Lyxter
Privacy Policy
Last updated: 28 July 2026
Lyxter ("we", "us") provides an AI diagnostic assistant for heavy-vehicle companies at
app.lyxter.ai. This policy explains what personal data we process, why, and what rights you have.
It is written to comply with the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The data controller is Lyxter ApS (CVR 46627571), Bjergegade 58, 6870 Ølgod, Denmark. Contact:
hello@lyxter.ai.
One category of data is different: the records your company keeps about its own customers -
under Customers, or when Service records work for one of them - the names, contact details, and
vehicle information you enter about those customers are
your company's data, not ours. For that data Lyxter acts only as a
processor, on your instructions, and your company is the controller - see section 6
for the data processing agreement.
2. What we collect
- Account data - your name, work email, and company name. The account owner, or an
admin they appoint, can also add the company's brand logo, address, VAT/CVR number, and phone number, which are printed on
the service reports your company produces. The logo is stored privately to your company account and
is never shown to any other Lyxter customer. Passwords are stored only as secure hashes by our
authentication provider; we never see them.
- Display preferences - the interface language you choose. It is stored with your
membership, used only to decide which language the interface is shown in, and never shared.
- Chat content - the fault codes, questions, messages, and screenshots you submit
to the AI, and the answers you receive. Chats are private to your company account. So that the AI
can pick up work your company has already done, it can search your company's own earlier chats and
is shown a short extract of the few that match this one: the date, the machine as it was recorded,
the fault codes, the first thing the mechanic asked, any diagnosis that chat reached, and the
mechanic's last message there. A chat is matched when it is about the same vehicle you have linked
from Fleet, or when it shares a fault code with this one. This covers your company's whole history
of chats, not only recent ones, and it includes chats with no fault code at all - a "won't start"
job or a how-to question is work your workshop did, and the point is that the AI can recall it.
To find them, we keep for each chat a technical search entry holding its fault-code search keys,
a numerical representation (an embedding) of what it was about, the date, and two markers saying
how many messages you wrote and whether the AI reached a diagnosis. That entry holds no
text from the conversation: the extract above is read from the chat itself each time,
so nothing extra about what was said is stored to produce it. All of it stays inside your company
account, is never shown to another company, and the search entry is deleted the moment its chat is
deleted.
- Machine details - the make, model, model year and vehicle type of the machine
a chat is about, whether you type them into the chat's "Which machine?" panel, they come from a
vehicle you linked from Fleet, or the AI reads them off a photo you send. They describe the machine
only: we do not ask who owns it. They are stored with the chat, are what let the AI scope its
answers to that machine, and are deleted when the chat is deleted. Because a make, model and year
describe a machine and not a person, they may also be recorded against a fault code in the shared
knowledge base described in section 4, where they never appear beside anything identifying you,
your company, or a customer.
- Your company's own case records - when a chat is a real diagnostic case
(it carries a fault code, or the AI assessed it as critical or a warning), Lyxter records what
that case turned out to be: the fault codes, the machine as it was described, a one-line
diagnosed cause, the reported symptom, and the fix. All of it is written by the AI from the
conversation, and the cause, symptom and fix text passes the same automatic scrubbing step in
our software described in section 4 before it is stored. The fault codes themselves are not
scrubbed: a fault code is a technical code, and long codes look like phone numbers to an
automatic scrubber. The AI searches these records in later chats at your company, so it can
tell you when your workshop has seen the same fault before, whether or not the chat is linked
to one of your vehicles. This record is private to your company account, is never shown to
another company, is never placed in the shared knowledge base described in section 4, and there
is no route by which it can become shared. If you delete a chat, its case record is deleted
with it.
- Fleet vehicle records - if you use Fleet, we store one record for each
machine you add, including the name you give it, its make, model, model year, its registration
plate, and any free-text specification note you add on the same form. You decide which of those
to fill in. The record also holds the odometer and engine hour readings you log, whether you
enter them directly or they are recorded when a service is completed, and a short profile of the
machine that the AI writes from the make, model, year and your specification note, keeps on the
record, and reads back in later chats about that vehicle. The record is private to your company
account and is never shown to another company. It is what your vehicle page, its history and its
service plans are built from, and the registration plate is printed on the service report your
company hands its own customer. If you delete the vehicle, the record is deleted with it.
