Trust centre · Privacy

Privacy Policy

What LumenQube Analytics Inc. collects when you use LumenQube, how we use it, who else touches it, and the rights you have. LumenQube is local-first by design — your files live on your device — and this policy is written to be exact about the moments a cloud feature transmits your content.

Effective
October 4, 2026
Previous
July 28, 2026
Length
—
Contents · 24 sections

01Who we are

LumenQube (the "Service," the "app") is provided by LUMENQUBE ANALYTICS INC. ("LumenQube," "we," "us," or "our"), a corporation incorporated under the Business Corporations Act (Ontario) on May 6, 2026, Ontario Corporation No. 1001600101. We are based in Mississauga, Ontario, Canada.

For the purposes of data-protection law, LumenQube is the controller of the personal information described in this policy when we determine why and how it is processed. Organization and customer agreements may allocate roles differently for particular processing. Our privacy contact is reachable at privacy@lumenqube.com. For product or billing support, use support@lumenqube.com.

02Scope of this policy

This policy applies to personal information we process when you:

  • download, install and use a published LumenQube desktop or mobile application;
  • create or use an account and our hosted services — account, AI allowance, sharing, web publishing — at app.lumenqube.com;
  • use the signed-in mobile companion, or open a document shared with you through our web viewer at view.lumenqube.com; or
  • visit our website at lumenqube.com, or contact us for support.

It does not apply to third-party products or websites that we do not control, even where we link to them, and it does not apply to information you choose to place in a service you have connected — that remains governed by that provider's own terms.

03Local-first by design

LumenQube is built so your documents stay on your device by default. The files you open and edit — PDFs, spreadsheets, documents, designs, slides and notes — are stored locally and are not uploaded to our servers in the background.

Some features you choose to use are, by their nature, cloud features: they work only by sending the relevant content to our servers or to a service provider. These are:

  • AI features — when you ask the app to generate, summarize, transform, transcribe or otherwise act on content, the relevant input is sent to our backend and on to our AI provider so a result can be returned (see §7).
  • Sharing & collaboration — when you share a document, its contents are stored on our servers, encrypted at rest, so the people you authorize can open it.
  • Publish to web — when you publish to a public or restricted link, the contents are stored so the web viewer can display them.
  • Connected services — when you connect or use a third-party service, LumenQube sends the account data, query or content needed to complete the action you authorized.
  • Support & diagnostics — a report may include logs, or attachments you choose to submit, so we can investigate.
  • Account & billing — your account, allowance balance and usage metering are stored on our servers.
In plain terms

If you do not use AI, sharing, web publishing, connectors, or send diagnostics with content attached, your document contents remain on your device. When you do use a cloud feature, only the content needed for that action is transmitted.

04Information we collect

4.1 Information you provide

  • Account information — your name, email address, and a securely hashed password when you create an account. If you sign in with Google, we receive your name, email address and Google account identifier.
  • Content you choose to process in the cloud — the documents, text, prompts, images, audio, connector requests and diagnostic attachments you submit to a cloud feature, as described in §3.
  • Signature requests (LumenSign) — when you send a PDF for signature: the document, the fields you place, and the names and email addresses of the people you send it to. When someone signs: what they enter (signature and initials images, text, ticks), their consent to sign electronically, and an audit trail of each step — the time, IP address and browser user agent — which is printed on the certificate of completion so the signed document can be verified. One-time email codes and access codes are stored only as salted hashes, and each request's document is encrypted at rest with its own key. Invitations, codes and completed copies are sent by email through our email provider (see §12).
  • Support communications — the contents of bug reports and messages you send us, which may include diagnostic error logs you choose to attach.
  • Payment information — when you buy an allowance or a subscription, your payment is processed by our payment provider (see §12). We do not receive or store your full card number; we receive limited billing details such as your name, email, country, the plan or pack purchased and the transaction status.

