Last updated October 10, 2026
Privacy policy
Short version: this website keeps your coins in your own browser and runs no trackers. In Lurk itself, we keep what we need to run your rewards, and we never sell it.
Starter draft. This page hasn't had a lawyer's review yet and may change before Lurk launches.
1. Who we are
Lurk turns what a brand's users do into rewards. This policy covers getlurk.com, the dashboard at app.getlurk.com, the Lurk API, the Lurk MCP server and Lurky, our Discord bot. "Lurk", "we" and "us" mean [Company legal name], [registered address].
Lurk has two kinds of people in it. Customers are the brands, builders and their teams who sign up and set Lurk up. Members are the customers' own users, who earn and spend units in a customer's app, site or community.
2. On getlurk.com
This website has no ads, no analytics and no third-party scripts.
- The coins you earn on this page, their receipts and your theme are saved in your own browser's local storage. They never leave your device, and clearing your browser's site data removes them.
- Like every website, our hosting provider sees your IP address and browser details when you load a page, and keeps them in short-lived logs to keep the site running and safe.
- If you email us, we keep the email so we can answer it.
3. What we collect from customers
- Account details: your name, email address, the organization and projects you create, and who on your team can do what.
- Billing: your plan, coins and gems, and invoices. Card details go straight to our payment provider; we never see or store your full card number.
- What you set up: units, rules, templates, views, API keys and agent keys, and the receipts Lurk keeps for every change.
- Usage and logs: requests to the API and MCP server, errors and sign-ins, so we can run Lurk, keep it secure and fix problems.
- Conversations with Lurky: what you ask Lurky in the dashboard, so it can answer and make the changes you ask for.
4. Members' data
When a customer sends Lurk events about their members (for example "checked in" or "posted"), Lurk stores those events, the member's balances and the receipts for every change. We process this data on the customer's behalf and only on their instructions: the customer decides what to send and is responsible for having the right to send it.
If you're a member and want to see, fix or delete your data, ask the brand you use first. We'll help them, and you can always write to us.
5. How we use it
- To run Lurk: evaluate rules, change balances, keep receipts and show you your data.
- To keep accounts and projects secure and to stop abuse.
- To bill you and to tell you about your account, changes and incidents.
- To understand which features are used, so we can improve them.
- We don't sell personal data, and we don't use customers' or members' data to train AI models.
7. How long we keep it
We keep account data while your account is open and for [period] after you close it. Recent events stay in our main database for about 30 days and are then archived to cheaper storage for [period]. Receipts are kept for as long as the project exists, because balances are built from them. When you delete a project, its data is deleted within [period], except what we must keep by law, such as invoices.
8. Security
Data is encrypted in transit [and at rest: confirm with hosting]. Every project's data is kept apart from every other project's, down to the database. Only a person on your team can take changes live, and every change has a receipt you can review. No system is perfectly secure; if something goes wrong that affects your data, we'll tell you without undue delay.
9. Your rights
Depending on where you live, you can ask to see, correct, export or delete your personal data, and to object to or limit how we use it. Email [email protected] and we'll answer within 30 days. If you're in the EU or UK, you can also complain to your data protection authority. Our lawful bases are running our contract with you, our legitimate interest in running and improving Lurk, and, where we ask for it, your consent.
10. International transfers
Lurk and its providers may process data outside your country, including in the United States. Where the law requires it, we use safeguards such as the EU Standard Contractual Clauses.
11. Children
Lurk isn't meant for children under 13 (or under 16 where local law sets that age), and we don't knowingly collect their data. Customers whose communities include young people must get the consent the law requires before sending their data to Lurk.
12. Changes and contact
If we change this policy, we'll update the date at the top, and for important changes we'll email customers before they apply. Questions: [email protected].