Privacy Policy
Version 1.0 · Effective 20 August 2026
This Privacy Policy for luqas.ai ("Luqas," "we," "us," or "our") describes how and why we collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you visit our website at luqas.ai or any website of ours that links to this Privacy Policy, download and use our mobile application (Luqas), or engage with us in other related ways, including marketing or events.
Questions or concerns? Reading this Privacy Policy will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have questions or concerns, contact us at privacy@luqas.ai.
Summary of key points
- What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with Luqas and the Services — including account and voice-model information, and the choices you make. See "What information do we collect?"
- Do we process any sensitive personal information? Yes. We treat voice recordings and voiceprints as biometric identifiers, and bereavement-related conversation content may reveal health-adjacent information. We only process this with your explicit, granular consent and additional safeguards. See "Voice and biometric data — special protections."
- Do we collect any information from third parties? We do not purchase or license personal information from data brokers or marketing lists. Source Material you upload will often contain other identifiable people (e.g., a voicemail with two speakers); see "Personal data of third parties in Source Material."
- How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, to comply with law, and — with respect to our own products only — for personalised marketing.
- In what situations and with which parties do we share personal information? We may share information with the specific service providers named in Section 4, and, if we are ever acquired or sell the business, with the acquiring party as part of that transaction. We do not sell or share personal information with third-party advertisers or data brokers.
- Do we use cookies or other tracking technologies? We currently use only strictly necessary cookies. We do not presently run Google Analytics or similar tools, but may add privacy-conscious analytics in the future — this Policy will be updated first.
- Is my data transferred internationally? No. We keep EEA/UK user data inside the EEA/UK, and US user data inside the US.
- How do we keep your information safe? We have technical and organisational measures in place, but no method of transmission or storage is 100% secure.
- Do we collect information from minors? No. Luqas is strictly for adults, and we will not knowingly create a Voice Model of anyone who was under 18, living or deceased.
- What are your privacy rights? Depending on where you are located, you may have rights that allow you greater access to and control over your personal information. See Sections 17, 18, and 19.
- How do you exercise your rights? The easiest way is by contacting us at privacy@luqas.ai. We will consider and act upon any request in accordance with applicable data protection law.
1. What information do we collect?
We collect personal information you provide to us, including account details and — central to our Services — voice recordings and biographical material about a person you want to preserve.
Personal information you disclose to us
We collect personal information that you voluntarily provide when you register for the Services, express interest in Luqas, or otherwise communicate with us. The personal information we collect depends on the context of your interactions with us and the choices you make, and may include:
- Account information: name, email address, password (hashed), account settings
- Voice and biometric information: recordings you upload, derived voiceprints and embeddings, trained Voice Models, and your own microphone audio during a live session (see Section 10)
- Subject profile information: biographical facts, relationships, stories, photographs, and speech characteristics about the person the AI Companion reflects
- Authorisation records: your self-attestation, made through the in-app Voice Consent screen described in our Terms of Service, that you consent to creation of the Voice Model, that you own the voice or have the necessary permission or authority, and that the voice is not a minor's. We do not, before a Voice Model is trained, collect or require supporting documentation such as a death certificate or letters testamentary — see Terms of Service section 7.4.
- Payment information: billing metadata and a subscription status token from our payment processor(s). We never receive or store full card numbers ourselves.
- Social login information: if you register using Google or Apple, we receive certain profile information from that provider — see Section 7
Sensitive information
When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information: biometric data (voiceprints and embeddings) and, where your conversations touch on grief or personal distress, health-adjacent data. See Section 10 and Section 13.
Information automatically collected
We automatically collect certain limited information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information, such as your device identifier, operating system, app version, timestamps, and coarse regional location used solely to route you to the correct regional infrastructure described in Section 8. We do not collect precise GPS location. Crash and error logging is not currently active.
