Privacy Policy

What information is collected, why it is collected, and how you maintain control of your data.

Overview

This Privacy Policy explains what information is collected and why it is collected. Account changes, exports, and deletions are currently handled by emailing info@lifub.com — there is no self-serve account dashboard yet.

Depending on your use of the Lifub website and its products, two types of information are collected: personal data and non-personal data.

Controller (Art. 4 No. 7, Art. 13(1)(a) GDPR)

Alexander Orlov (natural person, trading under the unregistered name "Lifub")
Clementine-von-Braunmühl-Weg 11, 81541 München, Germany
E-Mail: info@lifub.com
Data-protection enquiries: info@lifub.com

The controller operates as a natural person under the Kleinunternehmer scheme (§ 19 UStG). No Data Protection Officer is mandatory because § 38 BDSG only requires one where 20 or more persons are regularly engaged in personal-data processing. The primary contact for data-protection enquiries is info@lifub.com.

Legal bases for processing (Art. 6 GDPR)

Art. 6(1)(b) — Contract performance
Account creation, API key issuance, delivery of purchased services, requested Monitoring email verification and alerts, and pre-contractual communication initiated by you (e.g. emailing info@lifub.com to request a service).
Art. 6(1)(f) — Legitimate interest
IT security via server logs (Recital 49 GDPR), anti-abuse rate limiting on anonymous API traffic, basic aggregated usage statistics without user-level tracking, and bot / AI-agent recognition (Analytics) from server-side request fingerprints for fraud / abuse prevention (Recital 47 GDPR).
Art. 6(1)(c) — Legal obligation
Retention of invoicing / accounting records for 10 years per § 147 AO.
Art. 6(1)(a) — Consent
Only where explicitly collected (e.g. opt-in to non-essential communication). None is required or requested for using Lifub products today.

Retention periods

Recipients / processors

A processor may use infrastructure or subprocessors outside the EEA. Where an international transfer is unavoidable, we rely on Art. 46 GDPR safeguards (Standard Contractual Clauses).

Site Audit reports

Site Audit fetches and transiently analyzes the public page selected by the user. Every completed browser report is published under an unguessable bearer UUID and kept for 90 days. Saving a browser snapshot adds its label only to local browser history; it does not make another server copy or extend the underlying report's expiry. Server-side API or MCP snapshots use the same 90-day TTL. A direct API or MCP audit requested without sharing or snapshot storage is not retained as a report. Stored reports contain bounded technical evidence, not the fetched response body, request headers, or cookies. Recent-site and browser-created snapshot-label history stays in the user's browser and is not sent to Lifub.

Monitoring email notifications

Monitoring works without an account or email address. If you explicitly enable email notifications, we store the address under your unguessable siteId and send a one-time UUID to prove that you control the mailbox. Only a SHA-256 hash of that UUID is stored in Monitoring state, it expires after 15 minutes, and successful verification consumes it. The raw UUID necessarily appears in the delivered verification message and may remain in sender or recipient mail systems under their retention settings. The verified address is used only for requested incident, recovery, and verification messages — never marketing. You can remove pending or verified Monitoring configuration at any time in the Monitoring gadget.

How our email is delivered

Every message Lifub sends — Monitoring incident, recovery and verification messages, the Site Search setup-information message, and Site Audit voucher delivery — is delivered by our own EU-hosted server straight to your mail provider. No third-party sending service or SMTP relay sits in between. Your provider necessarily receives the message and processes it as your mail host rather than ours.

A Site Audit voucher-delivery message carries a bearer credential. Anyone who reads that voucher can spend its remaining paid audits. Keep it private; retrying fulfillment for the same settled provider transaction returns the same voucher rather than another balance.

The Site Search setup-information message carries a credential on purpose. It is sent to the address you enter in the Getting Started gadget, which is labelled accordingly, and it contains your Site ID and your Site Secret — the value that authorizes crawls, page writes and profile changes for that index. Treat it like a password: we cannot recover it for you, and anyone who reads that message controls the index.

Two mechanisms exist so that a delivery problem neither loses your message nor turns us into a source of junk mail, and both retain data for a bounded period — see Retention periods above. A message a receiver refuses temporarily is held whole and retried for a little over 5 hours. An address a receiver refuses permanently, as nonexistent, is recorded for 30 days and sent nothing further; if that was a mistake, tell us and we will clear the entry immediately.

Your rights (Art. 15–22 GDPR)

To exercise any of these rights, email info@lifub.com. We respond within one month (Art. 12(3) GDPR). We may verify your identity by requiring the request to come from the email address registered with the service.

Supervisory authority

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for this service is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach, Germany
lda.bayern.de

Types of Data

Personal Data

As defined in GDPR, or "Personally identifiable Information" (PII), is any information that may be used to identify, contact, or locate you as an individual.

