Privacy Policy
Last updated: September 30, 2025
Overview
Redactra ("the Service") is operated by Luxore LLC. This Privacy Policy explains how we collect, use, and protect your information when you use our text redaction service.
Most importantly: Your document content is processed entirely in your browser and is never transmitted to our servers or any third party.
What We Do NOT Collect
- No editor content: Text you paste, files you upload, redaction results, and all content processed in the editor remains entirely on your device. This data is never transmitted to our servers or any third party under any circumstances.
- No keystroke or clipboard data: We do not monitor, log, or transmit what you type or paste.
- No document metadata: File names, timestamps, or any metadata about your documents are not collected or transmitted.
Information We Collect
1. Account Information
If you create an account to access premium features, we collect:
- Email address
- Password (encrypted and hashed—we never see your actual password)
- Full name (optional, if provided during sign-up)
- Authentication tokens and session information
Account data is stored securely using Supabase, a SOC 2 Type II certified authentication provider.
2. Billing Information
If you subscribe to a paid plan, payment processing is handled by Stripe, a PCI-DSS compliant payment processor. We store:
- Stripe customer ID (for managing your subscription)
- Subscription status and tier
- Transaction history for billing purposes
We do not store your credit card numbers or full payment details. All payment data is securely processed and stored by Stripe.
3. Web Traffic Analytics
We use Umami Analytics (self-hosted at umami.luxore.net) and Cloudflare to collect anonymized web traffic data, including:
- Pages visited and navigation patterns
- Referring websites
- Browser type and operating system
- Device type (desktop, mobile, tablet)
- General geographic location (country/region level, not precise location)
- Anonymized IP addresses (IP addresses are hashed and not stored in identifiable form)
Privacy-focused analytics: Umami is a privacy-first analytics platform that does not use cookies, does not track users across websites, and does not collect personally identifiable information. All analytics data is aggregated and anonymized.
Cloudflare: Our website is served through Cloudflare's CDN for performance and security. Cloudflare may collect technical information such as IP addresses and browser data for security and optimization purposes. See Cloudflare's Privacy Policy for details.
How We Use Information
- Account data: To authenticate you, manage your subscription, and provide customer support.
- Billing data: To process payments, manage subscriptions, and comply with tax and accounting requirements.
- Analytics data: To understand how users interact with the Service, improve performance, identify bugs, and guide product development.
- Support communications: If you contact us via email, we use your email address and message content solely to respond to your inquiry.
Client-Side Processing
All text redaction operations are performed entirely in your browser using JavaScript. Your documents:
- Are processed locally on your device
- Are never uploaded to our servers
- Are never transmitted over the network under any circumstances
- Remain in your browser's memory only while you are using the editor
- Are automatically discarded when you close the tab or navigate away
- When you download or export results, the file is saved directly from your browser to your local disk—no server involved
There is no backend server that processes your content. Because processing is entirely local, we have no technical capability to access, recover, or backup your content.
Data Sharing and Third Parties
We share data only with trusted service providers necessary to operate the Service:
- Supabase: Secure authentication and account management (SOC 2 Type II certified)
- Stripe: Payment processing (PCI-DSS compliant)
- Cloudflare: CDN, DDoS protection, and security
- Umami Analytics: Privacy-focused, self-hosted analytics (no third-party tracking)
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
Cookies and Local Storage
We use minimal cookies and browser storage for essential functionality:
- Authentication cookies: To keep you logged in (session management via Supabase)
- Local storage: To remember your theme preference (dark/light mode)
- No advertising or tracking cookies: We do not use cookies for ads or cross-site tracking
Data Retention
- Account data: Retained while your account is active and for a reasonable period after account closure for legal and operational purposes.
- Billing data: Retained as required by law for tax and accounting purposes.
- Analytics data: Aggregated and anonymized data may be retained indefinitely for historical analysis.
- Support communications: Retained as needed for customer support and legal purposes.
Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct your account information
- Deletion: Request deletion of your account and associated data (subject to legal retention requirements)
- Portability: Request your data in a portable format
To exercise these rights, contact us at [email protected].
Security
We implement industry-standard security measures, including:
- HTTPS encryption for all web traffic
- Secure authentication and password storage via Supabase
- Payment security handled by Stripe (PCI-DSS compliant)
However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Children's Privacy
The Service is intended for users 18 years and older. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected such data, please contact us immediately.
International Users
The Service is operated from the United States. If you are accessing the Service from outside the U.S., your data may be transferred to and processed in the United States or other countries where our service providers operate. By using the Service, you consent to such transfers.
Changes to This Policy
We reserve the right to modify this Privacy Policy at any time, at our sole discretion. When we make changes, we will update the "Last updated" date at the top of this page. For material changes that significantly affect your rights, we will make reasonable efforts to provide notice (such as by posting a prominent notice on the Service or sending an email to the address associated with your account).
Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the revised policy. If you do not agree to the modified policy, you must stop using the Service.
Contact Us
For questions, concerns, or requests regarding this Privacy Policy or your data, please contact:
Luxore LLC
Email: [email protected]