- Vehicle service history - when a chat is linked to one of your vehicles and
raises an issue, Lyxter records what that case turned out to be on the vehicle's own history: the
fault codes it carried, a one-line diagnosed cause, and the fix. All three are written by the AI
from the conversation, and the AI reads them back in later chats about the same machine, which is
how it can tell you what has happened to that vehicle before. This record is private to your
company, is never placed in the shared knowledge base described in section 4, and the cause and fix
text passes the same automatic scrubbing step in our software described there before it is stored.
The fault codes themselves are not scrubbed: a fault code is a technical code, and long codes look
like phone numbers to an automatic scrubber.
- Uploaded manuals - documents your company owner chooses to upload.
- Customer records - the customer name, contact person, phone, email,
address, VAT/CVR number and notes your team enters under Customers, or on a Service job for a
customer's vehicle rather than your own fleet. A machine in your fleet can be marked as belonging
to one of those customers. This data belongs to your company; we process it as a processor, not a
controller (section 1). It is never shared with any other Lyxter customer and never used to train
or improve our AI.
- Priced work documents and invoices - the hours, parts and extras your team
records for one machine, each with its description, quantity, unit price and any discount, plus the
VAT rate and the totals our software works out from them. A document can be linked to one of your
customer records and to a service job. It stays private to your company account, is never shown
to any other Lyxter customer, is never placed in the shared knowledge base described in section 4,
and is never used to train or improve our AI.
When your team turns a document into an invoice, we additionally store the invoice
number, its date and due date, and a copy of your company's own details and your customer's name,
address, contact details and VAT/CVR number as they stood at that moment - so the invoice still
reads correctly years later, and still reads correctly if the customer record is edited or deleted
afterwards. Your team can then email that invoice to the customer. We send it only
when someone in your company asks us to and confirms the recipient's address first; we never send
one automatically. The mail goes out in your company's name with the invoice PDF attached, through
the email provider in section 6, and replies go to your company rather than to us.
- Billing data - subscription status, seat count, and invoices, handled by Stripe.
Card numbers never touch our systems.
- Usage data - message counts per company (used for fair-use limits), technical
metadata about each AI request (which model was used and how many tokens it processed, kept so we
can monitor our own costs - never the content of the request), and standard technical logs
(IP address, browser type) kept by our hosting provider for security.
- Contact data - if you request a demo or join the launch list, we store the
details you submit (name, email, company, message).
Cookies and local storage. We do not use advertising, analytics, or tracking
cookies of any kind. Everything we store in your browser is strictly necessary for features you
ask for, which is why Lyxter shows no cookie consent banner. The complete list:
- Login cookies - two cookies (
sb-access-token, about 1 hour, and
sb-refresh-token, up to 30 days) keep you signed in. They are httpOnly, are never
readable by page scripts, and are deleted when you log out.
- Session marker - one readable cookie (
lx-session-mark, up to
30 days) and one value in your browser's local storage (lx-session-epoch) let a
page tell that the session it was drawn for has ended, so pressing Back after signing out
cannot bring a previous user's screen back from the browser's history cache. The marker is a
one-way hash: it carries no name, email, or account identifier, and it grants no access on its
own. The cookie is deleted when you log out.
- Preferences - your chosen theme (light/dark), price currency (EUR/DKK) and
the plan you were looking at before you signed up (Standard/Pro) are kept in your browser's
local storage so the choice survives a reload and the billing page opens on the plan you
picked. The plan is a display preference only: it is not an account identifier and not a record
that you bought anything. They stay on your device and are not sent to us or anyone else.
- In-app hand-offs - navigating from the fleet page to a chat briefly stores
the vehicle reference in local storage; it is removed as soon as the chat opens.
Our pages load no third-party scripts; fonts are hosted by us. There is one third-party request,
and only inside a chat: where an answer drew on a web source, your browser loads that source site's
small icon from the site itself. It is described in section 4. Content served by our own providers
(section 6), such as your uploaded photos, is not a third-party request: those providers act only
on our instructions.
3. Why we process it (legal bases)
- To provide the service (contract, art. 6(1)(b)) - accounts, chats, AI answers,
manuals, billing, support.
