This Privacy Notice reflects the currently verified Livariant product and infrastructure state and will be updated when material data flows change.
1. Controller
Robin Lester
c/o POSTFLEX PFX-888-203
Emsdettener Straße 10
48268 Greven
Germany
Email: contact@einfachrobin.de
Website: https://www.einfachrobin.de
No Data Protection Officer has been designated.
2. Local processing by default
Livariant is a local Windows desktop application. Project registrations, local checkout paths, Project Brain state, diagnostics state, provider connection state and locally prepared Provider Context are generally processed on the user's device.
The current product includes no Livariant-operated usage analytics, no Livariant-operated crash reporting, no advertising identifiers and no Livariant user account. Project content is not transmitted to an external service merely because it exists in Livariant.
Where information is processed exclusively on the user's device and is not transmitted to Robin Lester or to an external service used by Livariant, Robin Lester does not receive that information.
3. Operator safety channel
Shortly after startup and approximately every five minutes afterwards, the Livariant Desktop requests the fixed HTTPS resource https://broadcast.livariant.dev/v1/operator.json.
Purposes include bounded operator-safety notices, version-specific update safety blocks and preventing use of an update path classified as unsafe. The request contains no project content and no user-selected endpoint. Hosting infrastructure may process ordinary technical connection information such as IP address, timestamp and HTTP/TLS metadata.
Legal basis: Article 6(1)(f) GDPR. The legitimate interests are the secure operation of Livariant, delivery of bounded security information and prevention of unsafe update paths.
The endpoint is hosted through Vercel. Vercel may process traffic and service-generated metadata. Vercel states that personal information may be processed in the United States and other countries and describes applicable transfer mechanisms, including Standard Contractual Clauses and participation in the EU-U.S. Data Privacy Framework where applicable.
For the currently evidenced Hobby configuration, Vercel exposes a one-hour visible Runtime Logs window for entries that actually appear there. This does not mean that every static request is logged or that all service-generated metadata is deleted after one hour. Vercel's current privacy and retention rules apply to any additional service metadata processed by Vercel.
4. Website access
When you access livariant.dev, the hosting infrastructure processes technically necessary connection information required to deliver the website. This may include the IP address, requested resource, timestamp, browser and operating-system information, referrer information where transmitted, and security-related request metadata.
The purpose is to provide, secure and operate the website. Legal basis: Article 6(1)(f) GDPR. The legitimate interests are reliable website operation, abuse prevention and infrastructure security.
The current website does not intentionally use advertising or marketing trackers and does not require a Livariant user account.
5. Optional GitHub connection
A GitHub connection is established only after explicit user action. Livariant uses GitHub's Device Flow and may, depending on the permissions granted by GitHub, identify the connected account, list accessible repositories, read supported repository metadata and clone a repository explicitly selected by the user.
The current GitHub integration is read-oriented. Connecting GitHub does not grant Livariant repository-write, merge or release authority.
On Windows, locally persisted GitHub credential material is protected using the current Windows user's DPAPI security boundary. Disconnecting GitHub removes the locally stored protected credential and clears any pending Device Flow state. It does not automatically revoke GitHub-side application authorization; if desired, that authorization must also be revoked through GitHub.
Legal basis for Livariant-side processing: Article 6(1)(f) GDPR. The legitimate interest is providing the GitHub integration explicitly requested by the user.
Recipients may include GitHub B.V. and/or GitHub, Inc., depending on the service used. GitHub states that data may be processed in the United States and other countries and describes Standard Contractual Clauses and other applicable international transfer mechanisms.
Locally protected credential material remains stored until the GitHub connection is disconnected or the corresponding local application state is removed. Server-side retention at GitHub depends on purpose, account status and GitHub's applicable policies.
GitHub General Privacy Statement
6. User-triggered update checks
Livariant does not automatically perform remote Desktop update discovery. An update request is made only when the user explicitly selects Check for updates.
