Last updated: 19 August 2026
Luria tests your website and makes it better, on its own. This policy covers luriart.com and the Luria service. It says what we collect, why we collect it, where we keep it, and how to get it deleted.
Which rules apply depends on whose data it is:
From merchants and prospects (we control):
luria_session) once you sign in. It is strictly necessary. It is
also HttpOnly, Secure, and SameSite=Lax. We do not use advertising or cross-site tracking cookies
on luriart.com.?ref=), we set a first-party cookie
(luria_ref) and a matching localStorage copy (luria-ref).
Both hold that partner's code. We keep it for 14 days from your last click. It has one use only:
to give the partner credit if you sign up in that time. It is strictly functional, and it expires
on its own. We record the partner code, never the cookie, on your account and on your Stripe
billing records. That is how the partner gets credit.From visitors to merchant sites (we process):
We do not knowingly collect data from children. We do not collect special-category data, so please do not send it to us. By that we mean data on your health or your biometrics. It also means political opinions, and the like.
Where the UK/EU GDPR applies, our lawful bases are: contract (running your account and the service), legitimate interests (to keep the service safe, to stop abuse, and to improve the product with aggregated data), and consent where consent is required for analytics on a merchant's site. You can withdraw consent at any time.
| Processor | What it holds | Where |
|---|---|---|
| Vercel | Site hosting, serverless functions, and server logs | United States |
| Supabase (Postgres + Storage) | Accounts, sites, events, scan results, screenshots | United States |
| Anthropic | Page content we send for analysis and new copy. They do not use it to train their models. | United States |
| Cloudflare | Turnstile bot check on public forms. R2 object storage for session recordings, page screenshots, and the ad creatives you upload. | Global |
| Shopify | Store data you authorise via OAuth | United States |
| Resend | Transactional email (sign-in links, reports) | United States |
| Hetzner | Scan workers that open your public pages during the onboarding scan | European Union |
We are based in the United States, so your data goes there and is kept there. For transfers out of the UK/EEA we rely on Standard Contractual Clauses with our processors. We keep this list current. We tell customers about material changes before they take effect.
Wherever you live, you may ask us to access, correct, delete, or export your personal information, and to object to or restrict how we use it. Under the UK/EU GDPR you may also complain. You can take it to your data protection authority. In the UK, that is the ICO.
If you are in California: we do not sell or share your personal information, as the CPRA defines those terms. We will not discriminate against you for using any right. You may use an authorised agent to make a request for you.
To make a request, email privacy@luriart.com. We reply within 30 days and may need to verify your identity first.
If you are a merchant using Luria: you are the data controller for your visitors.
You can erase their data yourself at any time, and you do not have to ask us. Sending
DELETE /api/sites/<your-site-id>/data from your account wipes out every record we
hold for that site about its visitors. You can ask us to run it for you instead. That covers events,
conversions, and the record of which page version each visitor saw. It covers sessions, visitor IDs,
scans, and reports. It covers your brand-brain data, and it covers your integration records too. You
cannot undo it. We keep your site rows and your test rows, so the history of what changed on your
website stays auditable. Those rows hold no visitor personal data. We log that a deletion took
place, and who asked for it. That way both sides can show that the request was met.
Luria runs on automated systems, and on AI. They suggest and make changes to a merchant's website. They also pick which page version each visitor sees. These choices affect page content only. They have no legal effect on anyone, and no effect of similar weight. We never set a price for a person based on their personal data.
Your data is encrypted in transit (HTTPS/TLS). Our processors also encrypt it at rest. We limit access to each merchant's own data. The database locks that in for us, with row-level security. We encrypt third-party access tokens before we store them. If a breach hits your personal data, we will tell you and the right regulator, as the law requires.
Our snippet honours the Global Privacy Control signal and DNT: 1. When
we see either one, we set no visitor ID. We send no analytics events, and we load no session
recording. The page still works as normal.
If we change this policy, we will update the date above. When a change is material, we tell customers directly.
Questions, requests, or complaints: privacy@luriart.com.
This page sets out what we actually do. It is not legal advice. Privacy counsel will review it before the paid tier launches. ← luriart.com · Terms of Service