Liminal - Privacy and Cookies Notice

Effective date: August 2026

Controller: Liminal Finance Ltd ("Liminal", "we", "us"), a company registered in England and Wales, company no. 16556039.

Registered address: 41 Pitfield Street, London, N1 6DA, United Kingdom

Contact: support@liminal.cash

Plain-English note: this notice explains what personal data we collect when you use the Liminal app, why we collect it, who we share it with, how long we keep it, and the rights you have over it. Short explanations like this one appear through the notice to make it easier to read, but the full text of each section is what counts.

1. Summary

  • We use your personal data to create and run your account, provide the app features you request (including Nim, our AI assistant), and support you.
  • We use your personal data to meet the compliance standards required by the third-party providers you access through the app (for example, identity verification and screening).
  • When you talk to Nim, your messages are processed by our AI infrastructure provider (Anthropic) to generate responses. Under our agreement with Anthropic, your data is not used to train their models.
  • We use PostHog to record product interaction events and crash diagnostics so we can fix broken flows and improve reliability.
  • We use Persona to collect and verify identity information for KYC checks that our third-party providers require.
  • We share personal data with third parties when you use their services through the app. Those third parties also process data under their own privacy notices.
  • We do not sell personal data, and we do not use your data for third-party advertising.

2. Liminal and How Data Responsibility Works

We're the controller for the app itself. The providers you use through the app are controllers for their own services.

Liminal provides a software interface that lets you use third-party services (for example wallet infrastructure, on/off-ramp and conversion providers, and open blockchain protocols). Liminal does not custody your funds.

  • Liminal Finance Ltd acts as controller for personal data processed to run the app, provide Nim, provide support, and maintain app security and reliability.
  • Third-party providers you use through the app - currently including Privy (wallet infrastructure), Bridge, a Stripe company (on/off-ramp), and Fern, a Rain company (currency conversion) - act as separate controllers for their own services and compliance obligations, under their own privacy notices.
  • Our processors act on our instructions to deliver parts of the service: Anthropic (AI processing for Nim), Persona (identity verification workflows), and PostHog (analytics and diagnostics).

3. Your Information and the Blockchain

Anything you put on a public blockchain is public, permanently. We can't delete it - nobody can.

When you use blockchain features, you publish transaction data to a public blockchain network. Public information includes:

  • wallet addresses
  • transaction hashes
  • token transfers and balances associated with addresses
  • timestamps and amounts

What does NOT go on-chain: your name, contact details, KYC documents, verification results, and other personal details never touch the blockchain. They stay within our systems and those of the relevant providers, as described in this notice. The only data published on-chain is your wallet address, transaction amounts, and timestamps. Therefore, the data on-chain is pseudonymous and does not itself reveal who you are.

Blockchain data is public by design and cannot be deleted or edited by Liminal or anyone else. Your rights to erasure and rectification under UK GDPR cannot be applied to data recorded on-chain.

4. The Personal Data We Process

Here's everything we collect, grouped by type.

  • A. Account and contact data: name, email address, phone number, physical address (if you provide it), and other contact information you provide.
  • B. Identifiers: user ID and internal account identifiers; device identifiers generated by the platform or SDKs (where enabled).
  • C. Identity verification (KYC) data - collected via Persona: identification documents and images (for example passport or driving licence); proof of address; selfie or liveness capture where required; date of birth and nationality where required; verification results and screening outcomes (pass/fail, risk flags, timestamps).
  • D. Nim conversation, memory, and personalisation data: the messages you send to Nim and Nim's responses, which may include financial information you choose to share in conversation; Nim's memory of your preferences, patterns, and prior interactions, maintained so it can assist you across sessions; the rules you set for Nim.
  • E. Usage data - via PostHog: product interaction events, for example screens viewed, buttons tapped, and feature usage sequences.
  • F. Diagnostics - via PostHog and platform tooling: crash reports, error logs, and performance metrics.
  • G. Location: coarse location, where enabled on your device.
  • H. Financial and transaction data: balances, transaction status, and payment information you provide or that a provider returns, for receipts, display, and support.
  • I. Linked bank account data (via Plaid): if you choose to connect a bank account through Plaid, we receive account data such as account details, balances, and transactions from the accounts you connect. By using Plaid's services, you provide your bank login credentials directly to Plaid and these are never visible to or stored by Liminal.

5. How We Use Your Data

This table maps each purpose to the data used, the legal basis, and what you can do about it.

