Lipi is a voice-controlled home system. This policy says exactly what we
collect, how, what it is used for, who else handles it on our behalf, and what
we never do. It applies to the Lipi apps for iPhone, Mac and Android, to the
Lipi web app, to controlling your home over WhatsApp, and to the Lipi skill for
Alexa.
Lipi is operated by Wiredleap Technology Private Limited,
2nd & 3rd Floor, No. 472/7, Balaji Arcade, 20th L Cross Road, AVS Layout,
Ejipura, Bengaluru 560095, India. “We”, “us” and
“Lipi” in this policy mean that company.
What we collect, and how
- Your phone number. You type it in to sign in. We send a
one-time code to it over WhatsApp and use it to identify your account, the
boxes you are a member of, and to name you in the activity log of a box you
share.
- Your home setup. The names you give your boxes, rooms,
lights, fans and sockets, whether each is on or off, your scenes, schedules
and dashboard layout. Created by you in the app; needed to show you your home
and act on your commands.
- Your commands and chats. The text of what you type or
say to Lipi, and Lipi's replies. Speech is turned into text on your own device
wherever the platform allows it (see How voice is handled), so what
reaches us is the sentence, not the sound. Chats are kept as history you can
reopen in the app.
- The activity log. Each switch action, which member did
it, from which surface (app, voice, WhatsApp, Alexa, schedule), and when.
Recorded by our server as the command is carried out; every member of the box
can see it.
- Devices on your home network. A Lipi box checks its own
Wi-Fi network every 30 seconds and reports which devices answer: their
hardware (MAC) address, the name they announce, and when they arrive and
leave. This is what the Devices page shows. It is collected by the
box you installed, on the network you own, and only members of that box can
see it. You can name, hide or forget any device, which also deletes its
arrival log.
- Connected services (optional). If you connect Swiggy
under Account → Skills, we store the sign-in token Swiggy issues so Lipi
can act on your behalf, and what Swiggy returns in a conversation — your
saved addresses, restaurants, cart, orders — passes through the chat like
any other message. Disconnecting revokes the token. If you connect Rapido,
we store the phone number and name on your Rapido account and keep a
signed-in browser session for it on our server, which Lipi drives to get
fares and book the rides you ask for; the pickup and drop you give, and the
ride status, pass through the chat the same way. Disconnecting ends the
session and deletes the account details.
- Basic technical data. App version, device type, box
firmware and Wi-Fi signal, and error logs, used to keep the service working
and to diagnose a box when you ask.
How voice is handled
iPhone and Mac. Speech is transcribed on the device by iOS
(Apple's speech recogniser). Only the finished text is sent to us. No recording
leaves the device and none is stored.
Android. Commands are transcribed on the phone by Android's
speech recogniser; only the text is sent to us. Hands-free is different and off
by default: when you switch it on, the phone listens locally for loudness and,
when something is said, sends that one short clip — a second or two of
audio — to our server, which has it transcribed by OpenAI's speech model,
reached through Vercel's AI Gateway (see below), to check whether it began with
the wake phrase. The clip is not stored by us or by them after
transcription.
Web app. Your browser's own speech recognition produces the
text; depending on the browser, that may involve the browser vendor's servers
under their policy. We receive text only.
Alexa. The Echo's microphone and Amazon's speech recognition
are Amazon's, under Amazon's policy; we receive the transcribed sentence from
Amazon.
The demo on lipi.me. The unauthenticated voice demo on our
landing page streams the audio you record to xAI for transcription. It is not
tied to an account and nothing is kept.
How Lipi understands you: AI processing
Working out that “switch off everything except the fan” means
three particular relays is done by a large language model, and that model is
not ours. When you use voice or chat, our server sends the following to
Google Gemini, via OpenRouter:
- the sentence you typed or spoke, and the last few messages of that
conversation;
- the names of your boxes, rooms and switches, their site tag (home,
office) and whether each is on or off — so the model can pick the right
one;
- if you ask Lipi to diagnose a box: its firmware, Wi-Fi network name and
signal, and its last few activity entries;
- if you have connected Swiggy and ask about food or groceries: what Swiggy
returns, including your saved delivery addresses and cart;
- if you have connected Rapido and ask for a ride: the pickup and drop
you name, and the fares and ride status Rapido shows.
