Lina · Legal
Privacy Policy
Last updated: · Revision 1
Effective for an account from the moment it accepts this version at signup. For an account that accepted an earlier version, or none: effective , or 30 days after we email notice to that account’s admin if later (Terms of Service, section 18).
The short version:
- We do not sell personal information or use it for advertising. We use no analytics, advertising or tracking services from third parties; Lina does keep first-party usage and interaction records as described below.
- Conversations, calls and content sent to AI tools are processed by AI providers to produce requested replies, summaries, drafts and other output. Our AI providers are listed on our Subprocessors page.
- If you talked to an organization that uses Lina, that organization controls your information — contact it first, and we will help.
1. Who we are
Lina is the trade name of Joseph Linares, a sole proprietor in San Diego, California (“Lina”, “we”, “us”). We run Lina, a service organizations use to answer the public with an AI assistant, at linasystems.org. Send privacy requests to legal@linasystems.org and anything else to support@linasystems.org.
2. Our two roles
- Controller. We decide how to handle information about our own visitors and customers: people who visit linasystems.org, request a demo, sign up, administer an organization’s account, or pay for it.
- Service provider (processor). For information an organization puts into Lina or collects through it — its visitors’ chats, its callers, its contacts and members, email forwarded to it, and its knowledge content — we act on behalf of that organization, follow its instructions, and are bound by our Data Processing Addendum. The organization decides what to collect and is responsible for its own privacy notice.
3. What we collect about our customers and visitors
- Account and sign-up. Organization name, the web address you choose, the admin’s email, team members’ names, emails and roles, and a password we store only as a salted hash. At sign-up we also record which version of our Terms you accepted, when, and from which IP address, and any invitation code used.
- Billing. Stripe collects your card details and billing address; we never see your full card number. We keep your Stripe customer and subscription identifiers, plan, billing email and payment status.
- Usage ledger. An append-only record, per organization and month, of AI answers, phone minutes and web-search lookups and their estimated cost, used to apply allowances and bill correctly.
- Security and operations logs. IP addresses, request times, sign-in events and an audit log of admin actions, used to secure and run the service.
- Messages to us. Emails you send us, and demo requests from our contact form (name, email, organization, sector and message; your IP address is used to limit spam).
- The live demo. What you type into the public demo is processed by our AI providers like any other conversation and may be kept in the demo’s logs.
- Cookies and browser storage. Only what the service needs: keeping you signed in to the Command Center, remembering the demo edition you picked, and keeping a visitor’s chat session on an organization’s site. There are no third-party analytics, advertising or tracking cookies or scripts, and our storefront pages load nothing from third-party servers.
4. What Lina processes for organizations
As a service provider, Lina stores and processes the following for each organization that uses it:
- Chat transcripts — what visitors type to the organization’s assistant and the assistant’s replies — and contact details a visitor gives when the organization asks for them (for example name, email, phone number and ZIP code).
- Phone calls. Before a call reaches the organization’s AI agent, and before any hold message the organization sets, our phone system plays a fixed notice: “You're speaking with an AI assistant. This call is transcribed to help us respond.” (adding “It may also be recorded.” when the organization records calls). Before voicemail records a message, and before any voicemail greeting the organization sets, it plays “You've reached an automated voicemail line. Your message will be recorded.” The AI agent is also instructed to open every call it answers with “Just so you know, you're speaking with the organization's automated AI assistant, not a live person.” Lina processes every call the AI agent answers with AI and keeps the caller’s phone number, the time and length of the call, call transcripts and an AI summary — call transcripts are kept even when recording is off — and details a caller gives, such as a pledge. By default the transcript and summary of each call are emailed to the organization’s chosen staff address. Live call audio is recorded only if the organization turns recording on; the AI agent is then also instructed to say “This call is being recorded.”, and no audio is kept until its opening has finished playing. In voicemail mode, callers hear the organization’s voicemail greeting after the voicemail notice, and their message is recorded whether or not call recording is on: our phone provider, Twilio, makes the recording, and Lina copies it into the call record and then deletes it at Twilio. A recording Lina has not copied stays at Twilio, and the call record links to it.
- Email forwarded to the organization’s inbound address (sender, recipients, subject and body — attachment names and sizes may appear in body notes, but attachments are not stored), AI-drafted replies, and email the organization sends through Lina.
