Privacy Policy
Effective Date: March 15, 2026 | Last Updated: September 29, 2026
1. Introduction
Lobstack ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at lobstack.ai and use the Lobstack platform — the Gateway, the Console and the Lobstack app, formerly Lob Bot (collectively, the "Service").
Our Role: With respect to personal data contained in Customer Data (as defined in our Terms of Use), Lobstack acts as a data processor on behalf of the Customer (the "data controller"). For account registration, billing, and sales enquiry data, Lobstack acts as the data controller. Enterprise customers may enter into a separate Data Processing Addendum (DPA) that supplements this Privacy Policy; it is available on request from hello@lobstack.ai.
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws. By using the Service, you consent to the data practices described herein. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account Information
When you create an account through our authentication system (Supabase Auth), we may collect:
- Email address
- Name and display name
- Avatar / profile picture URL
- Authentication identifier
2.2 Billing & Payment Information
When you subscribe to the Service, we collect and process billing information via Stripe:
- Stripe customer ID and subscription ID
- Subscription status, plan tier, and billing period dates
- Payment method details (stored and processed exclusively by Stripe — we do not store your full card number)
2.3 Enquiries and the mailing list
If you submit the sales enquiry form we collect what you put in it — your name, work email, company, and whichever of job title, company size, website, intended use and free-text message you fill in — together with the page you sent it from. It goes to Airtable, which is where we read it. If you give us your email address for the mailing list we store that address and where you gave it to us, and nothing else.
2.4 Gateway Request Data
When you send a request to the Gateway we write two rows: a trace of the call, and a priced ledger entry. Neither holds the content of your prompt or of the model's response — we do not store either. What is recorded is:
- Request: The request id returned to you on the call, the timestamp, the endpoint, whether the response was streamed, and the client identifier your caller sent
- Routing: The model you asked for, the model served, whether the router substituted one, the provider, and the mode (managed, BYOK or direct)
- Token Usage: Prompt tokens, completion tokens, total tokens, and the cost and any savings frozen at the time of the request
- Outcome: The HTTP status returned, and for a failed call its error class, error code and the provider's own error message
- Latency: Total round trip, and time to first token for a streamed response
- Attribution: The API key and the organization the call is billed to
2.5 Organization & API Key Data
To operate your account and authenticate your requests, we store:
- Your organization, its members and their roles, and the email addresses of people you invite to it
- Your plan, subscription status and billing period, and the spend recorded against your allowance
- For each API key: the name you give it, its non-secret prefix, its scopes, and when it was last used
- A SHA-256 hash of each API key. The key itself is shown once, at creation, and is never stored
2.6 Your Own Provider Keys
On a paid plan, an owner or admin of your organization can add an API key from a third-party AI provider in the Console under Settings › Provider keys, one key per provider. We encrypt the key with AES-256-GCM before storing it, using an encryption key held outside the database, and bind it to your organization and that provider. We decrypt it only to call the provider that issued it, so your key is sent to that provider and to no other. We use it for nothing else. Once saved, it is never shown again; members of your organization see only its last four characters. An owner or admin can remove it there.
2.7 Automatically Collected Information
When you visit this website we count page views with Vercel Web Analytics. It sets no cookie. For each page view it records the page path (without the query string, apart from any utm_ campaign tags), the site you came from, your approximate location (country, region and city), and your device type, operating system and browser. Vercel tells visitors apart with a hash of the request that it discards after 24 hours, and does not store your IP address with the count.
We also count a few steps, never linked to you or your account:
- when a Download button is pressed: which platform (Windows, macOS or Linux) and which page it was on;
- when the app is downloaded from this site: the platform, the app version, and the page the button was on. We store this in our own database with the time and nothing else: no IP address, no browser details, no account;
- when the Lobstack app starts or finishes signing in: the app version, and whether a welcome credit came with it.
