Privacy Policy
How Jobrella Technologies INC. (operating as Lughlabs) handles information on the One website, in the hosted One service, and in the One apps.
This policy is written for the people who use One and for the people whose information reaches One through a customer. Short summaries open each section; the detail follows.
It covers the website at https://lughlabs.ai, the hosted One service we operate, and the One web, desktop, and mobile apps when they are connected to a deployment we operate. A One deployment run by someone else on their own servers is governed by that operator's own practices, not by this policy.
Who we are
One is made by Jobrella Technologies INC., a Delaware corporation, which operates under the Lughlabs brand. When this policy says "we", "us", or "Lughlabs", it means Jobrella Technologies INC..
You can reach us about privacy at hello@lughlabs.ai or by post at 1095 Wayne Ave, Chambersburg, PA 17201, United States.
Some of the facts in this policy, such as our legal name and incorporation state, were supplied by the company. We keep the underlying records; this policy does not reproduce them.
At a glance
| Question | Short answer | Details |
|---|---|---|
| Do you sell my personal information? | No. We do not sell personal information, and we do not share it for cross-context behavioral advertising. | How we share information |
| Do you train AI models on my content? | No. We do not use your prompts, files, conversations, calls, or connected-account data to train or fine-tune machine-learning models, and we do not operate models of our own. | AI processing |
| Who else sees my content? | The model, speech, integration, computer, and telephony providers that you or your workspace connect, and the infrastructure providers that run the hosted service. We name the categories and the reasons. | Providers |
| Do you use tracking cookies? | The hosted service uses a session cookie to keep you signed in. The website uses no advertising trackers. Optional website analytics, when enabled, respects Global Privacy Control and Do Not Track and can be turned off on the privacy choices page. | Cookies and analytics |
| Can I delete my data? | Yes. You can delete bots, conversations, Library sources, and your whole account from inside the product, and you can email us for anything the product cannot delete itself. | Your rights and choices |
What this policy covers
This policy applies to three things: the marketing website at lughlabs.ai; the hosted One service, which is the account, workspace, and agent platform we run for customers; and the One apps for web, desktop, and mobile when they connect to a deployment we operate.
One can also be deployed by another operator on infrastructure they control. If you use One on a deployment run by your employer, a customer, or another operator, that operator decides how your information is handled. Ask them for their notice; this policy does not apply to their deployment, even though the apps look the same.
This policy does not cover third-party websites, model providers, integration platforms, telephony carriers, or app stores that you interact with through One. Their own policies apply to what they receive.
Who this policy is about
- Visitors
- People who browse the website, read the documentation, or use the contact form.
- Account holders
- People who create an account on the hosted service, including workspace owners, administrators, and members.
- Customers
- Individuals and organizations that agree to our Terms of Service and use the hosted service for their own purposes.
- People in customer content
- People whose information reaches One because a customer brings it in: email correspondents, contacts, calendar attendees, callers and call recipients, chat participants, people named in uploaded documents, and people mentioned in prompts. We process this information for the customer, and the customer decides why it is collected.
Information we collect
In short: we collect what you give us to create an account and use the product, the technical information needed to run it, the content you and your agents create or connect, and the details providers send back about your usage. We do not buy data about you.
Information you give us
- Account details. Your email address, the name you enter, and a password, which we store only as a salted hash. The hosted service supports sign-in with email and password; it does not offer social sign-in.
- Profile and preferences. Display name, character and appearance settings, language, notification preferences, approval rules for agent actions, and similar settings.
- Workspace content. Instructions you give bots, prompts and messages, files and folders you upload to a bot or to a Space's Library, public pages you ask a bot to read, memory documents, blueprints, boards, notes, and the outputs bots produce for you.
- Provider credentials. API keys and sign-in tokens for the model, speech, image, computer, telephony, and other providers you choose to connect. They are encrypted at rest with a key that is separate from the database and are never returned by our API after you save them.
- Contact form and email. When you write to us, the name, email address, and message you send. The website contact form drafts an email in your browser; unless a delivery endpoint has been configured, nothing is sent until you send it from your own email account.
