AI Privacy & Data Retention
This page explains what data Luciq's AI capabilities use, how long it is retained, and the security standards behind it.
For general, per-product data retention, see License Entitlements and Restrictions. For the full list of third parties, see Sub-processors. For PII controls and data deletion, see GDPR.
The short version
AI capabilities are opt-in and off by default.
We only process the non-PII technical data you choose to send.
AI-derived data is retained for the same period as the data it is based on, nothing more.
Your data is never used to train any AI model.
What data do AI capabilities use?
Only the non-PII technical and diagnostic data you choose to send for a given function, for example a crash stack trace, masked logs, or a bug description.
AI capabilities are opt-in and off by default, so if you do not enable them, none of your data is processed by any AI service. Luciq does not need or capture your end users' personal or telecommunications data to operate; we capture technical data and product-engagement signals (such as screen visits or taps), under your control.
How long is AI data retained?
In Luciq
Any AI output shown in your dashboard (a suggested fix, a summary, an issue grouping) is stored alongside the data it is derived from and follows the same retention period as that data type, as defined by your plan in License Entitlements and Restrictions. Enabling AI does not extend retention: an insight derived from a crash follows your Crash Reporting retention, an output derived from a bug follows your Bug Reporting retention, and so on. It is not deleted until that window elapses or you request deletion.
At our AI providers
To produce a result, the relevant non-PII data is sent to an AI model provider, processed, and the result is returned. At this layer the data is automatically and permanently deleted within no more than 30 days (retained only transiently for the providers' abuse and safety monitoring) and is never used to train or improve any model. The AI model providers we use are themselves SOC 2 Type II certified. See Sub-processors.
Isolated compute (code-fix generation)
Capabilities that generate a code fix run inside a dedicated, isolated compute sandbox that is created on demand and permanently destroyed the moment the task completes. Your code and the context used are never written to persistent storage and are never co-located with another customer's workload. There is no retention at this layer.
Is the retention period configurable or fixed?
In Luciq: retention is set by your plan and agreement, and Enterprise plans are configured to match your requirements (through your contract and account team). Data retention can also be extended on request.
At our AI providers: the processing window is fixed and short by the providers' published terms.
Do you use our data to train AI models?
No. Our AI model providers do not use data submitted through their APIs to train or improve their models, and Luciq does not opt in to any data-sharing or training programs.
How do I delete data or control PII?
You control what personal data is captured through masking and the Luciq APIs, and you can remove a specific end user's data on demand with the Delete User API. See GDPR for details.
The security standards behind it
Luciq is built for enterprise security and audited independently. These certifications and controls apply across the platform, including the AI capabilities.
SOC 2 Type II
Certified
ISO 27001
Certified
GDPR
Compliant; DPA available
HIPAA
Compliant; BAA available
Encryption
At rest and in transit
For a security review, a custom questionnaire, or copies of our reports, contact your Luciq account team or [email protected].
Last updated