What stays on your device, and exactly when it doesn’t.
LumenQube is local-first by design — your files live on your device. This is the one place that says when a feature you choose sends content, what it sends, and who receives it.
- Local first
- Documents stay on your device by defaultOpening, editing and saving a local file does not upload its contents.
- Your choice
- Cloud features process only what they needAI, sharing, publishing, connectors and diagnostics each have a stated boundary.
- No ad model
- We do not sell your informationDocument contents are never used for advertising, and there is no ad business here to fund.
- Off by default
- Product analytics needs your opt-inMonthly rotating pseudonyms, no document content, and off until you turn it on.
01The boundary
Six ways content crosses it. Nothing else does.
Pick a feature to see exactly what it sends, what stays behind, and who receives it. Ordinary editing is listed too — it is the row where the answer is nothing.
Opening, editing, saving and exporting a file happens entirely on your machine. There is no background sync and no check-in on a document you never shared.
- SENT
- Nothing. Not the file, not its name, not its contents.
- STAYS ON DEVICE
- Everything — the documents, the context graph, and anything held in your OS keychain.
- WHO RECEIVES IT
- No one.
You ask for something; the request goes through our managed backend to the model provider for that feature, and the result comes back to the document.
- SENT
- The prompt, plus the selection, file or recording the action operates on.
- STAYS ON DEVICE
- The rest of the document, and every file you did not act on.
- WHO RECEIVES IT
- LumenQube’s backend, then the model provider — listed by name in Privacy Policy §12.
A shared document is a copy stored on our servers so collaborators can open it. Your local file keeps being your local file.
- SENT
- The revision you shared, encrypted at the application layer and again by the platform at rest.
- STAYS ON DEVICE
- Your original, and every document you did not share.
- WHO RECEIVES IT
- LumenQube servers, and the people you authorized — at the role you gave them.
Publishing puts a copy where a browser can reach it. That is the feature; there is no version of it that keeps the content on your disk.
- SENT
- The revision the viewer renders, plus any passcode you set — stored only as a hash.
- STAYS ON DEVICE
- Everything you did not publish.
- WHO RECEIVES IT
- LumenQube servers, and whoever holds the link until you revoke it.
A connected account is authorized separately, scoped to what you granted, and disconnectable at any time from Settings.
- SENT
- Only the query or content the approved action requires — not your library.
- STAYS ON DEVICE
- Your credentials are not there to send: tokens live server-side, encrypted, never inside a document.
- WHO RECEIVES IT
- The provider you connected, under that provider’s own terms.
A report filed from inside the app carries diagnostics so we can investigate. You decide whether a document goes with it.
- SENT
- Diagnostic logs, plus any attachment you choose to add — and nothing you did not add.
- STAYS ON DEVICE
- Every file you did not attach.
- WHO RECEIVES IT
- LumenQube support.
The one crossing that is always on while you are signed in. It carries the account, not the work.
- SENT
- Your account record, allowance balance and usage counters.
- STAYS ON DEVICE
- Your documents. Metering counts requests, not content.
- WHO RECEIVES IT
- LumenQube servers, and the payment provider at checkout.
In plain terms: do not use AI, sharing, publishing, connectors or diagnostics with attachments, and your document contents never reach us at all. Use one, and only the content that feature needs is sent. The Privacy Policy is the field-by-field version of this paragraph.
02Your controls
Six you can use yourself, right now.
No request form and no waiting. Each one names the exact place in the app, as Privacy Policy §18.1 lists them.
Product analytics
Off by default. Turn it on, or back off, whenever you like.
Settings → Privacy & data → Share anonymous product trendsAgent run outcomes
Off by default, set separately on each computer. Turning it off discards outcomes that have not been sent.
LumenAgent settings → Devices → Share anonymous run outcomesMemory & context
Read what is stored, exclude an object, forget one, or switch the whole engine off.
LumenAgent settings → MemoryConnected services
Disconnecting deletes LumenQube’s stored token record and asks the provider to revoke its grant where the provider offers that: Google once no other Google service you connected relies on it, Dropbox, Slack user tokens and hub apps that publish revocation. Microsoft access and Slack workspace installs are revoked in the provider’s own controls. Neither step undoes actions already taken or deletes saved content.
Settings → disconnect the providerSharing
Revoke a link, remove a collaborator, or rotate the document key after an access change.
Share panel → Revoke · Remove · Rotate keyVerification, receipts and security notices come with the account. Any optional message carries an unsubscribe link.
Unsubscribe — in every optional message03The privacy policy
Twenty-four sections, written to be read.
Exact about the moments a cloud feature transmits your content — field by field. Effective 27 September 2026.
Read the full policy04Assurance
Published with the gaps left visible.
Every answer we filed is public on the registry entry — 603 questions, including the controls still open. The registry is the version of record; this page summarises it.
STAR Level 1
Across the Cloud Controls Matrix. The assessment separates LumenQube, customer and upstream-provider responsibilities, and records open controls as open rather than leaving them blank.
STAR for AI Level 1
On responsible AI and AI security, assessed as an application provider using managed model APIs. We do not train a foundation model on customer content.
What we do not hold
- We have not completed a SOC 2 examination
- We do not hold ISO 27001 certification
- We have not commissioned a published third-party penetration test
If procurement needs one, tell us what and by when.
- The company
- LumenQube Analytics Inc., a Canadian company
- Where data is processed
- Canada, the United States and other countries where providers operate
- Region pinning
- Not offered today — no in-region residency
- The full list
- Security §07 and Policy §12
05Report a vulnerability
Report it privately, and we will not come after you.
Email the affected product or URL, reproduction steps, impact and any evidence. Reports are triaged by severity; there is no fixed response-time promise and no paid bounty programme today. Good-faith research within scope is safe-harboured.
06Questions
Security, in plain language.
Are shared documents end-to-end encrypted?
No. Shared and published documents are encrypted in transit and at rest, including application-layer encryption of stored revisions — but LumenQube manages the keys so authorized server processes can render and synchronize the content. That is encryption at rest, not end-to-end encryption, and we will not describe it as the latter.
When does a document leave my device?
Only when you use a feature that needs cloud processing: AI, sharing, web publishing, a connected service, or a support report with attachments. Ordinary local editing does not upload document contents at any point.
Do you train AI models on my content?
LumenQube does not use your content to train a generalized AI model as a product purpose. Content is sent only when you request an AI feature, to the selected processor or eligible fallback needed for that request. A provider’s own data use, retention and permitted security or legal processing depend on the service and our account terms and settings. See Privacy Policy §7.
Can I revoke access to work I already shared?
Yes. Owners can change member roles, remove collaborators, revoke browser links, and rotate the document key after an access change. A copy somebody already downloaded is outside LumenQube’s control — that is true of every system, and worth planning for.
Where is my data stored?
Providers and connected services may process data in Canada, the United States and other countries where they operate. LumenQube does not offer a region-pinned deployment or in-region data residency. See Privacy Policy §12.
What is your CSA STAR status?
Listed in the CSA STAR Registry since 31 July 2026, carrying STAR Level 1 (CAIQ v4.1) and STAR for AI Level 1 (AI-CAIQ v1.1). Level 1 is a provider self-assessment that CSA publishes — not an independent audit, a third-party certification, or a penetration test.
How do I make a privacy request?
Email privacy@lumenqube.com from your account address. Privacy Policy §18 explains the access, correction, deletion, portability, objection and restriction rights that may apply where you live.
Privacy should be understandable in practice.
Install it, sign in once with a free account, and edit offline — ordinary editing never sends your documents to our servers.