- Knowledge, uploads and site content — typed knowledge, pages and text its crawler fetches, uploaded PDF and image files, and the organization’s hosted website.
- Contacts, members, volunteers and donors the organization records or imports, together with its notes about them.
- Campaign-edition data, including campaign information and political content and donation, pledge or charge-issue details captured from calls, such as a donor’s name, contact details, amount, date, ZIP code and issue description.
- Staff AI (MIND) conversations and requests the organization’s team makes to Command Center AI tools (summaries, drafts, website edits).
- Text messages sent or received through the organization’s number, and opt-out requests, if the organization uses texting.
- First-party interaction and disclosure logs — event times, opaque session identifiers, screens viewed and actions such as donation-link clicks or contact-form submission; when disclosure logging is enabled, AI-disclosure impressions and the model/prompt version used for some events. The event log itself contains no names, emails, phone numbers or IP addresses, but its session identifier can relate it to a chat or contact record.
We use this information only to provide Lina to that organization — to answer, route, summarize, store and show it in the organization’s Command Center — to keep the service secure, and where the law requires.
5. How we use information
We use the information in section 3 to provide, secure and support Lina; to apply allowances and bill; to send service emails (email verification, password resets, billing notices, usage alerts and security alerts); to answer your requests; to meet legal obligations; and to improve the service using usage data.
We do not sell personal information, and we do not “share” it for cross-context behavioral advertising. We do not use personal information for advertising or to train AI models.
6. AI and other providers
To answer a conversation, Lina sends it — with the relevant parts of the organization’s knowledge — to Google’s Gemini models, or to OpenAI’s models when we switch the chat assistant and staff AI to OpenAI. Web-search lookups send the question to Google Search. Phone calls the AI agent answers stream the caller’s audio to Google’s Gemini Live model, whether or not the call is recorded. The dedicated email-reply suggestions and email and conversation summaries use OpenAI. The admin assistant, Website Editor and other Command Center AI paths can use Google or OpenAI depending on their model and fallback configuration; OpenAI may also process a call transcript if configured as the fallback summary provider. We run all of this on our own provider accounts, and we send data to these providers only to produce what was asked for. Lina and its database are hosted by Railway. Email goes through Resend (including the call transcripts and summaries sent to an organization’s staff), phone and text through Twilio (which makes voicemail recordings; Lina copies them into the call record and deletes them at Twilio, as section 8 describes), payments through Stripe, and inbound email through Cloudflare. Optional instant alerts go through Telegram when Lina’s operators or an organization route alerts there, and nightly backups are stored with GitHub. The full list — what each provider handles, and where — is on our Subprocessors page.
External information sources. If a district lookup is requested with an address or ZIP-containing query, Lina may send that query — including any surrounding message text — to the U.S. Census Bureau’s public geocoder. When an organization asks Lina to crawl a site or retrieve a public social feed, the selected site or platform receives the requested URL or public account identifier and ordinary request information. These are independent information sources, not our contracted subprocessors.
7. Who else sees information
- The organization you interacted with (for information in section 4).
- The public, when an organization publishes content or uploaded files on its hosted site.
- Our subprocessors, only to run the service.
- Authorities or others when the law requires it, or to protect people’s rights and safety.
- A buyer or successor of the business, who must keep treating it under this policy.
8. How long we keep it
- While an account is active, chat transcripts, contacts, forwarded and sent emails, AI drafts, knowledge, uploaded files and website content are generally kept until the organization deletes them. When a chat is deleted for good, Lina keeps a recovery copy of it in the account for 30 days and then removes it. Some histories, AI-draft originals, caches and interaction/disclosure logs are bounded; older entries may be dropped when their storage caps are reached. Keep your own copies of records you need to preserve.
- Call records are kept until the organization deletes them. Automatic call-record deletion is off by default; an organization can turn it on. When a call captured donation or charge-issue details, those details and that call’s transcript are deleted automatically after 90 days by default (the organization can change this). Everything else in a call record — including the caller’s number, the AI summary, any recording and the transcripts of other calls — stays until the call record is deleted or the caller is erased.
