Privacy Policy

Privacy Policy

Last updated: August 2026.

This Privacy Policy explains what personal data LUMEN BI LLC ("we", "us") collects, how we use and share it, and the rights you have. It applies to our websites, the Lovaetes application, and related services. It complements the Terms of Service and the Security page. LUMEN BI LLC is the controller of account and usage data, and the processor of data you upload or connect to a workspace ("Customer Data").

1. Data we collect

We collect the following categories of data:

  • Account data — name, email, password hash, authentication provider IDs, organization, role, locale.
  • Customer Data — files you upload, datasets you connect, dashboards, analyses, KPIs, alerts, chat history, comments.
  • Billing data — plan, subscription status, billing email, payment processor IDs, invoices. We do not store full card details; these are handled by our payment processor.
  • Usage & telemetry — pages viewed, features used, query latency, error reports, device and browser metadata, IP address.
  • Support communications — messages you send to support, sales, or legal.

2. How we use data

We process data for the following purposes (and only as long as needed for them):

  • Providing, securing, and improving the Service (contract / legitimate interests).
  • Authentication, fraud prevention, and abuse detection (legitimate interests / legal obligation).
  • Billing and tax compliance (contract / legal obligation).
  • Sending transactional emails (contract) and, where permitted, product updates (legitimate interests or consent — you can opt out at any time).
  • Complying with law and responding to lawful requests (legal obligation).

3. AI training

Lovaetes does not use customer data to train any AI model. We do not operate, fine-tune, or retrain foundation models on your uploaded files, datasets, dashboards, or chat history.

AI requests are routed through enterprise API endpoints from OpenAI. OpenAI's standard API terms state that content submitted through their paid API is not used to train their models. The applicable terms are set by the upstream provider; Lovaetes relies on those contracts rather than making an independent guarantee on the provider's behalf.

4. Workspace isolation

Customer data is stored in a managed Postgres database. Every table that contains customer content has Row-Level Security (RLS) enabled, and policies restrict reads and writes to the owning user and workspace. Isolation is enforced at the database layer, not only in the application UI.

5. What is sent to AI providers

When an AI feature is invoked, the request includes:

  • The user's prompt or the specific chart, KPI, or finding being analyzed.
  • A bounded business-context summary (for example, a small set of KPI values, project totals, or aggregated chart data) needed to answer the request.

The following are not sent to AI providers:

  • Raw uploaded files.
  • Full source datasets in their entirety.
  • Connected data-source credentials.
  • Other users' or other workspaces' data.

6. Credentials and encryption

Credentials for connected data sources (databases, sheets, APIs) are encrypted at rest using authenticated encryption (AES-GCM) before being stored. They are decrypted only inside server-side connection handlers and are never exposed to browser code or sent to AI providers.

Data in the managed database is encrypted at rest by the underlying infrastructure provider, and all traffic between your browser, the application, and AI providers uses TLS.

7. Cookies & analytics

We use a small number of strictly-necessary cookies for authentication, security, and session persistence. We may use privacy-preserving product analytics to understand aggregate feature usage. We do not use third-party advertising cookies. See our Cookie Policy for the full list.

8. Retention and deletion

You can delete your data at any time from the Security Center. Two actions are available:

  • Delete all my data — removes datasets, analyses, dashboards, KPIs, alerts, SOPs, chat history, recommendations, and connected source credentials owned by your account. Your profile and sign-in remain so you can re-onboard.
  • Close account — performs the deletion above and also removes your profile and role assignments, then signs you out.

Backups: deleted data may persist in encrypted backups for up to 30 days before being overwritten. Audit logs, invoices, and tax records are kept for the period required by applicable law (typically 7 years). AI prompts and responses sent to upstream providers are subject to those providers' own retention windows on their API tier.

9. Sharing & subprocessors

We share data only with sub-processors that act on our instructions to operate the Service (hosting, AI model providers, email, payments, monitoring). The current list is on the Subprocessors page. We do not sell personal data. We may disclose data to law enforcement where required by valid legal process; we will challenge overbroad requests where lawful and notify you unless prohibited.

10. International transfers

Data may be processed in the United States, the European Economic Area, the United Kingdom, and other countries where our sub-processors operate. Where required, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent safeguards.

11. Your rights

Depending on where you live (e.g., EEA/UK GDPR, California CCPA/CPRA, Brazil LGPD, Canada PIPEDA), you may have the right to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. To exercise these rights, contact support@lumenbi.app. We respond within the timeframes required by applicable law (generally 30 days). You may also lodge a complaint with your local data protection authority.

For Customer Data inside a workspace, the workspace owner is the controller and you should direct your request to them; we will assist as the processor.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Security

We apply administrative, technical, and physical safeguards designed to protect personal data. See the Security page for details. No system is perfectly secure; please report suspected vulnerabilities to support@lumenbi.app.

14. What this page is not

This page describes controls implemented in the product. It is not an audit report and does not claim SOC 2, ISO 27001, HIPAA, PCI-DSS, or GDPR certification. If your organization requires specific contractual commitments (DPA, regional data residency, zero-data-retention API tiers, named subprocessor list) please contact us so we can scope them explicitly.

15. Changes to this Policy

We may update this Policy. We will notify you of material changes in-product or by email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

16. Contact