1.Who we are
LumenQube (the "Service," the "app") is provided by LumenQube Analytics Inc. ("LumenQube," "we," "us," or "our"), a corporation incorporated under the Business Corporations Act (Ontario), Ontario Corporation No. 1001600101, located in Ontario, Canada.
For the purposes of data-protection law, LumenQube is the controller of the personal information described in this policy. If you have any questions, you can reach our privacy team at privacy@lumenqube.com.
2.Scope of this policy
This policy applies to personal information we process when you:
- download, install, and use a published LumenQube desktop or mobile application;
- create or use an IO account and our hosted services (account, AI credits, sharing, web publishing) at app.lumenqube.com;
- use the signed-in mobile workspace or view a document shared with you through our web viewer at view.lumenqube.com; or
- visit our website at lumenqube.com or contact us for support.
It does not apply to third-party products or websites that we do not control, even where we link to them.
3.Local-first by design
LumenQube is built so that your documents stay on your device by default. The files you open and edit — PDFs, spreadsheets, documents, designs, slides, and notes — are stored locally and are not uploaded to our servers in the background.
Some features you choose to use are, by their nature, cloud features: they only work by sending the relevant content to our servers or to a service provider. These are:
- AI features — when you ask the app to generate, summarize, transform, transcribe, or otherwise act on content, the relevant input is sent to our backend and on to our AI provider so a result can be returned (see Section 7).
- Sharing & collaboration — when you share a document, its contents are stored on our servers (encrypted at rest) so other people you authorize can open it.
- Publish to web — when you publish a document to a public or restricted web link, its contents are stored on our servers so the web viewer can display them.
- Connected services — when you connect or use a third-party service, LumenQube sends the account data, query, or content needed to complete the action you authorize.
- Support & diagnostics — a report may include logs or attachments you choose to submit so we can investigate the problem.
- Account & billing — your account, credit balance, and usage metering are stored on our servers.
In plain terms: if you do not use AI, sharing, web publishing, connectors, or send diagnostics with content attached, your document contents remain on your device. When you do use a cloud feature, only the content needed for that action is transmitted.
4.Information we collect
4.1 Information you provide
- Account information — your name, email address, and a securely hashed password when you create an account. If you sign in with Google, we receive your name, email address, and Google account identifier.
- Content you choose to process in the cloud — the documents, text, prompts, images, audio, connector requests, and diagnostic attachments you submit to a cloud feature, as described in Section 3.
- Support communications — the contents of bug reports and messages you send us, which may include diagnostic error logs you choose to attach.
- Payment information — when you buy credits or a subscription, your payment is processed by our payment provider (see Section 9). We do not receive or store your full card number; we receive limited billing details such as your name, email, country, the plan or pack purchased, and the transaction status.
4.2 Information we collect automatically
- Required usage & AI metering — the billable feature, provider units, credits, and cost needed to deliver paid or credit-limited services, prevent abuse, and maintain billing records. These operational records are linked to the account or organization responsible for the usage; they are not described as anonymous product analytics.
- Optional product analytics — only when you turn on Share anonymous product trends, we record the LumenQube service category, a visit count, capped foreground-active time, platform, and a keyed installation pseudonym that rotates every calendar month. The stored trend record does not include your account ID, name, email, IP address, filename, file path, document content, prompt, connector query, or individual action timeline. The authenticated endpoint confirms that the request is from a signed-in LumenQube client, but it does not add the account identity to the analytics record. Turning the setting off stops future collection.
- Device & technical information — your app version, operating system and platform, and an IP address observed by our servers, which we use for security, rate-limiting, fraud prevention, and to serve the correct software updates.
- Logs — server logs that record requests to our backend (such as time, route, status, and IP) for reliability and abuse prevention.
