Legal / Privacy
Privacy policy.
This policy explains what information Lumiora processes, why it is needed, where it comes from, and the choices available to customers and users.
1. Scope
This Privacy Policy applies to Lumiora's website, Slack application, connected integrations, support communications, and related services (collectively, the “Service”). “Lumiora,” “we,” and “us” refer to the provider of the Service.
Organizations that connect Lumiora determine which workspaces, sites, projects, spaces, channels, and other resources Lumiora may access. For customer content, Lumiora generally acts as a service provider or processor on the organization's behalf.
2. Information we process
Account and identity information
We process workspace and site identifiers, user and account identifiers, display names, profile information, roles, and permissions supplied by Slack, Atlassian, PagerDuty, and other connected providers.
Customer content
When authorized and needed to provide the Service, Lumiora may process Slack messages and threads; Jira projects, issues, comments, and metadata; Confluence spaces, pages, comments, labels, and page relationships; PagerDuty incidents, services, responders, and timelines; and content from other integrations a customer enables.
Derived knowledge and actions
Lumiora creates summaries, extracted facts, decisions, incident context, conversation relationships, provenance records, and references to external resources. It also records actions requested through Lumiora, such as creating or updating a Jira issue or Confluence page.
Credentials and connection metadata
We process OAuth access and refresh tokens, Slack installation tokens, granted scopes, connected-resource identifiers, and connection status. Credentials are stored separately from customer content and are not included in AI prompts.
Operational information
We may process request timestamps, diagnostic events, error records, API usage, rate-limit information, security events, and standard network information needed to operate and protect the Service. The public website does not currently use advertising or behavioral analytics trackers.
3. How we use information
- Provide answers, summaries, analysis, and requested actions.
- Build and maintain a tenant-isolated map of authorized organizational context.
- Avoid repeatedly retrieving or reprocessing unchanged source information.
- Maintain integrations, refresh authorization, and synchronize resource metadata.
- Secure, troubleshoot, monitor, and improve the Service.
- Respond to support, privacy, and security requests.
- Comply with legal obligations and enforce applicable agreements.
4. AI processing
Lumiora may send selected, relevant portions of customer content and instructions to AI service providers, including OpenAI, to perform analysis or generate a requested response. Lumiora is designed to retrieve locally first and limit model input to information relevant to the request.
OAuth credentials, API keys, and other authentication secrets are not intentionally sent to AI providers. Customers should still avoid placing secrets in ordinary messages or documents that they authorize Lumiora to process.
5. When information is shared
We may disclose information only as needed to:
- Operate the Service through infrastructure and processing providers such as AWS and AI service providers such as OpenAI.
- Communicate with integrations selected by the customer, including Slack, Atlassian, and PagerDuty.
- Comply with law, legal process, or valid governmental requests.
- Protect users, customers, Lumiora, or the public from harm or abuse.
- Complete a corporate transaction, subject to appropriate confidentiality and data-protection measures.
We do not sell personal information or customer content.
6. Storage, retention, and deletion
Lumiora stores authorized source snapshots, normalized content, derived knowledge, provenance, provider-resource metadata, user identifiers, and operational records. This information is tenant-scoped and may be retained while the relevant workspace or integration remains active so Lumiora can answer future requests without repeatedly retrieving the same content.
OAuth credentials are retained until they are replaced, revoked, disconnected, or no longer needed. Retention periods may also depend on customer configuration, contractual requirements, security needs, backup cycles, and legal obligations. Disconnecting a provider stops future authorized access but does not by itself guarantee immediate deletion of previously stored content.
A customer administrator or affected individual may request deletion by contacting support@lumiora.io. We will verify the request and delete or de-identify information as required, subject to legitimate security, backup, contractual, and legal needs.
7. Security
Lumiora uses administrative, technical, and organizational safeguards designed to protect information. These include encrypted transport, encrypted credential storage, tenant-scoped storage keys, access controls, tenant isolation, audit records, and monitoring. No system can guarantee absolute security.
8. Your choices and rights
Depending on location, individuals may have rights to access, correct, delete, restrict, or object to processing of personal information. Because most customer content is controlled by the organization that connected Lumiora, users should normally submit requests to that organization first. Requests may also be sent to Lumiora using the contact below.
Customers can revoke provider access through the relevant provider and can contact us to disconnect an integration or request deletion of retained tenant data.
9. International processing
Lumiora and its service providers may process information in countries other than the country where a user is located. Where required, we use appropriate safeguards for cross-border transfers.
10. Children
The Service is intended for organizations and workplace users. It is not directed to children, and we do not knowingly collect personal information from children.
11. Changes and contact
We may update this policy as Lumiora evolves. Material changes will be reflected by a new effective date and, when appropriate, additional notice.
Questions, requests, or complaints can be sent to support@lumiora.io or through the Lumiora support page.