Privacy Policy

Last updated: October 1st, 2026

1. Introduction

This Privacy Policy explains how Luzora collects, uses, stores, shares, protects, and deletes personal information when you use the Luzora browser extension, Luzora websites, accounts, password reset and deletion pages, The Hive, Manifesto, public profiles and leaderboards, referrals, check-ins, quests, quizzes, campaign and reward features, newsletter forms, support channels, and related services.

The controller responsible for this processing is Luzora Task Limited, a private company limited by shares incorporated in Nigeria on August 28, 2026, with company registration number RC 9811642 and contact location in Abuja, Nigeria. In this Policy, "Luzora", "we", "us", and "our" refer to Luzora Task Limited.

Luzora combines a browser-first recurring task manager with The Hive, a voluntary community participation system. The extension helps you save website routines as tasks, schedule reminders, open saved links, track completions, and sync across supported browsers. The Hive lets eligible members create a profile, participate in quests and quizzes, receive Hive Points, use referrals, and appear in public community features. Because these products handle different kinds of information, this Policy explains both clearly.

By using Luzora, you acknowledge that we will handle personal information as described in this Policy. If you do not agree with this Policy, please do not use Luzora.

2. Plain-language privacy commitments

These commitments are central to how Luzora is designed:

  1. 2.1 User action first

    Luzora inspects the current page only when you open a current-page experience, start creating a task, use Add current website, trigger Luzora Bolt, save a page, or otherwise ask Luzora to work with the active page. This includes generating task suggestions after you open the Add Task screen.

  2. 2.2 No sensitive-field reading

    Luzora is not designed to read passwords, payment details, card numbers, bank details, seed phrases, private keys, API keys, secret tokens, private form values, or hidden sensitive form values.

  3. 2.3 No sale of task data

    We do not sell your task titles, saved links, project names, reminder settings, or completion history.

  4. 2.4 Purpose-limited browser data

    Data from browser permissions is used to provide user-facing Luzora features, such as suggesting actions for the current page, saving that page as a task, opening saved links, displaying reminders, syncing tasks, and improving reliability.

  5. 2.5 Do not store secrets in Luzora

    Luzora is for tasks, routines, and website follow-ups. Do not save passwords, API keys, private keys, seed phrases, card details, bank information, or other sensitive secrets in task titles, folders, notes, project names, or links.

2.6 Chrome extension data disclosure

This section describes the current Luzora browser extension data flow in one place. It is intended to make clear what the extension handles, why it handles it, where it is stored, and which external providers receive it.

  1. Data kept in your browser

    Luzora stores authentication session data, task drafts, a local task cache, folders, schedules, completion history, preferences, notification state, Auto Return state, language and shortcut settings, and analytics identifiers in browser storage. This local data is used to keep the extension working across popup closures and browser restarts.

  2. Data sent to Supabase

    Luzora sends your email address, authentication information, Luzora user identifier, profile settings, tasks, task titles, projects, folder names, saved URLs and domains, favicons, schedules, reminders, task versions, completion history, preferences, referral records, and limited usage metadata to Supabase. Supabase provides authentication, database storage, account management, Edge Functions, and cross-browser sync. Passwords are processed by Supabase Auth and are not stored in Luzora task or profile tables.

  3. Data sent to PostHog

    The extension sends PostHog a randomly generated analytics identifier, event names, event timestamps, extension version, current Luzora screen, time zone after login, feature activity, task count, project count, folder count, completion count, session status, sync status, and similar product-use measurements. After login, the analytics identifier is associated with the internal Luzora user identifier so activity across sessions can be measured.

    The extension's analytics filter removes properties identified as email addresses, passwords, authentication tokens, secrets, API keys, private keys, task titles, task links, saved URLs, folder names, project names, website names, and domains before analytics events are sent. PostHog does not receive task content or saved browsing destinations through Luzora analytics.

  4. Data sent to Google's favicon service

    When Luzora generates an icon for a recognised website, the extension may request that icon from Google's favicon service. The request contains the website domain and may expose ordinary request information such as your IP address, browser information, and request time to Google. This service is used only to display the website icon beside a task or project.

  5. Data not sent by the extension to website analytics or email providers

    The extension does not send extension activity to Google Analytics, Vercel Web Analytics, or Resend. Google Analytics and Vercel Web Analytics are used on Luzora website pages. Resend is used by Luzora website and backend flows for verification, transactional, Manifesto, deletion, and subscription emails.

