Privacy Policy
Last updated: 3 August 2026 · Effective: 3 August 2026
1. Who we are
Lumnian (“Lumnian”, “we”, “us”) operates the Lumnian content research and publishing platform at lumnian.com and app.lumnian.com (the “Service”). This policy explains what information the Service collects, why, how long we keep it, and who else sees it.
It applies to everyone who signs up for an account, and to visitors of our public website. It does not apply to third-party sites we link to, or to sites you publish using the Service — those are governed by their own policies.
2. Information we collect
Account information
When you register we collect your username, email address, optional first and last name, and a password. Passwords are stored only as a salted one-way hash — we never store or have access to your plaintext password. Accounts require approval by an administrator before they become active.
Content you give us
The Service exists to work on material you supply. That includes projects, categories, topics, keywords and seed terms, uploaded or pasted documents and notes, style and house rules, target site configuration, and the drafts and published pages produced from them. We treat this as your confidential content.
Credentials for services you connect
You may optionally connect third-party accounts so the Service can act on your behalf. Depending on which you enable, we store:
- a Google Ads OAuth refresh token (see section 3);
- a GitHub OAuth token or installation credential, used to publish pages to repositories you designate;
- API keys you paste in for AI model providers, image storage (e.g. S3-compatible buckets), and the Amazon Product Advertising API.
These secrets are encrypted at rest with a key held by the application and are never displayed back to you in full or shared with other users.
Material we retrieve on your behalf
To research a topic the Service fetches publicly available web pages and search engine results pages, and stores the retrieved text, extracted facts and metadata so it can cite sources. If you install our optional browser extension, it can fetch pages using your own browser session at your instruction; the extension sends the retrieved page content to your Lumnian account and does not transmit your browsing history, cookies, or credentials to us.
Information collected automatically
Our servers record standard operational data: IP address, user agent, requested URL, timestamp, response status, and error diagnostics. We use a session cookie (or an equivalent token in local storage) to keep you signed in. We do not use advertising cookies and we do not run third-party ad or cross-site tracking pixels on the Service.
3. Google user data
This section describes exactly how the Service accesses, uses, stores and shares data from Google APIs. It is deliberately specific, because we want you to be able to check it against what the app actually does.
The scope we request, and why
When you choose Connect Google Ads in Settings, we send you to Google's own consent screen and request a single scope:
https://www.googleapis.com/auth/adwords
We request it for one purpose: so that keyword research you run inside Lumnian is authorized against the Google Ads API under your own credentials and quota, rather than a shared pool. This is what lets the Service show search volume and competition estimates for the keywords and topics you are working on.
What we actually call
With the token you grant, the Service makes exactly two kinds of Google Ads API calls:
| Call | When | What it returns to us |
|---|---|---|
CustomerService.listAccessibleCustomers |
When you connect, and when you press “Test connection” | The resource names of Google Ads accounts your login can reach. We use this only to confirm the connection works, and we do not store the result. |
KeywordPlanIdeaService.generateKeywordIdeas |
When keyword research runs for your projects | Keyword ideas with aggregate search volume and competition estimates for the seed terms you supplied. These are market statistics, not information about you or your account. |
What we never do
- We do not read your campaigns, ad groups, ads, creatives, keywords, budgets, bidding strategies, conversion data, audience or customer-match lists, or billing and payment information.
- We do not create, modify, pause or delete anything in your Google Ads account.
- We do not spend your advertising budget. Keyword planning queries consume API quota only.
- We do not use Google user data for advertising, for building profiles, or to train, retrain or fine-tune any machine learning or AI model — including generalized models operated by us or by anyone else.
- We do not sell Google user data, and we do not transfer it to data brokers or information resellers.
Storage
We store one item of Google data: the OAuth refresh token, encrypted at rest and associated with your Lumnian user account. Access tokens are short-lived and held only in memory for the duration of a request. Keyword volume and competition figures derived from the API are stored against your keywords so that reports stay stable between runs; they describe the search market, not you.