2. How do we process your information?
We process your information to provide, improve, and administer our Services, to communicate with you, for security and fraud prevention, and to comply with law. With your consent, we also use your information to personalise marketing of our own products.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including to:
- facilitate account creation, authentication, and account management;
- create and operate your AI Companion and Voice Model, as authorised under our Terms of Service;
- detect and respond to expressions of crisis, self-harm, or suicidal ideation during a conversation;
- respond to your enquiries and support requests;
- send administrative information, such as changes to our terms or policies;
- send you marketing communications about our own products and features, where you have not opted out — see Section 9. We do not run marketing on behalf of third parties, and we do not sell your data for anyone else's marketing;
- protect our Services, including fraud monitoring and prevention;
- identify usage trends for safety and product-quality purposes only, never to maximise engagement — see Terms of Service section 4.5; and
- comply with our legal obligations.
3. What legal bases do we rely on to process your personal information?
We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law.
If you are located in the EU, UK, or Switzerland, this section applies to you. The GDPR and UK GDPR require us to explain the valid legal bases on which we rely to process your personal information.
If you are located in Canada, we may process your information if you have given express or implied consent, or where permitted by law (e.g., fraud detection, an emergency threatening life/health/security, or an investigation).
6. Do we offer artificial-intelligence-based products?
We provide features, products, and services powered by artificial intelligence, machine learning, or similar technologies, through the specific providers below.
- Google Gemini for conversational text generation, with OpenAI and Groq configured as backup providers we may switch to without a code change (see Section 4);
- Qwen open-weight voice models, hosted by us on RunPod infrastructure, for voice cloning, text-to-speech, and speech-to-text;
- Cohere for text embeddings used in memory retrieval.
We do not use your Source Material, Voice Models, conversations, transcripts, or Output to train, fine-tune, or evaluate any AI model — ours or a third party's.
8. Is your information transferred internationally?
No. We keep your data within your own region — EEA/UK data stays in the EEA/UK, and US data stays in the US.
Where our limited administrative or support access to EEA/UK data could constitute a transfer outside that area, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) as our transfer mechanism, supported by appropriate technical measures.
We do not route voice, biometric, or conversation data of US or EEA/UK residents to any provider located in, or subject to the jurisdiction of, a country designated as a country of concern under US Executive Order 14117 and 28 C.F.R. Part 202.
If two jurisdictions' rules genuinely conflict — for example, one requiring your data to stay within its borders and another requiring it to be transferable elsewhere — we do not silently comply with one at the expense of the other. Your account continues to be served from its current region while we review the conflict, we do not delete your data, and we provide a full export at no charge for as long as the review continues. See Terms of Service section 19.3 for the complete process.
9. How do we handle personalised marketing?
We may personalise marketing for our own products using your data; we never share your data for anyone else's marketing.
Where permitted, we may use information about your account and usage to personalise marketing communications about Luqas's own products and features. You can opt out of marketing messages at any time using the unsubscribe link in any marketing email, or through your account settings; opting out does not affect service or transactional communications. We do not share your personal information with any third party for that third party's own marketing or advertising purposes, and we do not sell your personal information.
10. Voice and biometric data — special protections
We treat voice recordings, voiceprints, and Voice Models as biometric identifiers and apply the highest tier of protection we offer to them.
We treat voice recordings, voiceprints, embeddings, and Voice Models as biometric identifiers and sensitive personal information under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the CCPA/CPRA, and Article 9 of the GDPR.
- Written release before capture. We obtain a written release before extracting any voiceprint or biometric feature, consistent with BIPA section 15(b).
- Published retention and destruction schedule. Our schedule, required by BIPA section 15(a), is published separately as our Biometric Data Retention and Destruction Schedule.
- We do not sell, lease, trade, or otherwise profit from your biometric identifiers within the meaning of BIPA section 15(c).
