1. Who we are
The Pharen platform (pharen.ai) is operated by Lucubra LLC, a Washington (USA) limited liability company. For everything this notice covers, Lucubra LLC is the data controller. Reach us at hello@pharen.ai or by mail at Lucubra LLC, 522 W Riverside Ave, Ste N, Spokane, WA 99201-0581, USA.
2. What this notice covers
This notice covers personal data we process about:
- visitors to pharen.ai;
- people who contact us — about early access, support, security reports, or anything else;
- the people on a customer’s team who operate a Pharen account (the console, the CLI, and control-plane APIs).
If you use an app built with Pharen, this notice is not the one that governs your data. Our customers use the platform inside their own apps. For their end users’ data, the customer is the controller and their privacy notice applies; Lucubra processes that data only on the customer’s instructions, under the Data Processing Agreement. To exercise privacy rights over data an app collected about you, contact the app’s developer. If you contact us instead, we will tell the relevant customer and assist them — we cannot answer in their place.
3. What we collect
What you send us. When you email us — early-access requests, support, security reports — we receive your email address and whatever you choose to include. We suggest what’s useful to include; you decide what to send.
Account data. Access to the console and CLI is authenticated with GitHub. The sign-in requests no OAuth scopes at all — it cannot read a repository or an organization, and we never see your password. We read exactly two things from your GitHub profile: your username and your numeric account ID. We do not request or store your email address or your avatar. The access token GitHub issues is used once to read those two fields and then discarded — it is never stored. Your role and your account’s tenant association are held in our deployment configuration, not in a profile we build about you.
Operational data. Operating the console, CLI, or APIs generates logs — IP address, user agent, timestamps, and the actions taken — kept for security, audit, and troubleshooting. Administrative actions on a customer account are recorded with the acting identity.
Site data. pharen.ai is a static site served through a content-delivery network; standard server logs (IP address, user agent, pages requested) exist at that layer for security and delivery.
Billing data — once paid plans launch. When we introduce paid plans, we will keep billing contact details and plan and invoice records. Payment-card details will go directly to our payment processor, Stripe — full card numbers never touch our systems.
4. What we don’t do
- No analytics scripts, no trackers, no advertising pixels on this site. pharen.ai loads no third-party scripts at all.
- We do not sell or share personal data (as U.S. state privacy laws define those terms), and we do not use it for targeted advertising. There is nothing here to opt out of; browser signals like Global Privacy Control are honored trivially, because no covered disclosure exists.
- No marketing lists. We email you about the Service and about things you asked us about. Tell us to stop and we stop.
- No automated decisions. We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you.
5. Cookies
This website sets no cookies. The console sets two, both strictly necessary and neither used for analytics or advertising: a sign-in cookie that lasts up to 30 days and is cleared when you sign out, and a ten-minute cookie that protects the sign-in exchange against cross-site request forgery. The sign-in cookie is scoped to pharen.ai, so your browser also sends it to this site — this site sets nothing, but the cookie travels with the domain. Our content-delivery network may set short-lived, strictly necessary security cookies (such as bot mitigation). We use no analytics or advertising cookies anywhere, which is why you don’t see a cookie banner.
6. Purposes & legal bases
| Purpose | Data used | Legal basis (where GDPR-style laws apply) |
|---|---|---|
| Providing and operating the Service and this site | Account data, operational data | Performance of a contract |
| Security, abuse prevention, and auditability | Operational data, site data | Legitimate interest (running a trustworthy platform) |
| Answering you, and onboarding conversations | What you send us | Legitimate interest (responding to people who contact us, and assessing whether the platform fits what they’re building); consent where required |
| Improving the Service | Operational data (aggregate) | Legitimate interest (understanding how the platform is used so we can make it more reliable) |
| Meeting legal obligations | Whatever the obligation requires | Legal obligation |
7. When we share information
We share personal data only with: service providers that host and deliver the Service under contracts limiting their use of it — Render (hosting), Cloudflare (content delivery and storage), GitHub as the sign-in identity provider, and, once paid plans launch, Stripe for payment processing (the vendors that process Customer Data are listed separately in the Subprocessor Register); authorities, where a law, legal process, or protection of rights and safety genuinely requires it — narrowly, and with notice to you where lawful; and a successor in a merger, acquisition, or sale of the business, bound to honor the commitments in this notice. Never anyone else, and never for their advertising.
8. Where data is processed
We are based in the United States and process data there. If you are in the European Economic Area, the United Kingdom, or Switzerland, data you send us is transferred to the U.S.; where such transfers require safeguards, we rely on the European Commission’s Standard Contractual Clauses (and their UK and Swiss equivalents) with our vendors — email hello@pharen.ai to request a copy of the safeguards we rely on. Lucubra is not certified under the EU–U.S. Data Privacy Framework; the Standard Contractual Clauses are the operative mechanism.
9. Retention
Per category: what you send us (correspondence) is kept for the life of the relationship it belongs to, then as legal obligations require; account data is kept while the account exists, plus the audit records needed to evidence the relationship for as long as law and good records practice require; operational data (logs) rotates on short, fixed schedules — sign-in sessions expire within 30 days, and logs are kept for security and troubleshooting, not archives; site data (delivery-layer logs) is retained briefly by our content-delivery network for security; billing records, once they exist, are kept as long as tax and accounting law requires. When a customer relationship ends, Customer Data follows the deletion windows in the DPA.
10. Your rights
You may have rights to access, correct, or delete your personal data, to receive it in a portable form, to restrict or object to processing, and to withdraw consent where processing rests on it. Lucubra is not currently a “business” as the California Consumer Privacy Act defines the term; we honor these rights for everyone, voluntarily, wherever you live. They cover the data this notice describes — data Lucubra controls (Section 3). For data an app built with Pharen collected about you, Section 2 applies: the app’s developer is the controller.
To exercise a right, email hello@pharen.ai. We respond within the period the applicable law allows: one month where the GDPR or UK GDPR applies (extendable by two further months for complex requests, with notice), and 45 days under U.S. state privacy laws (extendable once by a further 45 days, with notice). We may need to verify that you control the email address or account the request concerns; an authorized agent may act for you with proof of authority. We will not discriminate against you for exercising rights. If we decline a request, we will say why within that period, and you may appeal by replying; the appeal gets a fresh review and an answer within 45 days, and if we deny it we will point you to the complaint route available where you live (in U.S. states with privacy laws, your state Attorney General). In the EEA or UK you may also lodge a complaint with your supervisory authority at any time — though we’d appreciate the chance to address it first.
11. Children
Neither this site nor the Service is directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it. (For our customers’ own apps, the AUP applies a separate, stricter rule: no data of children under 13 without our prior written agreement — different subjects, deliberately different lines.)
12. Security
Data in transit is encrypted with TLS; data at rest is encrypted by our hosting providers; access is limited, credentialed, and logged; and customer data is isolated per tenant by construction — every record is scoped, and unscoped access fails closed. The DPA’s security annex describes the measures in detail, and the architecture page explains the design. To report a vulnerability, email hello@pharen.ai.
13. Changes & contact
When this notice changes, the version and effective date above change with it, and the history below records what moved. For a change that materially reduces protections, we give advance notice to account contacts. Questions, requests, complaints: hello@pharen.ai, or write to us at the address below.
Version history
- 1.0 — September 2, 2026 — initial publication.
The Pharen platform is operated by Lucubra LLC, a Washington (USA) limited liability company, operating the Pharen platform. 522 W Riverside Ave, Ste N, Spokane, WA 99201-0581, USA · hello@pharen.ai