5.How we use information
We use personal information to:
- provide, maintain, and secure the Service and your account;
- deliver the cloud features you request, including AI results, sharing, and web publishing;
- meter and manage AI credits, process payments, and prevent fraud and abuse;
- provide customer support and respond to your requests;
- send you essential service communications (for example, email verification, password resets, security notices, and billing receipts);
- monitor, debug, and improve the reliability, performance, and quality of the Service; and, if you opt in, understand aggregate service adoption, repeat use, and foreground-active time;
- comply with our legal obligations and enforce our Terms of Service.
We do not sell your personal information, and we do not use the contents of your documents to advertise to you.
6.Legal bases (EEA/UK users)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:
- Performance of a contract — to provide the Service and the features you request, and to administer your account and billing.
- Legitimate interests — to secure the Service, prevent abuse and fraud, and improve our products, balanced against your rights.
- Consent — for optional product analytics and optional communications; you may withdraw consent at any time in Privacy & data settings.
- Legal obligation — to comply with applicable laws, including tax and accounting requirements.
7.How AI features handle your content
AI features are powered through our managed backend. When you invoke an AI feature, the relevant input — for example a prompt, a selection of a document, an attached file or image, or an audio recording you ask us to transcribe — is sent over an encrypted connection to our servers and then to our AI processor so a response can be generated and returned to you.
- We use commercial/API offerings from our AI providers. Under their current business-data terms, inputs and outputs are not used to train their models by default.
- Provider retention depends on the service and feature. Request data may be retained for abuse monitoring, legal obligations, or application state under the provider's current policy and our configuration.
- AI outputs can be inaccurate or incomplete. You are responsible for reviewing AI results before relying on them, and AI output is not professional (legal, medical, financial, or other) advice.
- You bring your own content; you should not submit content to AI features that you are not permitted to share with a service provider.
Our current AI providers are listed in Section 9. You can also review the providers' current business-data terms directly: OpenAI business data and Anthropic commercial data use.
7.1Google API data
Google Sign-In and the Google Drive, Gmail, Calendar, and YouTube connectors are optional. Each connector is authorized separately and is used only to provide the user-facing feature you choose. The precise permissions and product actions are documented on our Google integrations & data access page.
- Data accessed. Depending on the service you connect, LumenQube may access your basic Google account identity, Drive file metadata and content, Gmail message metadata and content, Calendar events, or the finished video and metadata you choose to upload to YouTube.
- How it is used. Google data is used only to complete the search, read, import, refresh, create, send, reply, RSVP, or upload action you request. Consequential write actions require your explicit action or approval.
- Storage and security. OAuth access and refresh tokens are encrypted at rest in our server-side vault. Google API responses are not routinely retained as a separate server-side dataset. A result may remain in a local LumenQube document or task history when you choose to use or save it.
- AI-assisted tasks and sharing. When you explicitly ask LumenAgent to summarize or transform connected content, the content needed for that request may be sent through our managed backend to the AI processor listed in Section 9. We do not sell Google user data, use it for targeted advertising, or provide it to data brokers.
- Human access. Our personnel do not read Google user data unless you give explicit permission for specific support, access is necessary to investigate abuse or a security incident, or access is required by law.
- Retention and deletion. The encrypted connector authorization remains until you disconnect, revoke access at Google, or delete your LumenQube account. Disconnecting deletes our stored token record for that service. Locally saved results remain under your control.
Google Limited Use. LumenQube's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7.2Microsoft, Dropbox & Slack connected-app data
Outlook, OneDrive & SharePoint, Dropbox, and Slack are optional connections. The exact delegated permissions and product actions are documented on our Connected apps permissions & data access page.
- Data accessed. Depending on the service you connect, LumenQube may access Microsoft account identity, Outlook messages, events and contacts, OneDrive or SharePoint file metadata and selected file content, Dropbox file metadata and selected file content, or Slack conversations where the installed LumenQube bot is a member.
- How it is used. Connected data is used only for the search, read, import, refresh, send, reply, calendar, contact, or Slack-posting task you request. Consequential actions require your explicit action or approval. Formatted Gmail and Outlook messages use a safe Markdown subset rendered to email HTML; they do not require additional provider permissions.