- To keep the service secure and improve it (legitimate interest, art. 6(1)(f)) -
security logs, abuse prevention, aggregated usage statistics.
- To contact you about the launch or a demo (consent, art. 6(1)(a)) - you can
withdraw at any time by emailing us.
4. AI processing and the shared knowledge base
Your messages are processed by AI models (see subprocessors below) to generate answers.
Lyxter learns from chats, but we never train the AI model itself on your data: your chats are
not used to train or fine-tune any AI model.
What the system learns goes into a shared knowledge base of fault codes and repair guidance
that improves answers for every company. It holds structured data only, never
your raw conversation text:
- Fault codes - when the AI answers a fault code it has not seen before,
we may store the code, the vehicle brand, model and model year, and a short AI-generated
description.
- Fixes and technical lessons - after a completed diagnosis, the AI may
write a short fix summary, and a general technical lesson (for example how a
system behaves or a diagnostic-tool procedure). These are AI-written to contain no
customer-specific details, and each new summary and lesson learned from a chat also passes
an automatic scrubbing step in our software before it is stored: it strips out the emails,
phone numbers, number plates, vehicle identification numbers, and other long identification
numbers it finds, and runs an automated check for names, companies, and locations. This
step runs in code, independent of the AI. Technical lessons are additionally reviewed
by Lyxter staff before the AI can use them at all; fix summaries follow the sharing rule
at the end of this list before any other company sees them.
- Fix outcomes - when a mechanic reports whether a suggested fix worked
(worked, did not work, or partly), we store that answer as a simple report with no free
text. Only the resulting counts ("worked for 4 of 5 reports") are shared with other
companies.
- When it reaches other companies - a fault-code description or fix
summary learned from your chat is used in your own company's diagnoses straight away, but it
is shared with other companies only once Lyxter staff have reviewed and approved it, or when
it restates knowledge Lyxter had already approved (an approved manual, or an approved fix for
the same fault code and brand). An entry staff reject is used nowhere, including for your own
company.
Your own words, chat text, and images are never placed in the shared knowledge base, and
neither is anything that identifies you, your colleagues, or your company.
Your company's own earlier chats, its own case records, and the chat search entries that find
them (all described in section 2) are not part of this shared knowledge base and
there is no route by which they can become part of it. They are used only in your own company's
chats. What an earlier chat of yours said is also never treated as a checked answer: the AI is
told plainly that nothing said in an earlier chat was reviewed, that it may have been wrong, and
that it may never be used as the source of what a fault code means or of a torque, pressure,
clearance, capacity or service interval. Recalling one also never stops the AI from looking a
fault code up properly.
When Lyxter cannot answer from its own reviewed knowledge base, your company's manuals or
the machine's own history, it may look the machine up on the public web. The search runs through
the same AI provider that already answers your questions (listed in section 6), which searches
the web on Lyxter's behalf using its own search partner. An entry learned from your own chats
that Lyxter staff have not reviewed yet does not count as an answer here: it is still used in
your own company's chats, and where Lyxter reads its review state it tells the AI the entry is
unreviewed, but it does not hold the lookup back, so an unchecked note in your own account is
not left standing as the meaning of a fault code. When your chat carries a fault code
that no reviewed Lyxter source describes, this lookup normally runs automatically as
the chat starts, or when the machine is first identified, before the AI writes
anything, so that its answer rests on a source rather than on what it happens to remember.
Nothing about what may be sent changes when it runs that way: it is the same wording, built
the same way, described below.
Your message is never sent. The search wording is
built by the software itself, out of a fixed, short list of technical fields and nothing else:
the machine brand (only when it is one of the brands Lyxter knows by name), the model and
engine designation (only when they look like a designation, such as "WA380" or "TCD 7.8"), the
model year from your fleet record, the fault code recorded on the case (only when it has the
shape of a diagnostic code - and where the code was typed inside a longer line, only the part
of that line that has the shape of a diagnostic code, taken word for word and never rewritten),
a few plain English technical words naming the part or system, and one of four fixed
phrases saying what kind of answer is wanted. Anything that fails one of those tests is left
out, and the words naming the part are additionally checked in software for personal details
and rejected if any are found.