Chrome Web Store Limited Use: Luzora's use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Luzora uses Chrome API data only to provide or improve the extension's disclosed, user-facing task, reminder, page-capture, sync, and return features. We do not sell Chrome API data, use it for personalised advertising, use it for credit or lending decisions, or allow humans to read it except with the user's specific consent for support, when required for security, when required by law, or after the data has been aggregated and anonymised for internal operations.

3. Who this Policy applies to

This Policy applies to visitors, extension users, account holders, Hive members, Manifesto signers, quest and quiz participants, people shown on public profiles or leaderboards, referral users, newsletter subscribers, people who contact support, and anyone who uses a Luzora page or service that links to this Policy.

Some privacy laws use terms such as "personal information", "personal data", "personally identifiable information", "controller", "processor", "business", or "service provider". When we use "personal information" in this Policy, we mean information that identifies, relates to, describes, can reasonably be associated with, or can reasonably be linked to an individual or household, as those terms are understood under applicable privacy laws.

4. Information you provide directly

We collect information you choose to provide to Luzora, including:

  1. 4.1 Account information

    Email address, recovery email where provided, account and authentication-provider identifiers, authentication status, sign-in method, password reset requests, and related account information. Depending on the sign-in option you choose, authentication data may come from X, Google, or another provider shown in the sign-in flow. Passwords are handled by Supabase Auth or the relevant identity provider. We do not intentionally store your raw password in Luzora-owned task or profile tables.

  2. 4.2 Profile information

    Username or Hive name, avatar or profile image, avatar emoji and background color, language preference, X handle and public X profile information such as follower count where used, optional Telegram username, referral information, username change count, and other profile settings you create or update.

  3. 4.3 Task and project information

    Tasks, task titles, project names, website or app names, folder names, saved links, domains, URLs, favicons, schedules, start dates, one-time dates, recurrence rules, task times, custom dates, paused states, edits, task versions, task completion history, and related task metadata.

  4. 4.4 Settings and preferences

    Notification preferences, daily summary time, snooze duration, shortcut preferences, language settings, local UI state, and other choices you make in the extension. If you use product onboarding, this also includes the profession you select or enter, the websites and actions you choose, preferred timing and cadence, whether you completed or skipped onboarding, and the sign-in method used to connect the response to your account.

  5. 4.5 Newsletter information

    Email addresses submitted through Luzora newsletter forms, together with limited submission metadata such as the page URL, referrer, and user agent.

  6. 4.6 Support and feedback

    Information you send to us by email, feedback forms, surveys, social messages, bug reports, screenshots, or other communications, including your email address and the contents of your message.

  7. 4.7 Deletion requests and feedback

    If you request deletion or delete your account, we may collect the deletion reason, optional explanation, deletion timestamp, and related request information. Deletion feedback may be retained in an anonymous or non-account-identifying form.

  8. 4.8 Hive participation information

    Manifesto status, membership status, referral relationships and codes, milestones, daily check-ins, Hive Point awards and adjustments, leaderboard position, campaign participation, eligibility information, and records needed to explain or audit your balance.

  9. 4.9 Quest information

    Quests you start, destination links you open, action status, submitted usernames, text, links, numbers, comments, evidence, completion claims, submission and verification times, review outcomes, rejection reasons, retry history, and communications about a review. Do not submit private messages, passwords, financial information, or unrelated personal information as quest evidence.

  10. 4.10 Quiz information

    Quizzes opened, question versions shown to you, selected answers, scores, attempts, retry history, completion status, time information, base and bonus awards, and review information displayed after submission.

  11. 4.11 Administrative and integrity records

    Review assignments, administrator decisions, moderation notes, point corrections, fraud and abuse signals, audit events, exports, and security records created when authorized personnel operate or protect The Hive.

5. Information collected through browser permissions

Luzora is a browser extension and uses browser permissions to provide its core features. Browser stores may describe these permissions broadly. The descriptions below explain how Luzora uses them.

  1. 5.1 Active tab

    Luzora uses active tab access after you interact with the extension, open Add Task, request current-page suggestions, select Add current website, or trigger Luzora Bolt. This helps Luzora identify the page you are actively choosing to use as a task source and keep the side panel aligned with the browser tab you are currently viewing.

