What stays on your device, and exactly when it doesn’t.

LumenQube is local-first by design — your files live on your device. This is the one place that says when a feature you choose sends content, what it sends, and who receives it.

Privacy policy
Effective 27 Sep 2026 · previous 28 Jul 2026
Security
Reviewed 2 Sep 2026
CSA STAR
Listed since 31 Jul 2026
Local first
Documents stay on your device by defaultOpening, editing and saving a local file does not upload its contents.
Your choice
Cloud features process only what they needAI, sharing, publishing, connectors and diagnostics each have a stated boundary.
No ad model
We do not sell your informationDocument contents are never used for advertising, and there is no ad business here to fund.
Off by default
Product analytics needs your opt-inMonthly rotating pseudonyms, no document content, and off until you turn it on.

01The boundary

Six ways content crosses it. Nothing else does.

Pick a feature to see exactly what it sends, what stays behind, and who receives it. Ordinary editing is listed too — it is the row where the answer is nothing.

Ordinary editingNothing crosses

Opening, editing, saving and exporting a file happens entirely on your machine. There is no background sync and no check-in on a document you never shared.

SENT
Nothing. Not the file, not its name, not its contents.
STAYS ON DEVICE
Everything — the documents, the context graph, and anything held in your OS keychain.
WHO RECEIVES IT
No one.
AIA prompt, and the selection it needs

You ask for something; the request goes through our managed backend to the model provider for that feature, and the result comes back to the document.

SENT
The prompt, plus the selection, file or recording the action operates on.
STAYS ON DEVICE
The rest of the document, and every file you did not act on.
WHO RECEIVES IT
LumenQube’s backend, then the model provider — listed by name in Privacy Policy §12.
SharingOne revision, for the people you name

A shared document is a copy stored on our servers so collaborators can open it. Your local file keeps being your local file.

SENT
The revision you shared, encrypted at the application layer and again by the platform at rest.
STAYS ON DEVICE
Your original, and every document you did not share.
WHO RECEIVES IT
LumenQube servers, and the people you authorized — at the role you gave them.
PublishA revision the web viewer can render

Publishing puts a copy where a browser can reach it. That is the feature; there is no version of it that keeps the content on your disk.

SENT
The revision the viewer renders, plus any passcode you set — stored only as a hash.
STAYS ON DEVICE
Everything you did not publish.
WHO RECEIVES IT
LumenQube servers, and whoever holds the link until you revoke it.
ConnectorsThe query for the action you approved

A connected account is authorized separately, scoped to what you granted, and disconnectable at any time from Settings.

SENT
Only the query or content the approved action requires — not your library.
STAYS ON DEVICE
Your credentials are not there to send: tokens live server-side, encrypted, never inside a document.
WHO RECEIVES IT
The provider you connected, under that provider’s own terms.
SupportThe logs, and whatever you attach

A report filed from inside the app carries diagnostics so we can investigate. You decide whether a document goes with it.

SENT
Diagnostic logs, plus any attachment you choose to add — and nothing you did not add.
STAYS ON DEVICE
Every file you did not attach.
WHO RECEIVES IT
LumenQube support.
AccountWho you are, and what you have used

The one crossing that is always on while you are signed in. It carries the account, not the work.

SENT
Your account record, allowance balance and usage counters.
STAYS ON DEVICE
Your documents. Metering counts requests, not content.
WHO RECEIVES IT
LumenQube servers, and the payment provider at checkout.

In plain terms: do not use AI, sharing, publishing, connectors or diagnostics with attachments, and your document contents never reach us at all. Use one, and only the content that feature needs is sent. The Privacy Policy is the field-by-field version of this paragraph.

02Your controls

Six you can use yourself, right now.

No request form and no waiting. Each one names the exact place in the app, as Privacy Policy §18.1 lists them.

Product analytics

Off by default. Turn it on, or back off, whenever you like.

Settings → Privacy & data → Share anonymous product trends

Agent run outcomes

Off by default, set separately on each computer. Turning it off discards outcomes that have not been sent.

LumenAgent settings → Devices → Share anonymous run outcomes

Memory & context

Read what is stored, exclude an object, forget one, or switch the whole engine off.

