Legal
Privacy Policy
Last updated 26 July 2026 · Version 1.1.0
This policy explains, in plain English, what personal data Luceria collects, why we collect it, who we share it with, how long we keep it, and the rights you have over your data. It is written so that a 16-year-old can understand it.
Luceria is an AI-powered career platform for anyone in the job market. We have tried to collect as little data as possible, to keep your data in the EU wherever we can, and to give you simple tools to export or delete it yourself.
If you only read one thing: we do not sell your personal data, we do not show you ads, we do not use cross-site trackers, and you can export or delete your account yourself from Settings at any time.
1. Who we are (data controller) and how to contact us
Luceria is the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we are legally responsible for it under UK and EU data-protection law.
Controller details
| Field | Detail |
|---|---|
| Trading name | Luceria |
| Legal entity name | LUCERIA LTD |
| Company number | 16900553 |
| Privacy contact email | [contact Luceria](/contact) |
| General support email | [contact Luceria](/contact) |
If anything in this policy is unclear, email [contact Luceria](/contact) and we will explain it.
2. Raising a data-protection complaint (your right to complain to us first)
Under the Data (Use and Access) Act 2025 (DUAA) — and reflecting the data-protection complaints duty that comes into force on 19 June 2026 — you have the right to complain directly to us about how we handle your personal data, and we have a duty to deal with that complaint properly.
This is a separate route from ordinary product support. Use it specifically for privacy and data-protection concerns (for example: you think we have your data wrong, kept it too long, shared it when we shouldn't have, or didn't honour one of your rights).
How to make a data-protection complaint
- By email: [contact Luceria](/contact) with the subject line "Data protection complaint".
What we promise
- We will acknowledge your complaint within 30 days of receiving it.
- We will give your complaint a reference so its status can be tracked.
- We will investigate and respond without undue delay, and tell you the outcome and what (if anything) we have done.
Complaining to us first does not remove your right to complain to the Information Commissioner's Office (ICO) or your local data-protection authority — see [Complaints to a regulator](#regulator-complaints).
3. What data we collect, why, our legal basis, and how long we keep it
Below is a full inventory of the data categories Luceria handles. For each one we set out the purpose, the UK GDPR Article 6 legal basis, and the retention period. Where the legal basis is legitimate interests, we have considered a balancing test to make sure our interests don't override your rights — see the note under the table.
| # | Data category | What it includes | Purpose | Art 6 legal basis | Retention |
|---|---|---|---|---|---|
| 1 | Account / identity | Email, full name, optional country, password hash (via Supabase Auth — we never see your plaintext password) | Create and secure your account; sign you in; send essential service messages | Contract (Art 6(1)(b)) | While your account is active; deleted on account deletion. |
| 2 | Onboarding profile | Stage, year level, field, goals, sector, blockers, situation, time commitment | Personalise the tone/level of AI help and tailor the product to you | Contract (Art 6(1)(b)) | While active; editable/clearable anytime; deleted on account deletion. |
| 3 | User content | resume documents, cover letters/artefacts, workflows + applications/tracker + tasks, Luceria Link posts/comments/reactions/bookmarks/profile, post-rejection reflections, AI Coach / chat history (chat is largely client-side with transient server processing) | Provide the core product features you ask for and store your work | Contract (Art 6(1)(b)) | While active; deleted on account deletion (Link posts/comments are hard-deleted). |
| 4 | Scam / risk-check inputs | Text you paste into the scam/risk checker (e.g. a recruiter message or job advert) — stored in the risk_checks table | Run the requested risk assessment and let you revisit past checks | Contract for signed-in checks (Art 6(1)(b)); legitimate interests for the public checker and abuse-prevention (Art 6(1)(f)) | |
| 5 | Fit / suitability-check inputs | The details you submit to the Fit/Risk (suitability) check | Produce the suitability assessment you requested | Contract (Art 6(1)(b)) | While active; deleted on account deletion. |
