Security

Privacy & security

Learn more about privacy, no training, zero data retention, local storage, DPA, integration data and security boundaries at Lurus.

Authoritative security information

You can find binding details on our current security, privacy, DPA, model and terms pages. There we provide information about GDPR-oriented processing, no training, zero data retention, ISO 27001-certified infrastructure and EU/EEA or EU-region processing for standard and optional model providers. These product guides help you use Lurus but do not replace legal review of your specific use case.

Additional compliance commitments, such as a standalone CLOUD Act assessment, apply only when we clearly state them on our legal or security pages.

AI processing and model providers

No training and zero data retention are central requirements for the models we offer. Our model and privacy pages explain the EU-hosted or EU/EEA operating paths for models and subprocessors. Depending on the feature, content can still be sent to enabled models, tools or integrations for processing.

  • No training means that customer data is not used to train AI models.
  • Zero data retention means that providers do not permanently store prompts and outputs for their own further processing.
  • We list subprocessors and optional model providers in our privacy and DPA materials. Review the current legal pages when a specific provider matters for your use case.

Local storage / zero-knowledge mode

Local storage mode stores chat histories, local messages, token usage data and local artifacts encrypted in the browser on your device. This gives you more control over chat history. However, local chats are not automatically synchronized with the server and cannot be shared like server-side chats.

Important: even with local storage, prompts, attachments and tool requests are sent at runtime to Lurus and to the selected models, tools or connected integrations so an answer can be generated. Local storage primarily affects chat history storage, not all processing during a request.

  • When switching devices, using incognito mode, changing browsers or deleting website data, local histories can be unavailable.
  • Browser storage limits can block local chats or local artifacts; Lurus shows the corresponding storage errors.
  • Team admins can allow, require or disable local storage depending on policy.
  • Exports are the practical backup option if you want to save local chats outside the browser.

Files, tools and integrations

Lurus processes uploaded files for analysis and passes them to the selected model depending on the task. Depending on the storage mode, we provide generated documents or images as private files or local artifacts for browser storage.

Web search and Deep Research retrieve external sources. Through integrations, Lurus accesses only connected providers, uses the permissions granted there and stores OAuth credentials in encrypted form. When you disconnect an integration, Lurus removes the connection; depending on the provider, you may also need to revoke permissions manually in the provider account.

Upload sensitive or special-category personal data only when your internal policies and the specific use case allow it.

Related pages