Information collected automatically
- Session records. When you sign in, we store a session token, the IP address, and the browser or app identifier that created the session, so we can show you your active sessions and stop misuse.
- Operational logs. Request timing, status codes, error messages, and correlation identifiers for the hosted service. Our logging layer redacts email addresses, prompts, messages, passwords, tokens, and API keys before a line is written.
- Usage records. For each model call an agent makes, the provider, the model, token counts, cached-token counts, and the estimated cost, attributed to your workspace and bot so you can see what your agents spend. Usage records do not contain the prompt or the response.
- Agent activity. Run and task records, tool calls, approvals, artifacts, and activity events, so you can review what an agent did and why.
- Computer activity. When a bot works in its own computer, the files in its home directory persist, and the deployment may keep a short screen recording of the bot's session for you to replay. Recordings cover only the bot's own desktop, never a screen a person controls, and the hosted service deletes them after roughly 24 hours.
- Push notification tokens. If you enable notifications in the mobile app, the device token needed to deliver them.
Information from connected services
When you connect an application, a model provider, a telephony carrier, or another service, One receives what that service returns for the actions you and your agents request: messages, contacts, calendar events, documents, search results, transcripts, call outcomes, and account identifiers such as the email address of the connected account. We keep what is needed to show you the result, to let the agent continue its work, and to give you a history.
Information about other people
Customer content often contains information about people who are not our users. We process that information only on the customer's instructions and only to provide the service. The section on people in customer content explains the customer's responsibilities and how those people can reach us.
What we do not collect
- We do not collect precise geolocation, and the apps do not ask for location permission.
- We do not collect biometric identifiers. Speech features transcribe words and synthesize speech through the provider you choose; they do not create voiceprints or identify people by their voice.
- We do not ask for payment card details on the website or in the product. Plans are arranged with our team, and any payment method is handled through the arrangement we agree with you.
- We do not use browser fingerprinting, advertising pixels, or third-party advertising cookies on the website or in the product.
How we use information
In short: to run One for you, to keep it secure, to support you, to understand how the service performs, and to meet our legal obligations. Nothing else.
- Providing the service. Creating and securing your account, running your bots and their computers, storing and retrieving your workspace content, sending your requests to the providers you choose, and delivering results back to you.
- Agent operation. Giving your bots the context they need: their instructions, the conversation, the Library sources you allowed, their memory, and the tools you assigned. Bots read only the sources their owner or the workspace has granted.
- Security and abuse prevention. Detecting unauthorized access, enforcing sign-up policy, verifying email addresses when a deployment requires it, rate-limiting, and investigating misuse.
- Support and communication. Answering your questions, sending transactional email such as verification and password-reset links, and telling you about material changes to the service or to this policy.
- Service performance. Reviewing aggregated usage, error rates, and cost estimates to plan capacity and improve reliability. We do this with operational records, not by reading your content.
- Legal compliance. Keeping the records the law requires, responding to lawful requests, and enforcing our Terms.
We do not use your information for advertising, and we do not build marketing profiles of you. If we ever want to send marketing email, we will ask for separate, optional consent first; none is collected today.
AI processing: what we do and what providers do
In short: One orchestrates models; it does not run them. Your prompts and context go to the model provider you or your workspace chose, under that provider's terms. We never use your content to train models, and we do not operate a model of our own.
Our processing
We store your conversations, instructions, files, memory documents, and agent outputs so your bots can keep working across sessions. When a bot runs, our servers assemble its context and send it to a model provider. When a bot searches the web, its query goes to a web search service and the pages it opens receive an ordinary web request. When a bot uses a tool, the tool's input and output are recorded in the run history so you can review them.
Model, speech, and image providers
One works with the provider you choose. Most customers bring their own API key or sign in to a provider subscription; a deployment may also offer a default model configured by the operator. Whichever it is, the provider receives the content of the request and applies its own privacy terms, including its own rules on retention and training. Some providers state that API traffic is not used for training; others differ. Review your provider's terms before you connect it, and prefer providers whose commitments match your needs.