  2. 5.2 What Luzora reads from the active tab

    Luzora does not request standing access to your tabs and cannot see tabs you are not actively using with Luzora. When you use a current-page feature, Luzora reads the active tab's title, address, and icon where the browser provides them. Luzora also opens saved task links and extension pages in a tab when you ask it to.

  3. 5.3 Scripting

    When you use current-page features, Luzora may run a safe page-inspection script in the active tab. This can read limited page signals such as title, URL, favicon, metadata, headings, visible labels, and common page patterns to suggest relevant task actions and attach the intended destination. Suggestions are generated from this limited context after a user action; the permission is not used for continuous background monitoring. Luzora does not use it to read passwords, payment details, private form values, or hidden sensitive form values.

  4. 5.4 Storage

    Luzora uses browser storage to keep local session data, draft task progress, local task cache, preferences, notification settings, shortcut settings, language settings, avatar settings, toast state, and analytics identifiers.

  5. 5.5 Alarms and notifications

    Luzora uses alarms and notifications to schedule task reminders, daily task summaries, snoozed reminders, badge counts, and test notifications. Browser notifications may display task titles or reminder text on your device screen.

  6. 5.6 Optional access to websites

    Auto Return is the only feature that asks for access to websites, and it is switched off until you turn it on. Luzora does not request this access when you install the extension. It is requested at the moment you enable Auto Return, and it is withdrawn from Luzora when you turn the feature off. Section 7 explains what the access is used for.

  7. 5.7 Luzora referral and welcome pages

    On Luzora's own secure welcome and referral pages, and only after you accept referral tracking, a content script may read a referral code from the page address or a Luzora referral cookie and pass it to the extension. It may also synchronize a pseudonymous browser identifier using the luzora_referral_browser cookie so an accepted referral can be carried through extension installation. The extension stores a pending referral code and browser identifier locally; it does not use this page-specific access to inspect other websites. If you decline, Luzora clears the referral cookies and does not hand referral data to the extension. If you later sign in or join through an accepted referral, Luzora may record the referral relationship as described in Section 8.6.

6. Task suggestions, Luzora Bolt, and page inspection

The Add Task suggestion feature and Luzora Bolt help create a task from the current page. They may use the active tab title, URL, favicon, page metadata, headings, visible labels, and known page patterns to suggest a small set of relevant actions. If you select a suggestion, its words are placed in the editable task description and Luzora may attach the current page address, recognised website name, and favicon to the draft. You can change, remove, close, or ignore suggestions and type your own task instead.

Page context is processed to produce the user-facing suggestion in the extension. Inspecting a page does not by itself save the page as a task. A destination URL, website name, favicon, and task description are stored or synced only when you choose to make them part of a draft, task, project, or related Luzora record.

In the side panel, Luzora can refresh this limited context after you change the active tab or complete navigation so that suggestions and Bolt use the page currently visible beside the panel. Luzora does not use these features to build a full browsing history, run background surveillance of every website you visit, sell web browsing activity, or send page content to analytics providers.

7. Auto Return

Auto Return brings you back to the page a task belongs to when that task falls due. It is switched off unless you turn it on, and turning it off withdraws everything described here.

  1. 7.1 Why it needs access to websites

    To return you to a page, Luzora needs to be able to open that page and to show a short countdown on it. Because a task can point at any website, the permission covers websites generally rather than a list we could fix in advance. Luzora asks for it when you enable Auto Return, not when you install the extension.

  2. 7.2 What Luzora does with that access

    Luzora uses it to open or switch to the page saved on a task, and to display a countdown notice on that page with the task name, so you can go now, cancel, or dismiss it. The countdown notice is rendered in an isolated container so that the content of your task cannot alter the page it appears on.

  3. 7.3 What Luzora does not do with it

    Luzora does not use this access to read the pages you visit, record your browsing history, collect page content, monitor activity in the background, or build a profile of the sites you use. It is used only to open a page you saved and to show the countdown on it.

  4. 7.4 Returning after your browser has been closed

    A browser extension cannot run while the browser is closed, so a return that falls due during that time cannot happen at the moment it was scheduled. When you next open your browser, Luzora may open the pages whose time has already passed that day, up to a small limit, and it will not repeat a return you have already been given or cancelled.

  5. 7.5 Turning it off

    Switching Auto Return off in settings stops the feature and withdraws the website access from Luzora. You can also remove the access at any time through your browser's extension settings.

8. The Hive, quests, quizzes, points, and referrals

The Hive is Luzora's voluntary community participation system. You can use the core extension without joining The Hive. If you join, the following processing applies.

  1. 8.1 Membership and the Manifesto

    When you join or sign the Manifesto, we collect the identifiers and profile information used by the applicable registration flow, the time you joined or signed, verification status, and any referral code. We use this information to create and secure your membership, prevent duplicate or abusive participation, and operate community features.

  2. 8.2 Public profile and leaderboard information

    Your Hive name, avatar, public identifier, rank, Hive Point balance, selected participation statistics, membership or completion status, and other fields clearly marked as public may appear on public Hive pages, leaderboards, completion cards, or campaign displays. Your email address, recovery email, authentication identifiers, submitted evidence, quiz answer history, administrator notes, and security records are not intended to be public.

    Public pages may be indexed, copied, screenshotted, or shared by other people or search services. Removing information from Luzora cannot guarantee deletion of copies previously made by third parties.

  3. 8.3 Hive Points

    Hive Points record eligible participation. We maintain a ledger of awards, bonuses, adjustments, reversals, reasons, and related activity so that balances can be calculated, explained, reviewed, and protected against abuse. Hive Points are not money, currency, cryptocurrency, a token, property, equity, or a promise of cash conversion.

  4. 8.4 Quests and evidence

    Quests may require you to open an external destination, perform an action, submit information or evidence, or request verification. Verification may be automatic, honor-based, or performed by authorized administrators. We use submissions to decide eligibility, award points, investigate abuse, resolve disputes, and improve quest reliability. A quest's action link may reveal ordinary request information to the external platform, whose own privacy policy applies.

  5. 8.5 Quizzes

    We record the quiz version, selected answers, score, attempts, completion status, and any base, perfect-score, or first-attempt award. Answers may be graded automatically against the quiz version's stored answer key. Authorized administrators can create and update quizzes and may inspect attempt records when necessary to resolve a support, integrity, or reward issue.

  6. 8.6 Referrals, milestones, and check-ins

    If you accept referral tracking on an invite page, Luzora stores the referral code in a cookie for up to 30 days and may use a pseudonymous browser identifier cookie for up to one year to carry the referral through installation and help prevent duplicate or abusive referrals. The extension also stores the accepted referral code and identifier locally. If you decline, referral cookies are cleared and the referral is not carried through installation. When you join or sign in through an accepted referral, we record the relationship needed to attribute it and detect self-referrals, duplicate accounts, automation, or other abuse. We also record milestones and daily check-ins where those features are available. We do not sell referral relationships or use them to advertise to the people you invite.

  7. 8.7 Administrative access and decisions

    Authorized personnel may view member profiles, submissions, evidence, scores, referrals, point records, and audit history where needed to create campaigns, review completions, correct points, provide support, enforce rules, export authorized operational records, and protect The Hive. Access should be limited by role and logged where supported.

  8. 8.8 Leaving The Hive

    You may request removal from The Hive or delete your full Luzora account using an available account control or by contacting us. We will remove your public Hive profile and delete or de-identify associated personal information from active systems, subject to limited retention required for law, security, fraud prevention, disputes, financial or corporate records, and backup cycles. Aggregate or de-identified statistics may remain. Section 21 explains account deletion in more detail.

9. Natural-language task entry

Luzora can parse natural-language task text to infer dates, times, recurrence, websites, project names, and related task details. The current natural-language parsing runs locally in the extension bundle. Task text is not sent to an AI provider for parsing in the current product.

If Luzora later adds cloud AI or third-party AI processing, we will update this Policy before using that feature in a way that changes how personal information is processed.

10. Information collected automatically

When you use Luzora, we may collect limited technical and usage information, including:

  1. 10.1 Device and browser information

    Browser type, operating system, extension version, language, approximate device information, and other technical information needed to operate, secure, and troubleshoot Luzora.

  2. 10.2 Usage metadata

    Feature usage, screen views, task count, project count, completion count, last active timestamp, session duration, sync status, first task created timestamp, first completion timestamp, password reset request status, and similar product usage metrics.

  3. 10.3 Logs and security data

    Server logs, request metadata, authentication events, error reports, and security-related records that help us protect users, detect abuse, debug problems, and maintain the service.

  4. 10.4 Website form metadata

    For website forms such as newsletter signup, we may collect the email submitted, page URL, referrer, user agent, and submission timestamp.