4.2 Information we collect automatically

  • Required usage & AI metering — the billable feature, provider units, allowance drawn and cost needed to deliver paid or limited services, prevent abuse and maintain billing records. These operational records are linked to the account or organization responsible for the usage; they are not described as anonymous product analytics.
  • Optional product analytics — only when you turn on Share anonymous product trends, we record the LumenQube service category, a visit count, capped foreground-active time, platform, and a keyed installation pseudonym that rotates every calendar month. The stored trend record does not include your account ID, name, email, IP address, filename, file path, document content, prompt, connector query, or individual action timeline. The authenticated endpoint confirms that the request is from a signed-in LumenQube client, but it does not add the account identity to the analytics record. Turning the setting off stops future collection.
  • Optional agent run outcomes — only when you turn on Share anonymous run outcomes in LumenAgent settings → Devices, that computer sends counts about each LumenAgent run: whether it finished and why it stopped, how long it took, the AI allowance it used, which model and model tier ran it, how many steps and model calls it took, whether a document edit was left unfinished, how many approval requests it raised and whether you approved, declined or let them expire, and a typed error code. It also sends how many times the AI — in LumenAgent or in any editor's AI panel — asked for a tool by name and did not have it. The upload is authenticated, so our server can confirm it came from a signed-in LumenQube desktop app, but it is stored only as daily totals — per day, run type and model tier, and per tool name — with no account ID, name, email, IP address, prompt, reply, document, filename, file path or tool input. A one-way keyed code for each upload, which is not linked to the totals and is deleted after 7 days, stops a retried upload from being counted twice. The setting is off by default and is chosen separately on each computer; it does not follow you through sync. Nothing counted before you turn it on is sent, and turning it off discards outcomes that have not been sent yet.
  • Device & technical information — your app version, operating system and platform, and an IP address observed by our servers, which we use for security, rate-limiting, fraud prevention and to serve the correct software updates.
  • Logs — server logs recording requests to our backend (time, route, status, IP) for reliability and abuse prevention. Logs record the request, not the document.
What we never collect

We do not track you across other websites, we do not buy personal information from data brokers, we do not build advertising profiles, and we do not read your local files to learn about you. There is no advertising business here that any of that could fund.

05How we use information

We use personal information to:

  • provide, maintain and secure the Service and your account;
  • deliver the cloud features you request, including AI results, sharing and web publishing;
  • meter and manage your AI allowance, process payments, and prevent fraud and abuse;
  • provide customer support and respond to your requests;
  • send essential service communications — email verification, password resets, security notices, billing receipts;
  • monitor, debug and improve the reliability, performance and quality of the Service; and, if you opt in, understand aggregate adoption, repeat use and foreground-active time;
  • comply with our legal obligations and enforce our Terms of Service.

We do not sell your personal information, and we do not use the contents of your documents to advertise to you.

06Legal bases (EEA/UK users)

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:

  • Performance of a contract — to provide the Service and the features you request, and to administer your account and billing.
  • Legitimate interests — to secure the Service, prevent abuse and fraud, and improve our products, balanced against your rights and freedoms.
  • Consent — for optional product analytics, optional agent run outcomes and optional communications. You may withdraw consent at any time in Privacy & data settings, or for agent run outcomes in LumenAgent settings → Devices, without affecting processing already carried out.
  • Legal obligation — to comply with applicable laws, including tax and accounting requirements.

07How AI features handle your content

AI features are powered through our managed backend. When you invoke one, the relevant input — such as your prompt and conversation context, selected document text or tool result, an attached file or image, audio you ask us to transcribe, a video you ask the review feature to assess, or text you ask the premium voice to speak — is sent over an encrypted connection to our servers and then only to the processor or processors selected by that feature's routing conditions so a response can be generated and returned to you.

  • Which processor receives content depends on the feature and configuration. Text requests can use Anthropic, OpenAI or Google AI according to the selected engine and any qualified automatic-routing policy. If a selected Google AI or OpenAI text engine lacks its required credential, that request uses the nearest Anthropic engine instead. A provider that is not selected does not receive that request.
  • Image requests use the configured OpenAI or Google AI path. If that provider lacks its credential, the other configured provider becomes primary. After an eligible failure, an OpenAI request may first retry an older OpenAI image model and may then use the other configured provider as a backup. A timeout, cancellation, spending or capacity refusal does not start cross-provider fallback. A request that reaches a backup may therefore have been processed by both the failed primary and the successful backup.
  • Transcription can use OpenAI or, when explicitly selected and configured, Google AI. If Google AI is selected but its credential is unavailable, transcription uses OpenAI; requests that require word timings or speaker labels also use an OpenAI transcription model when the required OpenAI path is available. Premium speech synthesis sends the text and delivery instructions to OpenAI only when an eligible user explicitly selects that metered voice; ordinary read-aloud and standard voiceover use our self-hosted speech service.
  • OpenAI also receives selected text used for semantic embeddings, and may receive a generation prompt and up to two submitted images for a content-safety check when that check is enabled. These paths are used for semantic recall and generation safety, not for every AI request.
  • We use commercial/API offerings from our AI providers. LumenQube does not submit customer content for generalized model training as a product purpose and does not build or fine-tune a foundation model on customer content. A provider's own data use, model-training treatment, retention, location and human-access terms depend on the specific service, our account terms and settings, and permitted security or legal processing.
  • Provider retention is service- and feature-specific. Request data may be retained for abuse monitoring, legal obligations or application state under the provider terms and settings that apply to the selected path. We do not promise universal zero retention.
  • AI outputs can be inaccurate or incomplete. You are responsible for reviewing AI results before relying on them, and AI output is not professional — legal, medical, financial or other — advice.
  • You bring your own content. You should not submit content to AI features that you are not permitted to share with a service provider.