Voice features send audio to the speech provider you connect for transcription and receive synthesized speech back. Image features send prompts to the image provider you connect. These are your credentials and your choice of provider.
Memory, Library, and embeddings
Bot memory and Space memory are stored as documents you can read, edit, and delete. Library sources are split into passages and short facts with citations to the passage they came from. If the deployment names an embedding model, passages are also converted into numerical embeddings by that model provider to improve search; otherwise search uses plain database matching. Deleting a source removes its passages, facts, and embeddings.
Training and evaluation
We do not train, fine-tune, or evaluate machine-learning models on customer content, and the product contains no pipeline that does so. If we ever propose to change that, we will describe the change plainly, update this policy, and give you a choice before it applies to your content.
Automated decisions
One does not make decisions about you that have legal or similarly significant effects. Agents act on your instructions and within the permissions you configure. Customers who use One to make decisions about other people, such as in hiring, lending, housing, or insurance, are responsible for the notices, human review, and assessments those uses require.
Connected accounts and integrations
In short: connecting an app lets your agents act in it. We access only what the connection's permissions allow and only for the work you ask for. Disconnecting stops future access; it does not by itself delete what an agent already saved into your workspace.
The hosted service can offer managed app connections through an integration platform. When you connect an app that way, the platform holds the OAuth tokens for the connection, and the requests your agents make to the app pass through the platform, which records the tool call and its result according to its own retention settings. You can also install your own HTTPS MCP servers and OpenAPI tool sources; credentials for those are encrypted in our secret store, and requests go directly from our servers to the endpoint you configured.
Permissions are visible in the product for each connection. Connect only the accounts and scopes your work needs, and disconnect a connection when the work is done.
Google user data
If you connect a Google account, our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features you ask for, we do not sell it, we do not use it for advertising, we do not let humans read it except with your consent, for security, or as the law requires, and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. Where the connection is made through an integration platform, the platform's own Google OAuth registration may apply as well.
Voice, phone calling, and messaging
In short: phone agents are optional and off unless a deployment enables them. Calls place audio with a telephony carrier and speech providers, produce transcripts, and may produce recordings only where recording has been enabled with a retention period. The customer running the phone agent is responsible for consent and for the laws that apply to their calls.
When a customer configures a phone agent, One runs the call through a self-hosted calling engine and the telephony carrier the customer connects. The carrier and the speech and language providers used for the call receive the audio and the conversation. One records the call's status, timing, the masked phone numbers, the transcript, structured outcomes, and any live tool calls the agent made during the call.
- Disclosure. A phone agent can be required to state that it is an automated assistant at the start of every call; when the disclosure is required and cannot be delivered, the call does not proceed.
- Recording. Audio recording is off by default. It can be enabled only on a deployment that has approved recording and defined a retention period, and only per phone agent. Transcripts are kept for the same retention period as the call's other content.
- Retention and purge. Each call carries a retention class. When it expires, the raw numbers, context, transcript, recording, results, and tool contents are purged from our systems and the calling engine, leaving only status, timing, and masked numbers. A call under legal hold is not purged.
- Do-not-call. A person who declines during a call is added to the workspace's do-not-call list, which stores only a keyed digest of the number. Numbers on the list are not called again from that workspace.
- Calling windows and limits. A deployment can restrict outbound calling hours and the number of daily attempts per destination.
Chat-app messaging surfaces, such as SMS, iMessage, Slack, WhatsApp, Telegram, and Lark, are optional and depend on the operator connecting them. When enabled, the messaging platform receives the messages you exchange with a bot under that platform's terms.
People who receive calls or messages from a customer's agent can ask us to stop and can ask what we hold about them; see people in customer content. Consent to receive a call, consent to be recorded, and consent to any later use of the conversation are separate, and the customer must obtain each one that applies.
Our role: when we decide and when the customer decides
For website visitors and for account, billing, security, and usage information about our customers, we decide how information is used. State privacy laws call this being a controller or a business.
