AI and Data Use
Cedar helps teams turn organizational records into reviewable inputs and explanations within Lumecon. This statement explains what Cedar processes, how AI is separated from the economic model and which data-protection commitments are currently in effect.
1. Where AI sits in the platform
Cedar reads documents supplied to Cedar Impact, proposes structured inputs, flags gaps and assumptions and helps draft reporting. Cedar Impact applies approved inputs to a deterministic input-output model; economic impact figures are calculated by that model, not generated by a language model. The person running the analysis reviews the assumptions and approves the final result.
2. What Cedar reads, and why
Cedar processes the documents and figures your organization selects for an analysis, which may include budgets, financial statements, payroll, program records and prior analyses. It uses that material to propose model inputs, identify questions and help explain results. ThePrivacy Policy describes how Lumecon uses customer content to operate and support the service.
3. What we do not do
Lumecon does not sell personal information or use customer information for third-party advertising. Service improvement may use usage metadata and information that has been aggregated and de-identified, as described in the applicable terms. Customer-specific limits on AI-provider use, retention and model training are confirmed in the applicable agreement during private beta. Cedar proposes work for review and does not approve an analysis.
4. Cedar on this website
The chat on lumecon.ai is a lightweight Cedar that answers questions about Lumecon. Most questions are answered by an in-browser classifier. If a backend is enabled, an unmatched message and an anonymous conversation identifier may be sent to the Lumecon API to produce an answer. The website chat is not connected to customer product data. Do not enter confidential or sensitive information in it.
5. AI providers and subprocessors
Some Cedar functions may use third-party AI providers. During private beta, Lumecon is finalizing written terms and technical controls covering each provider’s processing purpose, retention, access and model-training practices. Before sensitive customer content is routed to a provider, those arrangements will be confirmed for the deployment and documented during security review. A current subprocessor list will be published as those arrangements are finalized.
6. Data sovereignty
Lumecon does not take ownership of customer content. For Tribal Nations and government customers, data-governance, publicity, access, retention and deletion requirements are addressed during procurement and recorded in the applicable agreement. An organization decides how its analyses are shared, subject to participant permissions and its agreement with Lumecon.
7. Security program and SOC 2
Lumecon is formalizing its security program against the AICPA Trust Services Criteria, with a future SOC 2 Type II examination as the target. Lumecon has not completed a SOC 2 examination and does not currently have a SOC 2 report. Current information about controls, subprocessors, data handling and readiness work is available through asecurity review.
8. Questions
Write to contact@lumecon.ai and a person will answer. This page will be kept consistent with the Terms of Service and Privacy Policy as counsel finalizes them, and updated here with a new date when it changes.
Contact: contact@lumecon.ai