The Lobstack app itself sends none of this. Everything here is counted by our website and server when your browser or the app talks to them. No session recording, no advertising, no behavioural profiling. Apart from this, what our hosting provider records in the ordinary course of serving a request is the request itself: the IP address it came from, the page asked for, the user agent, and the time.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide & Operate the Service: Operate the Gateway and the Console, authenticate your API keys, forward your requests to a model provider, and meter what they cost
- Process Payments: Handle subscription billing, invoices, and payment-related communications through Stripe
- Enable AI Functionality: Transmit your requests to the AI model provider serving the selected model, and record the tokens and cost of each call
- Monitor & Maintain: Monitor platform health, latency and error rates, and ensure uptime and reliability
- Improve the Service: Analyze aggregated, anonymized usage patterns, diagnose technical issues, and develop new features
- Communicate: Send service-related notifications, billing alerts, and respond to support requests
- Ensure Security: Detect and prevent fraud, unauthorized access, and other malicious activity
- Comply with Legal Obligations: Respond to legal requests and prevent harm as required by law
What We Do Not Do: We do not use Customer Data for profiling, automated decision-making, cross-customer analytics, or marketing targeting. Customer Data is processed solely for the purpose of providing the Service.
4. Legal Bases for Processing
Under the GDPR and similar data protection laws, we process personal data based on the following legal bases:
| Legal Basis | Processing Activities |
|---|---|
| Contract Performance | Account creation, service operation, request routing and metering, payment processing, subscription management |
| Legitimate Interests | Service improvement, security monitoring, fraud prevention, infrastructure optimization |
| Consent | Optional marketing communications |
| Legal Obligation | Tax record retention, regulatory reporting, responding to legal process |
Where we rely on legitimate interests, we have conducted balancing tests to ensure our interests do not override data subject rights. Assessments are available upon request for enterprise customers.
For enterprise customers where Lobstack acts as a data processor, the legal basis for processing Customer Data is the Data Processing Addendum and the Customer's documented instructions.
5. How We Share Your Information
We do not sell your personal information. We may share your information with the following categories of third parties (acting as subprocessors), solely for the purposes described in this Privacy Policy. All subprocessors are bound by written data processing agreements with obligations at least as protective as those in our DPA.
| Third Party | Purpose | Data Location |
|---|---|---|
| Supabase | Authentication, database hosting, and storage | US (AWS) |
| Stripe | Payment processing and subscription management | US |
| Anthropic | AI model inference (messages sent for responses) | US |
| OpenAI | AI model inference (messages sent for responses) | US |
| Google (Gemini API) | AI model inference (messages sent for responses) | US |
| xAI, DeepSeek, Mistral, Groq, Alibaba, Moonshot | AI model inference, for calls served by one of their models | Operated by the provider; region not verified by Lobstack |
| Vercel | Website and application hosting, and cookieless page-view counts (Web Analytics, see 2.7) | US (Edge) |
| Resend | Sending our email: budget and spend alerts, and replies to reports and enquiries | Operated by Resend; region not verified by Lobstack |
| Airtable | The sales enquiry form, where one is submitted | US |
A request reaches a model provider only when that provider serves the model selected for the call. It is not copied to the others. Which provider serves which model is listed in our Documentation.
Lobstack conducts due diligence on all subprocessors prior to engagement, including review of their security practices, data protection measures, and compliance certifications. We may also disclose your information if required by law, in response to valid legal process, to protect rights, or in connection with a merger, acquisition, or sale of assets.
6. Subprocessors
The subprocessors engaged by Lobstack to process Customer Data are the ones named in Section 5 and listed below. This list is current as of the date at the top of this document; see Section 21 for how changes to it are notified.
- Change Notification: Lobstack will provide at least thirty (30) days prior written notice before engaging a new subprocessor or replacing an existing one. Notification will be sent via email to the Account Administrator.
- Objection Right: Customers may object in writing to a new subprocessor within fifteen (15) days of notification. Lobstack will work in good faith to address the objection. If the parties cannot reach a resolution, the Customer may terminate the affected services without penalty.
- Subprocessor Obligations: All subprocessors are bound by written agreements that impose data protection obligations materially consistent with those in our DPA, including confidentiality, security, and data handling requirements.
7. AI-Specific Data Disclosures
Because the Service involves artificial intelligence, the following additional disclosures apply:
- Conversation Processing: The contents of a Gateway request are forwarded to the provider that serves the model selected for that call, and to no other. These providers may have their own data retention and privacy policies that govern how they handle this data.
