Luria
PRIVACY

Privacy Policy

Last updated: 19 August 2026

Luria tests your website and makes it better, on its own. This policy covers luriart.com and the Luria service. It says what we collect, why we collect it, where we keep it, and how to get it deleted.

1. Two different roles

Which rules apply depends on whose data it is:

2. What we collect

From merchants and prospects (we control):

From visitors to merchant sites (we process):

We do not knowingly collect data from children. We do not collect special-category data, so please do not send it to us. By that we mean data on your health or your biometrics. It also means political opinions, and the like.

3. What we do not do

4. Why we are allowed to use it

Where the UK/EU GDPR applies, our lawful bases are: contract (running your account and the service), legitimate interests (to keep the service safe, to stop abuse, and to improve the product with aggregated data), and consent where consent is required for analytics on a merchant's site. You can withdraw consent at any time.

5. Where your data lives

ProcessorWhat it holdsWhere
VercelSite hosting, serverless functions, and server logsUnited States
Supabase (Postgres + Storage)Accounts, sites, events, scan results, screenshotsUnited States
AnthropicPage content we send for analysis and new copy. They do not use it to train their models.United States
CloudflareTurnstile bot check on public forms. R2 object storage for session recordings, page screenshots, and the ad creatives you upload.Global
ShopifyStore data you authorise via OAuthUnited States
ResendTransactional email (sign-in links, reports)United States
HetznerScan workers that open your public pages during the onboarding scanEuropean Union

We are based in the United States, so your data goes there and is kept there. For transfers out of the UK/EEA we rely on Standard Contractual Clauses with our processors. We keep this list current. We tell customers about material changes before they take effect.

6. How long we keep it

7. Your rights

Wherever you live, you may ask us to access, correct, delete, or export your personal information, and to object to or restrict how we use it. Under the UK/EU GDPR you may also complain. You can take it to your data protection authority. In the UK, that is the ICO.

If you are in California: we do not sell or share your personal information, as the CPRA defines those terms. We will not discriminate against you for using any right. You may use an authorised agent to make a request for you.

To make a request, email privacy@luriart.com. We reply within 30 days and may need to verify your identity first.

If you are a merchant using Luria: you are the data controller for your visitors. You can erase their data yourself at any time, and you do not have to ask us. Sending DELETE /api/sites/<your-site-id>/data from your account wipes out every record we hold for that site about its visitors. You can ask us to run it for you instead. That covers events, conversions, and the record of which page version each visitor saw. It covers sessions, visitor IDs, scans, and reports. It covers your brand-brain data, and it covers your integration records too. You cannot undo it. We keep your site rows and your test rows, so the history of what changed on your website stays auditable. Those rows hold no visitor personal data. We log that a deletion took place, and who asked for it. That way both sides can show that the request was met.

8. Automated decision-making

Luria runs on automated systems, and on AI. They suggest and make changes to a merchant's website. They also pick which page version each visitor sees. These choices affect page content only. They have no legal effect on anyone, and no effect of similar weight. We never set a price for a person based on their personal data.

9. Security

Your data is encrypted in transit (HTTPS/TLS). Our processors also encrypt it at rest. We limit access to each merchant's own data. The database locks that in for us, with row-level security. We encrypt third-party access tokens before we store them. If a breach hits your personal data, we will tell you and the right regulator, as the law requires.

10. Global Privacy Control

Our snippet honours the Global Privacy Control signal and DNT: 1. When we see either one, we set no visitor ID. We send no analytics events, and we load no session recording. The page still works as normal.

11. Changes

If we change this policy, we will update the date above. When a change is material, we tell customers directly.

12. Contact

Questions, requests, or complaints: privacy@luriart.com.


This page sets out what we actually do. It is not legal advice. Privacy counsel will review it before the paid tier launches. ← luriart.com · Terms of Service