Privacy Policy
Effective date: July 20, 2026
This Privacy Policy explains what information Lulu ("we", "us", "our") collects across getlulu.dev, ads.getlulu.dev, and app.getlulu.dev, and how we use it.
The short version
We collect the account information you give us as a publisher or advertiser, and standard website analytics from this site. Our ad-matching mechanism itself is built to not see your end users' personal data โ see "What the SDK does not collect" below. We do not sell your data.
Information we collect
- Publisher accounts: the name, contact email, and (optionally) server URL you provide when registering, plus a hashed API key. We never store your API key in plaintext after issuing it once.
- Advertiser accounts: the company name, contact email, ad copy, destination URL, and category you provide when creating a campaign.
- Website analytics: we use PostHog to collect standard web analytics on getlulu.dev โ pages visited, general device/browser information, and approximate location derived from IP address. This is used to understand how visitors use the site; it is not linked to your publisher or advertiser account unless you separately identify yourself (e.g., by signing up).
What the SDK does not collect
When a publisher's MCP server requests a sponsored slot, the SDK sends only a small, fixed set of allowlisted context fields (such as the tool name and category) to our matching service. It never sends message content, transcripts, user names, emails, or any other personally identifiable information belonging to a publisher's end users โ any such field is dropped before the request leaves the SDK, not filtered downstream by policy.
How we use information
- To operate the service โ matching sponsored slots, tracking conversions, and processing payouts.
- To communicate with you โ account notifications, integration verification, and payout confirmations.
- To improve the product โ understanding usage patterns via website analytics.
- To detect and prevent fraud or abuse.
How we share information
We do not sell your personal information. We share it only with: service providers who help us operate (e.g., email delivery, analytics, payment processing), affiliate and advertiser demand partners โ who receive only conversion-relevant data (such as whether a click converted), never raw publisher or end-user data โ and when required by law.
Cookies and similar technologies
This site uses cookies and local storage, primarily via PostHog, to recognize your browser across visits and measure site usage. You can control cookies through your browser settings; disabling them may affect some site functionality but will not prevent you from using Lulu Ads as a publisher or advertiser.
Data retention
We retain account information for as long as your publisher or advertiser account is active, and for a reasonable period afterward as needed for legal, tax, or dispute-resolution purposes. You may request deletion of your account information at any time โ see "Your rights" below.
Your rights
You may request access to, correction of, or deletion of your personal information at any time by emailing hello@getlulu.dev. Depending on your location, you may have additional rights under laws such as the GDPR or CCPA; we will honor applicable requests consistent with those laws.
Children's privacy
Lulu Ads is a developer- and business-facing service and is not directed at children. We do not knowingly collect personal information from anyone under 16.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated effective date.
Contact
Questions about this policy? Email us at hello@getlulu.dev.
Terms of Service ยท ยฉ 2026 Lulu