- No Conversation Storage: Lobstack does not store the content of your prompts or of the model's responses. There is no conversation history and no persistent memory held on your behalf. What is retained about a call is the metadata listed in Section 2.4.
- Token Usage Tracking: We track the number of tokens consumed per interaction for billing transparency and usage monitoring purposes.
- The Lobstack app: The Lobstack app runs on your own computer. Its bots, their notes, their permissions and everything they have done live in a folder on your disk, and are not sent to us. It sends us no telemetry, no analytics and no automatic crash reports. A report about a crash or a failure reaches us only when you press Send report, and you see it first: the app's version, your system and processor, the engine's name, what failed and its error, and the last lines of the app's log with keys, tokens, email addresses and your home folder taken out, plus a note and a reply-to address only if you type them. We store it without your IP address. When it runs on the Gateway, which is its default once you sign in with Lobstack, each model call passes through the Gateway exactly as an API call does and is handled as described in 2.4 Gateway Request Data: we record the metadata and the cost, not the prompt or the response. Signing in sends us a hash of a one-time secret and your computer's name, which becomes the name of the key it receives. If you use one-click connector sign-in, the provider's token passes through us encrypted and is deleted when the app collects it. If you pair a phone, sealed copies of waiting approval cards pass through lobstack.ai. It can't read them. If you give a bot a webhook trigger, webhook bodies sent to its trigger URL are kept on lobstack.ai for up to 7 days so your app can collect them, and are removed as soon as it has. If you run it on GitHub Copilot or your own provider key instead, it needs no Lobstack account. It also checks for updates, asking whether a release newer than the one you have exists. That request carries your platform, your processor architecture and your installed version — in the URL, because that is how the updater is built — along with the IP address any web request carries. It carries nothing about your bots or your work. Where you let it act — on your files, your browser or a connector — the data involved goes to those services and not through Lobstack.
- No Training on Your Data: Lobstack does not use your prompts, the responses you receive, or any other user content to train AI models. Your data is used solely to provide the Service to you.
8. Data Retention & Deletion
We retain your data according to the following schedule:
| Data Type | Retention Period | Basis |
|---|---|---|
| Account data | Duration of active account | Contract performance |
| Gateway traces and priced ledger rows, request by request | Shown for your plan's history (7 days to unlimited, see /pricing); may be deleted once older than that plus 30 days, never within the current billing month; deleted on request | Contract; billing records |
| Monthly usage totals per client and model | Kept while the account exists; deleted on request | Contract; billing records |
| Billing & payment records | 7 years | Tax and accounting compliance |
| Platform and security logs | 90 days | Security monitoring |
Deletion Procedures
- Account Deletion: Request via hello@lobstack.ai. Processed within 30 days, except where retention is required by law.
- Data Export: Customers may request export of their data in standard formats (JSON/CSV) prior to deletion.
- Secure Deletion: Deletion is carried out by us on request: Customer Data is removed from the production database and from our providers' systems, and backups containing it are purged within ninety (90) days. We do not currently offer self-service deletion, and we do not claim a cryptographic key-destruction step.
9. Data Processing Agreement (DPA) Framework
Where Lobstack processes personal data on behalf of the Customer as a data processor (under GDPR Article 28), the following framework applies. A standalone DPA is available on request from hello@lobstack.ai.
- Documented Instructions: Lobstack processes Customer Data only on the documented instructions of the Customer, unless required by applicable law.
- Confidentiality: All personnel with access to Customer Data are bound by confidentiality obligations.
- Security Measures: Lobstack implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 16).
- Subprocessor Management: Lobstack engages subprocessors only with prior notice and imposes equivalent data protection obligations (see Section 6).
- Data Subject Rights: Lobstack assists the Customer in responding to data subject access requests, rectification, erasure, and portability requests.
- Data Protection Impact Assessments: Lobstack assists the Customer with DPIAs and prior consultations with supervisory authorities where required.
- Return or Deletion: Upon termination, Lobstack will delete or return all Customer Data within thirty (30) days, at the Customer's election.
- Audit & Compliance: Lobstack makes available information necessary to demonstrate compliance with data processing obligations and allows for audits as described in Section 16 of our Terms of Use.
