← Back to Lyre

Privacy policy

Updated September 17, 2026

Lyre runs your projects on your computer. You do not need an account to use Lyre on your own network, and you do not need to upload your project to a Lyre-hosted builder. If you sign in and use the encrypted relay or managed Lyre AI, the account, directory and usage data described below apply. Relay traffic is end-to-end encrypted between your host and authorized client.

Lyre is operated by Jonathan Bakhit, an independent developer based in Texas, United States. For privacy questions or requests concerning information we hold, contact [email protected].

Local project access

Local previews run on your computer. Projects do not need to be uploaded to a hosted builder. You select the project folders Lyre can access.

Lyre can store working data on your devices, including project information, unsaved drafts, checkpoints and diagnostic logs. These local records are distinct from uploading your project to a hosted service. Optional provider integrations and services you choose to use may handle data separately, as described below.

Account and host directory

Signing in is optional. If you sign in, account and authentication data is handled by Supabase, our account and database provider. This includes the email address on your account, your account identifier, your sign-in method (email, Google, GitHub or Apple, where available) and the session records that keep you signed in. We also keep host records and billing state associated with the account.

While a computer is signed in to your account, Lyre publishes a short-lived directory entry so your own devices can find it. Each entry contains the host's server identifier, its public key, the relay endpoint and whether TLS is used, plus two display-only fields: the computer name (your operating system's hostname) and the operating system (macOS, Windows or Linux). The entry is stored against your account and is only ever listed back to your account. It is not shown to other users, and it is not an access grant. Entries expire, and they are removed when you sign out, withdraw a host, or when the lease ends.

Optional AI providers

Optional agents may send prompts, project context and tool output to their providers under your account settings. Lyre does not yet enforce exact outbound-context approval for CLI agents. Your chosen provider's terms, privacy policy, and account settings apply to information sent to that provider.

Choosing a local model does not prevent a CLI agent from making network requests or sending data to external services. CLI file and network access follows the provider and your environment settings; local inference is not a network isolation guarantee.

Managed Lyre AI

Lyre AI is an optional paid plan. When you use it, your host obtains a short-lived, host-scoped key from our server and sends model requests to OpenRouter, the model provider behind Lyre AI, under your account. We record metered usage for your account: the amount reserved and settled for each request, the host and session it came from, and the running total against your monthly allowance. We do not record the prompts you send or the replies you receive; those are handled by the model provider under its terms.

Voice input

Voice input is optional. When you use managed voice, a Lyre service, your host sends the recorded microphone audio to Groq, our speech-to-text provider, which returns a transcript. Groq receives that audio and transcript under its own terms and retention policy. If you use a speech provider you configured yourself, that provider receives the audio instead. An operating-system microphone permission does not mean the audio stays on your device.

Payments

Web subscriptions are processed by Stripe on Stripe-hosted pages. Card details are entered on Stripe's pages and are never received or stored by Lyre. We store the resulting customer identifier, subscription status and entitlement. Purchases made inside the iPhone or Android app are processed by Apple or Google; we receive purchase and transaction identifiers to verify and maintain your subscription.

Device connections

Direct connections on your private network are preferred. Those local-network connections may use unencrypted HTTP, so treat a local network as trusted. For supported relay connections, your host establishes an outbound connection, and project traffic is end-to-end encrypted between the host and authorized client. The relay, hosted on Cloudflare, forwards encrypted payloads without the keys needed to read their contents. Access is scoped to the grants issued by your host.

Encryption depends on the path, not on the app as a whole. Relay project traffic is end-to-end encrypted. Requests to our cloud services — account, billing, voice and hosted features — use HTTPS. Some direct local-network connections use unencrypted HTTP, and traffic that reaches an optional AI provider you configure is protected only by that provider's own transport.

Encryption protects the contents of relay traffic; it does not hide all connection metadata. The relay can see IP addresses, connection timing, message sizes, session identifiers and the public handshake keys used to set up encryption. It cannot read your project files, prompts or messages. Web and relay hosting run on Cloudflare, which may keep limited operational logs.

Email

We send transactional email, such as sign-in links and account notices, through our email provider, Resend.

Safety reports and contributions

If you submit a safety report from the app, the report and the response excerpt you choose to include are sent to Lyre's operator for review. Reports are not retained: they are reviewed and then deleted, so we keep no copy. This is separate from encrypted relay traffic: the operator can read content you deliberately submit as a report.

Optional Sponsor contributions are one-time payments made through a Stripe-hosted page. Stripe processes them under its privacy policy. Sponsor payments are separate from Pro subscriptions and grant no product features or benefits.

Service providers

We use these providers only for the purposes described above: Supabase (accounts, database and server functions), Stripe (web payments and Sponsor contributions), Apple and Google (in-app purchases), Cloudflare (relay and app hosting), Resend (transactional email), Groq (managed voice transcription) and OpenRouter (the Lyre AI model provider). We do not sell your personal data.

Your control

You can stop local previews and manage paired-device access from your host computer. Local source files remain editable outside Lyre. Stopping a preview does not remove information already sent to an optional AI provider.

Account deletion

To request deletion of your Lyre Studio account and associated data, delete it from the account screen in the app, follow the account deletion steps or email [email protected]. Requests are reviewed in about two days. After ownership verification, we delete the account and its associated data, including account-linked directory entries, host associations and billing records, within one week. We keep no account billing records after deletion. A single one-way purchase-source identifier remains permanently so an old store purchase cannot be reassigned to another account; it contains no account, computer, contact or purchase proof. We retain records only where the law requires it. The guide explains local files and independent provider accounts, which this request does not erase.

Children

Lyre is intended for adults aged 18 and over and is not directed at children. If you believe a child has provided personal information, contact [email protected].