Privacy Policy
Last updated
Effective date: 12 September 2026
1. Who we are
Luminars is made by Matteo Giardino, Via Camandona 17, Torino, Italy, VAT number 12623180010 ("Luminars", "we", "us"). For anything in this policy, write to matteo@luminars.io.
This policy covers the website at luminars.io, the Luminars desktop app for macOS and Windows, the web console at luminars.io/app, and the hosted service that sits behind them. It applies to visitors, to people who install the app, and to the members and admins of a workspace.
2. The short version
- The app watches how you work on your own computer. The screen frames, the audio and the text read out of them stay on that computer. We do not receive them.
- What leaves your computer is the derived work: your account, your workspace, the processes you record or the engine discovers, the records of their runs, and counters of how much AI you used. The people in your workspace see those, never the raw capture.
- With the "Help improve Luminars" switch on, which it is from the first launch and which you can turn off in Settings, a copy of what the app produced (drafts, conversations, run transcripts, recording traces with their key frames) also goes to Luminars, to improve the engine. Only Luminars reads that copy. Your workspace admins do not.
- The AI runs through our hosted service in the EU and, from there, through AI providers. We always keep counters of that use. We keep the text of a request and its answer only while the switch above is on, in the same copy, and never for your workspace admins to read.
- You control capture: pause it, exclude apps, set hours where nothing is captured, delete a time range, and choose how many days screen and audio media are kept.
The rest of this policy says the same things in full.
3. What the app captures on your device
When you install the app and grant the operating system permissions it asks for, it records, on your computer:
- Screen frames, and the text layer of each frame (what the operating system's accessibility interface and optical character recognition read out of it).
- Which apps and windows are in front, their titles, and, in a browser, the page address.
- Input events: where a click or a keystroke happened, which is how the app knows where a step starts and ends. The text you type is captured as part of this stream. Clipboard content is captured only while you are recording a process, during the deliberate session whose indicator is on screen; outside a recording the app notes that a copy happened, not what was copied. The scope screen at first run says so. There is no separate switch for typed text: what stops it is the controls in 3.1, which is to exclude the app, set quiet hours, pause, or delete the range afterwards, and content you mark secret never leaves the device at all.
- Microphone audio, when you allow the microphone, and the transcript made from it.
- Narration during a recording: what you say while you show a process.
All of this stays on your computer. The app never uploads screen frames, audio or the raw text layer to us or to your workspace. The hosted service refuses raw capture at the schema level: there is no table it could go into.
3.1 Your controls
From the app's Settings and from the menu bar icon you can, at any time:
- Pause capture, for a set time or until you resume. Every stream stops within seconds and the paused state is visible.
- Exclude an app: nothing from that app is captured on any stream. A default list of sensitive apps is excluded from the first run; you edit it.
- Set quiet hours: recurring windows in which nothing is captured.
- Delete a time range or an app's capture, retroactively, from every stream, physically.
- Choose the retention window for screen and audio media: a number of days you set (the default is 14). After that the media is deleted. Text already derived from it (transcripts, the text layer) stays, so your days remain searchable after the pictures are gone. "Forever" is a choice you can make; it is never the default.
- Mark content as secret. Content tagged secret never leaves the device, neither to your workspace nor to Luminars.
3.2 What the app derives on your device
From the raw capture the app builds, still on your computer: day logs (a readable account of your day), the record of each recording session, drafts of processes, the conversations you have with the assistant about a draft, and the transcript of each run. These are the "derived artifacts" the rest of this policy talks about.
4. What leaves your device, and where it goes
Three flows leave your computer. Each is named, with its destination and the consent that controls it, on the app's data page in Settings.
4.1 To your workspace (the hosted plane)
Your workspace lives on our hosted service. The app syncs to it:
- Your account: your email address, the sign-in codes we send you, your language preference.
- Your workspace and membership: the workspace's name, who belongs to it and with which role (admin or member), the invitations that were sent (the invited email, the job role and company context the inviter typed, whether the invitation is sponsored).
- Your installation: the app version, the platform, the last time the app checked in, and the consents you gave at install.
- Your Discovery Profile: your role, the tasks you ticked, the apps you named, the company context, and every revision of it. This is your own account of your job, written by you in the interview and editable in Settings.
- Your processes: each process's description and every revision of it, with the evidence the draft cites in words.