Non-Personal Data

Information that cannot be used to identify or contact you. E.g., browser settings, search queries, and statistical data involving the use of Page Finder website.

When Data is Collected

  1. When you integrate Page Finder into your website
  2. When you log in to access your Page Finder dashboard
  3. When you optionally enter an address for Monitoring email notifications
  4. When you simply browse this website

Page Finder Integration — What Data is Collected from Your Users?

When we process your visitors' data on your behalf as a data processor under the Data Processing Agreement, we permanently ensure that our operations are executed in accordance with GDPR requirements. To make sure your privacy is protected:

User's Search Query

Search queries provide the core of your search analytics. This information is aggregated in your dashboard and is not personally identifiable. Stored until you delete your account.

User's IP Address

Used to ignore logging from certain users and to prevent spam and abuse techniques. Blocked-IP entries (anti-abuse list) are retained for 14 days. General server access logs that incidentally contain IP addresses are retained for 30 days per the "Retention periods" section above.

HTTPS and API traffic uses TLS 1.2 or later; direct email uses STARTTLS when the receiving server offers it.
What we store about your end users: their search query (Site Search) or their IP address (IP Intelligence API) for the duration of the service relationship + 30 days, then deleted. We do not store names, emails, or other contact data of your end users.

Analytics — What Data is Collected from Your Visitors?

Analytics is a web-analytics tag whose purpose is bot and AI-agent recognition. When you embed it we act as your data processor under the Data Processing Agreement. By default Analytics sets no cookies and assigns no cross-site identifier — it never follows a visitor across different websites. A site owner may optionally enable a single first-party, same-site cookie to tell new visitors from returning ones (see Returning-visitor cookie below); it is off unless the owner turns it on. To tell real humans from bots, Analytics processes and stores server-side request fingerprints for each visit:

The IP address is personal data under the GDPR, and the pseudonymous hash that replaces it is treated as personal data too — a hash is pseudonymisation, not anonymisation. We process these fingerprints on the basis of Art. 6(1)(f) legitimate interest — fraud and abuse prevention (Recital 47), which is the core function you embed Analytics for. The data is scoped to your individual site, used only to compute each visit's human / bot verdict and your aggregated analytics, and is never used for cross-site profiling, advertising, or sold to anyone. Retention follows the "Retention periods" section above. We store no names, emails, or other contact details of your visitors.

Returning-visitor cookie (optional, off by default)

A site owner may switch on a single first-party cookie (loxal_vid) so Analytics can distinguish new from returning visitors. It holds only a random per-browser id, is same-site only (never read on any other website), is no advertising or cross-site identifier, and expires after ~180 days. Because it is not strictly necessary, it is written only with the visitor's consent — obtained either through Analytics' own built-in consent banner (with an equally-prominent Accept / Reject) or through the site owner's own consent platform. With the cookie off (the default) Analytics is fully cookieless.

What we collect when you request access

Access that requires approval is granted manually by email. When you email info@lifub.com to request a Free or Pro API key (or a managed Site Search install), we collect only what you supply:

How we use this information

  1. To issue an API key and reply to you.
  2. To understand how the service is being used so we can prioritise.
  3. To send service messages (e.g. key revocation notice). We do NOT send marketing emails — there's no list to be on.

To update or delete your record, email info@lifub.com. There is no self-serve dashboard / "Profile settings" UI yet — the current operating scale does not justify building one. We respond within one month per Art. 12(3) GDPR.

Vynx full browser extension build

Vynx is our browser extension: multi-provider AI chat, a Browser Agent that acts in a visible tab, an MCP Bridge that lets a coding agent drive the browser, and developer power tools. Because it runs inside your browser, it is worth being precise about what it reads, what leaves your device, and what never does. We operate no server-side profile of your extension use: there is no analytics, no advertising, and no browsing-history collection.

What the extension reads

What leaves your device, and to whom

Your prompts, your Browser Agent instructions, and any page content you ask an agent to work with are sent to the AI provider you selected — Anthropic, OpenAI, Google, GitHub, Perplexity, xAI, DeepSeek, Moonshot, MiniMax, Z.ai or Lifub — inside your own session with that provider, and are then governed by that provider's privacy policy. Choosing the provider is choosing the recipient. Nothing else is transmitted, and the extension sends nothing to us that you did not direct at the Lifub API yourself.

What stays on your device

Vynx no longer contains a password vault. That surface became the separate Keyring extension on 28 August 2026, and Vynx now ships no vault code and no clipboard access on any platform.

Permissions that look alarming, and why they exist

The extension's source is public at github.com/loxal/lifub, so every claim above can be checked rather than taken on trust. Questions: info@lifub.com.

Keyring browser extension

Keyring is our standalone password and passkey manager. It is a single-purpose extension: it contains no AI, no browser agent, no diagnostics and no bridge code. It is currently a beta, distributed unlisted, and its behaviour may still change.

