Privacy Policy
What Lyra collects,and why.
Last updated: July 19, 2026
This Privacy Policy is issued by Lyra ("we", "us", or "our") and applies to the website at trylyra.ai (the "Site"). It governs the manner in which any data from which you can be identified ("Personal Data") is collected, processed, stored, and used when you access or use the Site. By accessing or using the Site, you consent to the practices described in this Privacy Policy. Where we refer to Lyra as "she", we mean the product itself.
1. Introduction
Lyra is an autonomous AI blog writer: she finds topics worth ranking for, writes each post in a repo's existing voice, fact-checks every claim and external link, and opens a pull request for a human to review and merge. This Site is her public marketing site and blog. It is not the Lyra application: there are no user accounts on this Site, and nothing you do here creates one.
Nothing in this policy is aspirational. Each category below is listed because a form handler, script, or storage call in the Site's code actually performs it. If a practice is not listed, we do not do it.
2. What information we collect
The following table lists the information we may collect from you when you use the Site, and the purposes for which we use it.
| What we collect | Why we collect it |
|---|---|
| Contact form data: your name, email address, and website, plus the optional fields you choose to fill in (your role, your blog's platform, how it gets written today, and your message), submitted through the contact page. | To read and respond to your enquiry. The founder replies to every message in person. We do not add you to a mailing list or a marketing automation tool. |
| Technical and log data: your IP address, an approximate location derived from it (country, region, and city, never precise coordinates), and your browser's user-agent, recorded alongside form submissions. | For security, abuse prevention, and rate limiting, and to understand the geographic reach of enquiries in aggregate. |
| AI visibility checker data: your brand name, domain, what you sell, and optionally a competitor, plus an email address, submitted through the free checker. The generated report and the raw AI answers behind it are stored with these inputs. | To run the check, to deliver your report by email and at a shareable link, to enforce the free quota, and so the team can reach out about Lyra where your report shows she would genuinely help. |
| Verification codes: a one-time code sent to your email when you use the checker. The code is stored only as a cryptographic hash and expires after ten minutes. | To verify that the email address you gave us is yours before we send a report to it. |
| Dormant waitlist data: an older waitlist endpoint still exists in the codebase but is not linked anywhere on the live site. If it is ever called, it stores an email address with the same technical metadata described above. | Not currently collected in practice. If the endpoint is ever used, the email is used only to notify you about access. |
| Correspondence data: any communications and information you provide directly to us through the contact page. | To assist you and resolve your enquiry, and for internal record-keeping. |
What we do not collect. There are no accounts on this Site, so we hold no passwords. Payments run through a dormant Stripe flow that nothing links to, so we collect no card details. There is no advertising tracking, no data brokerage, and no sale of Personal Data of any kind.
3. How we use your personal information
We use Personal Data only for the purposes for which it was collected, as set out in the table above. In summary:
- to read and respond to your enquiries;
- to operate the AI visibility checker, including verifying your email, enforcing the free quota, and delivering your report;
- to protect the Site through abuse prevention and rate limiting;
- to measure, in aggregate, how the Site is used, so we can improve it;
- to reach out about Lyra where your enquiry or report suggests she would genuinely help.
We do not use your Personal Data for advertising, we do not build advertising profiles, and we do not sell, rent, or broker your Personal Data to anyone.
4. Disclosure and sharing of personal information
We do not share your Personal Data except in the following limited circumstances:
- Service providers. We share data with the third-party service providers listed in the Sub-processors section below, strictly to the extent needed for them to perform their function (for example, the checker's inputs are sent to the AI providers that produce its answers).
- Legal requirements. We may disclose Personal Data where required by applicable law, or on a valid request from a competent governmental authority, a court of competent jurisdiction, or law enforcement.
- Protection of rights. We may disclose Personal Data where necessary to protect and defend our rights or property, or the safety of our users or the public.
We do not share your Personal Data with advertisers, data brokers, or any partner network, and we do not have group companies with whom data is shared.
5. How your personal information is secured
We apply reasonable technical and organizational measures to protect the Personal Data we hold: the Site is served over encrypted connections, checker verification codes are stored only as hashes, in-flight checker runs delete themselves after twenty-four hours, and stored submissions live in a managed database with access limited to the team members who need it to respond to you.
No method of transmission or storage is ever fully secure, and we cannot guarantee absolute security. If a suspected data breach affects your Personal Data, we will notify you and any applicable regulator where required by law.
