> ## Documentation Index
>
> Fetch the complete documentation index at: https://lithi.ai/llms.txt
>
> Use this file to discover all available pages before exploring further.

# Privacy and proof

## Start with three separate decisions

Source permission lets a chosen feature read specified information. Sending approval authorizes the exact reviewed invitation plan. Optional learning is a separate choice about retaining and using confirmed message information for improvement. One decision does not supply either of the others.

You can decline optional learning and still use otherwise permitted local personalization and approved sending. You can also leave an invitation unapproved, skip a person, or stop without sharing a Mac.

## Understand the source boundary

The Email network scan reads local email headers with your permission. Preparing a relevant message can use additional authorized, bounded relationship context. Do not treat permission to scan headers as permission to copy an entire mailbox, employee files, or contact history into another service.

LinkedIn is an optional external-account connection. Its supported path reads current account and existing-connection information through that service. It is not equivalent to an entirely local Mail scan, and it does not authorize cold discovery or new connection requests.

Use only information you are allowed to use for the selected person. Correct uncertain roles and relationships instead of presenting a guess as a reason you know them.

## Know what crosses the Mac boundary

An approved Email message goes through the selected email service to its recipient. A supported LinkedIn message goes through the connected service to the selected existing connection. Those services and recipients receive the approved content; sending is not a nothing-leaves-the-Mac operation.

Lithi also needs limited account, device, status, attribution, and receipt information for the permitted workflow. A public introduction link is not a password, device enrollment, or evidence that someone accepted a plan. Do not put private message text or secrets in a link.

## Review optional learning on its own

When Optional learning is available, read the workspace, channel, disclosure, and retention policy before confirming the choice. The permitted private learning record concerns the exact message actually sent, not permission to collect unrelated conversations. Shared learning uses restricted summaries rather than recipient identity, relationship excerpts, or reconstructable personal messages.

An unavailable or expired learning policy is not permission to invent a retention period. Declining learning does not erase necessary operational records or receipts, and withdrawing it is not an instruction to unsend a message.

## Keep provider work separate from your private work

Mac-provider setup grants bounded participation in suitable Compute work. It does not grant customer tasks access to your unrelated Mail, Contacts, browser sessions, or documents, and a customer result cannot approve a local invitation.

Encrypted transfer is different from processing: authorized execution may need plaintext in its permitted memory or workspace. Encryption, a signed device, or an independent check does not establish that every host is confidential or every result correct. Use the Trust Center for the applicable processing and security boundaries.

## Read proof without overstating it

A Lithi Receipt identifies the event and evidence it records. A setup receipt does not prove accepted work; an invitation receipt does not prove a reply; an earnings record does not prove payment. Missing or stale evidence remains missing, not a successful outcome.

For a concern, preserve the visible notice, app version, approximate time, and a safe record reference. Remove message bodies, contact lists, tokens, private keys, and bank details before contacting support. Changing a source permission cannot recall content already delivered to a recipient or remove copies held by their service.