| 6 | Usage metering | usage_counters / user_usage — token counts and estimated cost only (no content) | Enforce fair-use and tier limits; bill accurately | Contract (Art 6(1)(b)); legal obligation for billing records (Art 6(1)(c)) | |
| 7 | Product events | events table — metadata only, flat primitives, no free text / no content | Operate, debug and improve the product; security and abuse detection | Legitimate interests (Art 6(1)(f)) | |
| 8 | Payment metadata (Stripe) | Subscription/transaction metadata via Stripe. Luceria never stores full card numbers. GBP only | Take payment, manage your subscription, prevent payment fraud | Contract (Art 6(1)(b)); legal obligation for tax/accounting (Art 6(1)(c)) | Invoice/tax records retained for the statutory accounting period ; see [Deletion vs retention](#deletion-retention) |
| 9 | Analytics and performance telemetry (Vercel Analytics and Speed Insights) | Privacy-conscious page/visit events, an allowlist of non-PII product events, and anonymous Core Web Vitals such as route, URL, browser, device, network, country and performance measurements — no resume text, names, emails, free text, or job descriptions | Understand aggregate usage and real-world page performance to improve the product | Legitimate interests (Art 6(1)(f)) | |
| 10 | Technical / IP (Upstash) | IP address / identifier (hashed) held transiently by Upstash Redis to rate-limit abuse (especially the public scam checker) | Protect the service from abuse and overload | Legitimate interests (Art 6(1)(f)) | Transient — each rate-limit counter expires with its window: between one minute and 24 hours depending on the limit. |
| 11 | Email delivery (Resend) | Email address + message metadata for transactional email (today: account and contact-service messages) | Send essential account emails | Contract (Art 6(1)(b)) | |
| 12 | Luceria Lens extension data | Your Luceria sign-in session and minimal local settings (Pro Plus extension); on-page job text is sent to Luceria's backend to generate suggestions but is not stored/logged | Provide on-page resume tailoring + scam-checked cover letters | Contract (Art 6(1)(b)) | Session/settings stored locally in your browser; job text not retained server-side. |
| 13 | Consent record | (migration 0017) accepted versions of terms/privacy/cookie/AUP, consent timestamp/IP/user-agent, marketing opt-in, age-16 confirmation, date of birth, country | Prove which terms you agreed to and when; honour age and marketing settings | Legal obligation / legitimate interests (Art 6(1)(c)/(f)) — keeping proof of consent | Kept as long as needed to evidence consent + a reasonable period after account closure. |
Note on legitimate interests. Where we rely on legitimate interests (rows 4, 7, 9, 10, 13), we have weighed our interest (running a safe, working, improvable service and preventing abuse) against your rights and freedoms, and we use the least intrusive data possible (for example, analytics carry no content and rate-limiting data is transient). You can object to legitimate-interests processing — see [Your rights](#your-rights).
4. Sensitive data (special-category and criminal-offence data)
Some of the things you can type or upload into Luceria are free text — for example a resume, a cover letter, a reflection, a Coach message, or text pasted into the scam checker. Free text can incidentally contain sensitive information.
Special-category data (UK/EU GDPR Article 9) includes data revealing your health, race or ethnicity, religion or beliefs, political opinions, trade-union membership, sex life or sexual orientation, and genetic/biometric data. Criminal-offence data (Article 10) includes information about offences, allegations, or related proceedings.
Luceria does not ask you for sensitive data and is not designed to collect it. To protect yourself:
- Please do not upload sensitive personal data you don't need to. A good resume or application rarely needs your health history, religion, political views, or details of any criminal record.
Where you voluntarily include such information, Luceria processes it only so far as necessary to provide the specific service you asked for (for example, generating help from the resume you chose to upload). We do not seek it out, profile you on it, or use it for any other purpose.
Nothing in this section gives Luceria a broad right to process sensitive data — it does not. If you would like sensitive content removed, contact [contact Luceria](/contact) or delete it yourself in the app.
5. How AI processing works
Several Luceria features use AI to help you (Resume Studio, AI Coach, Mock Interview, Interview Prep, the scam/risk checker, the Fit/suitability check, and Luceria Lens).
