Privacy Policy
Last Updated: January 26, 2026
1. Introduction
Welcome to LUPA ("we," "our," or "us"), provided by LUPA Labs Inc. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it.
This policy applies to all information collected through our website (https://lupalabs.ai), our application (the "Platform"), and any related services (collectively, the "Services").
We value plain language. Our goal is to be transparent about how we handle your data, especially your scientific research.
2. Data Controller
For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, the Data Controller is:
LUPA Labs Inc.
- 1111B S Governors Ave # 40123 Dover, DE 19904
- Email: info@lupalabs.ai
3. Information We Collect
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
A. Personal Information You Provide
- Account Data: We collect your First Name, Last Name, and Email Address to create your account and verify your identity.
- User Content: We store the research data you upload or generate, including manuscripts, notes, PDF files, and citations ("User Content"). Your User Content is private to you. We do not access your User Content unless required for technical support (with your permission) or legal compliance.
- Payment Data: If you upgrade to a paid plan (Pro or Enterprise), our payment processor (Stripe) collects your payment method details. We do not store your full credit card number.
B. Information Automatically Collected
- Usage Data: We collect information about how you interact with our Services, such as the pages you visit, the features you use, and the time spent on the platform.
- Device Data: We collect device information such as your IP address, browser type, operating system, and device identifiers.
- Telemetry & Errors: We collect technical data to identify system crashes and performance issues.
4. How We Use Your Information
We process your information for purposes based on legitimate business interests, the fulfillment of our contract with you, compliance with our legal obligations, and/or your consent.
- To Provide the Service: To allow you to create an account, log in, and use the workspace features.
- To Facilitate Payments: To process your subscription via Stripe.
- To Improve Our Product: To understand which features are most valuable and to fix bugs.
- To Communicate with You: To send you administrative information (e.g., password resets, ToS updates) and, with your consent, product updates.
5. Artificial Intelligence & Your Data
We know that data privacy is critical for scientific research. We have strict policies regarding Artificial Intelligence (AI).
No Training on User Content
LUPA Labs Inc. does NOT use your User Content (manuscripts, notes, uploaded papers) to train, fine-tune, or improve our proprietary artificial intelligence models.
Third-Party AI Providers
We utilize third-party AI providers to generate responses to your queries. We access these models via their APIs:
- OpenAI: We have opted out of data training. Your data is not used to train their models.
- Anthropic: We have opted out of data training. Your data is not used to train their models.
- Google: Your data is not used to train their models.
6. Third-Party Service Providers (Sub-Processors)
We share your data with selected third-party vendors who perform services for us. We have contracts with these vendors to ensure they safeguard your data.
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & Authentication | User Content, Account Data |
| Stripe | Payment Processing | Billing Info, Email |
| Vercel | Hosting & Infrastructure | IP Address, Request Logs |
| Sentry | Error Tracking | Stack Traces, Device Info |
| PostHog | Product Analytics | Usage patterns, Feature clicks |
| Google Analytics | Website Traffic Analysis | Aggregated traffic data |
| Hotjar / Usetiful | UX Improvements & Onboarding | Session heatmaps (anonymized) |
| Consent Studio | Cookie Consent Management | Consent preferences |
7. Cookie Policy
We use cookies to access or store information.
- Necessary Cookies: Required for the app to function (e.g., keeping you logged in via Supabase, security checks via Stripe).
- Analytics Cookies: Used to understand how you use the site (Google Analytics, PostHog, Hotjar).
We use Consent Studio to manage your cookie preferences. By default, non-essential cookies (Analytics) are blocked until you give your explicit consent via our cookie banner. You can change your preferences at any time via the "Cookie Settings" link on our website.
8. Data Retention
- Active Accounts: We retain your personal information and User Content for as long as your account is active.
- Deleted Accounts: If you request to delete your account, your User Content and personal data are permanently removed from our active databases within 30 days. We may retain billing records for up to 7 years to comply with tax obligations.
9. Your Privacy Rights (GDPR & CCPA)
Depending on your location, you have certain rights regarding your personal information:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): You can ask us to delete your personal data.
- Right to Restrict Processing: You can ask us to limit how we use your data.
- Right to Data Portability: You can request your data in a structured, commonly used format.
- Right to Opt-Out: You can opt-out of marketing communications at any time.
To exercise these rights, please contact us at info@lupalabs.ai.
10. Security
We have implemented appropriate technical and organizational security measures to protect your personal information.
- Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest (in our database).
- Access Control: Access to production data is restricted to authorized personnel with a business need.
11. International Data Transfers
Our servers are located in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities and by those third parties with whom we may share your personal information.
We rely on the Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs) to ensure your data is protected when transferred internationally.
12. Updates to this Policy
We may update this privacy policy from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. We encourage you to review this privacy policy frequently to be informed of how we are protecting your information.
13. Contact Us
If you have questions or comments about this policy, you may email us at info@lupalabs.ai or by post to:
LUPA Labs Inc. 1111B S Governors Ave # 40123 Dover, DE 19904