Privacy Policy
This policy explains what personal data WebDIY collects, how we use and share it, how your prompts and generated code are processed, how long we keep it, and the rights you have over it.
Overview
This Privacy Policy explains how Lumeio, Inc. (a Delaware corporation), which operates WebDIY (the “Service”), collects, uses, shares, and protects your personal data. For the personal data described here, Lumeio acts as the controller.
Separately, when you use the Service to build applications that collect data from your own end users, you are the controller of that data and Lumeio acts as your processor — see Your responsibilities.
Information we collect
Information you provide
- Account information — your email address (required to sign in), and, if you use Google sign-in, the basic profile information Google shares (such as name and email). You may add a display name and preferences.
- Content you submit — your prompts, chat messages, uploaded files and attachments, and the code and applications the Service generates for you (your “Inputs” and “Generated Output”).
- Payment information — when you subscribe to a paid plan, our payment processor collects and processes your payment details. We do not store full card numbers.
- Communications — information you provide when you contact support or otherwise communicate with us.
Information we collect automatically
- Device and log data — IP address, browser and device type, and timestamps.
- Security and audit data — sign-in and security events, including IP address, user-agent, approximate location (country), and bot-detection signals, used to secure accounts and prevent abuse.
- Usage data — how you interact with the Service, and metering data such as tokens and credits consumed per request.
- Cookies and similar technologies — see our Cookie Policy.
We ask that you not submit sensitive personal data (such as health, precise geolocation, or government-identifier data) in your prompts, files, or generated apps.
How we use your information
We use personal data to:
- provide, operate, maintain, and support the Service, and generate output in response to your Inputs;
- authenticate you, secure accounts, and detect, prevent, and investigate fraud and abuse;
- process payments and manage subscriptions and credits;
- communicate with you about the Service, including service and security notices;
- analyze usage to understand and improve the Service; and
- comply with law and enforce our terms.
Where the GDPR or similar laws apply, we rely on these legal bases: performance of a contract (to provide the Service), legitimate interests (security, fraud prevention, and improving the Service), consent (for example, non-essential cookies and marketing), and legal obligation.
How your prompts and output are processed
To build and edit your projects, your prompts, chat history, uploaded files, and the code the Service generates are stored as part of your project and are sent to third-party AI providers — including Anthropic, OpenAI, Google, and xAI (see Sub-processors) — solely to generate responses for you. These providers process your content only to provide the service and do not use it to train their own models.
Your responsibilities for apps you build
Applications you build with the Service may collect and process personal data from your own end users (including through the databases and authentication we provision for your projects). For that data, you are the controller and we are your processor. You are responsible for:
- giving your end users a compliant privacy notice and obtaining any required consents;
- honoring your end users’ privacy rights and requests;
- complying with laws that apply to your application, including children’s-privacy laws (such as COPPA) where relevant; and
- not using the Service to process sensitive data unless permitted and properly safeguarded.
Data retention and deletion
We keep personal data for as long as your account is active and as needed to provide the Service, then delete or de-identify it, subject to the exceptions below.
| Data | Retention |
|---|---|
| Account and project data (prompts, generated code, files) | Kept while your account/project is active; deleted after you delete the project or account |
| Deleted accounts | Deleted within 30 days of your deletion request, subject to the exceptions below |
| Security and audit logs (incl. IP, user-agent, country) | Up to 90 days |
| Backups | Deleted on a rolling basis within a limited period after the source data is deleted |
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; to withdraw consent; and to opt out of the sale or sharing of personal data and of targeted advertising. You also have the right not to be discriminated against for exercising these rights.
To exercise your rights, use your account settings where available, or contact us at compliance@web.diy. We will verify your request and respond within the time required by law. If we decline, you may appeal by replying to our response. EU/UK/Swiss users may also lodge a complaint with their supervisory authority.
US residents: see our US State Privacy Notice for state-specific rights (California, Colorado, Connecticut, Virginia, and others) and how to submit a “Do Not Sell or Share” request, including via Global Privacy Control.
International data transfers
We are based in the United States, and we and our providers process data in the United States and other countries. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK Addendum.
Security
We use administrative, technical, and organizational measures — including encryption in transit, access controls, and monitoring — designed to protect personal data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Do not include secrets, passwords, or API keys in your prompts or shared content.
Children's privacy
The Service is not directed to children under 13 (or under 16 in the EU, or the higher age required where you live). We do not knowingly collect personal data from children under those ages. If you believe a child has provided us personal data, contact compliance@web.diy and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. If a change is material, we will provide notice and update the “Last updated” date above. Your continued use of the Service after the change takes effect means you accept the updated policy.
Contact us
For privacy questions or to exercise your rights, contact Lumeio, Inc. at compliance@web.diy, or by mail at Lumeio, Inc., 16192 Coastal Highway, Lewes, DE 19958, United States.