Privacy Policy
Last updated: August 9, 2026
Levito is a conversion optimization service. Our customers install Levito on their own websites, and Levito tests different versions of the words on those pages to find which ones convert better. This policy explains what we collect from people who use Levito, and what we collect from our customers' website visitors.
What information does Levito collect from visitors and users?
When you create a Levito account we collect the information you give us: your name, your email address, and, when you become liable for a fee, the billing information required to process payment. Card details themselves go directly to our payment processor and are not stored by us, as described below. We also collect the information your browser sends when you use our website and app, such as your IP address, browser type and the pages you visit, which we use to keep the service running and secure.
Two of those uses are worth calling out, because they store your own IP address rather than using it in passing. We record the IP address an account was created from, so that we can detect and slow down automated signup abuse. And when you sign in to the app, we add the IP address you are browsing from to your account's excluded-traffic list, so that your own visits to your own pages are not counted as visitor traffic and do not distort your test results. You can see that list, and add to or remove from it, in your account settings. Entries we captured automatically are dropped after ninety days without a sign-in from that address. We also remember which browsers we have seen arriving from one of those addresses, so that your own visits are not counted when you are away from that network. We forget a browser ninety days after we noted it, and nothing you or it does extends that; if it arrives from one of those addresses again afterwards, we note it afresh.
Why is information collected?
To provide the service, to communicate with you about your account, to bill you, to provide support, and to detect and prevent abuse.
How does Levito protect my information?
We have implemented a variety of security measures to maintain the safety of your personal data. Personal data is held behind secured networks and is accessible only by staff who need it to operate the service.
Where it is necessary to transmit personal data to a third party in order to provide the service to you, we require that recipient to keep it confidential, to use it only for the intended purpose, and not to disclose it further.
Will Levito disclose the information it collects to others?
We do not sell or share the data we collect with unrelated third parties, except to provide the products or services you have requested, or where:
- we respond to subpoenas or court orders, or need to establish or exercise our legal rights; or
- we believe it is necessary in order to investigate, prevent or act on illegal activity, suspected fraud, threats to anyone’s physical safety, or violations of our Terms of Service, or where the law otherwise requires it.
Does Levito use cookies?
Levito sets a small number of cookies, all of them strictly necessary to operate the service. None of them stores personal data, and none of them is used for advertising:
- one that keeps you signed in to your account;
- one that carries a confirmation message from one page to the next, and is cleared as soon as it is shown;
- one that remembers which page you were trying to reach when you were asked to sign in, so we can return you to it; and
- one that records that a sign-in attempt from your browser needs an additional security check. It holds nothing but a marker that the check is required.
We do not use cookies for advertising, we do not use advertising or analytics pixels on this site, and we do not load third-party tracking scripts on it.
On our customers' websites, Levito sets a first-party identifier so that it can tell whether the same visitor who saw a tested page later converted. That identifier is a random value. It is not linked to a name, an email address, or an advertising profile, and it is not used to track anyone across unrelated websites.
Can I access, modify or delete the personal data Levito collects?
The personal data we hold about you as a Levito user is your name, your email address and the billing records associated with any fee you have paid. You can view and change your name and email address at any time from your account settings, and your card details are held and can be changed at our payment processor. Closing your account deletes the data we hold about you.
What information does Levito collect from customers' visitors?
If you are a Levito customer, you should understand exactly what Levito records about the people who visit your pages, because you are responsible for telling them about it.
For each visitor who is shown a tested page, Levito records which version they were shown, whether the visit came from a mobile device, whether it was identified as automated traffic, the page address, and the time. When a visitor completes one of the goals you have set up, Levito records that too.
Levito does not store your visitors' IP addresses or email addresses. It stores one-way cryptographic hashes of them:
- IP address. The visitor’s IP address is passed through a keyed hash (HMAC-SHA256, using a secret we hold) together with your site’s identifier, and only a short prefix of the result is stored. The original address is discarded and is never written to our database. We use this value to recognise repeat visits from the same network for accuracy, to filter automated traffic, and to investigate unusual traffic that would otherwise distort a customer's test results. It is erased from our records after thirty days.
- Email address. If your setup passes us an email address so that a conversion can be attributed to the right visitor, we normalise it and store only a SHA-256 hash of it, salted with a secret unique to your site. Because the salt differs per site, the same person’s email produces a different value on every site, so these hashes cannot be matched across sites or against a list obtained elsewhere. The address itself is never written to our database.
Raw IP addresses and browser user-agent strings exist only for the moment it takes to derive the values above, and are not retained.
Depending on how you configure Levito, you may send us other personal data. You remain responsible for having a lawful basis to collect it and for obtaining any consents your visitors are entitled to.
