Security
Your visitors' privacy is the point, not a setting
Lomen is pre-launch. This page describes only how the product handles your data right now — no roadmap, no promises, no certification claims.
What the product does with your data
These are the controls in place in the product as it stands.
No credentials to hand over
Lomen measures your site with a single script tag you host yourself. There is no API key, no third-party account to connect and no write access to anything you own.
Removal is yours
Delete the snippet and collection stops immediately. Remove the site in Lomen and its entire pageview history is deleted with it, without waiting on a support request.
Row-level security on our database
Every table is behind row-level security. You can only read your own sites, pageviews and billing row, and privileged billing fields are protected by a SECURITY DEFINER trigger so they cannot be altered from a client session.
No cookies, no IPs, no fingerprinting
The tracking script sets no cookies, stores no IP addresses and builds no device fingerprint. It records a pageview, the path, the referrer and a coarse device type — nothing that identifies a person.
Managed cloud hosting with TLS
The site and its backend run on managed cloud infrastructure with TLS on all traffic. There is no self-hosted server and no public database endpoint exposed by the app.
Incident response and data rights
If we discover a personal data breach affecting your account, we will notify you without undue delay and report it to the relevant supervisory authority within 72 hours where required. You can request data export or deletion at any time.
Compliance status, stated plainly
Lomen is an early-stage product maintained by the Lomen team, and this page is app-owner maintained content rather than an independent audit. We are not currently certified under SOC 2, ISO 27001 or any equivalent scheme, and we will not claim otherwise. This page describes the product as it is today; we will update it if that changes.
Responsibility is shared. We secure the Lomen platform, its infrastructure and the data you send to it. You remain responsible for where you install the snippet, who you give access to your account, and how you handle exported reports.
Found a vulnerability? Email security@lomenanalytics.com. We acknowledge reports within one business day and will keep you updated until resolution.