# Data processing & GDPR

How Luuphub handles the personal data your customers submit through the feedback
widget and portal.

## Who processes it

Every sub-processor and what it does is listed in [the privacy policy](https://luuphub.com/privacy).
Our error tracking and product analytics projects are listed in our data-processing record.

## Never trained on your data

Luuphub uses AI to transcribe recordings and to triage, deduplicate, and summarize
feedback. Your feedback is never used to train third-party AI models. OpenAI does not keep the recordings it
transcribes; xAI, which transcribes recordings on the Free plan, keeps requests for up to 30 days for abuse review.

## Consent

The widget shows a consent line before storing a visitor token. A visitor who declines can
still read and submit — each submission simply requires an email, and no persistent token
is written.

## Export

Account owners can export a full JSON archive of every site’s data, including recording
transcripts, at any time from **Settings → Privacy & data**. The download is login-gated and single-use — it is never a
public link.

## Erasure

On an erasure request, a visitor’s identity is fully anonymized: their email, name, and
tokens are removed from every list (including suppression), their comments are
re-attributed to “Deleted user”, their votes are anonymized while public counts stay
accurate, and any AI-derived text and captured screenshots are purged or redacted. Their
voice notes, videos and their transcripts are deleted. Their submitted text is removed even
from soft-deleted and merged records.

A visitor can edit or delete their own recent post or comment, and request erasure of their
own identity, from the portal footer.

## Account deletion

Deleting an account produces a final export first, cancels any queued emails, takes public
pages offline immediately, and permanently erases all data after a 30-day grace window
during which the deletion can be cancelled.