- Run records: the run's header only, which is the process that ran, when, how it ended, its steps, the effects it had on connected tools, and its meter. The outcome report, the model's own prose about how the run went, is refused by the hosted service at the schema level and never reaches your workspace. The run's full transcript does not sync to your workspace either. It goes only to Luminars' own store, and only with the switch in 4.2 on.
- Usage metering: how much AI you used (tokens and seconds of audio), run minutes, and their cost against your plan.
- Product usage events: named events such as "recording started" or "export saved", with numbers and short enumerated values only. The list of allowed events is fixed in the app; an event cannot carry text you typed or the app captured.
- The app's own log: a bounded, structured tail of the app's log and its last crash record, so we can see that the app is healthy. No captured content.
- Diagnostics, when you send them: a support file, generated only when you press Send on the data page. It holds the app's state, its log tail and its last crash record, is built so that it cannot contain anything you wrote, said or recorded, and is byte-checked before upload. A message you type beside it is sent with it and stored beside it, never inside it.
Day logs do not sync to the workspace. They stay on your device.
The people in your workspace see, through the console: the library of processes, the runs, the hours returned, the usage, the members, and the support files that were sent. They never see raw capture, because it never leaves your computer.
4.2 To Luminars, to improve the engine (the "Help improve Luminars" switch)
The app has one switch, "Help improve Luminars", stated in one sentence on the scope screen at first run and on the data page in Settings. It is on from the first launch. You can turn it off at any time.
With it on, the app sends a copy of what it produced and what you decided to Luminars' own store, on the same hosted service but separate from your workspace:
- every process revision with its draft and evidence;
- the questions the draft asked and your answers;
- every conversation with the assistant;
- every run's transcript and closed record;
- every recording session's marks, spans, trace and its key frames at full size, and the clipboard journal of that session;
- the day logs and the daily context statistics;
- every export;
- the product usage events and the app's log described above.
Content tagged secret is dropped on the device and never included.
We use this copy to improve the engine: to see where a draft was wrong, where a run stopped, what a good process looks like, and to build the evaluation sets that decide whether a change to the engine is better. Only Luminars reads it, under the service role of our database. Your workspace admins cannot read it; it is not a workspace artifact.
Turning the switch off stops new sends. What was already sent stays until you ask us to delete it (section 9). Turning it on again back-fills what was produced in the meantime.
4.3 To the AI providers, through our hosted service
Nothing in the app talks to an AI provider directly. Every AI request goes to our hosted service, which checks your plan and your allowance, and forwards the request to a provider.
What is sent: the text the engine needs for that step (excerpts of the text layer of your screen, transcripts, the draft, your answers in the conversation, the process being run) and, for transcription, the audio.
Our service always records, for each request, which role and model answered, how many tokens or seconds it used and what it cost. Whether it also records the words depends on the same "Help improve Luminars" switch as 4.2:
- With the switch off, only those counters are kept. The request and the answer are not stored by us anywhere.
- With the switch on, the request as we forwarded it and the answer as we received it are stored too: in our own database beside the counters, and in Langfuse, the tool we read traces in, in the European Union. This is the copy described in 4.2, seen from the AI side, and we use it to find where an answer went wrong. Only Luminars reads it. Your workspace admins cannot.
Chat requests reach the provider through Vercel AI Gateway, which routes them and, by its published policy, deletes the prompt and the answer once the request has finished. Transcription goes to the provider directly.
The providers today are OpenAI and Groq (section 8). OpenAI states that data sent to its API is not used to train its models, and that it keeps API requests and answers for up to 30 days to monitor for abuse before deleting them; we have not applied for its zero-retention option. What Groq does with API content is set by its own data processing agreement rather than by a published figure. Content you marked secret never reaches either of them, because it never leaves your computer.
5. The website and the console
- Analytics. The site and the console use PostHog to understand which pages are read, which buttons are used and where visitors come from. It runs from your first visit, and a banner on that visit says so and offers to stop it: press Decline and the script stops at once, its cookies are deleted from your browser, and it is not loaded again. You can change that answer at any time from the footer of the site (see the Cookie Policy). Our PostHog project is on PostHog's European cloud and is set to discard the visitor's IP address as it arrives, so we never hold it. We do not record sessions, we do not use heatmaps, and we run no surveys. The product usage events described in 4.1 are forwarded to PostHog as well, so we can see how the app is used. They carry your account id, and your profile in our PostHog project holds your email address, your name and job title as your workspace recorded them, your role in the workspace (admin or member), your language, and the app version you started with; your workspace's profile holds its name, plan, number of seats, and the dates it was created and first paid. We use this to see who uses what, and our own and test accounts are marked so they are left out of the figures. The same project also keeps a read-only copy, refreshed a few times a day, of a few facts from our database: accounts and their workspace, workspaces and their plan, seats and payments, access requests, invitations, and when interviews were opened and closed. It never includes what you typed, said, recorded or wrote.