A Voice Model may be created by any user who completes the in-app Voice Consent screen described in Terms of Service section 7.2, confirming they own the voice or have the Subject's permission to use it, and that the Subject is not a public figure or someone who has not consented. See Terms of Service section 7.
Storage. Voice audio is encrypted in transit (TLS) and stored in the same bucket and under the same access credentials as other application media, distinguished by file path rather than a separate encryption key. Unlike other stored media, voice recordings have no public web address and can only be accessed through internal, authenticated processes (upload, deletion, and the account data-export flow).
Withdrawal is destruction, not a status flag. Withdrawing consent to voice enrolment or Voice Model creation triggers destruction of the associated biometric artefacts, whether or not you keep your account.
11. Personal data of deceased individuals
The law on a deceased person's data varies significantly by country, and several countries give a non-user relative enforceable rights.
The GDPR does not itself apply to a deceased person's data (Recital 27), and most US privacy statutes define a "consumer" as a living individual — but Recital 27 expressly permits EU member states to legislate, and several have (Italy, Spain, France, Denmark, and others), giving a relative other than our account holder the ability to exercise rights, including erasure, over a deceased person's data. Independently, a deceased person's voice and likeness may be protected by post-mortem publicity rights (e.g., California, New York, Tennessee, Indiana, Germany, Spain).
Multiple family members. We do not share, link, or pool data between accounts. Where more than one person independently creates an AI Companion of the same deceased Subject, each person's account, authorisation records, Voice Model, and AI Companion are entirely separate — a strict one-to-one relationship between an account and its own data. Deleting your own account or AI Companion deletes only your own data.
12. Personal data of third parties in Source Material
Recordings often contain other identifiable people who never contacted us directly.
A voicemail has two people on it; a family video has a room full. Where technically feasible, we isolate the Subject's speech and avoid processing other speakers' audio for voice modelling. We rely on our and your legitimate interest in preserving family memory (Art. 6(1)(f)) for this limited, private processing, and any identifiable living person appearing in Source Material may object at likeness@luqas.ai.
13. Consumer health data
Conversations about bereavement can reveal health-adjacent information, which we treat with the same protection as biometric data.
Conversations about bereavement may reveal information about your mental health, which may constitute "consumer health data" under the Washington My Health My Data Act, the Nevada consumer health data law, and comparable statutes. We currently handle this under the same consent and protections as other biometric/conversation data, described in this Policy and our Terms of Service.
14. How long do we keep your data?
We keep your data for as long as your account is open and delete it when you ask; voice data is tied to actual use of a companion; and a small set of records we're legally required to keep survive account deletion for the period the law requires.
Retention. We keep your account, companions, conversations and memories for as long as your account is open. You can delete any of them at any time from the app, and deleting your account removes all of it.
Voice data is treated separately because it is biometric information. A voiceprint is kept only while it is in use by a companion, and is destroyed when you delete that companion, withdraw your consent, or delete your account. In addition, if a Voice Model has gone unused for 18 consecutive months, we automatically and permanently delete it, after advance email notice sent at 17 months — see Terms of Service section 8.6 for how this works and how to prevent it.
Where the law requires us to keep certain records for a set period — for example, records of transactions or of consent you have given — we keep those records for the period the law requires and no longer, even after the rest of your data is deleted.
You may delete your account and all associated data at any time. See Section 21 for how.
15. How do we keep your information safe?
We aim to protect your information through appropriate technical and organisational measures.
We maintain a written information security programme with annual risk assessment and testing. No system is perfectly secure, and no method of transmission or electronic storage is 100% secure; although we will do our best to protect your information, transmission to and from our Services is at your own risk.
If a security incident results in unauthorised access to your personal information, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where required by GDPR Art. 33, and we will notify affected individuals without undue delay where the incident is likely to result in a high risk to their rights and freedoms (GDPR Art. 34) or where required under applicable US state breach-notification law. Regardless of whether a legal threshold for notice is met, we will notify you individually of any breach involving your voice, biometric, or health-adjacent data.