- Where the AI runs. When you use an AI feature, the relevant content is transmitted server-side only to an AI provider acting as our processor — it processes the data on our instructions to return a result, and it is never called from your browser. For most features that provider is Anthropic (Claude). One exception: free-tier workflow plan generation may be processed by OpenAI (GPT-4.1 nano) where that route is enabled; on the paid tiers, and whenever the OpenAI route is unavailable, it runs on Anthropic instead.
- Assistive only. Luceria's AI is assistive. It helps you draft, prepare, and assess — it does not make decisions about you. There is no solely-automated decision producing legal or similarly significant effects about you (UK GDPR Article 22). A human (you) stays in control of what you do with the output.
- Your judgement matters. AI can be wrong. Always review AI output before relying on it, and don't paste anything into Luceria you're not comfortable sending to a third-party AI provider under the terms above.
The transfers of data to Anthropic (US) and OpenAI (US) are covered in [International transfers](#international-transfers).
6. Who we share data with (sub-processors)
We use a small number of trusted service providers (sub-processors) to run Luceria. They process data on our behalf under contract, only for the purposes below. We do not sell your personal data and we do not share it for cross-context advertising.
| Sub-processor | Purpose | Data shared | Region | Transfer safeguard |
|---|---|---|---|---|
| Anthropic | AI inference (Claude) | The content you submit to an AI feature (e.g. Resume text, prompts, scam-check text) | United States | See [International transfers](#international-transfers) |
| OpenAI | AI inference (GPT-4.1 nano) for free-tier workflow plan generation, where enabled | The brief/context you submit for a free-tier workflow plan | United States | See [International transfers](#international-transfers) |
| Supabase | Database + authentication | Account, profile, content, risk checks, documents (object storage) | EU | Data hosted in EU (primary residency) |
| Stripe | Payments | Payment/subscription metadata (no full card numbers) | United States and global infrastructure | See [International transfers](#international-transfers) |
| Vercel | Hosting + Vercel Analytics and Speed Insights | Requests served; privacy-conscious non-PII analytics events and anonymous Core Web Vitals | UK (London) | Request handling in the UK (EU-adequate); personal data at rest stays in the EU with Supabase; |
| Upstash | Rate-limiting (Redis) | IP address / identifier, transiently | UK (AWS eu-west-2, London) | Processed in the UK; provider is US-established |
| Resend | Transactional email | Email address + message metadata |
We may also disclose data where we are legally required to (for example, a valid court order), or to protect the rights, safety, and security of our users and the service.
7. International transfers and data residency
Primary residency is the EU. Your core data (account, profile, content, risk checks, uploaded documents) is stored with Supabase (EU, Ireland) and served via Vercel (London, UK) — both within the UK/EU. Data at rest stays in the EU; request handling runs in the UK, which the EU recognises as providing an adequate level of protection (EU–UK adequacy).
Transfers outside the UK/EU. The main transfers are to Anthropic in the United States for AI inference and, for free-tier workflow plan generation where enabled, to OpenAI in the United States. Where we transfer personal data outside the UK or EEA, we rely on an appropriate safeguard so your data keeps an equivalent level of protection.
- Anthropic (US):
- OpenAI (US):
- Other providers processing outside the UK/EEA: covered by the safeguards listed in the [sub-processor table](#sub-processors).
You can ask us for more detail about the safeguards in place by emailing [contact Luceria](/contact).
