Privacy Policy
Effective date: {{EFFECTIVE_DATE}}
This Privacy Policy explains how {{LEGAL_ENTITY}} ("Lumen", "we", "us") collects, uses, and protects your information when you use the Lumen study workspace. This document is provided for transparency and is not a substitute for legal advice.
Who this service is for
Lumen is a general-audience productivity tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact {{CONTACT_EMAIL}} and we will delete it.
Information we collect
- Account information. Your email address and an encrypted password, or, if you sign in with Google, the basic profile identifiers Google shares with us.
- Content you upload. Notes, documents, files, tags, folders, and audio recordings you add to your workspace.
- Derived content. Text transcripts we generate from your audio recordings using on-device speech-to-text processing.
- Technical data. Limited logs and error reports needed to operate and secure the service.
How we use your information
- To provide the workspace and its features (storage, search, transcription).
- To authenticate you and keep your account secure.
- To diagnose errors and improve reliability.
- To communicate with you about your account (e.g. confirmation and password-reset emails).
We do not sell your personal information, and we do not use your uploaded content or transcripts to train machine-learning models.
How your data is processed and stored
Your content is isolated per user and protected by database row-level-security policies so that only you can access your rows. We use the following service providers ("sub-processors") to operate Lumen:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Railway — the background transcription worker.
- Sentry — error monitoring (does not receive your content).
- Google — optional sign-in.
- Resend — to deliver account emails (confirmation and password-reset links).
Audio recordings are transcribed by a speech-to-text process we run ourselves; the audio is not sent to a third-party transcription service. Temporary copies created during transcription are deleted afterward.
The optional AI assistant
Lumen includes an optional in-app AI assistant. It is off until you enable it by adding your own Anthropic API key, which we store encrypted on your behalf. When you use the assistant, your question and relevant excerpts of your notes and transcripts are sent to Anthropic (the Claude API) to generate a response, under your own API key and Anthropic's terms. If you never enable the assistant, no content is sent to Anthropic. You can stop using it and remove your key at any time.
Data retention
We keep your content for as long as your account is active. When you delete content, or your account, we remove the associated data from our active systems; residual copies in backups are purged on our standard backup rotation.
Your rights
Depending on where you live (including under the EU/UK GDPR and the California CCPA), you may have the right to access, correct, export, or delete your personal information, and to restrict or object to certain processing. To exercise these rights, contact {{CONTACT_EMAIL}}. You may also delete content directly within the app.
Security
We use industry-standard measures including encrypted transport, per-user access controls, and row-level-security. No system is perfectly secure, but we work to protect your information and will notify affected users of a material breach as required by law.
International users
Your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
Changes to this policy
We may update this policy. Material changes will be announced in the app or by email, and the effective date above will be updated.
Contact
{{LEGAL_ENTITY}}, {{COMPANY_ADDRESS}} — {{CONTACT_EMAIL}}.