10. Data Breach Notification
In the event of a confirmed personal data breach affecting Customer Data, Lobstack will:
- Notify Without Undue Delay: Provide notification to affected Customers as soon as reasonably practicable, and within seventy-two (72) hours of becoming aware of the breach, in compliance with GDPR Article 33.
- Notification Content: Include the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address and mitigate the breach.
- Designated Contact: Provide a dedicated point of contact for further information and coordination.
- Cooperation: Cooperate with the Customer's own breach notification obligations to supervisory authorities and affected data subjects.
- Ongoing Updates: Provide supplementary information as it becomes available during the investigation.
- Breach Record: Lobstack maintains a record of all personal data breaches, including the facts, effects, and remedial actions taken, as required by GDPR Article 33(5).
11. Your Rights Under GDPR (European Economic Area)
If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate personal data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Request restriction of processing of your personal data
- Right to Data Portability: Receive your personal data in a structured, machine-readable format
- Right to Object: Object to processing of your personal data for certain purposes
- Right to Withdraw Consent: Withdraw your consent at any time where we rely on consent for processing
Exercising Your Rights
Contact our Data Protection team at privacy@lobstack.ai. We will respond within thirty (30) days. Complex or numerous requests may be extended by an additional sixty (60) days in accordance with GDPR Article 12. You also have the right to lodge a complaint with your local data protection authority.
Data Protection Assessments
Lobstack conducts Legitimate Interest Assessments (LIAs) for all processing based on legitimate interests. We also conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities as required by GDPR Article 35. Assessment documentation is available to enterprise customers upon request under NDA.
12. Your Rights Under CCPA (California)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request information about the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it
- Right to Delete: Request deletion of personal information we have collected from you
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: We do not sell or share your personal information for cross-context behavioral advertising. Therefore, no opt-out mechanism is required
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights
To submit a verifiable consumer request, contact us at hello@lobstack.ai. We will verify your identity and respond within 45 days.
13. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States and other jurisdictions where our third-party providers operate. These countries may have different data protection laws than your jurisdiction.
Transfer Mechanisms
For transfers of personal data from the EEA, UK, or Switzerland, we rely on the following safeguards:
- EU-U.S. Data Privacy Framework (DPF): Where applicable, transfers to U.S.-based subprocessors certified under the DPF.
- Standard Contractual Clauses (SCCs): The European Commission approved SCCs (June 2021 modular clauses) are incorporated into our subprocessor agreements.
- UK International Data Transfer Addendum: The UK Addendum to the EU SCCs is used for transfers originating from the United Kingdom.
- Swiss-U.S. DPF: For transfers originating from Switzerland, where applicable.
Supplementary Measures
In addition to legal transfer mechanisms, Lobstack implements supplementary technical measures including encryption in transit and at rest, pseudonymization, and access controls. Transfer Impact Assessments (TIAs) are conducted for each transfer destination and are available to enterprise customers upon request.
14. Data Residency & Sovereignty
Lobstack runs in one region and offers no choice of region. If a jurisdiction is a hard requirement for you, the answer today is no.
- No Region Selector: There is no region selector in the product and no residency commitment to make. Postgres, authentication and the request ledger are a single Supabase project, and the application runs on Vercel.
- Database Hosting: That database is hosted on Supabase (US-based, on AWS infrastructure). Account data, organization membership, API key records, request traces and the priced ledger are all stored there.
- Model Inference: The contents of a request leave that database region for whichever provider serves the model selected for the call, in whatever region that provider operates. The providers are listed in Section 5.
- Enterprise Data Residency: We cannot meet a residency or sovereignty requirement today, and it is not something an Order Form can arrange. Bring-your-own-cloud deployment is on the roadmap and is not available; what is running and what is only planned is set out control by control on our security page.
15. Data Anonymization & Pseudonymization
Lobstack applies the following data minimization and protection techniques:
- Anonymization: Aggregated usage statistics and platform analytics are anonymized so they cannot be attributed to individual users or organizations. Anonymized data is not considered personal data and may be used for service improvement.
- Pseudonymization: Where possible, Lobstack applies pseudonymization techniques during processing, using internal identifiers rather than directly identifiable information.