We do not sell your data. We use it for the following purposes:

Purpose and what we doData usedLawful basis (UK GDPR)Your control
Provide the app and core functionality - create your account, authenticate you, display your balances and transactions, send service messagesAccount/contact data; identifiers; financial and transaction dataContract (Art. 6(1)(b))If you don't provide core account data, you can't use the app.
Provide Nim - process your messages to generate responses, carry out the instructions you give, apply the rules you set, and retain context so Nim can assist you across sessionsNim conversation and personalisation data; financial and transaction data; identifiersContract (Art. 6(1)(b))You choose what to tell Nim. You can ask us to delete Nim's retained context about you (Section 9).
Connect your bank accounts - let you link external accounts through Plaid and display the resulting account data in the app (including to Nim, so it can assist you with your full financial picture)Linked bank account data; identifiersContract (Art. 6(1)(b))Connecting a bank account is optional. You can disconnect an account at any time in the app.
Provide customer support - respond to requests, investigate issues, maintain support historyContact data; identifiers; support communications; relevant diagnosticsLegitimate interests (Art. 6(1)(f))You choose what you share in support requests.
Meet third-party provider compliance standards (KYC) - collect identity information through Persona, run verification, store results, pass required outputs to the relevant providersKYC data; contact data; identifiers; verification resultsLegitimate interests (Art. 6(1)(f)) in enabling providers to meet legal and licensing requirements. Explicit consent (Art. 9(2)(a)) for biometric data where the flow requires it.If you don't complete KYC, you can't access KYC-gated features. You can refuse biometric consent; the KYC flow then can't complete where the provider requires it.
Security and abuse prevention - detect suspicious access, prevent account abuse, maintain audit trailsIdentifiers; device data; coarse location (if enabled); diagnosticsLegitimate interests (Art. 6(1)(f))You can object. We stop unless we demonstrate compelling grounds.
App reliability and bug fixing - record crashes and errors, diagnose causes, fix broken releasesDiagnostics; identifiers (where linked)Legitimate interests (Art. 6(1)(f))You can object. If we can't investigate an issue without diagnostics, support outcomes degrade.
Product analytics - identify drop-off points, broken flows, and feature usageUsage data; identifiers (where linked)Legitimate interests (Art. 6(1)(f))You can object at any time (Section 9).
Legal claims and disputes - preserve evidence, defend or bring claimsAny relevant data categoryLegitimate interests (Art. 6(1)(f))Processing runs only when needed for claims and disputes.
Law enforcement and regulator requests - respond to valid requests and legal processAny relevant data categoryLegal obligation (Art. 6(1)(c)) where applicable; otherwise legitimate interests (Art. 6(1)(f))You don't control processing where disclosure is legally required.

Our legitimate interests are: operating a secure and reliable app, preventing abuse, improving usability, and meeting third-party provider compliance standards so you can access the services you request.

6. Nim and AI Processing

What actually happens to your data when you talk to Nim.

  • When you send Nim a message, that message - together with relevant context such as your recent conversation and account information needed to answer - is processed by Anthropic, our AI infrastructure provider, to generate Nim's response. Anthropic acts as our processor under a data processing agreement incorporated into our contract with them: we remain the controller of your data, and Anthropic processes it only on our instructions to provide the service.
  • Under Anthropic's commercial terms, your conversations and data are contractually excluded from being used to train Anthropic's models, and Anthropic's operational API logs are deleted after a short period (currently 7 days) by default.

Nim's memory: Nim builds and maintains a structured memory of your interactions - such as your preferences, recurring patterns, the rules you set, and context from past conversations - so it can assist you across sessions without you repeating yourself. This memory is used only to provide and personalise the service to you. It is never used for advertising, never sold, and never used to make automated decisions about you. You can view what Nim remembers by asking it, and you can ask us to delete Nim's memory about you at any time (Section 9).

  • Nim does not make solely automated decisions about you that have legal or similarly significant effects. Nim acts only on your instructions or under rules you have set and can change or cancel at any time; every action is authorised by you (see our Terms of Service, Section 3).
  • Don't share other people's personal data with Nim unless you're entitled to do so.

7. Processors and Third Parties

Who touches your data, and in what capacity.

A. Processors acting on our instructions

  • Anthropic: AI processing for Nim conversations.
  • Persona: identity verification and KYC data collection workflows.
  • PostHog: product interaction analytics and crash/diagnostics logging.

B. Third-party providers you use through the app

When you use a third-party service through Liminal - currently including Privy (wallet infrastructure), Bridge, a Stripe company (on/off-ramp), Fern, a Rain company (currency conversion), and Plaid (bank account connections) - that provider processes personal data as a separate controller under its own privacy notice. We share only the data required to enable the service and satisfy that provider's compliance standards. We recommend reviewing their privacy notices.

C. Other disclosures

We may disclose personal data to our professional advisers, to a buyer or successor in the event of a merger, acquisition, or asset sale (in which case this notice will continue to apply to your data), and to authorities where required by law.

8. International Transfers

Some of our providers are outside the UK. When data leaves the UK, safeguards apply.

