted). Traffic counts: kept as numbers with nobody in them. The notary chain: permanent, and permanently about no one.

Children

Liir is not for children under 13, and we do not knowingly hold a child's data; if we learn we do, we delete it. Doors that require being an adult are separately and explicitly gated.

If something goes wrong

If a breach ever touches something of yours, we tell you: fast, plainly, and with what it actually means for you. The law's famous 72-hour clock is for notifying regulators, and where it applies we honor it; telling you inside 72 hours of knowing is our own promise, stricter than any statute asks. The architecture is built so that the honest answer is usually “they got ciphertext”: here is exactly what an attacker can and cannot get.

Never

No ads. No trackers. No data brokers. No selling, renting, or “sharing with partners.” You're the customer, not the product: Liir answers to the people who use it, no one else.

Questions

Write to hello@liir.net. A person reads it.

This page is the policy. Two named companions carry detail it already summarizes: mail custody and the terms (what happens when a subscription lapses). Nothing else is incorporated, and there is no smaller print. If it changes, this date changes and the change is named here, not slipped in: August 22, 2026.