8. Your rights and how to use them
Under UK GDPR (and EU GDPR where it applies to you), you have the following rights over your personal data. We will respond to a valid request within one month (extendable by up to two further months for complex requests — we'll tell you if so).
| Right | What it means | How to use it |
|---|---|---|
| Access | Get a copy of your data | Export a JSON copy yourself: Settings → Export (GET /api/account/export). See the export note below. |
| Rectification | Correct data that's wrong | Edit your profile, workflows, documents, and Link content directly in the app; or email [contact Luceria](/contact) |
| Erasure | Delete your data ("right to be forgotten") | Delete your account yourself: Settings → Delete account (POST /api/account/delete, typed "DELETE" confirmation). See [Deletion vs retention](#deletion-retention) |
| Restriction | Pause our use of your data in certain cases | Email [contact Luceria](/contact) |
| Portability | Get your data in a portable, machine-readable format | Use the JSON export above |
| Objection | Object to processing based on legitimate interests | Email [contact Luceria](/contact) — we'll stop unless we have compelling legitimate grounds |
| Withdraw consent | Withdraw consent you gave (e.g. marketing, cookies) | Change settings in-app (e.g. marketing opt-in) or email us; withdrawing doesn't affect processing before withdrawal |
| Rights re automated processing | Not be subject to solely-automated significant decisions | We don't make such decisions (see [AI processing](#ai-processing)); contact us with any concern |
Export note. The in-app JSON export includes your profile and onboarding entries, workflows and step state, tracker/application data, tasks, artefacts, documents, risk checks, reflections, assistant actions, email imports, search preferences, usage/metering records, consent history, product events, and the Luceria Link content and interactions you created. Private document files are supplied through signed download links that expire after 10 minutes, so download those files promptly for a permanent copy. Certain security, fraud, billing, and moderation records may require a verified access request and individual review because they can be subject to legal retention duties or contain another person's data; email [contact Luceria](/contact) for those records.
Using your rights is free in most cases, and we won't penalise you for it.
9. Account deletion vs. data retention
You can delete your account at any time from Settings → Delete account (you type "DELETE" to confirm). This triggers an immediate cascade that removes your data across roughly 19 tables.
Deleted immediately on account deletion:
- Your authentication record, profile, and onboarding data.
- Your content: workflows, applications/tracker, tasks, artefacts, resume documents, cover letters, risk checks, fit checks, reflections, and Coach/chat history.
- Luceria Link posts and comments — hard-deleted (not just hidden).
- Usage counters tied to your account.
Retained for a limited time or for legal reasons:
- Backups: copies of data may persist temporarily in encrypted backups until those backups rotate out on their normal cycle.
- Payment, invoice, and tax records: retained for the statutory accounting period we are legally required to keep them.
- Legal / security / fraud-prevention records: a minimal set of records may be retained where needed to comply with the law, resolve disputes, or prevent abuse/fraud.
- Consent record: kept as needed to evidence the terms you agreed to.
For users under 18. If you are under 18 and want your public Luceria Link posts or profile removed quickly, you don't have to delete your whole account — email [contact Luceria](/contact) (subject "Under-18 removal") or use the in-app delete/report tools, and we will prioritise the request and remove the public content promptly.
10. Staff and admin access to your data
Access to your data by Luceria staff is limited to what is necessary and controlled.
- Staff may access account or content data only where genuinely needed — for example to provide support you asked for, investigate a safety report, debug a fault, or meet a legal obligation.
- Access is role-based and restricted; not everyone can see everything.
- Database access uses Postgres Row-Level Security, and administrative access is limited.
We do not read your private workflows, documents, or messages for product development without a lawful basis and, where required, your consent.
11. Children and younger users (16+)
In short, for younger users: Luceria is for ages 16 and over. We try to collect as little about you as possible, we keep your privacy settings switched to high by default, we do not profile you or send you targeted marketing, and we ask you not to upload sensitive information you don't need to. You can export or delete your data yourself in Settings, and if you're under 18 we'll remove public posts especially quickly.
Because many of our users are 16–18 school-leavers, we treat children's-data obligations (including the ICO Children's Code / Age Appropriate Design Code) as applying throughout the product:
- High-privacy defaults for under-18s.
- No profiling and no targeted marketing to minors without a documented assessment showing it's in their interests.
- Proportionate age assurance — we ask you to confirm you are 16+ and record your date of birth as part of consent (migration 0017).
- A clear warning not to upload sensitive data (see [Sensitive data](#special-category-data)).
