Privacy Policy
Last updated July 11, 2026
This policy explains what personal data Lucenta collects when you use the website, the dashboard, or the API, and why. It doesn't cover the content of text you submit to the moderation or redaction API — that's addressed specifically below, because it's the thing most worth being precise about. Lucenta is operated from the United Arab Emirates, and this policy is written with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL) in mind, alongside the general principles of GDPR and CCPA referenced elsewhere on this site for visitors those laws apply to.
Text you submit for checking or redaction
Text sent to /v1/check or /v1/redact is processed in memory for the duration of that single request only. It is never written to a database, never logged in full, and never used to train or fine-tune any model. What is recorded is a request counter — whether the result was flagged/had entities, and how long the request took — used to power the site's live stats and for basic rate-limiting and abuse detection, not the text itself.
Account information
There's no password to create or store — signing in works by emailing you a one-time link, and clicking it is treated as proof you control that inbox. I store your email address, the optional description of what you're building (if you provide one), and the labels and hashes of your API keys — never the keys themselves in plain text. A signed-in session is a short-lived cookie in your browser, not a record kept on a server; it simply expires after an hour.
Cookies
Lucenta uses a small number of strictly necessary cookies (authentication and your cookie-consent preference) and, only if you accept them, advertising cookies set by Google AdSense and analytics cookies set by Google Analytics. Full detail, including how to change your preference at any time, is on the Cookie Policy page.
How information is used
Account and API key data is used to authenticate requests, enforce rate limits, and let you manage your own keys. Aggregate, non-identifying request statistics (like total requests processed today) power the public stats shown on the site. If you email me, I use your email address only to reply to you.
Third-party processors
Cloudflare (Workers, Workers AI, Vectorize, D1, and KV) hosts the API and processes requests as they happen, including the short-lived sign-in tokens used by the magic-link flow. Resend delivers the sign-in emails themselves — it receives your email address for that single purpose. Google AdSense may serve ads and Google Analytics may measure site traffic, both setting cookies, once you've consented. None of these providers receive the raw text you submit for checking or redaction beyond what's needed to process that single request.
Data retention
Aggregate request statistics are retained to power historical stats on the site. API key metadata is retained until you or I revoke the key. Account data is retained until the account is deleted. Submitted text itself is never retained in the first place — there's nothing to delete.
Your rights
You can request a copy of the account data I hold about you, ask me to correct it, or ask me to delete your account and associated API keys, by emailing support@lucenta.dev. I'll respond within a reasonable time, typically a few business days.
Children's privacy
Lucenta isn't directed at children, and I don't knowingly collect personal data from anyone under 13. If you believe a child has provided personal data to Lucenta, email support@lucenta.dev and I'll remove it.
Changes to this policy
I may update this policy as the service changes. Material changes will update the "last updated" date at the top of this page.
Contact
Questions about this policy, or a privacy request? Email support@lucenta.dev.