Legal

Privacy policy

How Locket collects, uses, and protects the data you and your customers entrust to us.

Effective January 15, 2026Last updated January 15, 2026

This policy explains what data Locket collects, how we use it, and the rights you have over it. It applies to everyone using locketailabs.com, our platform, and our APIs. We aim for plain language: if anything reads unclear, tell us and we will fix it.

Who we are

Locket is operated by Locket AI Labs, Inc. ("Locket", "we", "us"). We build an AI marketing intelligence platform for brand teams. When you use Locket, we act as a data processor on your behalf for your customer data, and as a data controller for the account and usage data you provide to us directly.

Data we collect

We collect three broad categories of data, each with a clear purpose:

  • Account data: name, work email, workspace, billing details. Used to run your account.
  • Customer data: the customer, event, and product data you connect via Klaviyo, Shopify, CSV, or our APIs. Used to power Sophei's signals and recommendations.
  • Usage data: pages visited, features used, error logs. Used to improve the product and keep it secure.

How we use data

We do not sell customer data. We do not use customer data from your workspace to train foundation models or share it across workspaces.

  • Operate and improve the platform, including generating recommendations and content
  • Provide support and communicate with you about your account
  • Comply with legal, tax, and security obligations
  • Detect abuse, fraud, and misuse, including automated safety checks on generated content

AI and sub-processors

Sophei relies on trusted infrastructure and model providers. When customer data is sent to a sub-processor for inference, it is scoped to the task at hand and processed under strict data-use terms, including no-training-on-customer-data commitments where available.

  • Model providers: Anthropic and OpenAI (inference only, no training on your data)
  • Cloud & storage: AWS (US and EU regions)
  • Payments, Paygentic / Stripe
  • Product analytics: first-party, self-hosted where possible

Your rights

Depending on where you are, you may have the right to access, correct, delete, port, or restrict the processing of your data. Enterprise workspaces can trigger full data exports and deletions from the admin console. Individual customers on your list can be deleted through your workspace or by contacting us directly.

Data retention

We retain account and workspace data for as long as your account is active. Customer data is retained under your workspace policy, you can set retention windows in settings. On workspace deletion, data is purged within 30 days from primary systems and within 90 days from encrypted backups.

International transfers

Locket is a US-headquartered company. If you are in the EU or UK, we rely on Standard Contractual Clauses (and the UK Addendum) to transfer data. EU customers on Growth and Pro plans can pin data storage to our EU region.

Changes to this policy

We will notify workspace owners by email at least 14 days before any material change takes effect. Older versions of this policy are available on request.

Contact

Questions about privacy? Email privacy@locketailabs.com. For general support, email hello@locketailabs.com.

Start free

Ready to market with intelligence?

Join hundreds of brand teams turning customer behavior into campaigns their audience actually wants. Setup in under 24 hours.