So your message, a description of a symptom, your photos, your files, and anything naming
you, your company, your customer, a place or a registration number are never sent to a search
provider. The one thing that can overlap with what you wrote is an ordinary technical word: if
you write that an injector is leaking, the word "injector" can be part of what is looked up.
Lyxter states this precisely rather than promising more than the software checks.
This is enforced by how the search is made, not only by what is put into it. The lookup runs
as a separate request whose entire content is that one built search wording:
the part of the AI that does the searching is never given your conversation, your photos, your
vehicle record or your customer record at all, so it cannot pass on something it was never
shown. The search is normally restricted to a curated list of manufacturer, technical and
workshop sites.
No account, no name and no address goes with the search, and it is not told who is asking:
the request is made by Lyxter's own servers, so your device never contacts the search provider
and your IP address is never sent to it. Lyxter treats what comes back as unverified: the answer
itself does not name the site it drew on, because the app attaches the sources to the answer for
you - a small chip under the reply that opens each source's site and page title. The chip
appears when one of the sources found names the fault code in question; where an automatic lookup
came back with none that does, no chip is shown at all, which is not a statement that nothing was
looked up. The AI must never state a torque figure, a pressure, a clearance or a service interval
on the strength of a web result.
That chip is the one place your own device does reach out: to show each source's site icon, your
browser loads that icon from the source site itself, so those sites can see your IP address and
browser type at that moment, the way they would if you opened the page. Nothing else goes with it -
no account, no name, nothing from your chat, and the request deliberately carries no referrer, so
the site is not told which app or page the icon was shown in. When an icon cannot be loaded, a
plain letter is shown instead. Opening a source from the chip is an ordinary visit to that site,
under that site's own privacy terms.
Manuals uploaded by your company are reviewed by Lyxter staff and then stay private to
your company by default: the AI uses them only in your company's own chats. After
approving a manual, staff may add a small number of short, AI-written technical lessons distilled
from it to the shared knowledge base described above; each lesson is reviewed before the AI can
use it, is written in the AI's own words rather than copied from the manual, and contains nothing
identifying you or your company. A manual itself becomes part of the shared knowledge pool only
if Lyxter staff explicitly decide to share it after review, for material that may lawfully be
shared (see the Terms of Service).
5. Staff access and quality assurance
A small number of Lyxter staff can view customer chats and account data when needed to provide
support, review the quality and safety of AI answers, and investigate problems. Staff access to
customer data is read-only, and every access is recorded in an internal log: who looked at what,
and when. While a learned knowledge entry is still waiting for that review it also shows those
staff which user and which chat it came from - staff-only, logged like any other access, private
to your company until the entry is approved, and cleared from the entry once it is approved and
shared.
To test the AI before changes go live, we may turn a real diagnostic case into an internal test
scenario. Before that happens, identifying details (names, company names, email addresses, phone
numbers, number plates and similar) are removed, the cleaned text is reviewed by staff, and images
are never included. Internal usage and cost figures are aggregated counts and contain no chat
content.
6. Service providers
We use a small number of carefully selected service providers (processors) to run Lyxter.
Where a provider processes data outside the EU/EEA, the transfer is protected by the EU
Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
| Category | Purpose | Location |
| Database and authentication | Storing accounts, chats, and documents | EU (Ireland) |
| Application hosting | Running the service | EU |
| AI model providers | Generating answers, reading images, and - when the wider
web lookup in section 4 is switched on for your account - searching the public web on
Lyxter's behalf | USA |
| Payment processor | Subscriptions and invoicing | EU/USA |
| Email delivery | Transactional email (confirmations, invites, service reminders),
and an invoice your company chooses to send to one of its own customers - which carries that
customer's name and address and the priced lines of the work | USA |
| Customer relationship management (CRM) | Managing customer and prospect
accounts: company name, plan and billing status, the name and work email of the people on
the account, and simple activity counts such as how many diagnoses a user has run and when
they were last active. No chat content, no photos, no vehicle or service records. | EU/USA |
| Network and DNS security | Traffic routing and protection | EU/global |
The wider web lookup described in section 4 adds no new provider to this list.
It runs through the AI model provider already named in it, which uses its own search partner to
fetch the pages; that partner receives only the built technical search wording described in
section 4, and never your message, your photos or anything naming you or your customer.
