Lilie · Legal

Security

Last updated: 4 May 2026

This page describes how Importify Limited ("Lilie") protects your data. We take security seriously and have built Lilie to minimize the surface area where your data could be exposed.

For details on what data we collect and how we use it, see our Privacy Policy.


Our security philosophy

The most secure data is data we don't have. Lilie is designed around three principles:

  1. Minimize what we retain. Where possible, we extract structured derivatives (voice profiles, embeddings) and discard the original content.
  2. Scope access tightly. All data is scoped to the user account that owns it. There is no shared data between users.
  3. Be honest about what we do. This page describes our actual practices, not aspirations. If something changes, this page changes.

Data protection

Encryption in transit

All connections to and from Lilie use HTTPS/TLS. This includes:

We do not accept connections over unencrypted HTTP.

Encryption at rest

Your data is encrypted at rest in our databases:

Authentication

Access controls


How your data is isolated

Per-user scoping

Every record in our database is tied to a specific user_id. All queries automatically filter by the authenticated user's ID. There is no cross-user data sharing.

This includes:

Row-level security

Our database uses Supabase's row-level security (RLS) policies to enforce user scoping at the database level. Even if an application-layer bug were to attempt a cross-user query, the database would reject it.

No training on user data

We do not use your data to train any machine learning model that is shared between Lilie users. Specifically:


What we don't store

To minimize attack surface, we deliberately avoid storing:


Subprocessors and supply chain

We use a small number of trusted subprocessors. Each is contractually obligated to maintain security standards equivalent to ours and to handle your data only for the purpose of providing their service.

For the current list, see lilie.app/subprocessors.

We monitor security advisories for our dependencies and apply patches in a timely manner.


Vulnerability disclosure

If you discover a security vulnerability in Lilie, please report it to support@lilie.app with the subject line "Security: [brief description]".

We commit to:

Please give us reasonable time to address the issue before public disclosure.


Incident response

If we discover a security incident that affects your data, we will:

  1. Investigate and contain the incident
  2. Notify affected users by email
  3. Notify relevant authorities as required by applicable law (generally within 72 hours of becoming aware of a breach involving personal data)
  4. Publish a post-incident summary describing what happened, what was affected, and what we've changed to prevent recurrence

Compliance and certifications

Lilie is currently in private beta. We have designed our practices to align with:

We do not currently hold formal third-party security certifications (e.g. SOC 2, ISO 27001). We will pursue these as the company scales and customer demand warrants.


Your security responsibilities

Security is a shared responsibility. To keep your account safe:


Contact

For security questions, vulnerability reports, or compliance inquiries:

Importify Limited Unit 1603, 16th Floor, The L. Plaza 367–375 Queen's Road Central Sheung Wan, Hong Kong

Email: support@lilie.app