Legal
Privacy Policy
What this website and Lyra store, why, and what we never do. Last updated 7 October 2026.
Who we are
Lyramic is a one-person publisher of AI-driven creative tools in the Netherlands. For anything in this policy: [email protected]. Euterpe and YourPlotline have their own privacy policies for their own services; this page covers lyramic.com and Lyra.
This website
- Analytics — our own first-party, cookie-free system (LyraPulse): aggregate page views without cross-site identity. No third-party trackers, no advertising.
- The waiting list — if you sign up for launch updates, we keep your email address and the products you chose, and send the confirmation and the updates through Postmark. The form is protected by Cloudflare Turnstile. Unsubscribe from any update, or ask us to delete you.
- Mail to us — if you write to us, we keep the correspondence.
There are no cookies to accept, which is why there's no cookie banner.
Lyra, the personal assistant
Lyra is a personal assistant that runs on its owner's own computer. Today its only user is the person who builds it, and it reads only the accounts he connects himself. Lyra is an adviser: it reads and suggests, and never sends, books, deletes or changes anything in an account it reads.
What Lyra reads from Google
When the owner connects his Google account, Lyra asks for two read-only permissions and nothing else:
- Gmail, read-only (
gmail.readonly) — his messages and their labels, so Lyra can remember what arrived and notice what needs his attention. - Google Calendar, read-only (
calendar.readonly) — his events, so Lyra knows what is coming up and when something moved or was cancelled.
Lyra cannot send mail, change labels, mark anything as read, or create, edit or delete calendar events: the permissions it asks for do not allow it, and its code asks for nothing else.
How that data is used, stored and protected
- Stored on the owner's own machine. The messages and events become entries in the owner's private memory, a database on his own computer. The Google sign-in token is kept encrypted with Windows' data protection for his user account, never in a file or in code.
- Labelled before anything else sees it. Every item is classified as public, private or sealed. Sealed material (for example health, banking or identity details) never leaves the machine.
- AI processing. To summarise, remember and decide what needs attention, text that is not sealed may be sent to AI providers under the owner's own keys: Anthropic, and models reached through OpenRouter. Anthropic's API does not use this content to train its models. Nothing is sent to any other party.
- Never sold, never shared, never used for ads. The data is not used to train any model of ours, not used for advertising, and not transferred to anyone except as needed to provide Lyra's features to its owner.
Limited Use. Lyra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deletion
The owner can disconnect Google in Lyra's settings, which deletes the kept token, or revoke Lyra's access at any time at myaccount.google.com/permissions. What Lyra already stored can be deleted from its memory on request.
Your rights
Under the GDPR you can ask for access, correction, export, or deletion of your personal data — email [email protected] and we'll act on it promptly. You can also complain to the Dutch DPA (Autoriteit Persoonsgegevens), though we'd rather fix it first.
Changes
If this policy changes materially, the date at the top changes with it, and for Lyra the change is made before the code that needs it.