Privacy Policy
At Lelu AI, security and data privacy are foundational to everything we build. This Privacy Policy details how we collect, safeguard, process, and handle information when you interact with our AI agent authorization engine, dashboard, APIs, and SDKs.
Zero Model Training
Your agent prompts, tool parameters, and payload data are strictly confidential and never used to train public or private LLM models.
Encrypted Audit Hashes
Every evaluation event produces cryptographically verifiable SHA-256 input/output hashes stored in encrypted audit logs.
Tenant Isolation
Data schemas and evaluation states are strictly isolated per workspace using AES-256-GCM encryption at rest.
Full Data Ownership
Export your complete audit history, security policies, and team activity logs at any time in machine-readable format.
1. Overview & Privacy Commitment
Lelu AI provides infrastructure that sits between autonomous AI agents and downstream execution APIs or enterprise tools. Because security and confidentiality are core to authorization, we adhere to strict data minimization principles. We collect only what is strictly necessary to evaluate agent policies, log verifiable execution audit trails, and operate our platform securely.
2. Information We Collect
We collect information in three main categories:
A. Account & Contact Information
Full name, business email address, password hash (via bcrypt/argon2), organization name, and billing details processed by our PCI-DSS compliant payment provider.
B. Agent Evaluation & Policy Telemetry
Agent identifiers, action names (e.g. database.write), policy evaluation status (allow/deny/review), confidence scores, evaluation latency, and SHA-256 payload hashes.
C. Technical & Diagnostic Information
IP address, user agent, API key ID, SDK version (TypeScript/Python), timestamp, HTTP response status, and diagnostic error tracebacks.
3. How We Process & Use Information
We process Customer data strictly for the following purposes:
- Evaluating real-time agent authorization requests against Customer's security policies.
- Routing low-confidence actions to human approval queues and sending webhook notifications.
- Constructing immutable, cryptographically verifiable audit logs for compliance and post-mortem analysis.
- Preventing malicious traffic, prompt injection attacks, API key abuse, and rate-limit violations.
- Sending essential transactional messages (email verification, security alerts, invoice receipts).
4. Agent Telemetry & Audit Trail Hashing
To reconcile strict auditability with privacy, Lelu employs Cryptographic Payload Hashing:
- Input parameters and output payloads can be hashed locally or on-the-fly into SHA-256 signatures before storage in our centralized audit engine.
- Customers retaining raw payload logging can configure payload encryption keys, ensuring raw tool arguments are accessible only to authorized team members within Customer's organization.
- Raw agent prompt text is never exposed to third parties or logged unencrypted.
6. Data Security & Encryption Standards
Lelu implements enterprise-grade technical and organizational safeguards:
- Encryption in Transit: All web traffic, API calls, and webhook communications enforce TLS 1.3 with strict HSTS policies.
- Encryption at Rest: All database storage, audit logs, and backups are encrypted using AES-256-GCM.
- Non-Human Identity (NHI) Protection: API keys and service tokens are salted and hashed; raw tokens are shown only once upon creation.
- Access Control: Strict Role-Based Access Control (RBAC) and least-privilege principles govern internal administrative access.
7. Data Retention & Account Deletion
Audit Log Retention: By default, evaluation audit records are retained for 90 days (or longer depending on Customer's subscription plan).
Account Termination: Upon account closure or written deletion request, Lelu permanently purges all Customer policies, API keys, and stored telemetry within 30 days, except where retention is required for legal or tax compliance.
8. Global Compliance (GDPR & CCPA/CPRA)
Lelu complies with applicable data privacy regulations, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
For European users, Lelu serves as a Data Processor for agent evaluation telemetry and a Data Controller for Customer account credentials. Standard Contractual Clauses (SCCs) and Data Processing Addendums (DPAs) are available for Enterprise customers upon request.
9. Your Rights & Data Portability
Depending on your jurisdiction, you possess the right to:
- Access a copy of your personal data and account records.
- Rectify inaccurate or incomplete account information.
- Export audit logs and custom policies in JSON / CSV format.
- Request the deletion ("Right to be Forgotten") of your account data.
- Object to or restrict certain data processing activities.
To exercise any of these rights, contact us at privacy@lelu-ai.com.
11. Children's Privacy
Our Service is designed for developers, security professionals, and enterprises. We do not knowingly solicit or collect personal information from individuals under the age of 18.
12. Policy Changes & Data Protection Officer
We may update this Privacy Policy from time to time to reflect technological changes, security enhancements, or legal requirements. Material updates will be communicated via email or dashboard notification prior to taking effect.