Our AI providers and their configuration-dependent purposes are listed in §12. You can also review provider information directly, including OpenAI business data and Anthropic commercial data use; those links do not establish which terms, retention choices or contractual options apply to our account.

08Google API data

Google Sign-In and the Google Drive, Gmail, Calendar and YouTube connectors are optional. Each connector is authorized separately and is used only to provide the user-facing feature you choose. The precise permissions and product actions are documented on our Google integrations & data access page.

  • Data accessed. Depending on the service you connect, LumenQube may access your basic Google account identity, Drive file metadata and content, Gmail message metadata and content, Calendar events, or the finished video and metadata you choose to upload to YouTube.
  • How it is used. Google data is used only to complete the search, read, import, refresh, create, send, reply, RSVP or upload action you request. Consequential write actions require your explicit action or approval.
  • Storage and security. OAuth access and refresh tokens are encrypted at rest in our server-side vault. Google API responses are not routinely retained as a separate server-side dataset. Content you use in a document or task can remain in that document or task history. When you use cloud or mobile task history, sync, sharing or publishing, the relevant saved content may also be stored on our servers under that feature's access controls and retention lifecycle.
  • AI-assisted tasks and sharing. When you explicitly ask LumenAgent to summarize or transform connected content, the content needed for that request may be sent through our managed backend to the AI processors listed in §12. We do not use Google user data to train generalized AI models, sell it, use it for targeted advertising, or provide it to data brokers.
  • Human access. Our personnel do not read Google user data unless you give explicit permission for specific support, access is necessary to investigate abuse or a security incident, or access is required by law.
  • Retention and deletion. Disconnecting a service in LumenQube deletes its stored token record and, once no other Google service you connected relies on the same authorization, asks Google to revoke it. Revoking access in your Google Account ends Google's authorization; it does not itself delete LumenQube's stored record. When a subsequent request detects an ended grant, the connection is marked as needing reconnection. You can disconnect it to delete the record. Disconnecting or revoking does not erase content already saved in documents, task histories, synced or shared items. Use the relevant document or conversation deletion controls and the account and data-deletion process for those copies. Local files remain under your control; cloud copies and backups follow §14.
Google Limited Use

LumenQube's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and, for Google Workspace data, the Google Workspace user data and developer policy, including their Limited Use requirements. This statement describes our required handling of Google user data; it is not a statement that Google has approved every OAuth client or requested scope.

09Microsoft, Dropbox & Slack connected-app data

Outlook, OneDrive & SharePoint, Dropbox and Slack are optional connections. The exact delegated permissions and product actions are documented on our Connected apps permissions & data access page.

  • Data accessed. Depending on the service you connect, LumenQube may access Microsoft account identity, Outlook messages, events and contacts, OneDrive or SharePoint file metadata and selected file content, Dropbox file metadata and selected file content, or Slack conversations where the installed LumenQube bot is a member.
  • How it is used. Connected data is used only for the search, read, import, refresh, send, reply, calendar, contact or Slack-posting task you request. Consequential actions require your explicit action or approval. Formatted Gmail and Outlook messages use a safe Markdown subset rendered to email HTML; they do not require additional provider permissions.
  • Storage and security. OAuth access and refresh tokens are encrypted at rest in our server-side vault. Provider responses are not routinely retained as a separate server-side dataset. A result may remain in a local LumenQube document or task history when you choose to use or save it.
  • AI-assisted tasks and sharing. When you explicitly ask LumenAgent to summarize or transform connected content, the content needed for that request may be sent through our managed backend to the AI processor listed in §12. We do not sell connected-app data, use it for targeted advertising, or provide it to data brokers.
  • Human access. Our personnel do not read connected-app content unless you give explicit permission for specific support, access is necessary to investigate abuse or a security incident, or access is required by law.
  • Retention, disconnect and revocation. The encrypted connector authorization remains in LumenQube until you disconnect it or close the applicable account. Disconnecting deletes LumenQube's stored token record and, where the provider offers revocation, also asks the provider to revoke the grant: Google once no other Google service you connected relies on it, Dropbox, Slack user tokens, and Connect Hub apps that publish a revocation endpoint. Microsoft offers no per-app revocation, and a Slack workspace installation is shared with your workspace, so revoke those in the provider's account controls, where you can also confirm any grant has ended. Disconnecting or revoking does not undo provider actions or delete messages, files, events, posts, downloaded copies or content already saved in LumenQube. Delete those copies through the relevant product/provider controls or a verified privacy request.

10The mobile app & device permissions

The LumenQube mobile app is a signed-in companion to the desktop application. It is distributed through the platform app store, and the store's own privacy label describes the same categories set out in this policy.

