Privacy Policy
Effective: 2026-07-10. Applies to the Lullad service (CLI, gateway, and lullad.com web app).
What we collect
Nothing about your prompts or generated responses. The CLI integration reports only ad-serving events needed for rewards. It does not read, store, or transmit the prompts you send or the responses you receive.
What we do collect for your account and bound devices:
- Your verified account email and a random device token used to bind each client to that account.
- An impression event when an ad line has been visible for a few seconds (ad ID, dwell time, timestamp).
- A click event when you click an ad (ad ID, timestamp).
- Your IP address at the request level for anti-fraud rate limiting. Not stored beyond the fraud check window.
- Points balance and history (your ledger, tied to the device token above).
What we don't
- Read, log, or transmit prompts, model responses, terminal output, or files from your tools.
- Sell, share, or hand device data to third parties beyond what's necessary to serve an ad request.
- Track you across sites for advertising other than serving Lullad's own ad slot.
- Fingerprint your browser or device beyond the random device token you were issued.
What happens when you click an ad
You are sent to a Lullad landing page (lullad.com/c/<ad-id>), which verifies the click on our server and redirects you to the advertiser's URL. The advertiser learns that traffic came from Lullad but not your identity.
Deleting your data
To reset a device, remove its local Lullad token. To delete server-side ledger data for a device, email hello@lullad.com with your user id (visible in lullad status) and we'll remove it.
Contact
Questions or concerns: hello@lullad.com