Liminal - Privacy and Cookies Policy

Effective date: 12 February 2026

Controller: Zenly Ltd (trading as Liminal) (UK company no. 16556039)

Registered address: 41 Pitfield Street, London, N1 6DA, United Kingdom

Contact: fifi@liminal.cash

This notice explains how Liminal processes personal data when you use the Liminal app (including TestFlight alpha releases).

1) Summary of how we use your personal data

  • We use your personal data to create and run your account, provide app features you request, and support you.
  • We use your personal data to meet the compliance standards required by third-party providers that you access through the app (for example, identity verification and screening).
  • We use PostHog to record product interaction events and crash diagnostics so we can fix broken flows and improve reliability.
  • We use Persona to collect and verify identity information for KYC/ID checks that our third-party providers require.
  • We share personal data with third parties when you use their services through the app. Those third parties also process data under their own privacy notices.
  • We do not sell personal data.

2) What Liminal is and how data responsibility works

Liminal provides a software interface that connects you to third-party services (for example wallet infrastructure, on/off-ramp providers, and decentralised protocols). Liminal does not custody your funds.

Controller roles

  • Liminal (Zenly Ltd) acts as controller for personal data processed to run the app, provide support, and maintain app security and reliability.
  • Third-party providers you use through the app act as separate controllers for their services and compliance obligations.
  • Persona acts as a processor for identity verification workflows that Liminal runs to satisfy third-party provider requirements, and Persona also processes certain information under its own operational controls.

3) Your information and the blockchain

When you use blockchain features, you publish transaction data to a blockchain network.

Public information includes

  • wallet addresses,
  • transaction hashes,
  • token transfers and balances associated with addresses,
  • timestamps and amounts.

Blockchain data is public and cannot be deleted or edited by Liminal.

4) The personal data we process

We process the categories below. The app privacy labels you provided indicate that many of these are linked to your identity, and that performance diagnostics are collected in a way that is not linked to your identity.

A. Account and contact data

  • name
  • email address
  • phone number
  • physical address (if you provide it)
  • other contact information you provide

B. Identifiers

  • user ID and internal account identifiers
  • device identifiers generated by the platform or SDKs (where enabled)

C. KYC / identity verification data (Persona)

  • identification documents and images (for example passport or driving licence)
  • proof of address documents
  • selfie or liveness capture where required by the KYC flow
  • date of birth and nationality where required by the KYC flow
  • KYC results and screening outcomes (pass/fail, risk flags, timestamps)

D. Usage data (PostHog)

  • product interaction events (for example screens viewed, buttons tapped, feature usage sequences)

E. Diagnostics (PostHog and platform tooling)

  • crash reports
  • error logs
  • performance metrics

F. Location

  • coarse location (where enabled on your device)

G. Financial and payment-related data

  • payment information you provide or that a provider returns for receipts and support
  • other financial information that appears in a flow you initiate (for example top-up status)

5) How we use your data

We do not sell your data. You can find the purposes for which we use your information, below:

PurposeWhat we doData usedLawful basis (UK GDPR)User control
Provide the app and core functionalityCreate your account, authenticate you, display features you request, send service messagesAccount/contact data; identifiers; limited financial flow dataContract (Art. 6(1)(b))If you do not provide core account data, you cannot use the app.
Provide customer supportRespond to support requests, investigate issues you report, maintain support historyContact data; identifiers; support communications; relevant diagnosticsLegitimate interests (Art. 6(1)(f))You can choose what you share in support tickets.
Meet third-party provider compliance standards (KYC/ID)Collect identity information through Persona, run verification, store results, and pass required outputs to the relevant third-party providersKYC/ID data; contact data; identifiers; KYC resultsLegitimate interests (Art. 6(1)(f)) in enabling providers to meet legal and licensing requirements; Consent (Art. 6(1)(a)) for biometric processing where the flow requires itIf you do not complete KYC, you cannot access KYC-gated features. If biometric consent is refused, the KYC flow cannot complete where the provider requires it.
Security and abuse preventionDetect suspicious access, prevent account abuse, maintain audit trails for security eventsIdentifiers; device data; coarse location (if enabled); diagnosticsLegitimate interests (Art. 6(1)(f))You can object. We stop unless we demonstrate compelling grounds.
App reliability and bug fixing (PostHog)Record crashes and error logs, diagnose causes, fix broken releasesDiagnostics; identifiers (where linked)Legitimate interests (Art. 6(1)(f))You can object. If we cannot investigate a specific issue without diagnostics, support outcomes degrade.
Product analytics (PostHog)Record product interaction events to identify drop-off points, broken flows, and feature usageUsage data; identifiers (where linked)Legitimate interests (Art. 6(1)(f))You can object. We stop unless we demonstrate compelling grounds.
Legal claims and disputesPreserve evidence and defend or bring claimsAny relevant data categoryLegitimate interests (Art. 6(1)(f))Processing runs only when needed for claims and disputes.
Law enforcement and regulator requestsRespond to valid requests and legal processesAny relevant data categoryLegal obligation (Art. 6(1)(c)) where applicable; otherwise legitimate interests (Art. 6(1)(f))You do not control processing where disclosure is legally required.

