Privacy Policy

Effective date: pending

DRAFT — pending legal review. Not yet in effect. This is not legal advice.

Lufer.ai ("Lufer", operated by Fede Urrea, Lufer LLC, Florida — in formation) provides passive cyber-visibility audits and monitoring. This policy explains what we collect and how we handle it.

What we collect

The domain you submit, your email address, your industry and language preference, and an optional business name. For paid subscriptions, Stripe collects your payment details — we never see or store your full card number.

The audit results we produce about your domain (email-authentication posture, SSL health, publicly observable ports, and public breach records naming your domain).

How we use it

To run your requested audit and email you the report, and — if you subscribe — to monitor your domain and alert you to new findings. Every scan is logged with a written reason for accountability.

Passive only

We only read public information — public DNS, SSL Labs, Shodan, and Have I Been Pwned. We never connect to, authenticate against, or otherwise touch your infrastructure.

Who we share it with

We do not sell, rent, or share your data. We use a small set of subprocessors strictly to operate the service: Cloudflare (hosting, DNS, storage), Anthropic (report generation — your data is NOT used to train any model), Shodan, Have I Been Pwned and SSL Labs (public lookups), Resend (email delivery), and Stripe (payments). We never use your data for advertising, data-broker resale, or AI training.

Retention and deletion

You can ask us to delete your data at any time by emailing audit@lufer.ai. If you opt out, we remove your personal information within 30 days and add you to a permanent exclusion list — checked before every request, so a later submission for the same address or domain is refused. That exclusion entry deliberately outlives the deletion: it stores only a one-way form of the address, because forgetting it along with everything else would let us contact you again.

Your consent and choices

We only audit a domain when the requester confirms the request by email (double opt-in). We will not scan a domain on behalf of someone who does not control the associated inbox, and we decline requests to scan third parties (e.g. a competitor).

Your rights

You may request access to, correction of, or deletion of your personal data. If you have questions about your rights under laws such as the CCPA or GDPR, contact us and we will respond.

Questions about this policy: audit@lufer.ai.

← Back