  5. 10.5 Hive and integrity metadata

    Quest and quiz timestamps, action status, attempt counts, verification results, point-ledger events, referral status, administrator actions, and signals reasonably needed to identify duplicate, automated, fabricated, or otherwise abusive participation.

11. Product analytics

The Luzora extension uses PostHog for product analytics. Luzora website pages use Google Analytics and Vercel Web Analytics. These services help us understand how features are used, whether sync and reminders are reliable, which website pages people visit, which screens need improvement, and how to make Luzora more useful. Extension activity is not sent to Google Analytics or Vercel Web Analytics.

We design analytics to avoid sending sensitive task content. Our analytics wrapper filters property names and values that look like emails, passwords, tokens, secrets, API keys, private keys, task titles, task links, URLs, folder names, project names, website names, or domains. We may still collect event names, timestamps, extension version, screen names, page paths, feature usage, task counts, completion counts, settings changes, session duration, and sync status.

There is currently no setting to turn product analytics off inside the extension. We would rather say so plainly than imply a choice that does not exist. If analytics matter to you, the filtering described above is what limits them: your task names, links, folders, project names and website addresses are removed before anything is sent, so what we receive describes how the product is used and not what you are using it for.

If you contact us about analytics deletion or privacy choices, we will review your request based on the information available to us and the capabilities of our analytics provider.

12. Cookies and similar technologies

The Luzora website may use cookies, local storage, or similar technologies for essential functionality, authentication, security, analytics, preferences, and referral attribution. On referral pages, we ask before setting referral-tracking cookies. Your accepted or declined choice is remembered for up to one year in the luzora_referral_consent cookie. If you accept, the luzora_extension_ref cookie stores a referral code for up to 30 days, and the luzora_referral_browser cookie may store a pseudonymous browser identifier for up to one year to carry an accepted referral through installation and help prevent abuse. If you decline, the referral cookies are cleared and the referral is not carried through installation. The browser extension also uses browser storage for extension functionality, including an accepted pending referral code that expires after 30 days and a pseudonymous browser identifier. You can change your referral choice from the invite page. The website may use other cookies or similar technologies for purposes described in this Policy; where applicable law requires consent for a non-essential technology, we will ask before using it. You can also control cookies and storage through your browser settings, although disabling essential storage may affect website, Hive, or extension features.

13. How we use personal information

We use personal information for the following purposes:

  1. 13.1 Provide Luzora

    Create and manage accounts, authenticate users, sync tasks, save projects, store completion history, process task edits, open saved links, maintain preferences, operate The Hive, display eligible public profiles and leaderboards, manage quests and quizzes, calculate scores and points, administer referrals and check-ins, and deliver the features you request.

  2. 13.2 Operate browser features

    Detect the active page when you choose to save it, suggest tasks through Luzora Bolt, store local drafts, show reminders, update badge counts, and open task links.

  3. 13.3 Communicate with you

    Send account-related messages, password reset emails, security notices, account deletion confirmations, support replies, product updates, and newsletter messages where applicable.

  4. 13.4 Improve the product

    Understand product usage, diagnose bugs, improve reliability, develop new features, measure onboarding, analyze aggregate usage, and evaluate user feedback.

  5. 13.5 Protect Luzora and users

    Prevent fraud, referral manipulation, fabricated quest evidence, quiz or points abuse, spam, unauthorized access, security incidents, policy violations, or misuse of Luzora and related systems; review disputed outcomes; and preserve an appropriate audit trail.

  6. 13.6 Comply with law

    Meet legal obligations, respond to lawful requests, enforce our Terms, resolve disputes, preserve records where required, and protect our legal rights.

14. Legal bases for processing

Under the Nigeria Data Protection Act 2023, and where other applicable privacy laws such as the GDPR or UK GDPR apply, we rely on one or more lawful bases. We process account, task, quest, quiz, and reward information where necessary to provide the service or perform our agreement with you. We rely on consent for optional communications, non-essential cookies where required, and other processing presented as optional. We rely on legitimate interests to secure and improve Luzora, prevent abuse, maintain appropriate business and audit records, operate fair community features, and understand non-sensitive product use, after considering the effect on your rights. We also process information to comply with legal obligations, respond to lawful requests, establish or defend legal claims, and protect vital interests where applicable.

You may withdraw consent where processing is based on consent. Withdrawing consent does not affect processing that occurred before withdrawal, and some features may no longer work if the information is required to provide them.

