Data processing & GDPR
How Luuphub handles the personal data your customers submit through the feedback widget and portal.
EU hosting
Application data and derived analytics are hosted in the EU. Our error tracking and product analytics projects are pinned to EU regions and are listed in our data-processing record; personal data never leaves the EU as part of normal operation.
Never trained on your data
Luuphub uses AI to triage, deduplicate, and summarize feedback. Your feedback is never used to train third-party AI models — providers process it transiently to return a result and do not retain it for training.
Consent
The widget shows a consent line before storing a visitor token. A visitor who declines can still read and submit — each submission simply requires an email, and no persistent token is written.
Export
Account owners can export a full JSON archive of every site’s data at any time from Settings → Privacy & data. The download is login-gated and single-use — it is never a public link.
Erasure
On an erasure request, a visitor’s identity is fully anonymized: their email, name, and tokens are removed from every list (including suppression), their comments are re-attributed to “Deleted user”, their votes are anonymized while public counts stay accurate, and any AI-derived text and captured screenshots/console logs are purged or redacted. Their submitted text is removed even from soft-deleted and merged records.
A visitor can edit or delete their own recent post or comment, and request erasure of their own identity, from the portal footer.
Account deletion
Deleting an account produces a final export first, cancels any queued emails, takes public pages offline immediately, and permanently erases all data after a 30-day grace window during which the deletion can be cancelled.