Privacy Policy

Last Updated: 02/12/2025

Introduction

Lure AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, process, and protect your information when you use our social media automation platform ("Service"). By using our Service, you agree to the collection and use of information in accordance with this policy.

Lure AI is a trading name of Otti Group Ltd. Otti Group Ltd is the data controller for all personal data collected through the platform.

Information We Collect

Information You Provide Directly

We collect information that you provide directly to us when you:

  • • Create an Account: We collect your email address, first name, last name, and password when you sign up for our Service.
  • • Complete Onboarding: We collect additional information including:
    • • Account type (agency or personal)
    • • Agency name (if applicable)
    • • Agency size or total social accounts
    • • Usage intent preferences
    • • Region (optional)
  • • Connect Social Media Accounts: When you connect your Instagram or Facebook accounts through Meta OAuth, we collect:
    • • Username
    • • Platform account ID
    • • Profile picture URL
    • • Access tokens (stored securely and encrypted)
  • • Create Models and Personas: We collect information about the models/personas you create, including:
    • • Model names, ages (personas must be 18+), and appearance descriptions
    • • Niche tags and content categories
    • • AI persona configurations and personality descriptions
    • • Avatar images
  • • Payment Information: When you subscribe to our Service, payment information is processed by Stripe. We do not store your full payment card details. We only store:
    • • Stripe customer ID
    • • Subscription tier and status
    • • Billing history

Information Collected Automatically

We automatically collect certain information when you use our Service:

  • • Usage Data: We collect information about how you interact with our Service, including:
    • • Pages visited and features used
    • • Time spent on different sections
    • • Actions taken within the platform
  • • Device and Browser Information: We collect technical information such as:
    • • Browser type and version
    • • Operating system
    • • Device type
    • • IP address
    • • Referral URLs
  • • Social Media Data: When you connect your social media accounts, we automatically collect:
    • • Posts and their engagement metrics (likes, comments, shares)
    • • Comments received on your posts
    • • Account status and health metrics
    • • Rate limit usage and API call statistics

Information from Third-Party Services

We receive information from third-party services you connect:

  • • Meta (Facebook/Instagram): When you authorize our app, Meta provides:
    • • Account information (username, profile picture, account ID)
    • • Access tokens for API access
    • • Post and comment data via webhooks
    • • Engagement metrics

How We Use Your Information

We use the information we collect for the following purposes.

Our lawful bases for processing data under the UK GDPR include contract, legitimate interests, and consent where applicable.

Service Provision

  • Account Management: To create and manage your account, authenticate you, and provide access to our Service.
  • Social Media Automation: To connect your social media accounts, fetch posts and comments, and manage your content.
  • AI Reply Generation: To generate personalised automated replies to comments using AI technology based on your configured personas.
  • Analytics and Reporting: To provide you with insights, metrics, and performance data about your social media accounts.

Service Improvement

  • Platform Development: To improve, optimise, and develop new features for our Service.
  • Error Resolution: To diagnose technical issues, fix bugs, and ensure Service stability.
  • User Experience: To personalise your experience and provide relevant content and features.

Communication

  • Service Updates: To send you important updates about your account, subscription, or the Service.
  • Support: To respond to your inquiries, provide customer support, and address technical issues.
  • Marketing: To send you promotional communications (only with your consent, and you can opt out at any time).

Legal and Security

  • Compliance: To comply with applicable laws, regulations, and legal processes.
  • Security: To protect the security and integrity of our Service, prevent fraud, and ensure user safety.
  • Enforcement: To enforce our Terms of Service and protect our rights and the rights of our users.

How We Process Your Information

Server and Hosting Locations

  • • Database and user data are stored in London, UK via Supabase.
  • • Our frontend is hosted on Vercel.
  • • OpenAI may process data in multiple locations depending on infrastructure.

We ensure appropriate safeguards for international transfers.

Data Processing Activities

  1. OAuth Token Management: We securely store and manage access tokens provided by Meta. Tokens are encrypted and stored in our secure database.
  2. Webhook Processing: We receive and process webhooks from Meta containing real-time updates about comments, posts, and account activity. This data is stored in our database to enable automated reply functionality.
  3. AI Reply Generation: We use OpenAI's API to generate replies based on your personas. We only send:
    • • Comment text
    • • Persona configuration
    • • Account context

    We do not allow or enable OpenAI to use data for model training.

  4. Data Storage: Your information is stored securely in Supabase with encryption at rest and Row Level Security (RLS) to ensure access only to your data.
  5. Analytics Processing: We process usage data and engagement metrics to provide you with insights and analytics about your social media performance.

