
Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains what information Lulu Berries ("the Service," "we," "us") collects, how it's used, and how it's protected. Lulu Berries is a task, project, and approval-tracking tool used by companies ("Customers") and their employees ("Users"). If you're an employee using Lulu Berries because your employer set up an account, your employer is the Customer and controls how your account is provisioned and removed; this policy describes how the Service itself handles data.
Information we collect
From Google Sign-In
Lulu Berries uses Google Sign-In as the only way to log in. When you sign in, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password — authentication happens entirely through Google.
Gmail sending permission
Lulu Berries requests permission to send email on your behalf (the gmail.send scope). This is write-only — we cannot read your inbox, contacts, or any existing email. This permission is used solely to send notifications that genuinely come from you: task assignments, approval requests, comments, digest summaries, and team invitations you send through the product. Every email sent this way is one you triggered through a specific action in the app (assigning a task, inviting a teammate, etc.) — Lulu Berries never sends email on your behalf outside of those in-product actions.
Content you and your company provide
This includes projects, tasks, comments, approval history, time entries, uploaded files and attachments, and knowledge base entries your company creates while using the Service. Files are stored in a cloud storage bucket (Amazon S3 or Google Cloud Storage, depending on how your Customer's instance is configured) and are only accessible through the Service's access controls, not publicly.
Client review information (if your company uses this feature)
Some Customers use Lulu Berries to share work with their own external clients for review and approval. If so, we collect the name and email address of that client (as provided by the inviting employee) and, if the client chooses to connect their own social media accounts (Facebook, Instagram, Google Business Profile, LinkedIn, Etsy, YouTube, or TikTok) to allow publishing approved work, we store the authorization tokens those platforms issue. These tokens are used only to publish content that client's team has explicitly approved through the Service, to accounts the client connected themselves — never to post anything without an approved action initiating it, and never to access any other data on those platforms.
How we use information
We use the information above to:
- Operate the core product — tasks, projects, approvals, and the workflows around them
- Send the notifications and emails described above, from your own identity
- Provide search (including AI-assisted search of your company's knowledge base, if your Customer has enabled it — see below)
- Publish approved work to social accounts, only when your company's client review workflow explicitly triggers it
- Maintain security, including the activity log each Customer can see for their own company
If your Customer has enabled AI-powered knowledge base search, the text of knowledge base entries is sent to a third-party AI provider (OpenAI, or an alternative your Customer has configured) to generate search embeddings. Only knowledge base content is sent for this purpose — not your tasks, projects, or personal information.
How we share information
We do not sell your information. We share it only in these circumstances:
- With other people at your own company, according to the roles and visibility your company's admin has set up — this is core to how the product works (everyone can generally see everyone's work; only you or your managers can edit your tasks)
- With the specific social media platforms you or your company explicitly authorize, only when publishing approved content
- With service providers who host the infrastructure (database hosting, file storage, email delivery) under standard confidentiality obligations
- If required by law, or to protect the rights, safety, or property of the Service, our Customers, or others
Companies using Lulu Berries are strictly isolated from one another. Employees at one company can never see another company's projects, tasks, files, or people, regardless of how many companies use the same Lulu Berries deployment.
Data retention and deletion
Your company's data is retained for as long as your company's account remains active. If you'd like your personal account information removed, or if your company would like its account and data deleted, contact us at the email below. A company's administrator can also deactivate accounts for employees who leave.
Security
Data is encrypted in transit (HTTPS) between your browser and the Service. Access to company data is restricted by the role-based permissions your company's admin configures. We do not store your Google password. No system is perfectly secure, but we take reasonable, industry-standard measures to protect your information.
Children's privacy
Lulu Berries is a business tool intended for use by employed adults and is not directed at children. We do not knowingly collect information from children.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we'll update the "Last updated" date above.
Contact us
Questions about this policy or your data can be sent to tarek@luluberries.app.