Business customers can request the named list of providers as part of a data processing
agreement by writing to hello@lyxter.ai. If your company records
customer data (section 2), that agreement is what makes the controller/processor relationship
in section 1 formal - write to us before you enter your first customer record if you need it in place
first.
7. How long we keep data
- Account and chat data: for as long as your company has an account, then deleted on request
or after account deletion. A single chat can also be deleted at any time from inside the app,
by anyone in your company: the conversation and the photos and files attached to it are removed
straight away and cannot be restored. The case record described in section 2 goes with it.
Three things deliberately survive it: the vehicle's own
service history entry, which keeps that case's fault codes, its one-line diagnosis and the
recorded fix so the machine's record stays complete, which stays private to your company, and
whose diagnosis and fix text has already passed the scrubbing step described in section 2;
the knowledge-base entries described in section 4, which are stripped of identifying details
before they are stored; and anything you chose to save to Manuals from the chat, which stays in
your company's library. Nothing else from the conversation is kept.
- Your company's own case records: for as long as your company has an account, then deleted
on request or after account deletion. A single case record is also deleted the moment the chat
it was written from is deleted, as above.
- The chat search entries described in section 2: for as long as the chat itself exists. Each
one is deleted with its chat, automatically and at the same moment, and they hold no text from
the conversation - so a deleted chat leaves no searchable trace of what was said in it.
- Customer records: for as long as your company has an account, then deleted on
request or after account deletion. Your company can also delete one at any time under Customers;
that removes the customer record only - the machines stay in the fleet with their history, and a
service report already produced keeps the details it was printed with. Because your company is
the controller for this data (section 1), how long it is kept beyond that is your company's
decision, not ours.
- Priced work documents: for as long as your company has an account, then deleted on request
or after account deletion. Anyone in your company can delete a DRAFT from inside the app; it and its
lines go for the whole company and cannot be restored. Deleting a customer, a machine or a service
job does NOT delete a document raised against it: the document keeps its own figures and simply
stops naming the record that is gone. Once a document has been turned into an invoice it can no
longer be edited or deleted in the app - it is a bookkeeping record, and the copy of your customer's
details described in section 2 is part of what makes it one. Because your company is the controller
for that customer data (section 1), how long the invoice is kept is your company's decision and
your company's bookkeeping obligation, not ours; account deletion removes it with everything
else.
- Billing records: as required by Danish bookkeeping law (5 years). This is the one thing
an account deletion does not remove.
- Fixes reviewed into the shared knowledge base: kept after account deletion. Names,
companies, contact details and locations are stripped before anything is shared (section 4),
so what remains identifies neither you nor your company.
- Deletion audit record: when we erase an account we keep a minimal record that we did -
the company name, the date, which of our staff carried it out, our internal reference ids, and
counts of how much was removed - for security and accountability, and it holds none of the
erased content and no personal details beyond the company name itself.
- Launch-list and demo-request contacts: until launch communication is done or you ask us
to remove you.
8. Your rights
You can ask us to access, correct, export, or delete your personal data, and to restrict or
object to processing. Write to hello@lyxter.ai - we respond
within 30 days.
Company owners can request deletion of their entire company account, including all user
accounts, chats, vehicles, service history, and uploaded manuals. There are two ways to ask, and
both file the same request: from inside the app, under Settings, Company, or on our public
account deletion page, which works whether or not you still have
the app installed. We confirm the request within 2 working days and complete the deletion within
30 days, and you can withdraw it until we do. That page lists exactly what is deleted and the
little we have to keep (see section 7). One of those things is a minimal record of the deletion
itself - the company name, the date, which staff member carried it out, reference ids and counts
of what was removed - kept so the erasure can be accounted for afterwards.
Customer records are the exception: if you are a workshop's customer and want to
access, correct, or delete what that workshop has recorded about you, ask the workshop directly.
They are the controller for that data, not us (section 1); we only act on their instructions and
will pass such a request on to them.
If you are unhappy with how we handle your data, you can complain to the Danish Data
Protection Agency (Datatilsynet, datatilsynet.dk).
9. Changes
We will update this policy as the service evolves and note the date above. Significant changes
will be announced to account owners by email.