Under the GDPR, you are the data controller and Levito is your data processor. Our Data Processing Addendum forms part of our agreement with you.
Does Levito use AI, and what does it send?
Levito uses a third-party large language model provider to write the alternative versions of your page copy that it proposes to you. What we send is the content of your page and the context you give us about your business. We do not send your visitors' personal data, and we do not send the hashed values described above.
How long does Levito keep information?
Different kinds of data are kept for different lengths of time:
- Your account. We keep your name, email address and billing records for as long as your account is open. Closing your account deletes them. A signup that is never confirmed is deleted within about a day.
- Test records. Impressions, conversions and results are kept for as long as you keep them. They are deleted when you delete the test they belong to, and all of them are deleted when you close your account. We do not delete them on a timer, because a test’s history is what your reporting is built from.
- The visitor IP value. The hashed value described above is erased thirty days after the record it belongs to was created. It is never needed after that.
- Records of measurements we declined to count. When we refuse to record a conversion, because it came from an address on your excluded-traffic list or because it repeated too quickly from one address, we keep a short record of the refusal so that we can explain a discrepancy in your numbers if you ask. It holds no more than the affected site, goal and visitor identifier; the hashed IP value in it is erased on the same thirty-day schedule as everything else, and the record itself is deleted when you close your account.
- The email-to-visitor mapping. Where your setup supplies email addresses for attribution, the salted hashes and the record of those requests are deleted after thirteen months.
- Security and diagnostic records. Sign-in attempts and expired sessions are cleared routinely; short-lived diagnostic records about page changes and failed swaps are deleted within two to fourteen days.
Where is information held?
Levito is operated from the United States and information you provide to us is stored on servers in the United States. If you are outside the United States, using the service involves transferring your information there. By providing personal data to us you acknowledge that transfer.
Opting out of email from Levito
Every marketing email we send includes an unsubscribe link, and you can turn off test-update emails for a workspace from your account settings. Even if you opt out, you will still receive messages about your account itself, such as security notices and billing receipts, unless you close your account.
How does Levito handle data deletion requests?
You control the data in your account. You can delete individual sites, pages, goals and tests from within the app, and doing so deletes the associated records. Closing your account deletes your account data.
If you need us to act on a deletion request from one of your own visitors, contact us at help@levito.com. Because visitor identifiers, IP values and email values are stored only as one-way hashes, we can act on such a request only where you can supply the information needed to derive the same value.
Can children or minors use Levito?
Levito is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If we learn that we hold personal data about a child, we will delete it. If you believe we hold information about a child, please contact us.
California privacy rights
If you are a California resident, the California Consumer Privacy Act gives you the following rights:
- the right to know what personal information we collect, use, disclose and process;
- the right to request deletion of your personal information;
- the right to correct inaccurate personal information;
- the right to opt out of the sale or sharing of personal information; and
- the right not to be discriminated against for exercising your privacy rights.
Levito does not sell or share personal information as those terms are defined under the CCPA, and has not done so. We use personal information solely to provide and improve our service and to meet our contractual obligations to our customers.
Where we process personal information on behalf of a customer, that customer is the business and Levito acts as a service provider. If you are a visitor to a customer’s website and want to exercise these rights over data collected there, contact that business; we will assist them in responding, subject to the limits described above for one-way hashes.
To exercise your rights, contact us at help@levito.com and we will respond in accordance with applicable law.
Third-party payment processor
We use Stripe, one of the internet’s largest third-party payment processors, to process payments made to Levito. Because Levito is not sold on a subscription, we ask you for a payment method when you become liable for your first fee rather than when you open your account.
When you provide one, your financial information, including your card number and billing address, is transmitted directly to Stripe for processing. Levito does not store your card details. The way Stripe uses, stores and discloses your information is governed by its own published privacy, security and other policies, and Levito has no liability or responsibility for Stripe’s privacy practices or other actions.
Links to other sites
This policy applies to the Levito website and to your dealings with Levito. Our site links to sites we do not operate, and we are not responsible for their privacy practices. We encourage you to read the privacy statement of every site that collects personal data from you.
Updates to this privacy policy
The service changes over time, and it may be necessary for us to change this policy. When that happens we will post the change here and update the date at the top of this page, so you can always see what we collect and how we use it. Where a change is significant we will also tell you by email or in the app.
Levito Terms of Service
Your access to and use of Levito is also subject to our Terms of Service.
Contacting Levito
If you have any question about this policy or about our privacy practices, contact us at help@levito.com, or write to us:
FM Media, Inc. d/b/a Levito
21750 Hardy Oak Blvd Ste 104
San Antonio, TX 78258-4946
USA
We only get paid if you do.
Free to start. Pay on results.