- Hosting logs. Our pages and functions run on Vercel, in its Dublin region. Vercel keeps the log of a request (its path, status, user agent, time, and the network address it came from) for one day on our plan, and then discards it.
- The download form. When you ask for the download you give us your email address. We use it to send you the link, to sign you in, and, if you do not choose a plan after installing, to write to you about it (section 7). Each such email has an unsubscribe link.
- Sign-in and service emails. Sign-in codes, invitations, receipts and notices are sent through Resend.
- Language. A cookie remembers the language you chose (see the Cookie Policy).
- Calls and sales contact. If you book a call, you do it on a page hosted by Cal.com, which takes your name, your email and the time you picked. If you write to us, or we write to you, we keep your name, email, company and our notes in Attio, our CRM. The mailbox we use for sales is connected to Attio, so the emails we exchange with you are copied into it.
6. Payments
Plans are paid through Stripe. When you choose a plan, you leave the app for a Stripe Checkout page in your browser. Stripe collects your card details and billing address; we never see or store card numbers. We store the Stripe customer and subscription identifiers, the plan and its state, the number of seats, the code you redeemed, and the invoices Stripe produces. Stripe's own privacy policy applies to the payment page.
7. Emails we send
- Service emails you cannot opt out of while you have an account: sign-in codes, invitations to a workspace, receipts, notices about your plan, security notices.
- Onboarding emails after you download the app and before you choose a plan: a short sequence that may include a code. Capture reminders to any member of a workspace, whatever its plan, when the app is not installed, has not started collecting, or has stayed paused for two days: at most two for each. Each of these emails has an unsubscribe link that works with one click.
- News about the product, only if you asked for it, with an unsubscribe link.
8. Sub-processors
We use these companies to run the service. Each one processes data on our instructions.
| Company | What for | Where |
|---|---|---|
| Supabase | The hosted database and file store: accounts, workspaces, artifacts, metering, the improvement store | Ireland (AWS eu-west-1) |
| Vercel | The website, the console and the functions that make up the hosted service; and, as AI Gateway, the hop that carries a chat request to its provider | Our functions run in Dublin, Ireland. Vercel Inc. is in the United States |
| Stripe | Payments, subscriptions, invoices | Stripe Payments Europe, Limited (Ireland) is the contracting entity for the European Economic Area; Stripe, Inc. is in the United States |
| Resend (Plus Five Five, Inc.) | Sending sign-in codes and service emails | United States |
| PostHog | Site and product analytics | Our project is on PostHog's European cloud; PostHog Inc. is in the United States |
| OpenAI | AI models behind the engine | United States |
| Groq (Groq LLC) | AI models behind the engine | United States |
| Langfuse | The trace of an AI call, only while the switch in 4.2 is on | European Union |
| Attio (Attio Limited) | Sales contact records, and the emails we exchange with you | United Kingdom, with onward transfers under standard contractual clauses |
| Cal.com, Inc. | The page you book a call on | United States |
| GitHub | Hosting the app's installers and updates; sees the IP address of a download | United States |
Where a sub-processor is outside the European Economic Area, we rely on the European Commission's standard contractual clauses or an adequacy decision, including the EU-US Data Privacy Framework where the company is certified. We will keep this list current on this page and tell workspace admins by email before adding one that would process workspace data.