10.1 Permissions the app may ask for

Every permission below is requested in context, at the moment a feature needs it, and can be withdrawn at any time in your device's system settings. Refusing one disables that feature and nothing else.

PermissionWhy it is asked forIf you decline
MicrophoneRecording a voice note or a meeting you choose to captureRecording is unavailable; everything else works
Photos & cameraAdding an image to a document, or scanning a pageAttach files from storage instead
Files & storageOpening and saving documents you chooseThe app can only use documents already in its own storage
NotificationsReminders you set, and completion of a task you startedNo push messages are sent

10.2 What is stored on the device

  • Session tokens are held in the platform keychain. Signing out clears the device's stored credentials.
  • Documents you have opened may be cached on the device so they are available offline; removing the app removes that cache.
  • The mobile app reads a separate cloud memory set from the desktop app's local one. The two do not reconcile, so they can genuinely differ — the Security Centre explains why.
  • Optional product analytics is a separate control on mobile — Privacy & devices → Optional product analytics — and it is off by default there too.

We do not use mobile advertising identifiers, we do not include third-party advertising or attribution SDKs, and we do not collect precise device location.

11When we share information

We share personal information only as described here:

  • With the providers and connected services listed in §12 when the corresponding feature is selected, configured and available. Their role, contract, location, retention and other terms depend on the specific service and account evidence described there.
  • At your direction — for example, when you share a document or publish it to a web link, it becomes accessible to the people or audience you chose.
  • Between the people in a signature request — when a request is complete, everyone in it (the sender, each signer and each copy recipient) receives the signed document with its certificate of completion, which lists every recipient's name and email address and each step's time and IP address, and shows each signer's adopted signature. That is shared at the sender's direction so the document can be verified; a signer cannot remove their entry from it.
  • For legal reasons — to comply with applicable law, a lawful request or legal process, or to protect the rights, property or safety of LumenQube, our users, or the public. Where we are permitted to do so, we will tell you about a request for your information before responding to it.
  • In a business transfer — if we are involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that transaction, subject to this policy. We will give notice before your information becomes subject to a different privacy policy.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under United States state privacy laws.

12Service providers & subprocessors

These providers or provider classes can receive information when the corresponding feature is selected, configured and available. Not every provider receives every request. The location, contractual role, retention, training treatment and transfer terms that apply depend on the specific service and our account settings and contracts; contact us for current procurement evidence before relying on one of those facts.

Provider or serviceConditional purpose and dataLocation / evidence boundary
Google Cloud PlatformApplication hosting, Firestore account and service state, and Cloud Storage objects for selected cloud, sharing, source, signature and video featuresProvider-operated; no region-pinned deployment is offered. Current account/service configuration must be confirmed.
AnthropicSelected or eligible fallback text/agent processing; authorized support-ticket analysis; selected or eligible fallback web searchProvider-operated; account terms, settings, retention and processing locations require current evidence.
OpenAISelected text, image, transcription, embeddings and premium voice; optional moderation; eligible image/transcription fallback pathsProvider-operated; account terms, settings, retention and processing locations require current evidence.
Google AI (Gemini APIs)Configured text/image paths and eligible image backup; explicit/configured transcription, video critique or web searchProvider-operated; not the same service or approval as Google Workspace OAuth. Account evidence is required.
fal.aiOptional AI video generation from the prompt and selected inputsProvider-operated; account terms, retention, training treatment and locations require current evidence.
Brave Search, Google Places and Jina AI ReaderConditional web/place search or public-page rendering; Jina receives the public URL only after the ordinary reader returns no usable text or refuses the readProvider-operated; path and location vary with selection and configuration.
Unsplash, Pexels, Pixabay and OpenverseOptional stock image, video or audio search and retrievalProvider-operated; selection and client-version conditions vary.
PolarCheckout, subscription and refund processing; limited billing and transaction state is returned to LumenQubeProvider/account role and current contractual terms must be confirmed.
MailjetTransactional, support, sharing and signature-request email, including delivery stateProvider-operated; account terms, retention, subprocessors and location require current evidence.
Google and Apple identityOptional account authentication and identity subject/index dataProvider-operated under the selected identity service and the user's provider relationship.
Google Workspace and YouTube APIsSeparately authorized Drive, Gmail, Calendar and YouTube actions using the scopes on our Google integrations pageProvider-operated; requested source scopes are not a statement of Google approval.
Microsoft Graph, Dropbox API and Slack APIOptional Outlook, OneDrive/SharePoint, Dropbox or Slack reads and user-approved writes described on our Connected apps pageProvider-operated; approval and production status are provider/account-specific.
Google Analytics, Search Console, Google Ads and Google SheetsOptional business reporting/table sources; Sheets write-back requires incremental write consent and the product write switchSource-present but not configured in the bounded environment we reviewed; do not infer availability or approval.
Microsoft Excel Online, Intuit QuickBooks, Xero, Salesforce and PipedriveOptional business table, accounting and CRM sources; Excel write-back also uses the product write switchSource-present but not configured in the bounded environment we reviewed; provider-console scopes and approval vary.
Connect Hub remote providersAn optional provider-operated remote tool selected by the user; the provider chooses or returns its authorization scopes, and tool inputs/results go to that providerOnly catalog entries that are deployed, configured and available should be shown. Source allowlisting is not provider approval.
Vercel, Netlify, Cloudflare Pages and GitHub PagesOptional user-directed deployment using a user-supplied token and selected project files; GitHub Pages creates a public repository by defaultThe remote account, repository/site and provider retention remain under that provider's controls.
Organization-selected SIEM endpointOptional organization audit-event streaming to the HTTPS destination configured by that organizationDestination, contract, event fields and remote retention are organization-specific.

