Privacy Policy
Last updated: July 17, 2026
This policy explains how Lokuna Inc. (“Lokuna”, “we”) collects, uses, discloses, and protects personal information in connection with the Lokuna service at app.lokuna.com. It is written to satisfy the transparency requirements of Quebec’s Act respecting the protection of personal information in the private sector (as amended by Law 25), PIPEDA, and — for users in the European Economic Area/UK — the GDPR.
1. Who is responsible
For operator accounts (the businesses that subscribe to Lokuna), Lokuna determines the purposes of processing and is the organization responsible (controller). For end-customer information (the customers of those businesses), the operator is responsible (controller) and Lokuna acts as its service provider (processor) under a Data Processing Addendum. If you are an end-customer, direct requests about your information to the business you have the relationship with; we will assist them in responding.
Person in charge of the protection of personal information (Privacy Officer): Elliot Charette, Founder & CEO — reachable at info@lokuna.com. This designation is published in accordance with Law 25.
2. Information we collect
Operator account information (from you)
- Identification and contact: name, business email, company name, website, timezone.
- Credentials: password (hashed by our authentication provider), session cookies.
- Configuration: sender identities, brand voice settings, offer guardrails, business profile facts you provide, and — encrypted — credentials for email/SMS providers you connect.
- Billing: your Lokuna subscription and metered-usage records. Payment card details are collected by Stripe directly; we never receive card numbers.
- Support and correspondence with us.
End-customer information (processed for operators)
- From the operator’s connected Stripe account: name, email address, phone number, subscription plan, billing status, subscription amounts (MRR), start/renewal/trial dates, timezone, and language.
- Message and engagement records: emails and SMS sent by the retention agent, delivery, open, click, bounce, and complaint events, and unsubscribe/STOP status.
- Content end-customers write: replies to emails and SMS, and free-text answers on the cancellation page (for example, the reason for cancelling).
- Where the operator connects a support tool (Intercom, Zendesk, HubSpot, Freshdesk, Help Scout): ticket status and sentiment signals associated with the customer.
- Derived signals: churn-risk and account-health scores computed from the above.
We do not collect government identifiers, payment card numbers, health, or biometric information, and we ask operators not to submit such data to the Services.
3. How we use information (purposes)
- Providing the Services: detecting churn and payment risk and taking the retention actions the operator has authorized (messages, offers, the cancellation page).
- Generating message copy with AI (Section 5).
- Billing, including computing metered Performance Fees.
- Security, abuse prevention, and troubleshooting.
- Communicating with operators about their account and the agent’s activity (e.g., weekly digests).
- Producing aggregated, de-identified statistics that do not identify anyone.
We do not sell personal information, do not use end-customer information to market Lokuna itself, and do not use your data to train our own or third-party AI models.
Where the GDPR applies, our legal bases are: performance of a contract (providing the Services to operators), legitimate interests (security, service communications, de-identified analytics), and consent where required. Operators are responsible for their own lawful basis to contact their customers.
4. Automated processing
Churn-risk scoring, send decisions, and retention-offer selection are performed by automated rules applied to the information described above, without human review unless the operator enables a review mode. If you are an end-customer and wish to make observations about, or request human review of, an automated retention decision that affected you (for example, an offer you were or were not shown), contact the business you deal with or info@lokuna.com; a person will review the decision.
5. AI-generated content
Message copy, cancellation-page copy, and reply drafts are generated by large language models operated by OpenAI. Relevant customer context (such as name, plan, billing status, churn-risk factors, and text the customer wrote) is transmitted to OpenAI for this purpose. Under our agreement with OpenAI, API data is not used to train their models. Decisions about money — discount amounts, pauses, whether to send — are made by deterministic rules, not by the model. See the AI Disclosure.
6. Who receives information (service providers)
We share personal information only with the service providers below, only for the purposes shown, under contracts that restrict their use of it:
| Provider | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database, authentication, and hosting of all service data | United States |
| Stripe | Source of operator-connected billing data; Lokuna subscription billing | United States / global |
| OpenAI | Generation of message and page copy (Section 5) | United States |
| Vercel | Application hosting and delivery | United States / global |
| Resend | Email delivery (platform default; operators may connect their own provider) | United States |
| Sentry | Error monitoring and diagnostics | United States |
| Cloudflare | Inbound email routing | Global |
| Upstash | Rate limiting | United States / global |
In addition, when an operator connects their own email, SMS, or support provider (e.g., SendGrid, Amazon SES, Postmark, Gmail, Outlook, Twilio, Vonage, MessageBird, Plivo, Intercom, Zendesk, HubSpot, Freshdesk, Help Scout), messages and related data flow through that provider under the operator’s own agreement with it. We may also disclose information where required by law, to protect rights and safety, or in a merger or sale of the business (with notice).
7. International transfers (information leaves Quebec and Canada)
Our service providers store and process personal information in the United States. Before communicating personal information outside Quebec we assess, as required by Law 25, whether it will receive adequate protection, and we bind each provider contractually — including, where the GDPR applies, the European Commission’s Standard Contractual Clauses. By using the Services, operators instruct us to process end-customer information with these providers.
8. Retention and deletion
- Operator account and end-customer information is retained while the operator’s account is active.
- Sent-message records are kept as an audit and billing-dispute trail for the life of the account.
- Deleting an operator account permanently deletes the workspace and all data in it — customers, events, messages, and archives — and can be done by the operator directly from Settings.
- Earlier deletion of a specific end-customer’s information can be requested through the operator (or via info@lokuna.com); see Section 9.
- Unsubscribe and STOP suppressions are retained so that the choice keeps being honored.
9. Your rights
Subject to applicable law (Law 25, PIPEDA, GDPR), you may request: access to your personal information; correction; deletion; a copy in a structured, commonly used format (portability); withdrawal of consent; and information about how your information has been used or disclosed. End-customers should address requests to the business they deal with — the controller — and we will assist that business; you may also contact us directly and we will forward the request. We respond within 30 days. You will not be discriminated against for exercising rights.
If you are unsatisfied with our response, you may complain to the Commission d’accès à l’information du Québec, the Office of the Privacy Commissioner of Canada, or your local EEA/UK supervisory authority.
10. Security
Safeguards include encryption in transit (TLS) and at rest, application-level AES-256-GCM encryption of connected-provider credentials, row-level tenant isolation with enforced workspace scoping, signature verification of provider webhooks, access controls, and security review of changes. No system is perfectly secure; we will notify affected parties and regulators of confidentiality incidents as required by Law 25, PIPEDA, and the GDPR.
11. Cookies
We use only the cookies necessary to operate the service (authentication/session) and an error-monitoring tool; see the Cookie Policy. We do not use advertising or cross-site tracking cookies.
12. Children
The Services are for businesses and are not directed to minors.
13. Changes and contact
We will post changes here with a new date and notify operators of material changes. Contact: Privacy Officer, Lokuna Inc., 2439 rue des Palmipèdes, Montréal, Québec H4R 0J2, Canada, info@lokuna.com.