Third-Party Service Providers

We use the following third-party services that process your information:

  • Supabase: Provides database, authentication, and storage services. Your data is stored in Supabase's secure infrastructure in London, UK.
  • OpenAI: Processes comment text and persona configurations to generate AI replies. OpenAI's use of your data is governed by their privacy policy. We have configured our integration to prevent data from being used for model training.
  • Meta (Facebook/Instagram): Provides OAuth authentication and social media API access. Meta's use of your data is governed by Meta's Privacy Policy and Data Policy. We only access data you explicitly authorize us to access.
  • Stripe: Processes payment information for subscription management. Stripe's use of your payment data is governed by their privacy policy.

We do not sell or transfer personal data to any other party.


Data Sharing and Disclosure

We do not sell your personal information. We may share your information only in the following circumstances:

  • With Your Consent: We share information when you explicitly authorize us to do so.
  • Service Providers: We share information with trusted third-party service providers (listed above) who assist us in operating our Service, subject to strict confidentiality obligations.
  • Legal Requirements: We may disclose information if required by law, court order, or government regulation.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
  • Protection of Rights: We may disclose information to protect our rights, property, or safety, or that of our users or others.

Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: Access tokens and sensitive data are encrypted both in transit (TLS/SSL) and at rest.
  • Authentication: We use secure authentication methods and require strong passwords.
  • Access Controls: We implement Row Level Security (RLS) policies to ensure users can only access their own data.
  • Regular Security Audits: We conduct regular security reviews and updates to protect against vulnerabilities.
  • Secure Infrastructure: Our Service is hosted on secure cloud infrastructure with regular security updates.

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

Breach Notification

If a data breach occurs affecting your personal information, we will notify affected users and/or regulatory authorities as required under UK GDPR within 72 hours of becoming aware of the breach, where feasible.


Data Retention and Deletion

We retain data only as long as necessary to operate the Service and fulfill the purposes described in this Privacy Policy.

When your account is deleted or access is revoked:

  • • All personal data and social media connections are immediately deleted
  • • All OAuth tokens are deleted
  • • All personas, configuration, and associated data are deleted
  • • Post and comment data stored in our database are deleted
  • • We do not retain analytics or aggregated data that can identify you

Please note: Instagram or Facebook posts/replies remain on those third-party platforms because they are controlled by those platforms, not by us.

Retention Exceptions:

  • • Payment and subscription information may be retained as required by law and Stripe's policies for financial record-keeping (typically 7 years).
  • • Some information may be retained for a limited period to comply with legal obligations or resolve disputes.

Your Rights and Choices

You have the following rights regarding your personal information under UK GDPR:

  • Access: Access and view your data through your account dashboard or by request
  • Portability: Export your data in a portable format
  • Correction: Correct inaccurate information
  • Deletion: Delete your data and account
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for marketing communications at any time
  • Disconnect Accounts: Disconnect social media accounts at any time

Data Deletion Requests

You may delete your account through settings or request deletion at:

Email: hello@otti.app

We process deletion requests within 30 days. Upon account deletion:

  • • All personal data and social media connections are immediately deleted
  • • All OAuth tokens are revoked and deleted
  • • All personas, configuration, and associated data are deleted
  • • Post and comment data stored in our database are deleted

Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. Personas and profiles representing individuals under 18 are not permitted.

If you believe we have collected information from a child under 18, please contact us immediately at hello@otti.app, and we will delete that information.


International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your country.

Data Processing Locations:

  • • Primary Storage: London, UK (Supabase)
  • • Frontend Hosting: Vercel (may process in multiple regions)
  • • AI Processing: OpenAI (may process in multiple locations depending on infrastructure)

We maintain appropriate contractual and security safeguards for all transfers, including:

  • • Standard Contractual Clauses (SCCs) where applicable
  • • Adequate security measures and encryption
  • • Compliance with UK GDPR requirements

Compliance

We are committed to data protection compliance and are working toward appropriate compliance and security certifications. We will update this policy as our compliance framework evolves.


Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • • Updating the "Last Updated" date at the top of this page
  • • Sending you an email notification (if you have an account with us)
  • • Displaying a prominent notice on our Service

Your continued use of our Service after any changes constitutes acceptance of the updated Privacy Policy.


Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: hello@otti.app


Additional Information for Meta Platform Users

If you use our Service with Meta (Facebook/Instagram) accounts:

  • Meta OAuth: We use Meta's OAuth 2.0 to securely connect your accounts. You authorize us to access your account data through Meta's authorization process.
  • Meta API Access: We use Meta's Graph API to fetch posts, comments, and engagement data, and to post replies on your behalf.
  • Meta Webhooks: We receive real-time updates from Meta via webhooks when comments are posted on your content.
  • Meta Data Usage: Meta's use of your data is governed by Meta's Privacy Policy and Data Policy. We only access data you explicitly authorize us to access.
  • Revoking Access: You can revoke our access to your Meta accounts at any time through your Meta account settings or by disconnecting accounts in our Service.
  • Token Deletion: All Meta tokens are deleted immediately upon revocation or account deletion.

This Privacy Policy is effective as of 02/10/2025 and applies to all users of Lure AI