The property that matters most: encryption and decryption happen in your browser, and we cannot read your entries. Your local Vault password and your recovery phrase never leave your device. What synchronises to the Lifub API is ciphertext, and we hold no key that opens it. There is no sign-up and no account — a vault is proven by a cryptographic challenge, not by an identity we hold.

What leaves your device, and to whom

Nothing else is transmitted. Keyring sends no page content, no page URLs, no browsing history, no cookies and no analytics, and it contains no advertising and no third-party service.

What stays on your device

Permissions that look alarming, and why they exist

Questions: info@lifub.com.

Vynx Store distribution build

The Vynx build distributed through browser and app stores is deliberately smaller than the full build. It includes first-party Lifub AI chat, an offline German-English dictionary, page dark mode, cookie-banner dismissal, and, on Chrome and macOS, Picture-in-Picture. The iOS build omits Picture-in-Picture and keyboard commands. Store builds do not include third-party provider sessions, the Browser Agent, MCP Bridge, HAR capture, or custom request headers.

Local page processing

These tools inspect or modify supported pages locally. Vynx does not send page content, visited URLs, dictionary search terms, cookie values, or credentials to Lifub from the Store build.

Network requests

What stays on your device

Extension storage keeps the selected theme and model, cookie-banner preference, domains where you enabled dark mode, and Picture-in-Picture preferences on platforms that include it. The dictionary keyboard command writes a one-shot local focus timestamp that the popup deletes immediately after reading, whether it is fresh or stale. IndexedDB holds the downloaded dictionary. Chat messages remain only in memory for the lifetime of the popup. Vynx has no advertising or third-party analytics, does not sell or share this data, and does not use it for credit, lending, or advertising decisions.

Chrome Web Store Limited Use

Vynx's use of information received from Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Vynx handles user data only to provide or improve the disclosed user-facing features and their security; it does not use or transfer that data for advertising, data brokerage, creditworthiness or lending, and does not permit humans to read chat content except with the user's specific consent or where access is necessary for security or legal compliance.

Payment Information

Site Audit normally uses a fixed-price, one-time Stripe Checkout. Revolut is available only when separately arranged as an operator fallback. Neither payment route creates a subscription or automatically issues the voucher. Lifub manually verifies the settled payment and delivers the bearer voucher by email. Lifub processes the checkout delivery email to verify and deliver the purchase; delivered messages remain subject to the sender's and recipient's mail-retention settings. Lifub stores the provider name, purchase-reference UUID, transaction and voucher hashes, balance, and issuance time needed for replay-safe fulfillment and accounting. Raw card number, expiry date, and CVC are submitted directly to the selected provider and are never stored on Lifub's servers.

Website Browsing Data

When browsing our site, you automatically send us non-personal data such as your device's IP address, referring website, pages visited, and browser information. We use this aggregated data to:

Cookies — essential only, no banner

This website uses only strictly-necessary cookies that are essential for the operation of the requested service (e.g. session cookies, CSRF tokens). Per § 25 Abs. 2 Nr. 2 TDDDG, such cookies are exempt from the consent requirement and we therefore do not show a cookie banner. We do not use third-party, advertising, or cross-site tracking cookies. The Analytics product can optionally set one first-party, same-site cookie to recognise returning visitors — off by default, and written only with the visitor's consent (see the Analytics section above); where we run it on our own pages, such as the Analytics demo, it is gated behind an explicit opt-in banner.

If we ever add non-essential cookies, we will request explicit opt-in consent via a banner with an equally-prominent "reject all" option (consistent with DSK Orientierungshilfe Telemedien v1.2, Nov 2024, and VG Hannover, 19 March 2025).

If your browser blocks essential cookies entirely, parts of the service (e.g. session continuity, form submission) will not work. You can still call the public API endpoints with curl without any cookies.

Protecting Your Information

Human administrative access to production is restricted to the operator. HTTPS and API traffic uses TLS 1.2 or later. Production service, root, container, and data contents on Mars are encrypted at rest in LUKS2 volumes. The root passphrase is supplied interactively at boot and is not stored on Mars. The boot, EFI, BIOS, and provider-configuration partitions remain unencrypted but contain no root unlock key. Encrypted off-site archives use a separate key derived from the operator-held recovery passphrase.

Sharing Your Information

We do not sell, rent, trade, or otherwise transfer any personal data without your consent. We do not run analytics, advertising-network integrations, or third-party tracking pixels — see the cookie section below.

Legal Compliance

CalOPPA

California Online Privacy Protection Act compliance—we state exactly what information we collect.

COPPA

Children Online Privacy Protection Act—we do not market to children under 13.

Fair Information Practices

We implement these principles and have updated our breach management process for GDPR compliance.

Data Breach Notification

Should a personal data breach occur and if it is likely to put our users' privacy at risk: