Privacy Policy
What we collect
We collect the information you provide, customer content needed to operate the product and limited technical information needed to secure and support the service. An access request or contact form may include your name, work email, organization, role and the analysis you want to run. Product content may include documents and figures you select for an analysis. Our servers may record request time, browser or device information, IP address and error details when needed to operate and secure the service.
The website Cedar stores the current conversation in session storage for the open tab. After a substantive Cedar answer, it also stores a topic identifier and timestamp in local storage for up to 30 days so a later visit can receive one welcome-back prompt. That record does not include the conversation text and is removed when it is used or found expired. Most questions are answered in the browser. If a backend is enabled, an unmatched message and an anonymous conversation identifier may be sent to the Lumecon API to produce an answer. Do not enter confidential or sensitive information in the website chat.
How we use it
We use contact and beta-request details to respond, to grant access and to tell you about the service you asked about. We use product content to run your analyses and support you. We may use usage metadata and information that has been aggregated and de-identified to maintain, secure and improve the service, as described in the applicable terms. We do not sell personal information or use your information for third-party advertising.
Analytics and your consent
Optional analytics are disabled until you opt in. The site self-hosts its fonts and does not load advertising trackers. If analytics are configured after consent, usage events may be sent to the provider identified in the current subprocessor disclosure. Requests needed for sign-up, login, checkout or a configured Cedar backend are service requests rather than analytics. You can change your choice through the Privacy choices control in the footer.
When we share
We share information with service providers who host and operate the platform for us, under obligations to protect it; when the law requires it; to protect the service, our customers or the public from harm; and as part of a financing, acquisition or similar transaction, in which case this policy continues to apply to the information transferred.
Retention and security
We retain information only as long as needed for the purposes described here, our contractual obligations and applicable law, then delete or de-identify it. Product content remains while an account is active unless the applicable agreement states otherwise. Closing an account ends access but may not trigger immediate deletion where retention is required by law, security needs or the applicable agreement. Lumecon is formalizing its security program against the AICPA Trust Services Criteria, with a future SOC 2 Type II examination as the target; it does not currently have a SOC 2 report. Current controls and readiness work are described on the Security page.
Your rights
Write to contact@lumecon.ai to ask what we hold about you, to correct it or to have it deleted, and we will respond within the time the applicable law sets. The service is for organizations and is not directed to children.
Changes
We will update this policy as the service evolves. Material changes will be posted here with a new date, and where the law requires it we will tell you directly.
Contact: contact@lumecon.ai