Revoking access and deletion
You can disconnect at any time from Settings → Connections → Google Ads in the app, which deletes the stored refresh token. You can also revoke our access independently at myaccount.google.com/permissions. Deleting your Lumnian account deletes the token as well.
Human access
No human at Lumnian reads Google user data except: with your explicit consent (for example, when you ask us to debug a connection problem); where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and anonymized so it no longer identifies any user or account.
Limited Use disclosure.
Lumnian's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use information
- To operate the Service — authenticate you, run research and generation jobs you request, and publish to destinations you configure.
- To keep it working — diagnose errors, prevent abuse, enforce rate limits, and secure accounts.
- To account for usage — we log AI model calls (provider, model, token counts, timing, and the call payload) so you can see what your account consumed. This log is visible to you and to platform administrators.
- To communicate with you — account approval, service notices, and responses to your support requests.
- To meet legal obligations.
We do not sell your personal information, and we do not use your content or your connected-account data to train our own models.
5. AI model providers
Generating and analysing content requires sending your material to a large language model. Depending on the provider and model you select in Settings, your prompts — which may include your notes, documents, keywords, drafts and retrieved source text — are transmitted to that provider for processing. Providers the Service supports include Anthropic, OpenAI, Groq and self-hosted or local models such as Ollama.
Your content is then also subject to the chosen provider's terms and privacy policy. If you configure the Service to use a locally hosted model, that content does not leave the infrastructure you point it at. We do not use your content to train any model, and we ask our providers not to either; where a provider's default terms differ, that provider's policy governs, so review it before selecting one.
6. How we share information
We share information only in these circumstances:
- Service providers we depend on, acting on our instructions: cloud hosting and managed database providers, and the AI providers described above. They may process your data only to provide the service to us.
- Destinations you choose. If you configure publishing to a GitHub repository or a website, we send the content you approve to that destination.
- Legal requirements. If compelled by valid legal process, or where disclosure is necessary to protect our rights, users, or the public. We will notify you unless legally prohibited.
- Business transfer. If the Service is acquired or merged, your information may transfer as part of that transaction, subject to this policy.
We do not sell or rent personal information to anyone.
7. Retention
We keep account information and your content for as long as your account is active. Operational logs are kept for a limited period sufficient for debugging and abuse investigation. When you delete your account we delete your content and stored credentials within 30 days, except where we must retain records to comply with law, resolve disputes, or enforce our agreements. Backups are purged on their normal rotation.
You can delete individual projects, topics, pages and connections at any time from within the app. To delete your whole account, contact us at the address below.
8. Security
All traffic to the Service is encrypted in transit with TLS. Third-party credentials and OAuth tokens are encrypted at rest. Access to production systems is limited to administrators who need it. Passwords are stored as one-way hashes.
No system is perfectly secure. If we become aware of a breach affecting your personal information we will notify you and any required regulator without undue delay.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, delete or restrict processing of your personal information, to object to certain processing, and to withdraw consent. If you are in the EEA or UK, our legal bases are performance of our contract with you (operating the Service), our legitimate interests (security, abuse prevention, improving reliability), your consent (connecting third-party accounts), and legal obligation.
If you are a California resident, you have the rights described in the CCPA/CPRA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information for cross-context behavioural advertising.
To exercise any of these, email us at the address in section 13. We will verify your identity via your account email address and respond within the period required by applicable law. You may also complain to your local data protection authority.
10. International transfers
The Service is operated from infrastructure located in the United States and, for some processing, in other countries. If you access it from outside those countries, your information will be transferred to and processed there. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
11. Children
The Service is not directed at children and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy. When we do, we will change the “Last updated” date above, and for material changes we will notify account holders by email or an in-app notice before the change takes effect. Continuing to use the Service after that means you accept the updated policy.
13. Contact us
Questions, requests, or privacy complaints: privacy@lumnian.com.
See also our Terms of Service.