What Liminal records
This page lists, as facts, what the Liminal service stores when someone reads, receives or publishes a document. It is a description of the product, not a privacy policy or terms of service.
Liminal に保存される情報の一覧です(法的な規約ではなく、製品の動作の説明です)。
Reading a published page
- A count of views per page per day. No cookie is set for this, no IP address is stored with it, and nothing identifies the reader.
- The domain of the referring site (for example
news.ycombinator.com), counted per day. Not the full referring URL. - On Pro pages, the
utm_sourceandutm_mediumvalues of the link, counted per day. No other query parameter is read. - The browser’s user-agent is read to skip known bots and is not stored.
- For a page with a password, a cookie that remembers it was unlocked on that browser.
Reading a deck with measurement turned on
Measurement is off unless the author turns it on for that deck, and a deck with it on tells its readers.
- Per slide and per day: how many readers reached it and how long they stayed, counted only when the reader also interacted with the page.
- Per day: clicks on the deck’s goal button. When the reader arrived from an ad whose link carried a click identifier, that identifier is stored with the click so the author can attribute it.
- No cookie, no IP address and no reader identity is stored with these counts.
Asking for a deck’s source
- When an author offers a deck’s source behind an email gate, the address a reader enters is stored for that author, with the deck it was for. The author can delete it per address or all at once.
- A question asked of a deck’s source, and the answer given, are stored for that deck’s author.
Receiving a sealed document
- The recipient’s email address, as the sender typed it, with the link.
- Each time the link is opened: the time. Not an IP address or a device. The recipient page says this.
- The document itself, its title, comments and returned edits are stored only encrypted. The service holds no key that opens them.
- If the recipient chooses to comment or edit: an account for their address, the public half of a key their browser generated (the private half stays in that browser), and where in the document each comment is anchored. A comment can be read by the sender and its author only.
- If the recipient confirms their address, a one-time code is sent to it through our sign-in provider.
Authors
- The account’s email address and handle, the pages published and their settings, and the subscription status reported by our payment provider.
- When an author uses AI editing or deck generation on the server, the text shown to them before sending is sent to the model provider. Requests are logged without their content.
Abuse limits
- Some public actions (opening a delivery link, unlocking a password, posting a comment) are rate limited. The limiter keeps a counter keyed by the client’s IP address for the length of its window, typically an hour; the counter is reused, not kept as a history.
This website
- The marketing pages (this one, the home page, profiles) use Vercel Web Analytics, which counts page views without cookies. Recipient links are removed from what it is sent. Published pages and decks do not load it.