- Voicemail recordings are kept in the call record, like other call audio, until the call record is deleted or the caller is erased. Lina copies each voicemail from Twilio into the call record and then deletes it at Twilio; if either step has not succeeded, Twilio’s copy remains until the call record is deleted or the caller is erased. When a call record is deleted — by the organization, by automatic deletion or with the account — or its caller is erased, Lina also asks Twilio to delete any copy it still holds; a deletion Twilio does not confirm is logged, and we remove that copy when asked at legal@linasystems.org.
- After an account ends, the organization’s space and data are kept for 30 days so it can export them or come back. The space then becomes eligible for deletion, and we delete it within 30 days.
- Backups. Nightly backups of the platform are deleted automatically after 30 days, so data — including the recovery and safety copies described here — leaves them within 30 days after it is removed from the account.
- Erasure safety copies. When an organization erases a person, Lina keeps a safety copy of the erased contact and call details so a mistaken erasure can be undone. Each organization keeps only the 200 most recent erasures, and they are deleted when the account’s data is deleted.
- The usage ledger and sign-up record are kept for the life of the account.
- Server logs are kept by our hosting provider for a limited period under its retention settings.
- Billing records are kept by Stripe as its own legal obligations require.
- Demo requests and support email are kept while we need them to respond and follow up; ask us and we will delete them.
9. Security
Traffic is encrypted in transit, passwords are stored as salted hashes, every request is tied to exactly one organization, sign-in sessions only work for their own organization, access inside an organization follows its admin / editor / viewer roles, and backups run nightly with a rehearsed restore. Our security page describes the controls in full. No system is perfectly secure; if a breach affects your personal information, we will tell you as the law and our Data Processing Addendum require.
10. Your rights and choices
- Organization admins can see and fix most information in the Command Center, download a copy of their data (Settings → Account → Export my data — call and voicemail audio and files over 50 MB are not included; the recordings Lina holds play on the Phone screen, so save any needed from there first), and delete the account (Settings → Account → Delete my organization’s account).
- Anyone can email legal@linasystems.org to ask for a copy of, a correction to, or deletion of their personal information.
- California residents have the right to know what personal information we collect, use and disclose (including specific pieces), the right to delete it, the right to correct it, the right to opt out of its sale or sharing (we do neither), the right to limit the use of sensitive personal information (we use it only to provide the service), and the right not to be treated differently for using these rights. You can use an authorized agent. We verify a request by matching it to information we already hold — for example, a reply from the account’s email address — and we respond within 45 days, or tell you if we need up to 45 more where the law allows.
- In the last 12 months we collected these categories: identifiers (names, email addresses, phone numbers, IP addresses); customer and commercial records (billing contact, plan, payment history and donation or pledge details an organization records); internet activity (logs); audio (voicemail, and call audio where an organization records calls); professional information (organization and role); and inferences (AI-generated summaries and intent tags). They come from you, your organization, the people who contact your organization, and our providers, and we use them for the purposes in sections 4 and 5.
11. If you talked to an organization that uses Lina
If you chatted with, called, texted or emailed an organization that uses Lina, that organization controls your information. Please contact that organization first — the Privacy & terms page on its Lina site links to its own policy. If you contact us instead, we will pass your request to the organization and help it respond. An organization can erase a person’s contact and call details from its Command Center, including from chats it has archived or deleted. Lina keeps the identifier the person was listed under — their email address or phone number, when they had one — as a record of the erasure, and the erasure does not rewrite chat transcripts, which the organization deletes separately.
12. Children
Lina is for organizations. It is not directed to children under 16, and we do not knowingly collect their personal information. Organizations must not use Lina to collect personal information from children under 13 or to target children under 16. If you believe a child has given us personal information, email legal@linasystems.org and we will delete it.
13. Where information is processed
Lina is hosted in the United States and intended for organizations in the United States. If you use it from elsewhere, your information is transferred to and processed in the United States.
14. Changes to this policy
We will post any change here with its updated date and revision. If a change is material, we will email account admins at least 30 days before it takes effect, unless the law requires it sooner. The Terms of Service explain how changes to our agreements work.
15. Contact
Lina (Joseph Linares, sole proprietor) · San Diego, California — privacy requests: legal@linasystems.org · everything else: support@linasystems.org