For customer content, including everything a customer's agents read, write, receive from connected accounts, or say on a call, the customer decides why the information is collected and we process it on the customer's instructions. State privacy laws call this being a processor, a service provider, or a contractor. Our Terms of Service contain the processing commitments those laws require of us in that role.
Providers we rely on
The specific providers depend on what a deployment enables and what you connect. The categories below are the ones the hosted service can use; the current list for our deployment, with links to each provider's privacy terms, is maintained with the trust and deployment information and updated when a provider changes.
- Model providers you connect directly or through a gateway, such as OpenAI, Anthropic, Google, xAI, Mistral, OpenRouter, GitHub Copilot, and OpenAI-compatible endpoints you run yourself.
- Speech providers for voice features: ElevenLabs, OpenAI, Cartesia, and Fish Audio, each with your own key.
- Image providers for image generation, with your own key.
- Integration platforms for managed app connections, plus the MCP servers and OpenAPI sources you install yourself.
- Computer providers for bot computers: local containers by default, or a remote provider the operator configures.
- Telephony carriers for phone agents, such as Twilio, Plivo, Vonage, Telnyx, or a SIP trunk you connect.
- Infrastructure for hosting, transactional email, and mobile push delivery.
- Public model catalogues, which our worker reads without sending any user data, to keep model lists and prices current.
Providers that process customer content for us are bound by contract to use it only to provide their service to us. Providers you connect with your own account or key are bound by their agreement with you.
Where information is stored
The hosted service and its database, files, and backups are stored in the United States. Providers you connect may process information in other countries according to their own terms. If you are outside the United States, you understand that your information is transferred to and processed in the United States, where privacy laws may differ from those in your country.
The hosted service is offered in the United States. We do not currently target the service to people in the European Economic Area, the United Kingdom, or Switzerland, and we do not make representations about compliance with the laws of those regions. If that changes, we will update this policy and our contracts first.
How long we keep information
In short: your workspace content stays until you delete it or close your account; operational records are kept for limited periods; call content follows the retention period set for the phone agent.
| Information | Kept for | Notes |
|---|---|---|
| Account, profile, and workspace content | Until you delete the item or close your account | Deleting a bot removes its conversations, memory, computer, and files; deleting a Space removes everything in it. |
| Sessions | Until they expire or you sign out | Password resets revoke every session. |
| Verification and password-reset links | One hour | Then they stop working and are removed. |
| Bot screen recordings | About 24 hours | Deleted automatically; you can delete one sooner. |
| Phone-call content | The retention period of the call's retention class | Purged automatically when it ends, unless a legal hold applies. Status, timing, and masked numbers remain. |
| Do-not-call entries | Until the workspace is deleted | Stored as a keyed digest so the list cannot reveal who asked. |
| Usage records | Until the workspace is deleted | Token counts and cost estimates, without content. |
| Operational logs | A limited rolling period set by log-volume limits | Redacted before writing; not searchable by content. |
| Backups | 7 days | Deleted content can persist in a backup until the backup is rotated; backups are not used to restore individual items. |
| Contact and support email | As long as needed to handle the request and keep a record of it |
When you close your account, we remove your bots, their computers, memories, files, sessions, and push tokens from live systems as part of the deletion itself, and we delete remaining account content from live systems within 30 days. We may keep the minimum needed to comply with law, resolve disputes, enforce our agreements, or preserve evidence under a legal hold.
Security
We protect information with measures that fit the risks of an agent platform, including encryption in transit, encryption of provider credentials and secrets at rest with a key separate from the database, salted password hashing, sandboxed bot computers that run without root privileges or added capabilities, origin checks on every signed-in request, redaction of sensitive fields in logs, signed communication between the service and the calling engine, and least-privilege access for our own operators.
No system is perfectly secure, and we do not promise that unauthorized access will never occur. If we learn of a breach that affects your information, we will notify you and any authorities as required by applicable law. Report security concerns to security@lughlabs.ai; please do not open a public issue for an unfixed vulnerability.
Your rights and choices
In short: you can see, correct, export, and delete your information, most of it from inside the product. For anything else, email us and we will verify that it is you and respond within the time the law allows, usually 45 days.