15. How we share personal information

We do not sell your task data. We may share personal information in the limited circumstances below:

  1. 15.1 Current service providers

    The current providers that receive Luzora user data include Supabase, PostHog, Google, Vercel, Resend, and an identity or social platform you choose to connect, as described below. If we add or replace a provider in a way that materially changes who receives personal information, we will update this Policy and provide any notice or choice required by law.

  2. 15.2 Supabase

    Supabase provides authentication, account management, database storage, password reset, Edge Functions, website backend functions, and cross-browser sync. Supabase receives the account, profile, task, project, saved-link, schedule, completion, preference, Hive membership, public profile, referral, check-in, quest, evidence, review, quiz, score, point-ledger, Manifesto, newsletter, deletion-request, administrative, audit, and usage data described in this Policy when the relevant feature is used.

  3. 15.3 PostHog

    PostHog provides analytics for the browser extension. PostHog receives an analytics identifier, the internal Luzora user identifier after login, time zone, event names and timestamps, extension version, screen and feature activity, counts of tasks, projects, folders and completions, session status, sync status, and similar product-use measurements. Luzora filters task titles, links, URLs, website names, domains, folder names, project names, email addresses, passwords, tokens, secrets, API keys, and private keys from analytics event properties.

  4. 15.4 Google Analytics

    Google Analytics provides analytics for Luzora website pages, not extension activity. It receives website page views, page paths, traffic sources, browser information, approximate region, device type, consent state, and basic website usage. We do not send task content, passwords, saved task links, or private form values to Google Analytics.

  5. 15.5 Vercel Web Analytics

    Vercel hosts the Luzora website and provides website analytics. Vercel may receive page views, page paths, referrers, device and browser information, approximate region, request logs, IP-derived network information, and information submitted to Luzora website API routes. We do not send task content, passwords, saved task links, or private form values to Vercel Web Analytics.

  6. 15.6 Resend

    Resend sends Luzora verification, transactional, Manifesto, deletion, newsletter, and subscription-related emails. Resend receives the recipient email address, message content and subject, sending and delivery identifiers, delivery status, subscription topic or audience information, and limited metadata needed to deliver, troubleshoot, suppress, and unsubscribe email. Extension activity and task data are not sent to Resend.

  7. 15.7 Browser vendors and extension stores

    Your browser vendor or extension store may process information related to extension installation, updates, permissions, browser APIs, and store interactions under their own policies.

  8. 15.8 Favicon and website icon services

    Luzora displays favicons supplied by the active browser tab and uses Google's favicon service to generate icons for recognised websites. A Google favicon request contains the requested website domain and can expose ordinary request information such as IP address, browser information, and request time to Google. The request is made only to display the relevant website icon.

  9. 15.9 Identity and social platforms

    If you sign in with or connect X, Google, or another identity provider shown by Luzora, that provider supplies the identifiers and public profile information authorized in the connection flow and learns that you connected to Luzora. If a quest opens an X, LinkedIn, Telegram, or other third-party action or intent link, that platform receives your request under its own privacy policy. Luzora does not receive your third-party password and does not perform the external action on your behalf unless a separate authorized integration clearly says otherwise.

  10. 15.10 Legal, safety, and enforcement

    We may disclose information if we believe disclosure is required by law, legal process, regulation, security needs, fraud prevention, protection of users, enforcement of our Terms, or protection of our rights and property.

  11. 15.11 Business transfers

    If Luzora is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, personal information may be transferred as part of that transaction, subject to appropriate confidentiality and legal safeguards.

16. Third-party links and social pages

Luzora may link to third-party websites and social platforms, including X, Reddit, YouTube, LinkedIn, Telegram, browser stores, support tools, quest destinations, and other websites. Intent links may prefill a like, repost, follow, comment, share, or other action, but you remain in control of whether to complete it. If you click a link, you leave Luzora and the third party's privacy policy applies. We are not responsible for the privacy practices, security, content, availability, verification decisions, or policies of third-party websites.

17. Local browser storage and synced storage

Some information is stored locally in your browser. This may include session cache, profile cache, task cache, unsaved draft progress, preferences, notification settings, language, shortcut settings, avatar settings, analytics identifiers, and reminder delivery state. Local data may be removed if you uninstall the extension, clear browser data, reset the browser profile, or use browser tools that delete extension storage.

Some information is synced to Supabase so you can access your account and task data across supported browsers. Synced data may include profile data, tasks, projects, links, schedules, task versions, completion history, preferences, and usage metadata.