LumenAgent settings → Memory

Connected services

Disconnecting deletes LumenQube’s stored token record and asks the provider to revoke its grant where the provider offers that: Google once no other Google service you connected relies on it, Dropbox, Slack user tokens and hub apps that publish revocation. Microsoft access and Slack workspace installs are revoked in the provider’s own controls. Neither step undoes actions already taken or deletes saved content.

Settings → disconnect the provider

Sharing

Revoke a link, remove a collaborator, or rotate the document key after an access change.

Share panel → Revoke · Remove · Rotate key

Email

Verification, receipts and security notices come with the account. Any optional message carries an unsubscribe link.

Unsubscribe — in every optional message
Deleting your account and dataPolicy §20 lists what each deletion route actually reaches, so nothing is left to guess. Requests go to privacy@lumenqube.com from your account address.
What each route reaches

04Assurance

Published with the gaps left visible.

Every answer we filed is public on the registry entry — 603 questions, including the controls still open. The registry is the version of record; this page summarises it.

CSA STARListed · 31 Jul 2026

STAR Level 1

283questions · CAIQ v4.1

Across the Cloud Controls Matrix. The assessment separates LumenQube, customer and upstream-provider responsibilities, and records open controls as open rather than leaving them blank.

CSA STAR for AIListed · 31 Jul 2026

STAR for AI Level 1

320questions · AI-CAIQ v1.1

On responsible AI and AI security, assessed as an application provider using managed model APIs. We do not train a foundation model on customer content.

So nobody has to infer it

What we do not hold

  • We have not completed a SOC 2 examination
  • We do not hold ISO 27001 certification
  • We have not commissioned a published third-party penetration test

If procurement needs one, tell us what and by when.

What Level 1 means. A public provider self-assessment, reviewed and published by CSA. It is not an independent audit, a third-party certification, a penetration test or a guarantee. Both assessments are reviewed at least annually, and again after any material service, provider, legal or threat-model change. Read the registry entry
The company
LumenQube Analytics Inc., a Canadian company
Where data is processed
Canada, the United States and other countries where providers operate
Region pinning
Not offered today — no in-region residency
The full list
Security §07 and Policy §12

05Report a vulnerability

Report it privately, and we will not come after you.

Email the affected product or URL, reproduction steps, impact and any evidence. Reports are triaged by severity; there is no fixed response-time promise and no paid bounty programme today. Good-faith research within scope is safe-harboured.

06Questions

Security, in plain language.

Are shared documents end-to-end encrypted?

No. Shared and published documents are encrypted in transit and at rest, including application-layer encryption of stored revisions — but LumenQube manages the keys so authorized server processes can render and synchronize the content. That is encryption at rest, not end-to-end encryption, and we will not describe it as the latter.

When does a document leave my device?

Only when you use a feature that needs cloud processing: AI, sharing, web publishing, a connected service, or a support report with attachments. Ordinary local editing does not upload document contents at any point.

Do you train AI models on my content?

LumenQube does not use your content to train a generalized AI model as a product purpose. Content is sent only when you request an AI feature, to the selected processor or eligible fallback needed for that request. A provider’s own data use, retention and permitted security or legal processing depend on the service and our account terms and settings. See Privacy Policy §7.

Can I revoke access to work I already shared?

Yes. Owners can change member roles, remove collaborators, revoke browser links, and rotate the document key after an access change. A copy somebody already downloaded is outside LumenQube’s control — that is true of every system, and worth planning for.

Where is my data stored?

Providers and connected services may process data in Canada, the United States and other countries where they operate. LumenQube does not offer a region-pinned deployment or in-region data residency. See Privacy Policy §12.

What is your CSA STAR status?

Listed in the CSA STAR Registry since 31 July 2026, carrying STAR Level 1 (CAIQ v4.1) and STAR for AI Level 1 (AI-CAIQ v1.1). Level 1 is a provider self-assessment that CSA publishes — not an independent audit, a third-party certification, or a penetration test.

How do I make a privacy request?

Email privacy@lumenqube.com from your account address. Privacy Policy §18 explains the access, correction, deletion, portability, objection and restriction rights that may apply where you live.

Privacy should be understandable in practice.

Install it, sign in once with a free account, and edit offline — ordinary editing never sends your documents to our servers.