The Desktop reads the fixed Livariant update feed over HTTPS and obtains installer or updater artifacts through GitHub Releases. Before installation, Livariant verifies the cryptographic Tauri updater signature and rechecks the intended update target.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is providing the update and security-checking function expressly requested by the user. The GitHub recipient, international-transfer and retention information described above also applies to this path.
7. External AI and Custom providers
Livariant supports local integration paths for OpenAI / Codex, Anthropic / Claude Code, Google / Gemini CLI and user-configured Custom providers.
Livariant prepares Provider Context locally. Connecting Claude Code, Gemini CLI or a Custom provider does not by itself transmit project or context data to the corresponding external service. External processing can arise when the user deliberately uses a provider function and the locally installed provider tool communicates with its service.
Livariant does not import or store Claude, Google or Custom provider API keys through these connection paths.
For Livariant-side processing that prepares or hands data to a provider tool following explicit user action, the working legal basis is Article 6(1)(f) GDPR. The legitimate interest is providing the provider function expressly requested by the user.
The provider's own processing is additionally governed by the user's provider account, product, contract and privacy relationship. Provider roles, retention periods and international-transfer mechanisms differ between account and product types. Livariant therefore does not claim one universal provider retention period or one transfer framework for all accounts.
Current provider privacy information: OpenAI, Anthropic, Google. For Custom providers, processing depends on the provider selected by the user.
8. Local project, provider and diagnostics data
Project and diagnostics information is generally processed locally. Depending on the configured features, local Livariant state may include project registration data, local repository associations, Project Brain information, provider connection intent, session or thread correlation evidence, diagnostics evidence and local configuration.
The diagnostics export is designed to exclude application credentials, raw prompts, project-file contents, local filesystem paths and free-form reasoning text. An exported diagnostics file remains local until the user decides to share it.
Local application state is retained while needed for the configured function or until the corresponding state is removed through the supported product function or by deleting local Livariant application data. Removing a project registration does not necessarily delete project-owned files or repositories.
9. Contact and support
If you contact Robin Lester, your message, contact details and information required to process the request may be processed. Depending on the nature of the request, the legal basis may be Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. The legitimate interest is responding to and documenting product, support and security-related requests.
Security issues should preferably be reported through GitHub Private Vulnerability Reporting or the documented private security channel. Do not place secrets, private project content or confidential exploit details in public GitHub Issues.
10. Data provision
The operator-safety channel is used automatically while Livariant is running in its current configuration and network access is available. If that endpoint cannot be reached, current operator safety notices or version-specific safety blocks may not be available.
GitHub connection, update checking and external provider use are optional. If the data required for one of these functions is not processed or the corresponding connection is not configured, only that function may be unavailable or incomplete. Livariant's local core functionality remains separate where technically possible.
11. Your rights
Subject to the applicable legal requirements, you may have rights including access under Article 15 GDPR, rectification under Article 16 GDPR, erasure under Article 17 GDPR, restriction of processing under Article 18 GDPR, data portability under Article 20 GDPR where its conditions are met, and objection under Article 21 GDPR to processing based on Article 6(1)(f) GDPR.
Requests may be sent to contact@einfachrobin.de.
An objection will be assessed under Article 21 GDPR in the individual case. Processing may continue where compelling legitimate grounds override the interests, rights and freedoms of the data subject, or where processing is required for the establishment, exercise or defence of legal claims, subject to the applicable legal requirements.
You also have the right to lodge a complaint with a competent data protection supervisory authority. For the controller in North Rhine-Westphalia, one competent authority is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW).
12. Automated decision-making
Based on the currently verified product state, Livariant does not perform solely automated decision-making that produces legal or similarly significant effects within the meaning of Article 22 GDPR.
13. Changes to this Privacy Notice
This Privacy Notice will be reviewed when relevant data flows, hosting, providers, logging configurations, account models or Livariant functionality materially change. In particular, Livariant-operated cloud processing, direct provider APIs, analytics, crash reporting, user accounts, hosted project storage or new recipient categories require renewed privacy review before publication.