Privacy Policy
Effective August 4, 2026 · Last updated September 18, 2026
This document is effective as of August 4, 2026 and is undergoing legal review; it may be updated.
1. Who we are
ggui.ai is operated by Loqu, Inc., a Delaware corporation (“Loqu”, “we”). This policy covers ggui.ai and its subdomains operated by Loqu, including the ggui.ai website, docs.ggui.ai, benchmarks.ggui.ai, console.ggui.ai, status.ggui.ai, registry.ggui.ai, and hosted GGUI — the managed cloud service — and its service endpoints (mcp.ggui.ai, api.ggui.ai, auth.ggui.ai). It does not cover guuey.com, which has its own documents, Loqu’s internal staff-only surfaces such as admin.ggui.ai, or third-party services we link to.
2. Whose data we process
For visitors to and account holders of the surfaces above, Loqu acts as the data controller, and the legal bases in section 8 apply as written.
The service also processes content on behalf of account holders and registered platforms — including identifiers of end-users (issuer and subject), per-render end-user identity, interaction events, and usage records of end-users who may hold no GGUI account. We process that data only to operate the service. If you are such an end-user, please direct data-rights requests to the platform or agent builder responsible for your relationship; if a request reaches privacy@ggui.ai by mistake, we forward it to the responsible party.
3. Data we collect
- Account data — email address and authentication records managed through Amazon Cognito. If you sign in with Google or GitHub, we receive the profile fields those providers share: email address, display name, avatar URL, and the provider’s account identifier.
- Content — what you and your agents submit to the service: prompts, contract specifications, and the interfaces generated from them.
- End-user data — for interfaces served to end-users: namespaced identity, per-render end-user identity, interaction events, and usage records (see section 2).
- Provider API keys you supply (BYOK) — stored at account and per-app level, encrypted with AWS KMS, and never stored or displayed in plaintext; we retain only the last four characters and a hash for re-identification.
- Billing data — your credit balance, an append-only transaction ledger, coupon redemptions, and payment identifiers from our payment processor (Stripe). We never store card numbers; Stripe collects those directly.
- Email addresses of non-account-holders — organization-invite recipients, and status-page subscribers together with verification state and service preferences.
- Usage, device, and analytics data — server logs, and product analytics via PostHog. PostHog sets an analytics cookie (name pattern
ph_<key>_posthog) scoped to.ggui.aiacross our subdomains, with a lifetime of about one year, used for analytics and funnel measurement including automatic event capture. When a page or the console hits an error in your browser, PostHog also records an error report: the error’s type and message, the code location (stack trace), the page address, and the same device and session details as other events; in the console it is linked to your account identity like the rest. We use these reports only to find and fix defects. On ggui.ai, www.ggui.ai and docs.ggui.ai (not the console), PostHog also records a replay of your visit: the page structure, your clicks and scrolling, and your browser’s console output. Anything you type is masked; text shown on the page is not. Replays are kept for 30 days. Events, error reports and replays are processed in the United States (us.i.posthog.com). In the console, this cookie is linked to your account identity. You can clear or block this cookie in your browser settings without affecting the service; see section 9 for Global Privacy Control.
4. How we use data
We use data to provide, operate, and improve the service: authenticating you, generating and serving interfaces, routing LLM requests (including with provider keys you supply), metering usage, billing and fraud prevention, delivering organization invitations and status or incident notifications, product analytics, and support.
5. AI processing disclosures
Platform-routed requests
When generation runs on our provider pool, your content is processed by the LLM providers we contract with: Anthropic (through AWS Bedrock and the Anthropic API), OpenAI, Google Gemini, and OpenRouter (which routes to further downstream model providers). We only enable platform providers whose terms prohibit training on API content: content routed through AWS Bedrock is excluded from model training under the AWS Bedrock service terms, and content sent to the Anthropic API is not used to train models under Anthropic’s commercial terms; equivalent commitments apply to each other enabled provider under its commercial terms.
Bring-your-own-key requests
When you supply your own provider API key, content on that leg is processed under your own agreement with that provider. Loqu makes no training representation for BYOK traffic.
Our own use
Loqu does not use your content to train models.
Social sign-in data
Google user data obtained through Google Sign-In is used solely for authentication and account provisioning. It is never used for advertising, never sold, and shared only with the subprocessors listed below. Our use of Google user data adheres to the Google API Services User Data Policy, including its Limited Use requirements. GitHub profile data is handled the same way: sign-in and account provisioning only.
6. Subprocessors
- AWS — cloud infrastructure and transactional email via Amazon SES (account and billing notices, status notifications, organization invites)
- Anthropic, OpenAI, Google, OpenRouter — LLM inference for platform-routed generation
- PostHog — product analytics
- Stripe — payment processing (Stripe collects card details directly; we never store them)
7. Data retention
- Renders and their event logs (the request, the data contract, the generated interface code, and interaction events) are kept until you delete them: there is no automatic expiry by default, so a card can always be reopened. An agent can bound an individual render with a per-render time-to-live, in which case that render and its events are purged at the TTL plus a seven-day grace window. Blueprints carry no expiry. Deletion happens through a per-render TTL, the account-erasure flow (which walks every app, blueprint, and render you own), or operator takedown. Bounded exceptions: the render cache (24 hours), generation logs (30 days), and the operator audit log (two years).
- Account data is retained while your account is active; deleted accounts are first deactivated and then permanently removed by a scheduled sweep.
- Billing and usage records (credit ledgers, usage rollups) are retained without automatic expiry for accounting and audit; account erasure scrubs personal identifiers from these records rather than deleting them.
- Revoked API keys are kept for a bounded audit window before removal.
- Published registry artifacts and installed copies persist per the Terms of Service; PostHog profiles follow PostHog’s retention settings.
8. Your rights — EEA and UK
Where GDPR or UK GDPR applies, we process personal data on these legal bases: performance of a contract (providing the service), legitimate interests (security, fraud prevention, product analytics), and consent where required. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. International transfers to the United States rely on Standard Contractual Clauses. Where we obtain personal data other than from you directly — for example, an organization member inviting you by email — this policy serves as notice under Article 14. Deletion requests are served by the in-product account-erasure flow in the console or via privacy@ggui.ai; analytics profiles held in PostHog are deleted as a separate step of the same request.
9. Your rights — California
We do not sell or share personal information as those terms are defined by the CCPA/CPRA. California residents have the rights to know, delete, correct, and limit use of sensitive personal information, without discrimination for exercising them. We honor Global Privacy Control signals for opt-out preferences. Requests: privacy@ggui.ai.
10. Children
The service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact privacy@ggui.ai and we will delete it.
11. Security
Data is encrypted in transit and at rest. Provider API keys you supply are protected with AWS KMS envelope encryption; plaintext keys are never persisted. Access to production systems is limited and audited.
12. Changes to this policy
Material changes are announced by email to your account address together with a dated update to this page; non-material edits update the “Last updated” date only. Prior versions are available on request via privacy@ggui.ai.
13. Contact
Data-rights requests: privacy@ggui.ai. General inquiries: hello@ggui.ai. We fulfill data-rights requests within the windows the applicable law sets, across our authentication, database, cache, and analytics systems.