Trust centre

Security & privacy

Lyra's whole design is to keep your data with you. This page is an honest account of what we do โ€” and, just as importantly, what we don't claim. Where something is planned rather than achieved, we label it Planned.

Data residency

What leaves your device โ€” and what doesn't

ModeWhat's sentWhere
Local modelsNothing โ€” processed on-deviceYour Mac
Cloud pipeline (paid)Your query, after PII redactionSydney, AU
BYOK cloud modelYour query (redaction applied first)The provider you choose

PII detection & redaction (Presidio)

Before any optional cloud call, personal identifiers โ€” names, emails, phone numbers, TFNs, Medicare numbers, dates of birth and financial data โ€” are detected and redacted using Microsoft Presidio, and sensitive queries default to on-device models.

Honest caveat: automated PII detection is best-effort, not a guarantee. No detector catches 100% of every identifier in every phrasing. Treat cloud mode accordingly, and keep the most sensitive work on local models.

Sub-processors

Third parties that may process data on our behalf when you use the optional cloud features:

Sub-processorPurposeRegion
VultrCloud pipeline hostingSydney, AU
StripeSubscription paymentsUnited States
CartesiaText-to-speech (Voice tier)United States
Anthropic / OpenAI / GoogleCloud LLMs โ€” only when you enable BYOKProvider's region
Transactional email providerDownload links & account emailUnited States

We keep this list current as our stack changes; material additions are posted here.

Retention & deletion

Data processing agreement (DPA)

Businesses can request our DPA. Email raj@pdvr.com.au with "DPA request" and we'll send it over.

Security contact & responsible disclosure

Found a vulnerability? Please report it to raj@pdvr.com.au. We'll acknowledge and work with you on a fix; please give us reasonable time before public disclosure.

Assurance status

We will not claim certifications we don't hold. Current status, stated plainly:

๐Ÿ”“ Verify any Lyra action yourself. The Trust Envelope uses RFC 8785 canonicalisation + SHA-256 + Ed25519 signatures over a hash-chained ledger. Everything is open and independently checkable: try the interactive demo โ†’ (generate โ†’ sign โ†’ verify โ†’ tamper, entirely in your browser) or read the source & spec on GitHub.

Download Lyra free โ†’