- Storage and security. OAuth access and refresh tokens are encrypted at rest in our server-side vault. Provider responses are not routinely retained as a separate server-side dataset. A result may remain in a local LumenQube document or task history when you choose to use or save it.
- AI-assisted tasks and sharing. When you explicitly ask LumenAgent to summarize or transform connected content, the content needed for that request may be sent through our managed backend to the AI processor listed in Section 9. We do not sell connected-app data, use it for targeted advertising, or provide it to data brokers.
- Human access. Our personnel do not read connected-app content unless you give explicit permission for specific support, access is necessary to investigate abuse or a security incident, or access is required by law.
- Retention and deletion. The encrypted connector authorization remains until you disconnect, revoke access at the provider, or delete your LumenQube account. Disconnecting deletes our stored token record for that service. Locally saved results remain under your control.
8.When we share information
We share personal information only as described here:
- With service providers (subprocessors) who process data on our behalf to run the Service, under contracts that require them to protect it — see Section 9.
- At your direction — for example, when you share a document or publish it to a web link, it becomes accessible to the people or audience you choose.
- For legal reasons — to comply with applicable law, a lawful request, or legal process, or to protect the rights, property, or safety of LumenQube, our users, or the public.
- In a business transfer — if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
9.Service providers & subprocessors
We use trusted providers to operate the Service. Availability varies by feature and account configuration; each provider receives only the data needed for the feature you choose:
| Provider | Purpose | Primary region |
|---|---|---|
| Google Cloud Platform | Hosting, application backend, and database for accounts, credits, encrypted shared documents, and logs | United States / Canada |
| Anthropic | AI processing (text generation, summarization, transformation, agents) | United States |
| OpenAI | AI image generation and audio transcription | United States |
| Polar | Payment processing and merchant-of-record for credits and subscriptions | United States |
| Mailjet | Transactional email (verification codes, password resets, receipts, share invites) | European Union |
| Google APIs | Google sign-in and optional user-authorized Drive, Gmail, Calendar, and YouTube connectors | Global / provider-selected |
| Microsoft Graph | Optional user-authorized Outlook, OneDrive, and SharePoint connections | Global / provider-selected |
| Dropbox API | Optional user-authorized Dropbox file search, import, and refresh | Global / provider-selected |
| Slack API | Optional user-authorized access to conversations joined by the LumenQube bot and approved message posting | Global / provider-selected |
| Unsplash, Pexels, Pixabay, and Openverse | Optional stock image, video, and audio search and retrieval | Global / provider-selected |
| fal.ai | Optional AI video generation when that feature is enabled | United States / provider-selected |
| Brave Search | Optional web search for LumenAgent queries | United States / global |
| GitHub | Distribution of desktop installers and optional user-directed source/deployment workflows | United States / global |
| Vercel, Netlify, and Cloudflare | Optional user-directed deployment of content or applications to an account the user connects | Global / provider-selected |
We may update this list as our infrastructure evolves; the current version is always available on this page. If you would like advance notice of changes to our subprocessors, contact privacy@lumenqube.com.
10.International data transfers
LumenQube is based in Canada, and several of our providers operate in the United States and elsewhere. When we transfer personal information across borders, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or a provider's adequacy/transfer mechanism, and we take steps designed to ensure your information receives a comparable level of protection.
11.Data retention
- Account data is retained while your account is active and for a reasonable period afterward to meet legal, tax, and accounting obligations and to resolve disputes.
- Shared / published content follows the applicable collaboration, ownership, publication, and legal-retention lifecycle. Revoking access or closing one account does not necessarily erase a room, revision, form, response, attribution, or object that another person still lawfully uses. Contact us for a verified account-specific disposition.
- AI inputs/outputs follow the provider and feature-specific retention described in Section 7; those policies and available retention controls may change.
