Privacy and cookies.
How L-Wiz handles information about you. Last updated 30 September 2026.
In short
We do not use analytics, advertising or tracking cookies, and we do not sell or share your information for marketing. We process only what is needed to run the service, keep it secure and apply fair daily limits. Your notes never leave your browser.
Who we are
L-Wiz is provided by TMR Technologies. We are the controller of the personal data described here. Contact us at [email protected].
What we process
When you use the demo
Your browser sends your IP address with every request. Our server uses it, with the usage cookie, to count search sessions and cases opened each day. It stores only keyed one-way hashes of these identifiers with the counters, never the raw IP address. It does not store your search text. Our request logs record the page or API path and response status, not your IP address or search terms. Web-server request error logs are disabled because they can contain the full request URL.
The first time you open the terminal, Cloudflare Turnstile checks in the background that a person is using the browser. This stops automated copying of the corpus. Cloudflare processes technical signals, such as your IP address and browser characteristics, for this check only. We record only the day the check passed, inside the usage cookie.
When you sign in to the closed beta
Cloudflare Access handles sign-in. It sends a one-time code to the email address you enter. After sign-in, our server receives your verified email address to show which account is signed in, and an account identifier to apply your daily limits. We store a keyed hash of that identifier with the counters, not your email address.
When you email us
We receive your email address and whatever you choose to tell us.
Cookies and browser storage
Every cookie and storage item below is strictly necessary for a service you ask for, so the law does not require a consent banner. None is used for analytics or advertising.
__Host-lwiz-demo | A cookie set by our server. It holds a random identifier, the day your browser passed the browser check and a signature, so daily limits apply fairly. It lasts 30 days and cannot be read by page scripts. |
|---|---|
CF_Authorization | Set by Cloudflare Access only if you sign in to the closed beta. It keeps you signed in for the session. |
__cf_bm | Set by Cloudflare to tell people from automated traffic. It lasts 30 minutes. |
lwiz:… (local storage) | Your notes, highlights, open workspaces and display preferences. They stay in your browser and are never sent to us. |
lwiz.demoNotice.seen (session storage) | Remembers that you have seen the demo notice, until you close the tab. |
You can clear these at any time in your browser settings. Clearing local storage deletes your notes, so export them first.
Why we process it
We rely on our legitimate interests in providing a reliable, secure service, preventing abuse and sharing capacity fairly. For the closed beta, we process your email address to give you the access you asked for. We reply to emails because you asked us to.
How long we keep it
Usage counters and their hashed identifiers are deleted after the day they count, normally within two days. The usage cookie expires after 30 days. Our server logs are overwritten as they fill. Cloudflare keeps its own logs under its policies. We keep emails for as long as we need them to deal with your message.
Your rights
You can ask us for a copy of your personal data, or ask us to correct or delete it, restrict its use or object to how we use it. Most of what we hold is hashed and deleted within days, so we may not be able to link it to you. To make a request, email [email protected].
If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk.