Privacy Policy
What Lumen collects, why, who it goes to, and how to get it back or deleted.
Last updated
This document is not finished: the business's legalName, address, jurisdiction, grievanceOfficer have not been filled in yet.
This policy covers Lumen at lumensite.in — the tool you sign into to build websites. It is operated by [registered entity name — not set], [registered office address — not set].
It does not cover the websites people build with Lumen. Those belong to the businesses that made them, and each of them is responsible for its own visitors. Where Lumen stores something on their behalf — an enquiry, an order — we act on their instructions, and the Data Processing Agreement sets that out.
1.What we collect
Only what the product needs to work. In practice that is four things.
- Your account: the email address you sign up with, your name if you give one, and a password that is stored hashed by our authentication provider and never seen by us. If you sign in with Google, we receive your email address, name and profile picture from Google.
- What you build: the prompts you write, the screenshots and images you upload, the sites Lumen generates for you, every saved version of them, and the conversation in the editor.
- Your settings: a model preference, an OpenAI key if you choose to add your own, and any connector you authorise. Keys and connector tokens are encrypted before they are stored.
- Billing: if you subscribe, our payment provider handles the payment and tells us your subscription status, its period, and an invoice record. We never see or store your card details.
2.What we do not collect
- We do not use advertising cookies or trackers, and we do not sell or share anything for advertising.
- We do not build profiles of the visitors to the sites you publish. Visits are counted using a one-way hash of the visitor’s address, browser and the day, salted with a secret. The hash cannot be reversed, it changes daily, and no cookie is set to do it.
- We do not read your generated sites to train anything of our own.
3.Why we are allowed to hold it
- To provide the service you asked for — this covers your account, your projects and your generated sites.
- To take payment, where you have subscribed.
- Our legitimate interest in keeping the service working and secure: rate limiting, abuse prevention, and error logs that have credentials stripped out of them before they are written.
- Your consent, where you gave it — for example by connecting a third-party account.
4.Who else sees it
Lumen is built on other people’s infrastructure, and the following receive data because the product cannot run without them. Each is bound by its own terms and processes data on our instructions.
- Supabase — the database, file storage and authentication.
- Vercel — hosting for the application and for published sites.
- OpenAI — receives the text of your prompt, the screenshot you uploaded if you used one, and the content of the site being edited, in order to generate or change it. If you supply your own key, the request goes under your key and your agreement with them.
- Razorpay — payments and subscription management, where you subscribe.
- Google — where you sign in with Google, or import a business from a Google listing.
Nobody else. We do not sell personal data, and we do not disclose it except where the law requires it of us, and then only what is required.
5.Where it is held
On infrastructure operated by the providers above, which may process and store data outside your country. Where that happens, we rely on the providers’ own transfer safeguards and contractual terms.
6.How long we keep it
- Your account and projects: until you delete them, or until you close your account.
- Deleted projects: removed from the application immediately; backups age out on our provider’s cycle.
- Enquiries and orders captured on a site you published: held for you until you delete them, because they are your customers’ records, not ours.
- Page-view counts: kept as daily totals with no identifier attached.
- Error logs: kept for troubleshooting and pruned; credentials and tokens are removed before an error is written down.
- Billing records: kept as long as tax and accounting law requires.
7.What you can ask for
Write to socialsprouts1@gmail.com and we will act on any of the following. We will confirm receipt and respond within 30 days.
- A copy of what we hold about you.
- A correction, where something is wrong.
- Deletion of your account and everything in it.
- A copy of your generated sites — you can also export these yourself at any time, without asking us.
- Withdrawal of a consent you gave, such as a connected account.
- An objection to how we are using something, or a restriction on it.
You never need our permission to leave. Every site you build can be exported as plain HTML and CSS and hosted anywhere.
8.Children
Lumen is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has an account, write to us and we will remove it.
9.If something goes wrong
If personal data is exposed in a way that is likely to harm you, we will tell you and the relevant authority without undue delay, describe what happened, and say what we have done about it.
Complaints go to our Grievance Officer, [name — not set], at socialsprouts1@gmail.com. If you are not satisfied, you may complain to your national data protection authority.
10.Changes
When this policy changes in a way that matters, we will say so in the product before the change takes effect. The date at the top is always the date of the current version.
Something here unclear, or not matching what the product does? Tell us — a policy that does not describe the real thing is a bug.