Lugh

Privacy

What Lugh keeps, why, who helps us run it, and how to delete it.

Last updated: 1 October 2026 (beta version of this page).

The short version

What Lugh keeps

WhatWhy
Account: your sign-in email address, a password (stored only as a secure hash by our database provider) and Your Lugh AddressTo sign you in and to know which forwarded emails are yours
Forwarded emails: the sender address, subject, date and text of each email you forward to Lugh (attachments are not kept), and whether Lugh could read itSo Lugh can find the bookings in it, show what happened to each forward, and read it again if needed
Trips and bookings: what Lugh found or you entered, such as type, supplier, booking reference, dates and times, places, flight numbers and airports, and your correctionsTo build your trips, timeline and map
Map positions and time zones for the places in your bookingsTo draw your journey and show local times. Lugh does not use your phone's location
Notification details (if you turn notifications on): a push address for each phone, its platform (iPhone or Android), its time zone, and a record of which notifications were sentTo send you the alerts you asked for, and never the same one twice
Usage counters: how many paid place look-ups your account used each dayTo keep Lugh's costs under control

Lugh does not use advertising identifiers, analytics or tracking tools.

How Lugh uses AI

To find the bookings in a forwarded email, Lugh sends the email's sender, subject, date and text (up to about 8,000 characters) to the OpenAI API. Lugh is usually right, but not always; when it isn't sure it marks the booking Needs checking. Anything you correct stays the way you set it.

OpenAI states that data sent through its API is not used to train its models unless the customer opts in (Lugh hasn't), and that API abuse-monitoring logs are kept for up to 30 days unless the law requires longer. Lugh doesn't ask OpenAI to store its requests.

Who helps us run Lugh

ServiceWhat it does for LughWhat it receives
SupabaseDatabase, sign-in and server functionsEverything in "What Lugh keeps"
PostmarkReceives the emails you forward and passes them to LughThe forwarded emails. Postmark keeps message content for 45 days by default
OpenAIReads forwarded emails to find bookingsSender, subject, date and email text (see above)
GeoapifyFinds map positions for placesPlace names and addresses only (for example "Hotel Artemide, Rome, Italy"), sent from our server. Never your name, email or account
Expo, with Apple and Google push servicesDelivers notificationsYour phone's push address and the notification text, for example "Booking added" and the supplier or trip name

Maps in the app are drawn by Apple Maps on iPhone and iPad. Map data © OpenStreetMap contributors.

How long we keep it

Deleting your account

In the app: Profile → Delete account…, type DELETE and confirm. Lugh deletes your sign-in, Your Lugh Address, forwarded emails, trips, bookings, devices and notification records in one step. If anything fails, nothing is deleted and the app tells you. Copies held by the providers above expire under their own policies (for example, Postmark after 45 days).

If you can't use the app, email support@getlugh.com from your sign-in address and ask us to delete your account.

Your rights

You can ask for a copy of your data, ask us to correct or delete it, or object to how we use it. Email support@getlugh.com. You may also complain to your local data protection authority.

Children

Lugh is for people organising their own travel and isn't directed at children.

Changes

If this policy changes, we'll update this page and its date. Big changes will also be announced in the app.

Contact

support@getlugh.com