lelu
Privacy & Data ProtectionEffective: August 4, 2026

Privacy Policy

At Lelu AI, security and data privacy are foundational to everything we build. This Privacy Policy details how we collect, safeguard, process, and handle information when you interact with our AI agent authorization engine, dashboard, APIs, and SDKs.

Zero Model Training

Your agent prompts, tool parameters, and payload data are strictly confidential and never used to train public or private LLM models.

Encrypted Audit Hashes

Every evaluation event produces cryptographically verifiable SHA-256 input/output hashes stored in encrypted audit logs.

Tenant Isolation

Data schemas and evaluation states are strictly isolated per workspace using AES-256-GCM encryption at rest.

Full Data Ownership

Export your complete audit history, security policies, and team activity logs at any time in machine-readable format.

1. Overview & Privacy Commitment

Lelu AI provides infrastructure that sits between autonomous AI agents and downstream execution APIs or enterprise tools. Because security and confidentiality are core to authorization, we adhere to strict data minimization principles. We collect only what is strictly necessary to evaluate agent policies, log verifiable execution audit trails, and operate our platform securely.

2. Information We Collect

We collect information in three main categories:

A. Account & Contact Information

Full name, business email address, password hash (via bcrypt/argon2), organization name, and billing details processed by our PCI-DSS compliant payment provider.

B. Agent Evaluation & Policy Telemetry

Agent identifiers, action names (e.g. database.write), policy evaluation status (allow/deny/review), confidence scores, evaluation latency, and SHA-256 payload hashes.

C. Technical & Diagnostic Information

IP address, user agent, API key ID, SDK version (TypeScript/Python), timestamp, HTTP response status, and diagnostic error tracebacks.

3. How We Process & Use Information

We process Customer data strictly for the following purposes:

  • Evaluating real-time agent authorization requests against Customer's security policies.
  • Routing low-confidence actions to human approval queues and sending webhook notifications.
  • Constructing immutable, cryptographically verifiable audit logs for compliance and post-mortem analysis.
  • Preventing malicious traffic, prompt injection attacks, API key abuse, and rate-limit violations.
  • Sending essential transactional messages (email verification, security alerts, invoice receipts).

4. Agent Telemetry & Audit Trail Hashing

To reconcile strict auditability with privacy, Lelu employs Cryptographic Payload Hashing:

  • Input parameters and output payloads can be hashed locally or on-the-fly into SHA-256 signatures before storage in our centralized audit engine.
  • Customers retaining raw payload logging can configure payload encryption keys, ensuring raw tool arguments are accessible only to authorized team members within Customer's organization.
  • Raw agent prompt text is never exposed to third parties or logged unencrypted.

5. Data Sharing & Subprocessors

We do not sell, rent, or trade personal data or customer agent telemetry to advertisers or data brokers. Data is shared only with trusted subprocessors strictly necessary to operate our infrastructure:

  • Cloud Hosting & Infrastructure: AWS / Vercel (Encrypted data centers).
  • Database & Search Engine: Managed PostgreSQL and Redis clusters with TLS 1.3 encryption.
  • Transactional Email: Amazon SES / Postmark for security alerts and verification links.
  • OAuth Providers: GitHub / Google (if Customer selects social sign-in).

6. Data Security & Encryption Standards

Lelu implements enterprise-grade technical and organizational safeguards:

  • Encryption in Transit: All web traffic, API calls, and webhook communications enforce TLS 1.3 with strict HSTS policies.
  • Encryption at Rest: All database storage, audit logs, and backups are encrypted using AES-256-GCM.
  • Non-Human Identity (NHI) Protection: API keys and service tokens are salted and hashed; raw tokens are shown only once upon creation.
  • Access Control: Strict Role-Based Access Control (RBAC) and least-privilege principles govern internal administrative access.

7. Data Retention & Account Deletion

Audit Log Retention: By default, evaluation audit records are retained for 90 days (or longer depending on Customer's subscription plan).

Account Termination: Upon account closure or written deletion request, Lelu permanently purges all Customer policies, API keys, and stored telemetry within 30 days, except where retention is required for legal or tax compliance.

8. Global Compliance (GDPR & CCPA/CPRA)

Lelu complies with applicable data privacy regulations, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

For European users, Lelu serves as a Data Processor for agent evaluation telemetry and a Data Controller for Customer account credentials. Standard Contractual Clauses (SCCs) and Data Processing Addendums (DPAs) are available for Enterprise customers upon request.

9. Your Rights & Data Portability

Depending on your jurisdiction, you possess the right to:

  • Access a copy of your personal data and account records.
  • Rectify inaccurate or incomplete account information.
  • Export audit logs and custom policies in JSON / CSV format.
  • Request the deletion ("Right to be Forgotten") of your account data.
  • Object to or restrict certain data processing activities.

To exercise any of these rights, contact us at privacy@lelu-ai.com.

10. Cookies, Sessions & Local Storage

We use essential session cookies and local storage tokens strictly for user authentication, security validation (CSRF protection), and maintaining user theme preferences (dark/light mode). We do not use intrusive third-party tracking cookies or advertising pixels.

11. Children's Privacy

Our Service is designed for developers, security professionals, and enterprises. We do not knowingly solicit or collect personal information from individuals under the age of 18.

12. Policy Changes & Data Protection Officer

We may update this Privacy Policy from time to time to reflect technological changes, security enhancements, or legal requirements. Material updates will be communicated via email or dashboard notification prior to taking effect.