Your phone number and your voice are never sent to the model. The model's
reply, when it is to be spoken aloud, is sent as text to
ElevenLabs to be turned into audio.
This happens only with your permission. The first time you
reach for voice or chat, the app shows what is sent and to whom and asks you to
allow it. You can withdraw that at any time under
Account → Privacy; voice, chat and hands-free then pause,
while tapping switches, scenes, schedules, members and the activity log carry on
unchanged, because none of those involve AI. Controlling your home over WhatsApp
or Alexa is the same AI path, and using those surfaces is how you consent to it
there.
Who handles your data for us
We do not sell or rent personal data, and we share it only with the
processors below, each of which acts on our instructions, under a contract that
forbids using your data for its own purposes, including training its models,
and that binds it to protection at least as strong as this policy.
- AiSensy (WhatsApp Business API) — delivers your
one-time sign-in code. Receives your phone number and the code.
- OpenRouter, routing to Google (Gemini) — understands
your commands and chats. Receives what is listed under AI
processing.
- TypeSafe — classifies each command before it is
acted on (is it a switch, a TV, a food order; is it for now or later; was
the wake phrase really said). Receives the sentence you said or typed and,
where needed, the names of your switches.
- ElevenLabs — turns Lipi's spoken replies into audio.
Receives the text of the reply.
- OpenAI, via Vercel AI Gateway — transcribes the
Android hands-free clip. Receives one short audio clip per utterance,
Android only, only when hands-free is on.
- Swiggy — only if you connect it, and only what is
needed to search, fill a cart and place the order you asked for, under
Swiggy's own terms as your service provider.
- Rapido — only if you connect it, and only the
pickup, drop and booking you asked for, through a browser session signed
in as you, under Rapido's own terms as your service provider.
- Amazon — only if you link the Alexa skill, under
Amazon's terms.
- Razorpay and Google Maps Platform — only when you
buy a Lipi box on lipi.me: Razorpay processes the payment, and Google's
Places service suggests your delivery address as you type it. Neither is
used by the apps.
Our own servers, which hold your account, home setup, chats and activity
log, are operated by us. Traffic between your apps, your boxes and our servers
is encrypted in transit.
Permissions that stay on your phone
Some things the Android app can do use a permission whose data never leaves
your phone:
- Auto-filling your sign-in code (optional). If you give
Lipi notification access, it reads WhatsApp notifications only while the
sign-in code screen is open, to pick out the six-digit code we sent you. It
ignores every other app and every other message, keeps nothing, and sends
nothing anywhere. The app explains this and asks before Android's
notification-access page opens, and you can turn it off any time in Android
Settings → Notifications → Notification access.
- Setting up a box. Android requires location or
"nearby devices" permission to list Wi-Fi networks and find a box over
Bluetooth. It is used only on your phone during setup; your location is
never sent to us.
What we never do
- We do not sell your personal data. Ever.
- We do not share it with advertisers or data brokers.
- We do not run advertising, analytics SDKs or third-party tracking in
the apps.
- We do not upload your voice from iPhone or Mac, and we do not keep any
recording anywhere.
- We do not send anything to an AI service before you have said yes in
the app.
- We do not listen when you have not pressed to speak, or switched
hands-free on yourself.
Who can see your home
Your home is owner-only by default. Nobody else can see or control it unless
you explicitly invite them by phone number, and you can remove their access at
any time from the app. Members of a box see its switches, its activity log and
its Devices page.
How long we keep things
Your account, home setup, chats and activity log are kept for as long as
your account is open, and chats can be deleted from the app at any time.
Sign-in sessions expire automatically after 30 days. The network-devices log
is kept per device until you forget that device. Diagnostic logs are rotated
and discarded within 30 days. Nothing is retained by the processors above
beyond what is needed to complete the request.
Your rights
You can ask us to show you the data we hold about you, correct it, or delete
your account and everything attached to it — home setup, chats, activity,
network-device logs and connected-service tokens included. Deletion is self-serve
and immediate: use lipi.me/delete-account, or
Account → Delete account in any of the apps. If you would
rather we did it, email us and we will action the request within 30 days.
Children
Lipi is not directed at children under 13 and we do not knowingly collect
their personal data.
Changes
If we change this policy we will update the date above, and for anything
material we will tell you in the app before it takes effect.
Contact
Questions, or want your data deleted? Email
support@lipi.me, or write to Wiredleap
Technology Private Limited at the address above.