Liminal - Privacy and Cookies Policy
Effective date: 12 February 2026
Controller: Zenly Ltd (trading as Liminal) (UK company no. 16556039)
Registered address: 41 Pitfield Street, London, N1 6DA, United Kingdom
Contact: fifi@liminal.cash
This notice explains how Liminal processes personal data when you use the Liminal app (including TestFlight alpha releases).
1) Summary of how we use your personal data
- We use your personal data to create and run your account, provide app features you request, and support you.
- We use your personal data to meet the compliance standards required by third-party providers that you access through the app (for example, identity verification and screening).
- We use PostHog to record product interaction events and crash diagnostics so we can fix broken flows and improve reliability.
- We use Persona to collect and verify identity information for KYC/ID checks that our third-party providers require.
- We share personal data with third parties when you use their services through the app. Those third parties also process data under their own privacy notices.
- We do not sell personal data.
2) What Liminal is and how data responsibility works
Liminal provides a software interface that connects you to third-party services (for example wallet infrastructure, on/off-ramp providers, and decentralised protocols). Liminal does not custody your funds.
Controller roles
- Liminal (Zenly Ltd) acts as controller for personal data processed to run the app, provide support, and maintain app security and reliability.
- Third-party providers you use through the app act as separate controllers for their services and compliance obligations.
- Persona acts as a processor for identity verification workflows that Liminal runs to satisfy third-party provider requirements, and Persona also processes certain information under its own operational controls.
3) Your information and the blockchain
When you use blockchain features, you publish transaction data to a blockchain network.
Public information includes
- wallet addresses,
- transaction hashes,
- token transfers and balances associated with addresses,
- timestamps and amounts.
Blockchain data is public and cannot be deleted or edited by Liminal.
4) The personal data we process
We process the categories below. The app privacy labels you provided indicate that many of these are linked to your identity, and that performance diagnostics are collected in a way that is not linked to your identity.
A. Account and contact data
- name
- email address
- phone number
- physical address (if you provide it)
- other contact information you provide
B. Identifiers
- user ID and internal account identifiers
- device identifiers generated by the platform or SDKs (where enabled)
C. KYC / identity verification data (Persona)
- identification documents and images (for example passport or driving licence)
- proof of address documents
- selfie or liveness capture where required by the KYC flow
- date of birth and nationality where required by the KYC flow
- KYC results and screening outcomes (pass/fail, risk flags, timestamps)
D. Usage data (PostHog)
- product interaction events (for example screens viewed, buttons tapped, feature usage sequences)
E. Diagnostics (PostHog and platform tooling)
- crash reports
- error logs
- performance metrics
F. Location
- coarse location (where enabled on your device)
G. Financial and payment-related data
- payment information you provide or that a provider returns for receipts and support
- other financial information that appears in a flow you initiate (for example top-up status)
5) How we use your data
We do not sell your data. You can find the purposes for which we use your information, below:
| Purpose | What we do | Data used | Lawful basis (UK GDPR) | User control |
|---|---|---|---|---|
| Provide the app and core functionality | Create your account, authenticate you, display features you request, send service messages | Account/contact data; identifiers; limited financial flow data | Contract (Art. 6(1)(b)) | If you do not provide core account data, you cannot use the app. |
| Provide customer support | Respond to support requests, investigate issues you report, maintain support history | Contact data; identifiers; support communications; relevant diagnostics | Legitimate interests (Art. 6(1)(f)) | You can choose what you share in support tickets. |
| Meet third-party provider compliance standards (KYC/ID) | Collect identity information through Persona, run verification, store results, and pass required outputs to the relevant third-party providers | KYC/ID data; contact data; identifiers; KYC results | Legitimate interests (Art. 6(1)(f)) in enabling providers to meet legal and licensing requirements; Consent (Art. 6(1)(a)) for biometric processing where the flow requires it | If you do not complete KYC, you cannot access KYC-gated features. If biometric consent is refused, the KYC flow cannot complete where the provider requires it. |
| Security and abuse prevention | Detect suspicious access, prevent account abuse, maintain audit trails for security events | Identifiers; device data; coarse location (if enabled); diagnostics | Legitimate interests (Art. 6(1)(f)) | You can object. We stop unless we demonstrate compelling grounds. |
| App reliability and bug fixing (PostHog) | Record crashes and error logs, diagnose causes, fix broken releases | Diagnostics; identifiers (where linked) | Legitimate interests (Art. 6(1)(f)) | You can object. If we cannot investigate a specific issue without diagnostics, support outcomes degrade. |
| Product analytics (PostHog) | Record product interaction events to identify drop-off points, broken flows, and feature usage | Usage data; identifiers (where linked) | Legitimate interests (Art. 6(1)(f)) | You can object. We stop unless we demonstrate compelling grounds. |
| Legal claims and disputes | Preserve evidence and defend or bring claims | Any relevant data category | Legitimate interests (Art. 6(1)(f)) | Processing runs only when needed for claims and disputes. |
| Law enforcement and regulator requests | Respond to valid requests and legal processes | Any relevant data category | Legal obligation (Art. 6(1)(c)) where applicable; otherwise legitimate interests (Art. 6(1)(f)) | You do not control processing where disclosure is legally required. |
Legitimate interests statement
Our legitimate interests are: operating a secure and reliable app, preventing abuse, improving usability, and meeting third-party provider compliance standards so you can access the services you request.
6) Processors and third parties
A. Processors we use
- PostHog: product interaction analytics and crash/diagnostics logging.
- Persona: identity verification and KYC data collection workflows.
B. Third-party providers you access through the app
When you use a third-party service through Liminal (for example an on/off-ramp, wallet infrastructure provider, or a protocol), that provider processes personal data under its own privacy notice. Liminal shares only the data required to enable the service and satisfy that provider's compliance standards.
7) International transfers
Our team is based in the UK. Some processors and third-party providers process data outside the UK. We use appropriate transfer safeguards required by UK GDPR for processor transfers. Third-party providers explain their own transfer safeguards in their privacy notices.
8) Retention
We retain personal data for defined periods:
| Data type | Retention period |
|---|---|
| Account and contact data | While your account is active, then 6 years to manage disputes and maintain security records. |
| Support communications | 3 years from ticket closure. |
| PostHog product analytics events | 13 months. |
| Crash logs and diagnostics | 90 days. |
| KYC/ID data and results (Persona) | For the period required by the relevant third-party provider compliance standard, then 5 years after the end of the relationship with that provider, unless the provider requires longer retention. |
| Blockchain data | Retained on-chain by the network. Liminal cannot delete or amend it. |
9) Your rights
You have the right to:
- access your personal data,
- correct inaccurate data,
- delete data in certain circumstances,
- restrict processing in certain circumstances,
- receive certain data in a portable format,
- object to processing based on legitimate interests,
- withdraw consent where processing is based on consent.
How to exercise rights
Email fifi@liminal.cash with your request. We verify your identity before responding.
Complaints
You can complain to the UK Information Commissioner's Office (ICO). But please first email Fifi! I'm sure we can resolve your complaint. – Fifi.
10) Consent boundaries (so users understand what they can and cannot "turn off")
- Core account operation runs on contract necessity. If you want us to stop that processing, you close the account.
- KYC/ID checks are required for KYC-gated features. If you want us to stop that processing, you do not use those features.
- Biometric data (if used in the KYC flow) runs on consent. You can refuse consent. The KYC flow then cannot complete where the provider requires biometric checks.
- Analytics and diagnostics run on legitimate interests. You can object.
11) Cookies and similar technologies (mobile SDKs)
Liminal uses SDKs and similar technologies that function like cookies on mobile apps.
Essential SDK functions
- session management
- security logging
- crash reporting required to keep the app stable
Analytics SDK functions (PostHog)
- product interaction events
- aggregated performance metrics
You can exercise controls through:
- device settings (for example location permissions), and
- contacting fifi@liminal.cash to object to analytics processing.
But really, if you don't want us to improve the product then don't use the product. – Yours, Fifi.
12) Security
We use access controls, encryption in transit, and operational security measures designed to protect personal data that we handle within our system.
You are responsible for protecting your device and credentials.
13) Children
The app is for users aged 18+. We do not knowingly process children's data.
14) Changes to this notice
We update this notice when our processing changes. We publish the updated version in the app and update the "Last updated" date.
15) Contact
Privacy questions and rights requests: fifi@liminal.cash
Controller address: 41 Pitfield Street, London, N1 6DA, United Kingdom
Notes on alignment with your screenshots
Your screenshots reflect collection of identifiers, contact info, usage data, diagnostics, financial info, and coarse location, with performance diagnostics not linked to identity. This notice preserves that structure and explains concrete uses and lawful bases, while avoiding vague purpose statements.