18. Notifications and on-device visibility

Luzora notifications may show task titles, reminder text, or counts of unfinished tasks on your device screen. Anyone with access to your unlocked device or notification center may be able to see those notifications. You can manage notification preferences in Luzora settings and in your browser or operating system settings.

19. Data retention

We keep personal information for as long as reasonably necessary to provide Luzora, operate our business, comply with legal obligations, resolve disputes, enforce agreements, protect users, prevent abuse, and maintain security.

  1. 19.1 Account and profile data

    Kept while your account is active, unless deleted earlier or retained for a limited legal, security, or operational reason.

  2. 19.2 Task data

    Kept until you delete tasks, clear task data, delete your account, or we delete the data according to our retention practices. Account-linked onboarding responses are kept until you delete your account or we delete or de-identify them earlier. Clearing task data does not delete the separate onboarding response.

  3. 19.3 Local browser data

    Kept in your browser until overwritten, cleared by you, removed by the browser, or removed when the extension is uninstalled.

  4. 19.4 Analytics and usage data

    Kept according to our analytics settings and provider retention periods, unless deleted or anonymized earlier where required or practical. Analytics events never contain task names, links, folder names, project names, or website addresses, because these are removed before anything is sent.

  5. 19.5 Hive Points, Manifesto and referral records

    Kept while your Hive membership is active and for as long afterwards as reasonably necessary to administer an award, resolve a dispute, prevent fraud or duplicate participation, maintain required corporate or financial records, or comply with law. When identifiable records are no longer needed, we delete or de-identify them. Public profile information is removed from Luzora-controlled active pages following a verified Hive-removal or full-account deletion request, subject to reasonable processing time.

  6. 19.6 Records kept after account deletion

    We retain only information reasonably necessary for legal compliance, security, fraud prevention, dispute resolution, suppression of communications you opted out of, financial or corporate records, and system integrity. A suppression record should contain only the minimum identifier needed to honor your request. Product totals may remain only in aggregate or de-identified form. We do not keep an identifiable username, email address, or lifetime activity record indefinitely merely to preserve product statistics.

  7. 19.7 Quest and quiz records

    Kept while needed to determine eligibility, calculate scores and awards, permit retries, show answer review, resolve support or review requests, prevent abuse, and maintain an appropriate audit record. Evidence and identifiable attempt records are then deleted or de-identified when those purposes and any applicable legal retention period end.

  8. 19.8 Support communications

    Kept as long as needed to respond, maintain business records, improve support, and protect legal rights.

  9. 19.9 Backups and logs

    Deletion removes your information from our live systems straight away. Encrypted backups are kept on a rolling basis and may still contain deleted information for up to 90 days, after which the backup containing it is discarded. We do not restore deleted information from backups for ordinary product purposes, and we do not use it after deletion is complete.

20. Clear task data

Luzora may offer a Clear tasks and projects feature. Clear task data removes your tasks, projects, folders, saved task links, task versions, and task completion history from Luzora-managed task tables. Your account, profile, preferences, login, and some usage metadata may remain active.

Clearing task data is different from leaving The Hive or deleting your account. It does not delete your Hive profile, quest submissions, quiz attempts, referrals, check-ins, or Hive Points. To remove those, request Hive removal or full-account deletion through an available account flow or contact us.

21. Account deletion

Luzora offers separate deletion scopes. Delete extension data, whether selected inside the extension or on the data-deletion page, removes the extension profile, tasks, projects, folders, saved links, task versions, completion history, reminders, notification preferences, onboarding responses, and associated extension usage records. It signs the user out of the extension but preserves the shared authentication identity and does not delete Hive membership, Hive Points, quests, quiz attempts, referrals, check-ins, or Hive progress.

Full Luzora account deletion, selected on the website data-deletion page, removes the shared Luzora authentication account and associated Extension and Hive data. This includes the Hive public profile, Manifesto membership record, quest submissions, quiz attempts, referrals, check-ins, and identifiable point history from Luzora-managed active systems, except for limited information we must or may lawfully retain.

Email-link verification is required for website deletion requests. After successful verification, the selected deletion scope is normally processed immediately. If a request cannot be completed automatically or requires additional review, we aim to complete it promptly and no later than 30 days after verification. Where additional time is legally permitted because a request is complex or unusually burdensome, we will notify you within the initial 30-day period and explain the reason for the additional time.

