Privacy Policy

LAST UPDATED: APRIL 2026

1. Who We Are

LiminalX LLC is a healthcare AI readiness company headquartered in Atlanta, Georgia, USA. We operate the LiminalX platform at liminal-x.ai. For privacy enquiries, contact info@liminal-x.ai.

2. What Data We Collect

We collect the following categories of personal data:

  • Account data: Name, email address, professional role, institutional affiliation, country, and other profile information you provide during registration and onboarding.
  • Usage data: Analytics data collected via PostHog, only with your explicit consent. This includes pages visited, features used, and session duration. We do not collect usage data without consent.
  • Assessment data: Human Readiness Level (HRL) scores, VERA assessment responses, and related assessment outputs. This data is never sold or shared at the individual level.

3. Legal Basis for Processing (GDPR)

For users in the European Economic Area and UK, we process data on the following bases:

  • Contract performance: Account data necessary to provide the Platform service.
  • Legitimate interest: Account data for security, fraud prevention, and service improvement.
  • Consent: Analytics cookies and usage tracking via PostHog, only when you accept via our cookie banner.

4. How We Use Data

We use your data to provide and improve the Platform, personalise your experience, compute readiness scores, generate anonymised aggregate research insights, communicate service updates (with your notification preferences respected), and comply with legal obligations.

5. Data Sharing

We do not sell individual user data. We may share data in the following limited circumstances:

  • Anonymised aggregates: We may publish or share aggregate, de-identified reports on AI readiness trends. Individual users cannot be identified from these reports.
  • Service providers: We use Supabase (database hosting), Vercel (application hosting), and PostHog (analytics, consent-based only). These providers process data on our behalf under data processing agreements.
  • Legal requirements: We may disclose data when required by law, regulation, or legal process.

6. Data Retention

We retain your account and assessment data for as long as your account is active. If you request account deletion, we will process the request within 30 days and remove personal data, retaining only anonymised aggregate data for research purposes. Usage analytics data is retained for 24 months from collection.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate data via your Profile settings.
  • Erasure: Request deletion of your data via Account > Security > Delete account.
  • Data portability: Request an export of your data in a machine-readable format.
  • Withdraw consent: Withdraw analytics consent at any time by clearing your cookies or contacting us.

To exercise these rights, email info@liminal-x.ai.

8. Cookies

We use the following cookies:

  • Session cookies (Supabase): Essential for authentication. Cannot be disabled.
  • lx_onboarded: Functional cookie that caches your onboarding completion status to improve performance. Set after completing onboarding. 1 year expiry.
  • lx_cookie_consent: Records your cookie consent preference. 1 year expiry.
  • PostHog analytics: Optional analytics cookies, only set if you accept via the cookie consent banner. Used to understand Platform usage patterns.

9. Contact

For privacy questions, data requests, or complaints, contact our Data Protection contact at info@liminal-x.ai.

LiminalX LLC, Atlanta, GA, United States of America.