- Operational error records have a 30-day deletion target. Payment-webhook delivery records have a 90-day target so we can reconcile a paid order or refund. Documented database TTL configuration supports these targets, but activation and operating effectiveness must be monitored; a configured target is not a guarantee of deletion at an exact instant.
- Usage, billing, tax, fraud-prevention, and accounting records are retained for the period required to operate the Service and meet legal obligations, then deleted or de-identified.
- Optional product analytics have a retention target of no more than 400 days. They use a monthly rotating installation pseudonym and contain no raw interaction timeline or account identity. The same operational-verification limitation for automated expiry applies.
12.How we protect your data
- Data in transit is protected with TLS encryption.
- Shared and published documents are encrypted at rest on our servers using server-managed keys. This is encryption at rest, not end-to-end encryption — because we manage the keys to operate features such as the web viewer, we are technically able to access this content where necessary to provide and secure the Service.
- On your device, sensitive local data such as notes and audio recordings can be encrypted at rest using your operating system's secure keychain.
- Passwords are stored only as salted, hashed values; we never store them in plain text.
- We apply access controls, rate-limiting, and account-lockout protections, and we maintain administrative and technical safeguards appropriate to the risk.
No method of transmission or storage is perfectly secure, but we work to protect your information and to continually improve our safeguards. See our Security Centre for a practical overview of current controls, important limits, and responsible disclosure.
13.Your rights & choices
Depending on where you live, you may have some or all of the following rights:
- Access a copy of the personal information we hold about you;
- Correct inaccurate or incomplete information;
- Delete your personal information;
- Port your information to another service;
- Object to or restrict certain processing; and
- Withdraw consent where we rely on it.
To exercise any of these rights, email privacy@lumenqube.com. We will respond within the time required by applicable law and may need to verify your identity first.
You can stop optional product analytics at any time in Settings → Privacy & data → Share anonymous product trends on desktop, or Privacy & devices → Optional product analytics on mobile. The control is off by default.
Canada (PIPEDA). You have the right to access and correct your personal information. If you have a concern we cannot resolve, you may contact the Office of the Privacy Commissioner of Canada.
California (CCPA/CPRA). We do not "sell" or "share" personal information as those terms are defined under California law, and we do not use sensitive personal information for purposes that would require an opt-out. You may exercise your access and deletion rights as described above, and we will not discriminate against you for doing so.
14.Deleting your account & data
You can request deletion of your account and associated personal information at any time by emailing privacy@lumenqube.com from your account email. The in-product account-close control disables authentication and removes the records covered by that automated flow; it is not, by itself, confirmation that every shared-content, form-response, mobile, deployment, subcollection, backup, billing, legal-hold, or physical-storage record has been erased. For a complete verified request, contact us so we can identify the applicable records, resolve other users’ rights and legal-retention duties, and provide the response required by law. Documents stored only on your device remain on your device and are within your control.
15.Children's privacy
The Service is not directed to children. You must be at least the age of majority in your jurisdiction (or have the consent of a parent or legal guardian) to create an account, and in any event at least 16 years old. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us so we can investigate and process the appropriate verified deletion request.
16.Cookies & similar technologies
Our marketing website uses minimal, essential storage to make the site work and to remember your preferences. Our app and web viewer use local storage and session tokens that are necessary to keep you signed in and to operate features. If you opt in to product analytics, the client also creates a random local installation identifier; it is sent only to our backend, which replaces it with a keyed monthly pseudonym before storage. We do not use third-party advertising cookies or cross-site tracking.
17.Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app or by email. Your continued use of the Service after an update means you accept the revised policy.
18.How to contact us
For privacy questions or to exercise your rights, contact:
LumenQube Analytics Inc. — Privacy
Email: privacy@lumenqube.com
Ontario, Canada
See also our Security Centre, Google integrations & data access, Microsoft, Dropbox & Slack permissions, Terms of Service, Docs, and Support pages.