We update this list as our services change. For a current procurement schedule or a question about a provider, email privacy@lumenqube.com.

13International data transfers

LumenQube is based in Canada, and the providers and connected services described above may process information in Canada, the United States and other countries where they operate. Information processed abroad can be subject to the laws and lawful-access powers of that country. We do not currently offer a region-pinned deployment or in-region data residency.

The contract and transfer mechanism, if any, that applies must be determined for the specific provider, service, account and transfer. A provider may offer a data-processing agreement, Standard Contractual Clauses, a UK Addendum, an adequacy route or another mechanism, but this policy does not represent any one of them as executed or applicable until it has been confirmed. If processing location or a particular transfer mechanism is a requirement, contact legal@lumenqube.com before deployment.

14Data retention

Retention differs by record and by where it is held. A duration below is a source-configured target, not a guarantee of deletion at an exact instant; records without an automatic expiry require a documented manual or request-based disposition. Provider logs, connected-service copies, legal holds, object versions and backups follow separate account settings and procedures.

WhatHow longWhy
Account profile & identityWhile the account is active; the account-close flow removes the account row and identity indexesTop-level, shared, provider and retained legal records are separate
Account activity180-day source expiry targetAccount history and security visibility
Required usage, metering & account eventsCategory-specific source targets, commonly 30, 180 or 400 daysService operation, allowance, abuse prevention and billing; not one universal “usage” period
Cloud documents, shared/published content, forms & responsesThe applicable content, collaboration, ownership and publication lifecycle; no general age expiryOther users' rights, revisions, submissions and stored objects can have separate lifecycles
Signature requestsUntil the sender deletes the account in the source-present flow; emailed/downloaded recipient copies remain outside that flowDocument, participants, fields, events and audit trail
AI inputs & outputsFeature, provider, service, account terms and settings specific — see §7Requested processing, provider abuse/security requirements and product state
AI-generated video jobs & private archived clips30-day source expiry target after the job finishes, plus the account-deletion sweepProvider/CDN copies follow separate provider terms
Support tickets, plans, approvals, results & notesNo automatic expiry currently configured in source; retained until manually disposed of or assessed in a verified requestSupport, security, dispute and workflow record
Admin auditNo automatic expiry currently configured in sourceOperator accountability and security; access/request treatment requires an approved schedule
Bug reportsNo automatic expiry currently configured in source; retained until manually disposed of or assessed in a verified requestDebugging and reliability
Client error reports30-day source expiry targetDebugging and reliability
Server error records30-day source expiry targetDebugging and reliability
Connector and deployment authorizationsUntil disconnect or account deletion; token expiry is not deletion of the durable connection recordMaintain the user-selected connection; provider grants and remote copies require separate controls
Optional product analyticsNo more than 400 daysTrend record with rotating pseudonym and no account identity
Optional agent run outcomesDaily totals: 90 days; upload idempotency codes: 7 daysAggregate run quality without account identity in the totals
Payment-webhook delivery records90-day source expiry targetOrder/refund reconciliation
Receipts, payment markers, tax & legal-hold recordsCategory and legal-obligation specific; some top-level payment markers have no automatic source expiryAccounting, fraud, statutory retention and disputes
Cloud logs, object versions & backupsCurrent production/provider schedule must be confirmed; no period is promised hereOperations, recovery, legal hold and deletion propagation
Local files, app data, keychain items & database profilesUntil you remove them from the deviceThey are not reached by the cloud account export or deletion flow

For a verified, account-specific disposition, contact privacy@lumenqube.com. We will identify the records in scope, explain any retention or third-party boundary, and respond within the period required by applicable law.