6. Cookies and similar technologies
Two analytics scripts load on every page of the Site: Google Analytics 4 and Ahrefs Web Analytics. They measure page views and traffic sources in the usual way, and Google Analytics sets its standard _ga cookies. We do not run advertising cookies.
Separately, if you arrive with campaign parameters (utm_* or gclid), the Site stores them in your browser's localStorage for up to ninety days, and your landing page in sessionStorage. When you click through to the Lyra app, those values are appended to the link so the app knows where you came from. Until that click, this data stays in your browser and is never sent to our servers.
Most browsers accept cookies by default, but you can modify your browser settings to decline or delete them. The Site remains readable without cookies; only analytics and attribution are affected.
7. How long we retain your personal information
Contact submissions and checker reports are kept until you ask us to delete them. In-flight checker runs delete themselves after twenty-four hours, verification codes after ten minutes, and rate-limit counters expire with their window. The attribution snapshot in your browser expires after ninety days, and clearing your browser storage removes it sooner. Where information is kept for analysis, it is kept in aggregate form that does not identify you.
8. Your data protection rights
If you are a resident of the European Economic Area, Switzerland, or the United Kingdom, the GDPR (and equivalent law) gives you the following rights, which we extend to every user regardless of location:
- The right to access : you may request a copy of the Personal Data we hold about you.
- The right to rectification : you may request that we correct inaccurate information or complete incomplete information.
- The right to erasure : you may request that we delete your Personal Data.
- The right to restrict or object to processing : you may request that we limit or stop processing your Personal Data.
- The right to data portability : you may request that we transfer the data we hold about you to you or to another organization.
- The right to withdraw consent : where processing is based on consent, you may withdraw it at any time.
If you are a California resident, the CCPA gives you the right to know what Personal Data we collect, to request its deletion, and to opt out of its sale. We do not sell Personal Data, and we do not discriminate against you for exercising any of these rights.
To exercise any of these rights, email us at info@trylyra.ai. Every request is handled personally, and we will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
9. Cross-border transfer of personal data
The service providers listed below operate in jurisdictions that may differ from yours, including the United States. By using the Site, you consent to the transfer of your Personal Data to these jurisdictions. We rely on these providers' own contractual and compliance safeguards for such transfers, and we share with each provider only the data its function requires.
10. Sub-processors and data processors
These are the third-party services that touch the data described in this policy. Each is listed because the code calls it, not because a template said so. If you are a controller of personal data and need a data processing agreement, email us at info@trylyra.ai.
| Processor | What it does for us |
|---|---|
| Vercel | Hosts and serves the site, and provides the approximate-location headers (country, region, city) we read on form submissions. |
| MongoDB Atlas | Stores contact form submissions, AI visibility checker runs and reports, and emails captured by the dormant waitlist endpoint. |
| Google Analytics 4 | Usage analytics (measurement ID G-WVS038PWK7). Sets the standard _ga cookies. |
| Ahrefs | A second, lightweight web-analytics script that measures traffic to the site. |
| SendGrid | Delivers the visibility checker's transactional email: the verification code and the finished report. |
| Anthropic, OpenAI, and Google | The visibility checker sends your brand, domain, and the prompts it generates to these APIs (Anthropic for prompt generation, ChatGPT and Gemini for the answers) so the check can run. |
| ipapi.co | Approximate IP geolocation on form submissions, used only when the hosting platform provides no location headers. It receives the IP address and nothing else. |
| Stripe | Payment processing for a dormant checkout flow. It is not linked anywhere on the live site, so no payment data is currently collected. |
11. Affiliate disclosure
This Site currently uses no affiliate links. Comparison posts link to other vendors' sites for citation, so readers can check a claim against the source; those links earn us nothing. If a post ever carries an affiliate relationship, the disclosure will appear on the post itself.
12. Personal data of children
The Site is not directed at children, and we do not knowingly collect Personal Data from anyone under the age of 16. If we learn that we have collected Personal Data from a child under 16, we will delete it as quickly as possible. If you believe a child has provided us Personal Data, please email us at info@trylyra.ai.
13. Changes to this privacy policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page and take effect when posted; the "Last updated" legend at the top of this page tells you when it was last revised. If you continue to use the Site after a change is posted, you are deemed to have accepted the updated policy. If you do not agree with a change, please stop using the Site. If any provision of this policy is held invalid or unenforceable, the remaining provisions are unaffected.
14. Contact us
If you have any questions about this Privacy Policy, or want to see, correct, or delete anything we hold about you, email us at info@trylyra.ai. Every message gets read, and data requests are handled the same way as everything else here: personally.