- Minimal Data Transmission: Only the minimum necessary data is transmitted to subprocessors. For example, messages sent to AI model providers contain conversation content but are not linked to individual user PII at the provider level.
- No Re-identification: Lobstack does not attempt to re-identify data that has been anonymized.
16. Data Security
The measures below are the ones protecting your data today. Controls that are designed and defined in infrastructure-as-code but not yet deployed are listed separately, and marked as such, on our security page. Nothing on that page is claimed here.
Encryption
- AES-256 encryption at rest for database storage — this is the disk-level encryption the managed database provides, applied to every table alike
- TLS 1.3 encryption for all data in transit
- Encrypted database connections
- If your organization adds its own provider key in Settings › Provider keys, it is encrypted with AES-256-GCM before it is stored, using an encryption key held outside the database and bound to your organization and that provider. It is decrypted only to call the provider that issued it, and only its last four characters are ever shown again. You never have to give us one — the Gateway uses our keys otherwise.
Network & Infrastructure
- No customer compute: the Gateway is a stateless API route, and nothing of yours runs on our infrastructure between requests. There is no customer machine to isolate, reach or seize
- The application and the database run on managed platforms — Vercel and Supabase. Lobstack operates no servers of its own
- Lobstack's own provider keys held as platform environment secrets, not in the application database
Access Control
- Row-level security policies enforced at the database level
- Scoped, revocable API keys — stored only as a SHA-256 hash
- Sign-in through GitHub, Google or an email link, and per-organisation membership checks on every query
- Principle of least privilege for all internal access
Monitoring & Audit
- Audit logging for administrative actions
- A per-request trace row for every Gateway call, retained and queryable
- Platform health monitoring and alerting
For full technical details, see our Security Documentation. While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure.
17. Security Certifications & Compliance
We would rather you learn this here than in a questionnaire. Lobstack holds no security certification today.
- SOC 2: No audit has been performed and there is no report to send you. Our controls are documented and mapped against the Trust Services Criteria, and that mapping is a plan, not evidence. A Type II audit is on the roadmap. What is running today, and what is only defined, is set out control by control on our security page.
- GDPR: We act as a processor and the Article 28 terms are in our DPA, which is available on request. We have not commissioned a third-party GDPR audit, and we do not claim certification.
- CCPA/CPRA: We do not sell personal information, we honour consumer rights requests, and the notices required are in this policy.
- HIPAA: We are not currently able to sign a Business Associate Agreement. Do not send protected health information to Lobstack.
- PCI DSS: Not applicable — Lobstack does not store or process payment card data. All payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified service provider.
- Penetration Testing: No third-party penetration test has been commissioned. When one is, we will say so here and the summary will be available under NDA.
- ISO 27001: Not certified, and no certification process has begun.
18. Cookies & Tracking Technologies
We use the following types of cookies and similar technologies:
- Essential Cookies: Required for authentication, security, and basic site functionality. These cannot be disabled.
- Authentication Tokens: Used by Supabase Auth to maintain your login session across visits.
- Analytics and advertising: We set no analytics or advertising cookie and sell nothing to advertisers. Page views are counted without cookies by Vercel Web Analytics, as described in Section 2.7.
You can control cookies through your browser settings. Disabling essential cookies may impair your ability to use the Service.
19. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete such information promptly. If you believe a child under 18 has provided us with personal information, please contact us at hello@lobstack.ai.
20. Third-Party Links & Services
The Service may contain links to or integrations with third-party websites and services that are not operated by us (including AI model providers, and the connectors the Lobstack app on your own computer may reach). We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Privacy Policy on this page and updating the "Last Updated" date. For significant changes, we may also provide notice through the Service dashboard or via email. Your continued use of the Service after changes are posted constitutes your acceptance of the revised Privacy Policy.
22. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how we handle your information, please contact us:
Lobstack — Data Privacy
General Inquiries: hello@lobstack.ai
Privacy & Data Protection: privacy@lobstack.ai
Legal & DPA Requests: legal@lobstack.ai
Website: lobstack.ai
For GDPR-related inquiries, you may also contact your local data protection authority. For CCPA-related inquiries, California residents may contact the California Attorney General's office.