Our team is based in the UK, but some of our processors operate infrastructure outside the UK:

  • Anthropic (Nim's AI processing) processes data on infrastructure in the United States and other regions, with data storage in the United States. This transfer is covered by Anthropic's data processing agreement, which incorporates the EU Standard Contractual Clauses and the UK Addendum.
  • PostHog (analytics and diagnostics) hosts our analytics data on AWS servers in the EU (Frankfurt) - covered by the UK's adequacy regulations for the EEA / the United States - covered by Standard Contractual Clauses with the UK Addendum under PostHog's data processing agreement.
  • Our US-based service providers - Privy (wallet infrastructure), Bridge, a Stripe company (on/off-ramp), Fern, a Rain company (currency conversion), and Plaid (bank account connections) - are US companies and process data in the United States. Where we transfer personal data to them, the transfer is covered by the data transfer terms in our agreements with them, incorporating the EU Standard Contractual Clauses with the UK Addendum. Each also explains its own transfer safeguards in its own privacy notice.

Where we transfer personal data outside the UK, we rely on safeguards recognised under UK GDPR: adequacy regulations where they apply, or the UK International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses. Third-party providers acting as separate controllers explain their own transfer safeguards in their privacy notices.

9. Your Rights

UK GDPR gives you real rights over your data. Here's how to use them.

You have the right to:

  • access your personal data
  • correct inaccurate data
  • delete data in certain circumstances (including Nim's retained context about you)
  • restrict processing in certain circumstances
  • receive certain data in a portable format
  • object to processing based on legitimate interests, including analytics
  • withdraw consent where processing is based on consent, at any time

How to exercise your rights: email support@liminal.cash with your request. We verify your identity before responding, and we respond within one month (extendable where requests are complex, in which case we'll tell you).

Complaints: you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with the data protection authority in your country. We'd welcome the chance to resolve your concern first - contact us at support@liminal.cash - but you can go to the ICO at any time.

Limits: some rights can't be applied to blockchain data (Section 3) or where we're legally required to retain data (for example, KYC records).

10. Retention

How long we keep each type of data.

Data typeRetention period
Account and contact dataWhile your account is active, then 6 years, to manage disputes and maintain security records.
Nim conversation, memory, and personalisation dataWhile your account is active, then deleted within 90 days of account closure. You can ask us to delete Nim's memory about you at any time while your account is open.
Support communications3 years from ticket closure.
Product analytics events12 months, in line with PostHog's retention policy.
Crash logs and diagnostics90 days.
KYC data and verification results (Persona)For the period required by the relevant third-party provider's compliance standard, then 5 years after the end of the relationship with that provider, unless the provider requires longer retention.
Linked bank account data (Plaid)While the connection remains active; deleted from our systems within 90 days of you disconnecting the account. Plaid retains data under its own policy.
Blockchain dataRetained on-chain by the network permanently. Liminal cannot delete or amend it.

11. What You Can and Can't Turn Off

A plain map of which processing is optional and which comes with the service.

  • Core account operation runs on contract necessity. If you want us to stop that processing, you close your account.
  • Nim runs on contract necessity: processing your messages is how Nim works. You control what you share with Nim, and you can delete Nim's retained context.
  • KYC checks are required for KYC-gated features. If you don't want that processing, don't use those features.
  • Biometric data (if used in the KYC flow) runs on explicit consent. You can refuse; the KYC flow then can't complete where the provider requires biometric checks.
  • Analytics and diagnostics run on legitimate interests. You can object at any time by emailing support@liminal.cash, and we'll stop unless we demonstrate compelling grounds.

12. Cookies and Device Storage

The app doesn't use browser cookies. It stores and accesses information on your device only where it has to, to provide features you've asked for.

The app is a native application and does not itself use browser cookies. It stores and accesses information on your device only where strictly necessary to provide features you request: to complete identity verification when you start a verification flow (via the Persona SDK), and to connect a bank account when you choose to (via the Plaid SDK). Because this storage and access is strictly necessary for services you have explicitly requested, it does not require your consent under the Privacy and Electronic Communications Regulations 2003.

Where a feature opens a secure web view provided by one of our partners - for example a Persona verification or Plaid bank-connection flow - that partner may use cookies or similar technologies within that web view, as described in its own privacy notice. You can manage device-level permissions, such as location and notifications, in your device settings.

13. Security

We protect what we hold. You protect your device and keys.

We use access controls, encryption in transit, and operational security measures designed to protect personal data handled within our systems. No system is completely secure, and you are responsible for protecting your device, credentials, and wallet recovery methods.

14. Children

The app is for users aged 18+. We do not knowingly process children's data. If you believe a child has provided us with personal data, contact us at support@liminal.cash and we will delete it.

15. Changes to This Notice

We update this notice when our processing changes. We publish the updated version in the app, update the effective date, and notify you of significant changes through the app or by email.

16. Contact

Privacy questions and rights requests: support@liminal.cash

Controller: Liminal Finance Ltd, 41 Pitfield Street, London, N1 6DA, United Kingdom