Legal
HomePrivacy Policy
Last updated: September 13, 2026
This Privacy Policy explains how lurq, operated by Jaden Ryu, an individual based in the Commonwealth of Virginia (“lurq”, “we”, “us”, or “our”), collects, uses, and shares information about you when you use the lurq website at lurq.run, the lurq command-line interface (“CLI”), the lurq MCP server, the lurq GitHub App, and any related services (together, the “Services”).
We built lurq as a tool for developers and collect as little personal information as we can to run it. Where we do collect information, this policy explains what, why, and what choices you have.
Information we collect
Information you provide to us
- Contact messages. If you use the contact form, we collect the name, email address, and message you enter, along with your IP address, approximate country, and browser user agent, which are included in the email we receive. The form is protected by Cloudflare Turnstile. If you email us directly, we receive whatever your email contains.
- Account information. If you create an account, our authentication provider (Clerk) collects the email address and credentials needed to create and secure it. API keys you generate are associated with your account; we store only a one-way hash of each key, never the key itself.
- Billing. If you buy a paid plan, Stripe collects your payment details and billing address on its own checkout page; we never see or store your card number. We store your Stripe customer and subscription identifiers, your plan, its status, seat count, and renewal date. If you ask to buy a plan while self-serve checkout is unavailable, we receive an email with your account identifier and the plan you chose.
- Account email. We email your account’s verified address about urgent changes to the dependencies and MCP servers you connect, which is on by default, and a weekly summary only if you turn it on. Every email has a link to turn it off. We read the address from Clerk when an email is sent and do not keep our own copy, and we record which alerts were sent so the same one is never sent twice. If you add a Slack, Discord, Teams, or webhook alert channel, we store its URL encrypted.
Information collected automatically
- Website and server logs. When you access lurq.run or our hosted API/MCP endpoints, our hosting providers record standard technical information such as your IP address, client type and version, request timestamps, and the resources you request. We use this to operate, secure, debug, and rate-limit the Services.
- Product analytics. Our website uses PostHog to capture usage such as page views, navigation, and page performance, and uses Vercel Web Analytics and Speed Insights for aggregate traffic and performance. When you are signed in, PostHog events are linked to your account. If you scan a GitHub profile or repository from the website, the name you typed and the resulting report’s summary (the GitHub login and its profile type) are recorded in PostHog. Our hosted service also records account-level product events in PostHog, such as creating an API key, which lurq tool was called and whether it succeeded, and the size and cost of dashboard Ask answers, but never the contents of your queries or questions. We do not use this to build advertising profiles.
- Query data. When you call a lurq tool through the CLI or MCP server, we receive the search terms, package names, or package context you submit, and return results. To answer a search, its text is sent to our embedding model provider; if you pass a document to the
plantool, it may be sent to our language model provider to break it into components. Search results are cached without being tied to your account. Linked to your account we keep daily counts of which tools you called, the packages your selection policy blocked or warned about, and any outcomes you report back (including the need you described), and which coding agent each call came from: the agent name that setup writes into that agent’s lurq connection (for examplecursor), and the name and version the agent’s MCP client reports when it connects. The CLI and MCP server do not send us any separate analytics or telemetry beyond the requests needed to serve you.
GitHub repositories you connect
If you install the lurq GitHub App, it has read-only access to the repositories you choose, including private ones. Our servers read the list of those repositories (name, default branch, and whether each is private), the repository’s file names (to find manifests and detect the package manager), and the dependency sections of its package.json files. We store those dependency lists and the scan results. Our servers do not read your source files, lockfiles, or commit history. When you remove a repository from the App or uninstall it, we delete the data we stored for those repositories.
Scanning a public GitHub profile or repository from the website reads the same kind of public dependency information through GitHub’s API.
What runs on your machine, and what it sends
lurq check-upgradereads your code on your own machine or CI runner to find call sites an upgrade would break. Your code is not uploaded. Only if you pass--reportdoes it send us the results: package names and versions, severity, the names of affected symbols, the number of call sites and the file paths they are in, and the CI run link. File contents are never sent.lurq mcp-scanconnects, from your machine, to the MCP servers configured in your coding agents and reads what each one declares. When an API key is configured it uploads that to your account unless you pass--no-upload: each server’s name, package name or remote address, version, transport, and status, the tool, prompt, and resource definitions and instructions the server publishes, and a one-way fingerprint of its configuration. The configuration itself, including any credentials in it, is not uploaded.
Dashboard Ask
If you use Ask in the dashboard, your question and the data from your own account needed to answer it (such as your connected repositories, their dependencies, alerts, and usage) are sent to Anthropic to generate the answer. We record what each day’s questions cost, not the questions themselves.
How we use information
- Provide, operate, and maintain the Services, including returning the results you request;
- Improve and develop the Services, including the quality and relevance of recommendations;
- Communicate with you: responding to your messages and sending the account emails described above;
- Process payments and manage subscriptions;
- Protect the Services, our users, and the public: detecting and preventing abuse, spam, fraud, and security incidents, and enforcing our Terms of Service; and
- Comply with legal obligations.
Legal bases for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information under these legal bases: consent (for the optional weekly summary email); legitimate interests (operating, securing, debugging, and improving the Services); performance of a contract (providing the Services you request, including paid plans); and legal obligation (complying with the law). You can withdraw consent at any time.
How we share information
We do not sell your personal information. We share it only as described here:
- Service providers (sub-processors). We rely on third parties to run lurq: Clerk (authentication), Stripe (payments and subscription billing), Neon (database), Railway (API hosting), Vercel (website and documentation hosting, Web Analytics, and Speed Insights), GitHub (the lurq GitHub App and repository scans), Anthropic (dashboard Ask), our embedding and language model provider (search queries and
plandocuments, as described above), Resend (email), Cloudflare (DNS, email routing, and Turnstile bot protection), and PostHog (product analytics). They process information on our behalf. - Legal and safety. We may disclose information if required by law or legal process, or where we believe disclosure is reasonably necessary to protect the rights, property, or safety of lurq, our users, or the public.
- Business transfers. If lurq is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information.
Data retention
We do not currently delete account data on a schedule. The information linked to your account (API keys, usage counts, reported outcomes, policy decisions, connected-repository data, upgrade reports, MCP scan history, and billing records) is kept while your account exists and until you ask us to delete it. Some of it expires or is removed sooner: cached search results expire automatically, and data for a GitHub repository is deleted when you remove it from the lurq GitHub App. Server and website logs are kept by our hosting providers under their own retention periods. Contact messages stay in our email until deleted. Stripe keeps payment records as the law requires.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal information, the right to data portability, and the right to withdraw consent. California residents (CCPA/CPRA) have the right to know, access, delete, and correct their personal information and not to be discriminated against for exercising those rights; we do not sell or “share” personal information for cross-context behavioral advertising. EEA/UK/Swiss residents may lodge a complaint with their local data protection authority.
To exercise any of these rights, including deleting your account data, email contact@lurq.run. You can turn off account emails at any time using the link in each email.
International data transfers
lurq is operated from the United States, and information is processed there and wherever our service providers operate. If you access the Services from outside the United States, you understand your information will be transferred to and processed in the United States and other countries, which may have different data protection laws than your own. Where required, we rely on appropriate safeguards for these transfers.
Security
We take reasonable technical and organizational measures to protect your information. No system is perfectly secure, however, and we cannot guarantee absolute security.
Children's privacy
The Services are intended for developers and are not directed to children. We do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after a change takes effect means you accept the updated policy.
Contact
Questions about this policy or how we handle your information? Reach us at contact@lurq.run.