Back to home

Luxi Privacy Policy

Data actually processed by the Luxi website, feedback, anonymous diagnostics, and desktop client.

Last updated: 2026-09-03

Scope

This policy applies to luxi.dougoos.com, its download service, product feedback, and the optional anonymous diagnostics feature in the Luxi desktop client.

Local task data

Luxi is local-first. Feedback and anonymous diagnostics do not upload full tasks, full conversations, raw logs, tool inputs or outputs, prompts, file paths, or user files. Only when you actively like, dislike, or submit feedback about a response does the client send the immediately preceding question and that response as described below.

Website data

  • Account: name, email, non-reversible password verification data, session data, and a network identifier used for security and abuse prevention.
  • Website feedback: account ID, account email, category, optional rating, message, submission time, and status.
  • Essential cookies: authentication session, language, and interface preferences.

We do not store a raw IP address in feedback records. The server applies HMAC with a Luxi-held secret and stores only the resulting network digest for rate limiting.

Desktop feedback data

Only when you press Submit, the client sends:

  • category, optional rating, optional contact email, and your message;
  • Luxi version;
  • macOS version;
  • CPU architecture (Apple silicon or Intel);
  • Luxi interface locale;
  • a locally generated random installation identifier.
  • PNG, JPEG, or WebP images that you actively select or paste (up to six).

When you like or dislike a response, the client sends that action, the preceding question, the current response, the app version, and the basic environment fields above. Detailed response feedback also sends the text you enter and images you actively choose. The server stores only an HMAC digest of the installation identifier, not the original value. Diagnostic logs and other session content are not attached automatically.

Optional anonymous diagnostics

Anonymous diagnostics are enabled by default in the Luxi desktop app. You can turn them off at any time under Settings → Privacy & Diagnostics. Turning them off immediately stops collection and deletes queued events and the rotating anonymous identifier.

Diagnostics are created only when an Agent ultimately fails or a related process crashes. They contain a strict allowlist: minute-rounded time, a controlled error code, up to eight package-internal Luxi/DeepSeek/Electron/Node locations, enumerated lifecycle steps, coarse app and runtime version categories, and a random identifier rotated every 30 days. Luxi does not read or send raw error messages, raw logs, conversations, prompts, tool parameters or results, commands, file contents or names, workspace paths, usernames, hostnames, model paths, URLs, secrets, or proxy addresses. The server stores only HMAC digests of the anonymous client and network identifiers, never their original values.

Diagnostic event details are retained for 30 days. Daily error aggregates with no client identifier are retained for 180 days. The network HMAC is used only for short-term rate limiting and is deleted with expired rate-limit records.

Use and retention

We use this information to provide accounts, show feedback status, investigate product issues, improve Luxi, and prevent abuse. Feedback text, response context, reactions, image attachments, and anonymous diagnostics are available only to authorized administrators. Images are stored privately without a public hostname. Except for the diagnostics periods above, we retain data for as long as necessary for these purposes and applicable legal requirements.

Service providers

Cloudflare Workers, D1, and R2 host the website, database, and downloads. We do not sell personal information. We disclose necessary information only to operate the service, meet legal obligations, or protect users and the service.

Your choices

Desktop feedback may be anonymous; contact email is optional. Website feedback requires an account so you can see history and status. Contact hello@luxi.hebox.one to request access, correction, or deletion of website data associated with you.

Security and changes

We use HTTPS, access controls, least privilege, and identifier hashing. No Internet service can guarantee absolute security. We will update the date on this page and provide an appropriate notice for material changes.

Contact

For privacy questions, email hello@luxi.hebox.one.