15How we protect your data

  • Data in transit is protected with TLS encryption.
  • Shared and published documents are encrypted at rest on our servers using server-managed keys. This is encryption at rest, not end-to-end encryption — because we manage the keys to operate features such as the web viewer, we are technically able to access this content where necessary to provide and secure the Service.
  • Connector OAuth tokens are encrypted at rest in authenticated AES-256-GCM envelopes and stay behind the server proxy.
  • On your device, sensitive local data such as notes and audio recordings can be encrypted at rest using your operating system's secure keychain.
  • Passwords are stored only as salted, hashed values; we never store them in plain text.
  • We apply access controls, rate-limiting and account-lockout protections, and maintain administrative and technical safeguards appropriate to the risk.

No method of transmission or storage is perfectly secure, but we work to protect your information and to keep improving our safeguards. Our Security Centre is the practical version of this section: current controls, the limits, and how to report a vulnerability.

16Security incidents & notification

We maintain a written incident-response procedure covering detection, containment, evidence preservation, recovery and closure. It is summarized publicly in the Security Centre.

If a security incident affects your personal information, we will notify you and the relevant supervisory authorities where applicable law requires it, within the timelines that law sets — including, where the GDPR applies, notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal-data breach.

A notification will describe, as far as we know it at the time: what happened, what categories of information were involved, what we have done, what we are still doing, and what we recommend you do. We will not delay a notification in order to make it read better, and we will update it if what we know changes.

17Automated decisions & profiling

We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.

  • AI features generate content at your request. They do not decide anything about you, and their output is a draft for you to review.
  • Automated abuse and fraud controls — rate limits, lockouts and payment-risk signals — can temporarily restrict an action. Where such a control affects your account, you can contact support@lumenqube.com to have it reviewed by a person.
  • We do not profile you for advertising, and we do not score, rank or segment users for marketing purposes.

18Your rights & choices

Depending on where you live, you may have some or all of the following rights:

  • Access a copy of the personal information we hold about you;
  • Correct inaccurate or incomplete information;
  • Delete your personal information;
  • Port your information to another service in a structured, machine-readable format;
  • Object to or restrict certain processing; and
  • Withdraw consent where we rely on it.

To exercise any of these rights, email privacy@lumenqube.com from your account address. We will respond within the time required by applicable law — generally within 30 days, extended only where the law allows and we tell you why — and we may need to verify your identity first. Exercising a right is free, and we will not treat you differently for doing so.

18.1 Controls you can use yourself, right now

  • Product analytics — Settings → Privacy & data → Share anonymous product trends on desktop, or Privacy & devices → Optional product analytics on mobile. Off by default.
  • Agent run outcomes — LumenAgent settings → Devices → Share anonymous run outcomes on desktop, set separately on each computer. Off by default. Turning it off discards outcomes that have not been sent.
  • Memory & context — LumenAgent settings → Memory (also reached from Settings → AI). Read what is stored, exclude an object, forget one, or switch the whole engine off. See how it works.
  • Connected services — disconnect a provider in Settings to delete LumenQube's stored token record; LumenQube also asks the provider to revoke the grant where it can, and you can revoke or confirm it in the provider's account controls. Neither step undoes provider actions or deletes content already saved locally, in LumenQube or at the provider.
  • Sharing — revoke a link, remove a collaborator, or rotate the document key from the share panel.
  • Email — service emails (verification, receipts, security) are part of the account. Any optional message carries an unsubscribe link.

18.2 Authorized agents

Where the law allows it, you can use an authorized agent to make a request for you. We will ask for written proof of the agent's authority and may still ask you to verify your own identity directly.

19Regional privacy rights

Your rights depend on where you live, so pick the one that applies to you rather than reading the four that do not. Everything in §18 is available to everyone, everywhere, regardless of what this section says.

European Economic Area & United Kingdom

The full set of GDPR / UK GDPR rights, and a regulator to go to if we get it wrong.

  • Everything in §18 — access, correction, deletion, portability, objection, restriction, and withdrawal of consent.
  • Object to legitimate-interest processing at any time. We stop unless we can demonstrate compelling grounds that override your interests, or we need it for legal claims.
  • Complain to a supervisory authority — in the EEA, the one where you live, work, or where the problem happened; in the UK, the Information Commissioner's Office.
  • You do not have to come to us first. We would like the chance, but it is not a precondition.
  • Any transfer mechanism must be confirmed for the applicable provider and transfer — see §13.

California — CCPA as amended by CPRA

There is no "Do Not Sell or Share My Personal Information" link on this site, and the reason is that there is nothing to switch off.

  • Know, delete and correct the personal information we hold, and opt out of sale or sharing.
  • We do not sell or share personal information, and we do not use sensitive personal information for any purpose that would require an opt-out.
  • We honour Global Privacy Control signals as an opt-out wherever they apply to processing we carry out.
  • The categories collected, their sources, and who they are disclosed to are in the table below.
  • No discrimination. Exercising a right never changes your price or your service.