Controls inside the product
- Profile. Change your name, password, appearance, language, and notification settings in Settings.
- Content. Edit or delete conversations, memory documents, Library sources, bots, and Spaces. Export a Space's Library as the original files plus a record of what was learned from them.
- Connections. Review the permissions of each connected app, provider credential, and MCP server, and disconnect or remove any of them.
- Agent actions. Set approval rules so consequential actions wait for you, and keep bots in preparation mode until you are ready to let them act.
- Sessions. Signing out ends the current session; changing your password ends every other session.
- Account. Delete your account from Settings in the web app or from Account in the mobile app. Deletion is permanent and removes your bots, conversations, memories, files, and connections.
Rights under state privacy laws
Depending on where you live, you may have the right to confirm whether we process your personal information and to access it; to correct inaccuracies; to delete it; to obtain a portable copy; to opt out of the sale of personal information, of sharing or targeted advertising, and of profiling that produces legal or similarly significant effects; and to limit the use of sensitive personal information. We do not sell, share for advertising, target advertising, or profile in ways that trigger an opt-out, and we do not use sensitive personal information for anything other than providing the service you asked for. We honor the other rights for everyone, regardless of where they live.
How to make a request
Email hello@lughlabs.ai from the address on your account, or write to us at 1095 Wayne Ave, Chambersburg, PA 17201, United States. Tell us which right you are exercising and, if you are not an account holder, how your information reached us, for example the customer or phone number involved. We operate online and have a direct relationship with our account holders, so email is our primary request channel; you do not need to call.
- Verification. For account holders, we verify a request by confirming it comes from the account's email address, and we may ask you to confirm from inside the product. For other people, we ask for enough information to match you to the record, and no more.
- Authorized agents. An agent may submit a request for you if they provide your signed permission. We may still confirm the request with you directly.
- Timing. We respond within 45 days of receiving a verifiable request, and we will tell you if we need up to 45 more days for a complex request.
- Appeals. If we decline a request, we will explain why. You can appeal by replying to our decision within 60 days; we will answer the appeal in writing within 45 days. If you are not satisfied, you may contact your state attorney general.
- No discrimination. We will not deny you service, charge a different price, or provide a different level of service because you exercised a privacy right.
If you are a customer's employee or a person in a customer's content, we will usually refer your request to that customer, because the customer decides what happens to the information, and we will help them respond.
Sensitive information
We do not ask for sensitive personal information such as health, financial account, government identification, precise location, biometric, or information about children. Customers may bring such information into their workspace, and agents may encounter it in connected accounts or on calls. When they do, we process it only to provide the service the customer asked for. Customers are responsible for deciding whether One is an appropriate place for such information and for obtaining any consent the law requires. One is not designed for regulated health records, and we do not claim compliance with HIPAA or similar sector rules unless we have agreed to that with you in writing.
Children
One is a work tool for adults. You must be at least 18 years old to create an account, and the website and product are not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided information to us, email hello@lughlabs.ai and we will delete it.
People in customer content
If a business or individual uses One and your information appears in their workspace, the customer is responsible for having a lawful basis to collect it, for any notice or consent their use requires, and for honoring your requests about it. That includes consent to receive automated calls or messages, consent to be recorded where the law requires it, and notice that they are speaking with an automated assistant where the law requires it.
You can also contact us directly at hello@lughlabs.ai. Tell us what you know about how your information reached One. We will identify the customer where we can, pass your request to them, and help them respond. If you ask us to stop calls or messages from a phone agent, we will add your number to that workspace's do-not-call list.
Changes to this policy
This is version 1.0 of the policy. It takes effect on 2026-09-22 and was last updated on 2026-09-22. When we make a material change, such as a new purpose for using information or a new category of recipient, we will post the new version here, update the effective date, and notify account holders by email or in the product before the change applies to information we already hold. Earlier versions are available on request.
Contact
Jobrella Technologies INC., 1095 Wayne Ave, Chambersburg, PA 17201, United States. Email hello@lughlabs.ai for privacy questions and requests, and hello@lughlabs.ai for product support.