- Data minimisation — we only collect what the feature needs.
EU users. The minimum digital-consent age varies by EU country (13–16). Before any active EU marketing or EU-targeted processing that relies on a child's consent, the relevant per-country age must be checked.
12. Voluntary California / US privacy disclosure
We provide the following voluntarily in a California-style format for transparency. This does not mean we are admitting we are covered by, or subject to, the CCPA/CPRA or any other US state privacy law.
- Categories we collect: identifiers (email, name); account/profile information; user content you create; commercial information (subscription/payment metadata via Stripe); internet/network activity (privacy-conscious analytics, transient IP for rate-limiting); and inferences only insofar as needed to tailor help. See [What data we collect](#data-we-collect) for detail.
- Categories we "disclose": we share data with the service providers listed in the [sub-processor table](#sub-processors), strictly to run the service.
- Sale / sharing: we do not sell your personal information, and we do not "share" it for cross-context behavioural advertising (as those terms are used under California law).
- Sensitive personal information: we do not seek it; see [Sensitive data](#special-category-data).
- Your choices: Californians (and other users) can access, delete, and correct their data using the in-app Settings tools or by emailing [contact Luceria](/contact), and we will not discriminate against you for exercising these choices.
13. Cookies and similar technologies
We use only a small set of cookies and similar technologies — mainly strictly-necessary ones for signing in and security, plus privacy-conscious analytics. We do not use Google Analytics, advertising cookies, cross-site trackers, fingerprinting, tracking pixels, link decoration, or tag managers.
For the full list (including sb-* auth/session cookies, the luc_prc scam-check quota cookie, functional luceria:* device-local storage, Vercel Analytics, Vercel Speed Insights, and Stripe-set cookies on checkout pages), please see our separate [Cookie Policy](/cookies), which also covers how PECR (the UK cookie rules) applies and how you can manage your choices.
14. How we protect your data
We take proportionate steps to keep your data secure, including:
- Encryption in transit (TLS) between you, Luceria, and our providers.
- Postgres Row-Level Security on user tables, so data rows are scoped to your user ID.
- Role-based, limited administrative access.
- EU hosting for primary data.
- No storage of full card numbers (payments handled by Stripe).
- Rate-limiting (Upstash) to protect against abuse, especially the public scam checker.
No system can be guaranteed 100% secure, but we work to protect your data and to keep these measures under review.
15. Data breaches
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, where we are required to do so.
If the breach is likely to result in a high risk to you, we will also notify you without undue delay and tell you what happened, what we're doing about it, and what you can do to protect yourself.
16. Complaints to a regulator
We'd like the chance to put things right, so please [complain to us first](#complaints-route). But you always have the right to complain to a data-protection regulator.
In the UK — the Information Commissioner's Office (ICO):
- Website: ico.org.uk
In the EU/EEA: you may complain to your local data-protection authority (DPA).
17. Contact enquiries
When you use the [Luceria contact form](/contact), we process the contact details you provide, your chosen topic, subject and message so we can route and respond to your enquiry. Please do not include passwords, full payment-card numbers, resumes or unnecessary sensitive information.
Our legal basis is contract where the enquiry concerns a service or account you use, steps at your request before a contract for a sales or pilot enquiry, and legitimate interests for feedback, service administration, abuse prevention and security reports. Technical identifiers used for rate-limiting are kept only for the short anti-abuse window. Enquiry records are kept only for as long as reasonably needed to respond, manage any follow-up and meet applicable legal, security or accounting obligations.
The form is delivered through Luceria and the message is forwarded through our transactional email provider, Resend, to the monitored support workflow. We do not publish the receiving mailbox as a separate public identity. Your rights in [Your rights](#your-rights) apply to this information.
18. Changes to this policy, version, and last updated
We'll update this policy when something material changes. The current version and last-updated date are shown at the top of this page and are recorded with account consent where required.
If a change meaningfully affects how we handle your data, we'll tell you — for example by email or an in-app notice — and, where appropriate, ask you to re-accept the updated terms.