Privacy Policy
Last updated: July 16, 2026
This Privacy Policy explains how lurq, operated by Jaden Ryu, an individual based in the Commonwealth of Virginia (“lurq”, “we”, “us”, or “our”), collects, uses, and shares information about you when you use the lurq website at lurq.run, the lurq command-line interface (“CLI”), the lurq MCP server, and any related services (together, the “Services”).
We built lurq as a tool for developers and collect as little personal information as we can to run it. Where we do collect information, this policy explains what, why, and what choices you have.
Information we collect
Information you provide to us
- Waitlist and contact details. If you join our waitlist, request a demo, or contact us, we collect the email address and any message contents you provide.
- Account information. If you create an account, our authentication provider (Clerk) collects the email address and credentials needed to create and secure it. API keys you generate are associated with your account.
Information collected automatically
- Website and server logs. When you access lurq.run or our hosted API/MCP endpoints, our infrastructure records standard technical information such as your IP address, client type and version, request timestamps, and the resources you request. We use this to operate, secure, debug, and rate-limit the Services.
- Product analytics. Our website uses PostHog to capture aggregate usage such as page views and navigation, so we can understand how the site is used and improve it. We do not use this to build advertising profiles.
- Query data. When you request a recommendation through the website, CLI, or MCP server, we receive the search terms or package context you submit and the recommendations returned. We use this to return your results and to improve the quality and relevance of recommendations. The CLI and MCP server do not send us any separate analytics or telemetry beyond the queries needed to serve your request.
What we do not collect
lurq operates on public package metadata. We do not read your source code, and the index itself is built entirely from public signals.
How we use information
- Provide, operate, and maintain the Services, including returning the package recommendations you request;
- Improve and develop the Services, including the quality and relevance of recommendations;
- Communicate with you: responding to your messages and, if you opted in, sending occasional updates about news, products, and services;
- Protect the Services, our users, and the public: detecting and preventing abuse, spam, fraud, and security incidents, and enforcing our Terms of Service; and
- Comply with legal obligations.
Legal bases for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information under these legal bases: consent (for update emails you sign up for); legitimate interests (operating, securing, debugging, and improving the Services); performance of a contract (providing the Services you request); and legal obligation (complying with the law). You can withdraw consent at any time.
How we share information
We do not sell your personal information. We share it only as described here:
- Service providers (sub-processors). We rely on trusted third parties to run lurq, including Clerk (authentication), Neon (database), Railway (application hosting), Resend (transactional and update email), Cloudflare (DNS, email routing, and Turnstile bot protection), and PostHog (product analytics). They process information on our behalf and are bound to protect it.
- Legal and safety. We may disclose information if required by law or legal process, or where we believe disclosure is reasonably necessary to protect the rights, property, or safety of lurq, our users, or the public.
- Business transfers. If lurq is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information.
Data retention
We keep personal information only as long as we have a reason to: to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Server logs and query data are retained for a limited period and then deleted or aggregated. Waitlist and contact information is kept until you ask us to delete it or it is no longer needed.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal information, the right to data portability, and the right to withdraw consent. California residents (CCPA/CPRA) have the right to know, access, delete, and correct their personal information and not to be discriminated against for exercising those rights; we do not sell or “share” personal information for cross-context behavioral advertising. EEA/UK/Swiss residents may lodge a complaint with their local data protection authority.
To exercise any of these rights, email contact@lurq.run. You can also unsubscribe from update emails at any time using the link in the email.
International data transfers
lurq is operated from the United States, and information is processed there and wherever our service providers operate. If you access the Services from outside the United States, you understand your information will be transferred to and processed in the United States and other countries, which may have different data protection laws than your own. Where required, we rely on appropriate safeguards for these transfers.
Security
We take reasonable technical and organizational measures to protect your information. No system is perfectly secure, however, and we cannot guarantee absolute security.
Children's privacy
The Services are intended for developers and are not directed to children. We do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after a change takes effect means you accept the updated policy.
Contact
Questions about this policy or how we handle your information? Reach us at contact@lurq.run.