16. Do we collect information from minors?
No. Luqas is strictly for adults, on both sides of the product.
We do not knowingly collect data from, or market to, anyone under 18 years of age. By using the Services, you represent that you are at least 18. We also do not create a Voice Model of anyone who was under 18 at the time of death, or who is currently under 18 — this prohibition is absolute and cannot be overridden by parental, guardian, or estate consent of any kind. If we learn that we have collected data from a user under 18, or that Source Material relating to a minor Subject has been uploaded, we will deactivate the account and delete the data as soon as possible.
17. What are your privacy rights? (EEA, UK & Switzerland)
You have rights that allow you greater access to and control over your personal information, and you may complain to a supervisory authority.
You have the right to: access your data (Art. 15); rectify inaccurate data (Art. 16); erasure (Art. 17); restrict processing (Art. 18); receive your data in a portable format (Art. 20); withdraw consent at any time without detriment (Art. 7(3)); object to processing based on legitimate interests (Art. 21); and not be subject to a decision based solely on automated processing which produces legal effects (Art. 22) — we do not make such decisions; our safety classifiers may interrupt a conversation, but never restrict your account without human review. You may also lodge a complaint with your local supervisory authority; in the UK this is the Information Commissioner's Office.
We respond within one month, extendable by two further months for complex requests.
18. Do United States residents have specific privacy rights?
Yes, if you are a resident of certain US states, you are granted specific rights regarding access to your personal information.
California (CCPA/CPRA). You have the right to know, access, delete, correct, port, opt out of sale or sharing, and limit the use of sensitive personal information, plus the right to non-discrimination. We do not presently sell or share personal information for cross-context behavioural advertising. An authorised agent may submit a request with proof of identity.
Washington, Nevada, and comparable consumer health data laws. See Section 13.
Illinois and Texas biometric laws. See Section 10.
Other states. Residents of Virginia, Colorado, Connecticut, Utah, Oregon, Montana, and other states with comprehensive privacy laws have rights of access, correction, deletion, portability, and opt-out, together with a right to appeal a refusal.
How to exercise: use the in-app controls, or email privacy@luqas.ai. We verify requests proportionately to their sensitivity.
19. Do other regions have specific privacy rights?
You may have additional rights based on the country you reside in.
Australia and New Zealand. We collect and process your personal information subject to the Australian Privacy Act 1988 and New Zealand's Privacy Act 2020, as applicable. You may make a complaint to the Office of the Australian Information Commissioner or the New Zealand Office of the Privacy Commissioner.
EU member states with post-mortem data rules. See Section 11.
20. Do we make updates to this notice?
Yes, we will update this notice as necessary to stay compliant with relevant law.
We may update this Privacy Policy from time to time. For material changes, we will give at least 30 days' advance notice before they take effect, by sending an in-app and email notification containing a link to the updated Policy. Where a change requires your consent under applicable law, we will ask for it rather than assume it.
21. How can you contact us about this notice, or review, update, or delete your data?
You can review, update, or delete your data at any time through your account settings, or by contacting us directly.
Based on the applicable laws of your country or state of residence, you may have the right to request access to, correct, or delete the personal information we collect from you. To request this, go to Privacy & Security under Settings in the app, or contact us:
- Privacy and data rights: privacy@luqas.ai
- Data Protection Officer: dpo@luqas.ai
- Estate and likeness objections: likeness@luqas.ai
7. How do we handle your social logins?
If you register using Google or Apple, we receive certain profile information from that provider.
Our Services offer you the ability to register and log in using your Google or Apple account. Where you choose to do this, we will receive certain profile information about you from Google or Apple, which may include your name, email address, and profile picture, as well as other information you choose to make available. We will use the information we receive only for the purposes described in this Policy or that are otherwise made clear to you. We do not control, and are not responsible for, how Google or Apple use your information; please review their respective privacy notices.