Following verified full-account deletion, your public Hive profile and active leaderboard entry will be removed. You will lose access to tasks, awards, points, quiz history, quest history, referrals, and other account features, and they generally cannot be restored. Information lawfully retained for security, fraud prevention, legal compliance, dispute resolution, financial or corporate recordkeeping, suppression requests, backup cycles, or system integrity will be access-restricted and used only for that purpose. Aggregate or de-identified statistics and anonymous feedback may remain.

Analytics events already collected will be deleted, de-identified, or retained according to the provider's available controls, applicable law, and whether we can reliably associate them with the verified requester. We do not use account deletion as a reason to keep identifiable analytics indefinitely.

The extension provides extension-only deletion. Use the website data deletion page and select full account deletion to remove both Extension and Hive data together. If you cannot access the deletion flow, contact us at hello@luzora.app.

22. Your privacy choices and rights

Subject to the Nigeria Data Protection Act 2023 and other applicable law, you may have rights to be informed about processing; obtain access to and a copy of your personal information; correct inaccurate or incomplete information; request deletion; restrict or object to processing; receive portable information in an applicable format; withdraw consent; and object to qualifying decisions based solely on automated processing. You also have the right to complain to the Nigeria Data Protection Commission.

You can exercise many choices directly in Luzora by updating your profile, changing notification settings, clearing task data, deleting tasks, logging out, or deleting your account. You can also contact us at hello@luzora.app.

We may need to verify your identity before fulfilling certain requests. We may decline or limit requests where permitted by law, including where a request is fraudulent, harmful to others, technically impossible, conflicts with legal obligations, or affects rights and freedoms of others.

23. Security

We use reasonable technical and organizational measures designed to protect personal information. These measures may include Supabase Auth, row level security for user-owned data, HTTPS, role-based administrative access, service-role key restrictions, password reset flows, current-password checks for sensitive account actions, audit records, analytics filtering, and safe page-inspection design. We review access and incident risks in proportion to the sensitivity and purpose of the information.

If a personal data breach creates a risk requiring notification, we will notify the Nigeria Data Protection Commission and affected individuals within the time and manner required by applicable law.

No method of transmission or storage is completely secure. We cannot guarantee that Luzora or any third-party provider will be free from unauthorized access, misuse, data loss, vulnerabilities, or interruptions. You are responsible for keeping your account credentials secure and for using a trusted device and browser.

24. International transfers

Luzora's service providers may process information outside Nigeria or outside the country where you live. Before making a restricted cross-border transfer, we rely on a basis permitted by the Nigeria Data Protection Act 2023 and other applicable law, such as an adequate level of protection, appropriate contractual or organizational safeguards, necessity for an agreement or legal claim, or explicit consent where valid. You may contact us for more information about safeguards relevant to your information.

25. Children

Luzora accounts, The Hive, quests, quizzes, and other participation features are intended only for people aged 18 or older. We do not knowingly permit an individual under 18 to create an account or participate. If you believe a person under 18 has provided personal information to Luzora, contact us at hello@luzora.app. We may request limited information to verify the report and will take appropriate steps to restrict the account and delete the information, subject to law.

26. Do not track

Some browsers offer "Do Not Track" signals. There is no consistent industry standard for responding to those signals, so Luzora does not currently respond to them. You can use browser settings, extension settings, and account controls to manage certain data choices.

27. Changes to this Policy

We may update this Policy from time to time. We will post the revised Policy and update the "Last updated" date. Before a material change takes effect, we will provide reasonable additional notice through the website, extension, Hive, email, or another appropriate means where practicable and required by law. Where a new purpose or processing activity requires consent, we will ask for it rather than rely only on continued use.

28. Contact us

The controller is Luzora Task Limited, company registration number RC 9811642, Abuja, Nigeria. If you have questions, requests, or concerns about this Policy or Luzora privacy practices, contact us at hello@luzora.app.

You may also lodge a complaint with the Nigeria Data Protection Commission. We would appreciate the opportunity to address your concern first, but contacting us does not remove your right to approach the Commission.

Luzora

Save recurring website activities and track today's tasks from a compact browser extension.

Product

Home Manifesto FAQs Brand Assets Contact Us

Legal

Terms of Service Privacy Policy Data Deletion

Socials

X Reddit YouTube LinkedIn

© 2026 Luzora. All rights reserved.

Built to help you stay consistent, one task at a time.