Virginia, Colorado, Connecticut, Texas and the rest

The comprehensive state privacy laws — including Utah, Oregon, Montana and Delaware, and others as they take effect.

  • Confirm, access, correct, delete, and obtain a portable copy of your personal information.
  • Opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects. We do none of those three, so there is nothing to opt out of.
  • Appeal a refusal. Reply to our decision, or write to privacy@lumenqube.com with "Appeal" in the subject.
  • We answer an appeal within the period your state's law sets, and if we decline again we tell you how to contact your Attorney General.

Canada — PIPEDA, and provincial law

We are a Canadian company, so this is the framework we are primarily regulated under.

  • Access and correct your personal information, and withdraw consent subject to legal or contractual restrictions and reasonable notice.
  • Our privacy contact is privacy@lumenqube.com.
  • If we cannot resolve a concern, you may contact the Office of the Privacy Commissioner of Canada, or your provincial regulator.
  • Quebec: the Commission d'accès à l'information, plus the right to be told when a decision is made exclusively by automated processing — which, as §17 says, we do not do.

Everywhere else

Brazil's LGPD, Australia's Privacy Act, or a framework this policy has not named.

  • Write to privacy@lumenqube.com and tell us which law you are relying on.
  • We would rather honour a right we have not listed than argue about whether it applies to us.
  • The rights in §18 are offered to everyone regardless of location, because operating one process is simpler than operating nine.

19.1 Categories of personal information we collect

Required by California law, and useful to everyone. In the preceding 12 months we have collected:

CategoryExamplesSourceDisclosed to
IdentifiersName, email, account ID, IP addressYou; automaticallyHosting, email and payment providers
Commercial informationPlan purchased, transaction status, allowance usageYou; the payment providerPayment provider; hosting
Internet or network activityApp version, platform, request logsAutomaticallyHosting provider
Audio, electronic or visual informationContent you submit to a cloud feature, including recordings you ask us to transcribeYouAI processors, for the action you requested
InferencesNone drawn for profiling or advertising——

Each category is collected for the business purposes described in §5 and retained as set out in §14. We do not collect the categories this table does not name — no precise geolocation, no biometric data, no government identifiers.

20Deleting your account & data

You can request deletion of your account and associated personal information by emailing privacy@lumenqube.com from your account email address. We may request additional information needed to verify identity, locate records, protect other people and apply a lawful retention or access exception.

The in-product account-close control reauthenticates the user, disables authentication, removes the account tree and runs the source-present document, automation, connection-object, signature, settlement and video sweeps. It is not, by itself, confirmation that every top-level support, diagnostic, audit, payment, organization, shared-user, provider, remote-deployment, local-device, object-version or backup record has been erased. A verified request inventories those boundaries and tells you what was deleted, de-identified, retained with a reason, or outside LumenQube's control.

20.1 What each route actually reaches

The difference between the two is the reason this section is longer than "click the button". Neither column is a promise about someone else's copy of a shared document.

RecordIn-app account closeVerified request to privacy@
Sign-in & authenticationDisabledRemoved
Account record & profileRemovedRemoved
Shared & published contentPartly — content another person still lawfully uses is not erased by one account closingAssessed against the other users' rights and our retention duties
Signature requests you sentRemoved — a request still in progress is cancelled and each signer who was sent it is told once; then every request, its audit trail and its stored copies are deleted. Copies already emailed to signers stay with themRemoved
Form responsesNot automaticallyAssessed individually
Account-scoped mobile records & deployment credentials/metadataRemoved from the account tree when account closure completes successfully. This does not delete a remote site or repository, revoke a provider grant, or prove deletion of provider copiesScope and completion checked; remote providers, retained top-level records and backups are handled separately
Support, bug, error & admin-audit recordsNot universally — top-level records are not all reached by account-tree deletionInventoried and deleted, de-identified or retained with the applicable reason
Provider grants & provider/recipient copiesSeparate — local token deletion does not prove provider revocation or remote deletionExplained with provider controls and any assistance available
Remote deployments & public repositoriesNot deleted remotelyProvider action required — the site or repository remains until removed at that provider
Backups & object versionsNot immediatelySchedule confirmed for the request — no universal period is promised here
Billing, tax, fraud & legal-hold recordsAssessed by category. A verified response identifies retained records and the applicable reason; this policy does not invent one universal period.

Documents stored only on your device stay on your device and remain within your control. Deleting your account does not delete your local files, and uninstalling the app does not delete your account.

21Children's privacy

The Service is not directed to children. You must be at least the age of majority in your jurisdiction — or have the consent of a parent or legal guardian — to create an account, and in any event at least 16 years old. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us so we can investigate and process the appropriate verified deletion request.

