Skip to content
← Back to Home

Data & Security

Last checked against the app: September 2026

A profile is worth the accounts logged into it, so it matters where it lives. Below is what stays on your computer, what we hold for you, where we hold it, how long, and what we never collect. Every line describes the build you can download today — not a roadmap.

What stays on your device

Everything a profile does while it is open.

Browser data never leaves
The app says it in Settings → Data Sync and it is exact: “Browsing history, saved passwords, open tabs, and site data stay on this device.” Cache, installed extensions and the cookie jar of a running profile are in that list too.
The profile folders are yours
Each profile is a directory in Liminal’s data folder on your machine. We have no agent reading it, and the app streams nothing out of an open profile — not URLs, not page content, not screenshots.
Nothing syncs on the free plan
Cloud sync is a paid feature. On Free the catalog lives on your machine only, so a reinstall starts from an empty list.

What syncs to the cloud

On Pro and Team, four groups — the four switches of Settings → Data Sync. Each one can be turned off on its own.

Profiles
Name, folder and workspace, the proxy and account bound to it, timestamps, and the profile’s fingerprint configuration — that last one so the same profile shows the same device on your other machine.
Accounts
The account cards: name, platform, domains, how many cookies they hold — and, if you imported cookies onto a card, those cookies themselves. Their values are encrypted (AES-256-GCM) before they are written. The key is ours, so this protects the data against a stolen database, not against us.
Proxies
Host, port, type, username and password. Passwords are encrypted the same way at rest and are sent back only to your signed-in client, because the browser needs them to open the connection.
App settings
The application-level preferences of the app itself, so a second machine comes up configured the way you left it.

Where that cloud is

Frankfurt, Germany. One region, no mirrors elsewhere.

API and database
Both run in DigitalOcean’s Frankfurt region (fra1): the API and a managed PostgreSQL cluster reachable only over TLS.
Installers
The builds you download come from a DigitalOcean Spaces bucket in the same Frankfurt region, over a signed link issued to your account.
Analytics
Product events go to Mixpanel’s EU ingest with IP capture switched off, so no location is derived from the request.
Credentials at rest
Account passwords are stored as bcrypt hashes (cost 12) — we cannot read them. Proxy passwords and imported cookie values are AES-256-GCM ciphertext.

How long we keep it

What we can state exactly, we state. What has no value set, we do not invent.

Deleting the account is immediate
It removes your user record and everything hanging off it — profiles, proxies, account cards with their cookies, settings, sessions, team memberships. There is no grace period and nothing to restore from.
Deleted items stay as tombstones
A profile, proxy or account you delete in the app is marked deleted rather than erased, so your other machines learn about the deletion on their next sync. The row keeps its fields until the account itself is deleted.
Backups roll for about a week
Our hosting provider takes a daily backup of the database and keeps roughly the last week of them. A deletion is gone from backups once that window passes.
The security log outlives the account
Sign-ins and other sensitive operations are logged with the IP and browser of the request. When an account is deleted those entries lose the link to it and stay as anonymous records.
What we have not set
We have not set a retention window for an unpaid account, and the app has no trash with a restore window yet. Rather than publish a number we do not have: today nothing is deleted for non-payment — the plan drops to Free and the data stays. When a window is set, it appears on this page.

What we never collect

Product analytics tell us which features are used, and are filtered before they are sent.

What an event carries
The name of the action, whether it succeeded, the app version and build, the platform, the plan, and one identifier — random until you sign in.
What is stripped out
Any field whose name looks like a secret or an identity — password, token, cookie, session, credentials, api key, device or machine id, hostname, serial, MAC address, fingerprint, canvas, WebGL, WebRTC, IP address, proxy host, user or password, file path, email — is dropped before sending.
And the values too
A value that looks like a token, an email, an IP address or a path to a file is replaced with [redacted], even when the field name looked harmless.
No browsing, no selling
We do not collect the sites you visit, the contents of a page, or the cookies in a running profile. We do not sell data and we run no advertising trackers. On this website nothing analytical loads until you accept the cookie banner.

Getting your data out, or deleting it

Both start in the app, in Settings → Account.

Where the buttons are
Settings → Account → Export Data and Delete Account both open your account page on this site in your system browser.
The export is a file
“Export my data” downloads one JSON file with everything we hold for you: profiles and their fingerprint settings, workspaces and folders, proxies with their credentials, account cards with their cookies, app settings, your teams and your payments. Browser data is not in it, because it never reached us.
Deleting is self-serve
“Delete account” asks you to type your email, then removes the account the moment you confirm — the immediate, cascading removal described above. Anything on your own computer stays where it is; delete the Liminal data folder yourself if you want it gone too.

The Privacy Policy says the same things in legal form. Anything unclear, or a claim here that does not match what you see in the app — [email protected].