Privacy Policy
Effective June 26, 2026 · Ludian.ai · Zero-Trust Architecture
1. Our Privacy Posture
Ludian.ai is designed under a zero-trust data architecture. We minimize what we collect, isolate tenants at the database row level, and never train production models on proprietary source code, business logic, or personally identifiable information (“PII”).
2. Information We Collect
- Account information. Name, email address, and organization, provided during sign-up or Google OAuth.
- Vault content. Code, prompts, edicts, and signals that you explicitly submit. Vault content is stored encrypted at rest in your tenant partition.
- Anonymized AST structural fingerprints. Numeric metrics describing the shape of code — language identity, nesting depth, cyclomatic complexity, import-graph topology — stripped of identifiers, comments, string literals, and source content.
- Operational telemetry. Route hits, latency, error stacks, and feature usage required to operate and improve the Service.
3. Training Isolation (Strict)
[LUDIAN.AI] // TRAINING_ISOLATION_GUARANTEE
Ludian’s self-improving model registry ingests only anonymized AST structural metrics — not proprietary code logic, identifiers, comments, string literals, secrets, credentials, customer data, or PII. Vault contents are never used to train cross-tenant models.
4. Tenant Vault Segregation (Row-Level Security)
All tenant data is segregated using Postgres Row-Level Security (RLS) on every public-schema table. Every read and write is constrained by auth.uid()-scoped policies; cross-tenant reads require a security-definer function with an explicit audit trail to the Logic Ledger.
5. How We Use Information
- To provide, operate, and improve the Service.
- To enforce safety controls (inspection workflow, SLM guardrail, anomaly detection).
- To meet legal, tax, and regulatory obligations.
- To communicate service updates and security advisories.
We do not sell personal information and do not share Vault contents with third parties except as required to operate subprocessors (cloud hosting, model providers you explicitly enable).
6. Compliance Posture
- GDPR (EU/UK). Lawful basis: contract performance and legitimate interest. Data subjects have rights of access, rectification, erasure, restriction, portability, and objection.
- CCPA / CPRA (California). California residents have the right to know, delete, correct, and opt out of sale/sharing (we do not sell or share for cross-context advertising).
- Third-party attestation. Ludian does not currently publish a SOC 2 or equivalent third-party attestation report. Security, availability, and confidentiality controls are described in this policy and in the Trust Center.
7. Data Deletion & Subject Rights
You may request export or deletion of your account and Vault contents at any time. We honor verified deletion requests within thirty (30) days, except where retention is required by law (e.g., audit history retained for 7 years). To exercise rights, contact sam@masterybusinessamerica.com.
8. Retention
- Account & Vault content: until deletion is requested.
- Operational telemetry: 13 months.
- Audit history (Logic Ledger): 7 years.
- Anonymized AST fingerprints: retained indefinitely (non-reversible, non-identifying).
9. Security
Encryption in transit (TLS 1.2+) and at rest (AES-256). Secrets managed via a dedicated vault with rotation. Production access is least-privilege, MFA-enforced, and audit-logged. Watermark signatures rotate on secret-version change. Continuous security scanning runs on every deploy.
10. International Transfers
EU/UK customers may pin data residency to the EU region. Cross-region transfers, where applicable, rely on Standard Contractual Clauses (SCCs).
11. Children
The Service is not intended for individuals under 16. We do not knowingly collect data from children.
12. Changes to this Policy
Material changes will be posted with a new effective date and, where required, communicated to account holders.
13. Contact
Privacy inquiries, data subject requests, and breach notifications: sam@masterybusinessamerica.com.