22Cookies & similar technologies

We use the smallest amount of browser storage that makes the product work. There are no advertising cookies, no cross-site tracking, and no third-party analytics scripts on any page of this website.

WhereWhatPurpose
Marketing websitelumen.theme in local storageRemembers whether you chose the light or dark theme
Marketing websitelh_at, lh_rt and lh_refresh_request in local storage, or in session storage when Keep me signed in is offStrictly necessary — keeps you signed in to your account pages and renews the session safely; removed when you sign out
Marketing websitelumen.idleLock in local storageRemembers the idle sign-out time you chose on this device
Marketing websitelumen.landing in local storageRemembers which home-page layout to show, so the page does not change after it loads
Marketing websitelumen.promo.dismissed in local storageRemembers which announcements you closed
Marketing websitelumen.docs.recent in local storageYour last five searches in the documentation, kept only in this browser
Marketing websitelqi_seen in local storageSite measurement — records only that this browser has visited before (not when, how often or who), so a visit can be counted as new or returning
Marketing websitelqi_s in session storageSite measurement — tells the first page of a visit from later ones; cleared when the tab closes and never sent
Marketing websiteOne visit summary, sent to our own server (app.lumenqube.com) when you leave a pageSite measurement — the page, the linking site's host (never its full address), campaign tags, device type, language, time on page, scroll depth, sections viewed, which of our buttons were clicked, and whether the visit is new, returning or signed in. No cookie, visitor identifier or fingerprint, and no IP address is stored; it is added to aggregate counts. When your browser sends Do Not Track or Global Privacy Control, neither lqi_ entry is written and nothing is sent
App & web viewerSession and refresh tokensStrictly necessary — keeps you signed in and authorizes requests
AppLocal preference and cache entriesStrictly necessary — remembers your settings and open documents
App (opt-in only)A random local installation identifierCreated only if you turn product analytics on; sent to our backend, which replaces it with a keyed monthly pseudonym before storage

Because none of this is used for advertising or cross-site tracking, we do not show a consent banner asking you to accept marketing cookies — there are none to accept. Your browser's Do Not Track and Global Privacy Control signals are respected where they apply to processing we carry out.

23Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Effective" date above and, where appropriate, notify you in the app or by email before the change takes effect. Your continued use of the Service after an update means you accept the revised policy.

VersionWhat changed
October 4, 2026Listed everything this website keeps in your browser: the first-party site measurement (lqi_seen, lqi_s and the visit summary sent when you leave a page, none of it when Do Not Track or Global Privacy Control is on), the account pages' sign-in storage, and the layout, announcement, idle sign-out and documentation-search preferences. Disconnecting a connected service now also asks the provider to revoke the grant where it offers revocation — Google once no other Google service you connected relies on it, Dropbox, Slack user tokens and Connect Hub apps that publish a revocation endpoint — and names the exceptions (Microsoft and a Slack workspace installation) to revoke in the provider's own account controls.
September 27, 2026Described signature requests (LumenSign): what a request and a signer's steps record, who in a request sees the certificate of completion, how long requests are kept, and that closing your account cancels the requests you sent (telling their signers) and deletes them.
September 26, 2026Described optional agent run outcomes: what a desktop sends when you turn on Share anonymous run outcomes, that it is stored only as daily totals without your account, the 90-day retention, and where to turn it off. Added how long a private copy of an AI-generated video clip is kept.
September 5, 2026Clarified Google token revocation versus record deletion, saved Google content in cloud/mobile task history and shared documents, and the restriction on generalized AI model training.
September 2, 2026Added the mobile app and device-permission section, a retention table, security-incident notification, automated-decision disclosure, expanded regional rights (Canada and Quebec, EEA/UK supervisory authorities, California categories and Global Privacy Control, other US states and appeals), and a cookie table.
July 28, 2026Optional product analytics described in full; Microsoft, Dropbox and Slack connected-app disclosures added.

24How to contact us

For privacy questions, or to exercise a right:

LUMENQUBE ANALYTICS INC. — Privacy

LUMENQUBE ANALYTICS INC., Mississauga, Ontario, Canada
Email: privacy@lumenqube.com

Security reports: security@lumenqube.com · General support: support@lumenqube.com · Legal: legal@lumenqube.com

See also our Security Centre, Google integrations & data access, Microsoft, Dropbox & Slack permissions, Terms of Service, Docs and Support pages.

Privacy should be understandable in practice.

Read the shorter security overview, or ask us a direct question — both are faster than reading this twice.

Open the Security CentreControls, infrastructure, incidents and responsible disclosure.Review security → Ask a questionAnswers to common questions, and the fastest route to a person.Visit support →