Privacy Policy

Effective: 1 May 2026 Last updated: 1 May 2026 Version: 1.0
Core privacy commitment
Your documents never leave your device. Lacuna Labs processes all uploaded files, PDFs, and research corpora entirely within your browser using local computation. No document content, file data, or corpus text is transmitted to Lacuna Labs servers at any time. This is an architectural guarantee, not a policy preference.
Contents
  1. Who we are
  2. Data sovereignty — what stays on your device
  3. What data we collect and why
  4. Legal bases for processing
  5. Data retention
  6. Your rights — GDPR & LGPD
  7. International transfers
  8. Third-party AI providers
  9. Cookies and local storage
  10. Security
  11. Children
  12. Contact and complaints

1. Who we are

Lacuna Labs is a company registered in England and Wales, with registered address at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.

We operate the Gap Intelligence Platform and its three product lines — Lacuna Core, Lacuna Signal, and Lacuna Scope — accessible at lacunalabs.eu and associated subpages.

For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Lei Geral de Proteção de Dados (LGPD), Lacuna Labs Intelligence Ltd is the data controller for personal data collected through our services.

Data Protection contact: hello@lacunalabs.eu

2. Data sovereignty — what stays on your device

Architectural privacy guarantee
The following data types are processed exclusively within your browser and are never transmitted to any server operated by Lacuna Labs or its partners. This is enforced by system architecture — there is no technical pathway by which this data can leave your device during normal platform use.

Gap Intelligence Advisor — special notice

The optional Gap Intelligence Advisor feature transmits a statistical summary of your corpus (term names and frequency counts only — never document content) to a third-party AI provider of your choice. Before any transmission occurs, the platform displays the exact text to be sent for your review and requires your explicit confirmation. You control which AI provider receives this data and may use your own API key.

Commercial and state secrets

Because document content never leaves your device, Lacuna Labs is architecturally compatible with the processing of commercially sensitive, legally privileged, and classified or restricted information. Organisations operating under national security classifications, professional secrecy obligations, or strict trade secret protection programmes may use the core analysis platform without any departure from their information security requirements. Institutional clients requiring formal assurance documentation should contact us at hello@lacunalabs.eu.

3. What data we collect and why

Account data

When you create an account, we collect your name, email address, and password (stored as a cryptographic hash). We use this data to provide access to the service, send transactional communications, and, with your consent, inform you of product updates.

Payment data

Payment processing is handled exclusively by Paddle.com (Paddle Payments Ltd, Judd House, 18-29 Mora Street, London EC1V 8BT, UK), acting as Merchant of Record. Lacuna Labs does not store card numbers, banking details, or payment credentials. We receive from Paddle only a payment confirmation, subscription status, and anonymised billing metadata. Because Paddle acts as Merchant of Record, they are an independent data controller for payment and tax data — their own Privacy Policy governs payment data processing.

Usage data

We collect aggregate, anonymised usage statistics (pages visited, features used, error logs) to improve the platform. This data does not identify individual users and is not linked to account data. Country codes are derived from IP addresses which are discarded immediately after derivation — the IP itself is never stored. In low-volume contexts, a country code may constitute indirect personal data; we retain country-level data only in aggregated form (combined with tier and date) and never linked to individual accounts.

Communications

If you contact us by email, we retain the content of that correspondence for the purpose of responding to your enquiry and for up to 36 months thereafter.

4. Legal bases for processing

5. Data retention

We retain account data for the duration of the active account relationship and for up to 36 months following account closure, unless a longer retention period is required by applicable law. Payment records are retained for 7 years in accordance with the UK Companies Act 2006 and HMRC requirements. You may request earlier deletion subject to Section 6 below.

6. Your rights — GDPR & LGPD

Depending on your jurisdiction, you have the following rights with respect to your personal data:

To exercise any of these rights, contact us at hello@lacunalabs.eu. We will respond within 15 business days. EU and UK residents have the right to lodge a complaint with their national supervisory authority. Brazilian residents may contact the Autoridade Nacional de Proteção de Dados (ANPD).

7. International transfers

Lacuna Labs Intelligence Ltd is incorporated in the United Kingdom. The platform is hosted by Infomaniak SA in Switzerland, which benefits from an EU adequacy decision under GDPR Art. 45. UK personal data transferred to Switzerland is covered by UK adequacy regulations. For users in the European Economic Area, transfers to the UK are covered by the EU adequacy decision for the UK (valid until June 2027, subject to review). For Brazilian users, transfers are covered by contractual safeguards consistent with LGPD Chapter V and ANPD guidance. We will update this section if the applicable adequacy frameworks change.

8. Third-party API keys and external service providers

⚠ Important — third-party data flows
When you configure API keys for external services in Settings, data flows directly from your browser to those providers. Lacuna Labs does not store your API keys and has no access to or responsibility for data transmitted to third parties.

The platform allows you to connect external APIs including AI providers (DeepSeek, OpenAI, Anthropic, Google Gemini), news sources (The Guardian, NewsData.io), patent databases (Lens.org, EPO OPS, PatentsView), and institutional databases.

API key storage — architectural guarantee

API keys you enter in Settings are stored exclusively in your browser's localStorage. They are never transmitted to or stored by Lacuna Labs servers. Lacuna Labs has no technical access to your API keys.

Third-party data flows — your responsibility

When you use a connected service, your API key and any query data are transmitted directly from your browser to that provider, outside Lacuna Labs infrastructure. Each provider's own privacy policy and terms of service govern that data. Lacuna Labs is not responsible for how third-party providers collect, store, process, or share data you transmit to them, nor for their compliance with LGPD, UK GDPR, EU GDPR, or other applicable law.

AI Advisor — specific notice

When activated, the AI Advisor transmits corpus term statistics (term names and frequency counts only — never document content) directly to your chosen AI provider. This is processed under that provider's privacy policy. Do not use the Advisor if your corpus contains classified information, legally privileged material, or personal data of third parties, unless you have verified the provider's data handling practices are compatible with your obligations.

Recommended precautions

9. Cookies and local storage

We use essential cookies only. We do not use advertising cookies, tracking pixels, or third-party analytics. The following data is stored in your browser's local storage:

All local storage data remains on your device and is not transmitted to our servers. You may clear this data at any time by clearing your browser's local storage or site data.

10. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include TLS encryption for all data in transit, cryptographic hashing of passwords, and access controls on all systems. Because document content is processed locally on your device, it is not subject to server-side data breaches. In the event of a personal data breach affecting account data, we will notify affected users and relevant supervisory authorities within the timeframes required by applicable law.

11. Children

Lacuna Labs is not directed at children. We apply a minimum age of 16 as a deliberate policy choice, consistent with the more protective standard available under UK GDPR Art. 8 and EU GDPR Art. 8, notwithstanding that the UK Data Protection Act 2018 permits a minimum age of 13 in certain contexts. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

12. Contact and complaints

Data controller: Lacuna Labs Intelligence Ltd
Trading as: Lacuna Labs
Email: hello@lacunalabs.eu
Address: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom

We take privacy complaints seriously and will respond within 15 business days. If you are not satisfied with our response, you have the right to escalate to the relevant supervisory authority in your jurisdiction.