Legitimate interests statement

Our legitimate interests are: operating a secure and reliable app, preventing abuse, improving usability, and meeting third-party provider compliance standards so you can access the services you request.

6) Processors and third parties

A. Processors we use

  • PostHog: product interaction analytics and crash/diagnostics logging.
  • Persona: identity verification and KYC data collection workflows.

B. Third-party providers you access through the app

When you use a third-party service through Liminal (for example an on/off-ramp, wallet infrastructure provider, or a protocol), that provider processes personal data under its own privacy notice. Liminal shares only the data required to enable the service and satisfy that provider's compliance standards.

7) International transfers

Our team is based in the UK. Some processors and third-party providers process data outside the UK. We use appropriate transfer safeguards required by UK GDPR for processor transfers. Third-party providers explain their own transfer safeguards in their privacy notices.

8) Retention

We retain personal data for defined periods:

Data typeRetention period
Account and contact dataWhile your account is active, then 6 years to manage disputes and maintain security records.
Support communications3 years from ticket closure.
PostHog product analytics events13 months.
Crash logs and diagnostics90 days.
KYC/ID data and results (Persona)For the period required by the relevant third-party provider compliance standard, then 5 years after the end of the relationship with that provider, unless the provider requires longer retention.
Blockchain dataRetained on-chain by the network. Liminal cannot delete or amend it.

9) Your rights

You have the right to:

  • access your personal data,
  • correct inaccurate data,
  • delete data in certain circumstances,
  • restrict processing in certain circumstances,
  • receive certain data in a portable format,
  • object to processing based on legitimate interests,
  • withdraw consent where processing is based on consent.

How to exercise rights

Email fifi@liminal.cash with your request. We verify your identity before responding.

Complaints

You can complain to the UK Information Commissioner's Office (ICO). But please first email Fifi! I'm sure we can resolve your complaint. – Fifi.

10) Consent boundaries (so users understand what they can and cannot "turn off")

  • Core account operation runs on contract necessity. If you want us to stop that processing, you close the account.
  • KYC/ID checks are required for KYC-gated features. If you want us to stop that processing, you do not use those features.
  • Biometric data (if used in the KYC flow) runs on consent. You can refuse consent. The KYC flow then cannot complete where the provider requires biometric checks.
  • Analytics and diagnostics run on legitimate interests. You can object.

11) Cookies and similar technologies (mobile SDKs)

Liminal uses SDKs and similar technologies that function like cookies on mobile apps.

Essential SDK functions

  • session management
  • security logging
  • crash reporting required to keep the app stable

Analytics SDK functions (PostHog)

  • product interaction events
  • aggregated performance metrics

You can exercise controls through:

  • device settings (for example location permissions), and
  • contacting fifi@liminal.cash to object to analytics processing.

But really, if you don't want us to improve the product then don't use the product. – Yours, Fifi.

12) Security

We use access controls, encryption in transit, and operational security measures designed to protect personal data that we handle within our system.

You are responsible for protecting your device and credentials.

13) Children

The app is for users aged 18+. We do not knowingly process children's data.

14) Changes to this notice

We update this notice when our processing changes. We publish the updated version in the app and update the "Last updated" date.

15) Contact

Privacy questions and rights requests: fifi@liminal.cash

Controller address: 41 Pitfield Street, London, N1 6DA, United Kingdom

Notes on alignment with your screenshots

Your screenshots reflect collection of identifiers, contact info, usage data, diagnostics, financial info, and coarse location, with performance diagnostics not linked to identity. This notice preserves that structure and explains concrete uses and lawful bases, while avoiding vague purpose statements.