9. How long we keep things
| Data | Kept |
|---|---|
| Screen and audio media on your device | The number of days you set; default 14; deleted after |
| Derived text and artifacts on your device | Until you delete them or uninstall the app |
| Account, workspace, processes, run records, Discovery Profile | For the life of the workspace. When you ask us to delete it, within 30 days |
| Usage metering and invoices | 10 years, as Italian law requires for accounting records |
| Product usage events and the app's log | For the life of the workspace in our database; the copy forwarded to PostHog for up to seven years, the retention set on our analytics project |
| Support files you sent | For the life of the workspace, and sooner if you ask |
| The improvement store (section 4.2) | Until you ask for deletion |
| The words of an AI call (section 4.3) | Only while the switch in 4.2 is on: for the life of the workspace in our database, and 30 days in Langfuse |
| Website analytics | Up to seven years, the retention set on our analytics project |
| Hosting logs | One day |
| Emails and CRM notes | For as long as we are in contact, and after that until you ask us to delete them |
Deleting a workspace deletes its members' rows, processes, runs, profiles, invitations, codes and plan on the hosted service. It does not touch what is on your computer; you uninstall the app and delete its data folder for that. Today, deletion is done by us on request; there is no self-service button yet. Write to matteo@luminars.io.
10. Why we may process your data (legal basis)
Under the GDPR we need a reason for each use.
- To provide the service you signed up for (contract, art. 6(1)(b)): your account, your workspace, syncing your processes and runs, running the AI, billing, service emails.
- Our legitimate interests (art. 6(1)(f)): keeping the service secure and healthy (the app's log, request logs), understanding how the site and the product are used, which is the analytics described in section 5, and contacting you about a plan after you downloaded the app. You can object at any time, and for analytics the banner and the footer control are that objection, exercised in one click (section 12).
- Your consent (art. 6(1)(a)): the "Help improve Luminars" switch, which covers both the copy in 4.2 and the words of an AI call in 4.3, and product news. You can withdraw either at any time, the switch from Settings in the app; withdrawal stops what follows it and does not affect what was done before.
- Legal obligations (art. 6(1)(c)): keeping invoices and accounting records.
11. Workplaces: members, employers and Italian law
Luminars is installed by a person, on the computer they work at, and that person controls capture (section 3.1). Nobody else can turn capture on, and an employer cannot read the raw capture: it never leaves the member's computer.
When a company runs a workspace, the company decides why the processes are recorded and what is done with them. For the workspace data listed in 4.1, the company is the data controller and Luminars processes it on the company's behalf; write to us to put a data processing agreement in place. For the copy described in 4.2 and 4.3, Luminars decides why the data is used, so there Luminars is the controller and the member's consent is what allows it.
For a personal workspace, Luminars is the controller.
Italian workplace note. Article 4 of the Workers' Statute (Law 300/1970, as amended by Legislative Decree 151/2015) governs tools that can monitor workers. Luminars is designed so that: the member installs it and can pause, exclude and delete at will; the employer receives only derived artifacts (process descriptions, run records, aggregates), never screen frames, audio, keystrokes or the text layer; every outbound flow is named in the app with the control that stops it. An employer that rolls out Luminars must inform its staff of how the tool works and how the data may be used, as article 4(3) requires, and should confirm with its own counsel whether Luminars falls within article 4(2) (a tool used by the worker to perform the work) or requires a union agreement or an authorisation under article 4(1).
12. Your rights
You can ask us, at any time, to:
- tell you what personal data we hold about you and give you a copy (access);
- correct it (rectification);
- delete it (erasure), subject to what we must keep by law;
- limit how we use it (restriction);
- give it to you in a machine-readable form (portability), which for your processes the app already does through export;
- stop using it where we rely on legitimate interest (objection);
- withdraw a consent you gave.
Write to matteo@luminars.io. We answer within one month. You also have the right to complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or to the authority of the country where you live.
Much of the data the app holds is on your own computer, where you can read, export and delete it directly. For those, you do not need us.
13. Security
The hosted service isolates each workspace in the database, so no query can read across workspaces. Every connection uses TLS. The app's installers are signed and notarised (macOS) and every update is signed and verified before it installs. AI provider keys live only on the hosted service, never in the app. Raw capture is refused by the hosted service by design, not by policy.
We are an early company. We do not hold a SOC 2 report or an ISO 27001 certificate. If you find a security problem, write to matteo@luminars.io.
14. Children
Luminars is a tool for work and is not directed at children. It is not for anyone under 18, and we do not knowingly collect their data.
15. Changes
When this policy changes, we update the date at the top and, for a change that matters to you, we tell workspace admins by email and note it in the app. Earlier versions are available on request.
16. Contact
Matteo Giardino Via Camandona 17, Torino VAT 12623180010 matteo@luminars.io