Privacy Policy
Last updated: March 2025
1. Data Controller
Lume ("we", "us") processes your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish data protection law.
2. Data We Collect
- Account data: Email, password (hashed), and profile information you provide when signing up.
- Usage data: Analyses you run, ideas you submit, and usage counts (e.g. analyses per month) for billing and limits.
- Payment data: Processed by Stripe; we do not store full card numbers. We store subscription status and customer IDs.
- Technical data: IP address, browser type, and similar data for security and analytics.
3. Legal Basis & Purpose
We process your data based on: (a) contract performance (providing the Service), (b) legitimate interests (security, analytics, improvement), and (c) consent where required (e.g. marketing). Your ideas and analyses are used solely to generate AI research and to display your saved analyses.
4. Third Parties
We use Supabase (auth & database), Stripe (payments), and Claude/Anthropic (AI processing). These providers process data on our behalf under data processing agreements. We do not sell your personal data.
5. Retention
Account and analysis data are retained while your account is active. You may request deletion at any time. We retain anonymized or aggregated data where legally permitted for analytics and improvement.
6. Your Rights (GDPR)
You have the right to: access your data, rectify inaccuracies, erase data ("right to be forgotten"), restrict processing, data portability, object to processing, and withdraw consent. You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet). Contact us at the email provided on the website to exercise these rights.
7. Security
We use industry-standard measures to protect your data, including encryption in transit (HTTPS) and at rest. Access to personal data is restricted to authorized personnel.
8. Cookies
We use essential cookies for authentication and session management. We may use analytics cookies to improve the Service. You can manage cookie preferences in your browser.
9. Changes
We may update this Privacy Policy. Material changes will be communicated via email or in-app notice. Continued use after changes constitutes acceptance.