← Home

LUCIFER AI · Legal

Privacy Policy

Effective date: October 10, 2026 · Website: luciferapi.com · Contact: lucifer@luciferapi.com

1. About this policy

This Privacy Policy explains how LUCIFER AI ("we", "us", or "our") handles information when you visit luciferapi.com or use its accounts, AI chat, project and API services, payments, referrals, or support features. It describes current practices and may be updated when those practices change.

2. Information you provide

Depending on the features you use, information may include:

  • Account name, email address, password credentials, date of birth, public account ID, and sign-in or verification details.
  • Optional profile details such as Telegram or X usernames, and referral information.
  • Messages and prompts you submit to AI chat, plus project briefs, API requests, uploaded files, and support messages.
  • Payment and purchase references, amounts, and status needed to process orders, wallet deposits, and purchased services.

Do not include passwords, payment card details, government identifiers, or other sensitive information in chat, project briefs, or support messages unless a feature specifically requires it.

3. Information collected through use

The service and its infrastructure may receive technical information such as IP address, browser and device details, request times, and security or error logs. During account creation, we create a SHA-256 hash of the signup IP address, with an application-specific prefix, for abuse prevention rather than saving that address in the signup-IP field.

We use an HTTP-only session cookie to keep you signed in. The site also uses browser storage for functional purposes: AI chat history and selected model in local storage, and some project-request drafts or download tokens in session storage. Browser storage remains on your device and can be cleared through your browser settings; clearing it may remove saved drafts or chat history.

4. How we use information

We use information as needed to:

  • Create and secure accounts, authenticate users, and send verification or password-reset emails.
  • Respond to prompts, process project and API requests, provide purchased services, and manage referrals and wallet transactions.
  • Provide customer support, prevent abuse or fraud, troubleshoot issues, and maintain and improve the service.
  • Meet legal obligations and protect the service, users, and our rights.

We do not sell personal information.

5. AI chat

When you use AI chat, your prompt and the conversation context you submit are sent from our server to OpenRouter to generate a response, using the model selected in the service. OpenRouter may route the request to the relevant model provider. That provider's handling of the request is subject to its own terms and privacy practices. Chat history is also saved in your browser's local storage for the chat feature. Do not submit information you are not comfortable sending to these providers.

6. Payments

Payments are handled by Razorpay. We use payment and order details returned by Razorpay to confirm and administer purchases or deposits. Payment card or bank credentials are handled by the payment provider, not stored by us as full payment credentials. Razorpay's processing is governed by its own privacy policy and terms.

7. Service providers

We use providers to operate the service and process information for the purposes described in this policy. These include Supabase for account authentication and database services, Cloudflare R2 for file storage, Vercel for hosting and service analytics, OpenRouter and its model providers for AI chat, Razorpay for payments, and an SMTP email provider for service messages. Providers may process information on our behalf or under their own terms when you use an integrated service.

Sign-in options may also use Google, X, or Telegram. If you choose one, that provider processes information under its own privacy terms. The Telegram sign-in option loads a Telegram widget from Telegram.

8. Cookies, storage, and analytics

Essential cookies support account sessions and sign-in security. These include lucifer_session and lucifer_owner_session for authentication, plus short-lived OAuth and Telegram state cookies when you start one of those sign-in flows. A preference cookie named lucifer_cookie_consent records that essential cookies are active, whether you allowed optional analytics, the consent version, and when you made the choice. It is stored for up to 180 days so we can remember your choice. Essential cookies cannot be switched off in the preference panel.

The functional sidebar_state cookie remembers whether a sidebar is expanded for up to seven days. Local storage also remembers your selected theme and chat history. Session storage holds project-request drafts and temporary download tokens. This first-party storage supports features you use and is not used for advertising. Clearing browser storage may remove saved items or interrupt a feature.

Vercel Analytics is optional. It is not loaded unless you explicitly allow analytics in the consent panel. When enabled, we measure views of selected public pages using normalized paths without query strings or project identifiers, and record generic conversion events after a project request, source-code purchase, or API Explorer purchase is verified. We do not send form contents, project names or codes, account or payment identifiers, or prices in these events; wallet deposits are not tracked as conversions. You can reject optional analytics or change your choice at any time using Cookie settings. If you withdraw analytics consent after it has been enabled, the page reloads to stop the active analytics script. Your choice is stored in the preference cookie for up to 180 days.

We do not currently use advertising cookies or marketing pixels. Payment checkout and the Telegram sign-in widget are loaded only after you choose to use those features. Those providers may process information under their own privacy terms.

9. Retention and security

We retain information for as long as reasonably needed to provide the service, maintain account and transaction records, address support issues, prevent abuse, and meet legal obligations. Retention periods can differ by information type and provider. We use reasonable safeguards, including protected session cookies and password hashing, but no internet transmission or storage system can be guaranteed completely secure.

10. Sharing and legal requests

We share information with the service providers described above when needed to deliver a feature. We may also disclose information when required by law or legal process, or when reasonably necessary to protect users, the service, or our rights. We do not sell personal information or share it for third-party advertising.

11. Your choices and requests

You can update certain account details in your account settings and clear locally saved data through your browser. You may also request access to, correction of, or deletion of personal information, subject to applicable law and records we may need to retain. Contact lucifer@luciferapi.com from your account email where possible. We may ask you to verify your identity before acting on a request.

12. Age and international processing

Accounts are intended for people aged 15 or older. We do not knowingly collect account information from anyone under 15. If you believe a person under 15 has provided account information, contact us so we can review it.

Our providers may process information in countries other than the country where you live. Where applicable law requires safeguards for an international transfer, we will take steps required by that law.

13. Changes and contact

We may revise this policy as the service or its data practices change. The effective date below shows when this version was published. For questions or privacy requests, contact us at lucifer@luciferapi.com.

LUCIFER AI · luciferapi.com

Also see our Terms and Conditions.

Last updated: October 10, 2026