Privacy Policy
Effective date: July 7, 2026
This Privacy Policy explains how Lumio Software FZ-LLC, a company registered in the Ras Al Khaimah Economic Zone (RAKEZ), United Arab Emirates ("Lumio", "we", "us"), collects and processes personal data in connection with lumioguard, including lumioguard.dev, the lumioguard application, and related services (the "Service").
Contact for privacy matters: support@lumioguard.dev
1.Our two roles
We process personal data in two distinct capacities:
- As a controller for data about visitors to our website and the people who sign up for and administer accounts (e.g. your name, email, and billing records).
- As a processor for data in the repositories and services a customer's workspace connects that we analyze on the customer's behalf (e.g. code authored by a team, commit metadata, and service configuration). For this data, the organization that runs your workspace is the controller, and we process it under their instructions and our Data Processing Agreement (available on request).
If you are a team member with questions about how data from your workspace's connected tools is analyzed, please contact your workspace administrator first; we will assist them in responding.
2.Data we collect
Account data. Name, email address, authentication identifiers from the provider you sign in with (for example GitHub or Google), workspace name, and role, provided when you create an account.
Billing data. Purchases are processed by our merchant of record, Paddle.com Market Limited. Paddle collects your payment details directly; we never receive full card numbers. We receive transaction records (plan, amount, country, tax status) needed to operate your subscription. Paddle's privacy policy applies to payment processing: https://www.paddle.com/legal/privacy
Connected tool data. When a workspace administrator connects tools such as a source control provider (e.g. GitHub) or live services (e.g. Supabase, Neon, Vercel), we collect content and metadata from those tools to provide the Service: repository code and configuration, and live service settings and statistics. We use this to compute the insights the Service provides (stack health scores across six pillars, evidence-cited findings, and suggested fixes). Repository code is fetched into an ephemeral sandbox for the duration of a scan and is not retained after the scan completes, what we keep are the normalized findings (identifiers, severities, scores, the code references cited as evidence, and suggested fixes). The optional deep database scan reads system catalogs and statistics only and does not read your application's row data.
Connection credentials. The OAuth tokens and API keys you authorize when connecting a platform, stored encrypted and scoped read-only by default (see Security below).
Usage data. Log data, device and browser type, and product interaction events, used for security, debugging, and improving the Service.
We do not intentionally collect special categories of personal data, and the Service is not directed at children under 16.
3.Purposes and legal bases
We process personal data to: provide and operate the Service (performance of contract, or the controller's instructions for workspace data); bill and manage subscriptions (contract, legal obligation); secure the Service and prevent abuse (legitimate interests); improve the Service using aggregated, de-identified data (legitimate interests); measure how visitors use our website (consent, given via the cookie banner and withdrawable anytime); send service communications (contract) and, with your consent where required, product news (consent, withdrawable anytime).
4.Sharing and subprocessors
We do not sell personal data. We share data only with:
- Amazon Web Services (AWS): cloud hosting, storage, and the single-tenant sandboxes scans run in.
- Cloudflare: application hosting, edge delivery, and database connectivity.
- Supabase: managed Postgres database hosting.
- Anthropic: the model that powers the scanning agent and analysis.
- Paddle.com Market Limited: merchant of record for payments, billing, and tax.
- PostHog, Inc.: website usage analytics (PostHog), loaded only if you consent via our cookie banner (see Cookies below).
- Service providers for email delivery (Resend), bound by data processing terms.
- Authorities where required by law, and successors in the event of a merger or acquisition (with notice).
We do not use your code or data to train third-party models for unrelated purposes. A current subprocessor list is available on request at support@lumioguard.dev.
5.International transfers
We operate globally and store data on cloud infrastructure. Where personal data subject to GDPR or UK GDPR is transferred internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum.
6.Retention
Account data is kept for the life of the account and deleted or anonymized within 90 days of account closure. Repository code is never retained after a scan completes. Connection credentials are deleted when you disconnect the relevant integration. Normalized findings and reports are kept while the workspace remains active and are deleted within 90 days after workspace deletion or a verified deletion request from the controller. Billing records are retained as required by tax and accounting law. Backups roll off within 35 days.
7.Security
We follow SOC 2-aligned security practices, including encryption in transit (TLS) and at rest, least-privilege access controls, audit logging, and periodic access reviews. Connection credentials are protected with AES-256-GCM envelope encryption using per-record data keys, with key-encrypting keys held separately from the encrypted data; API keys and similar secrets are stored only as HMAC hashes. Scans run in fresh, single-tenant sandboxes that are destroyed when the scan finishes, and results are written to a tenant-isolated database protected by fail-closed row-level security. No system is perfectly secure; we will notify affected customers of a personal data breach without undue delay and in accordance with applicable law.
8.Your rights
Depending on your location (including under GDPR and UK GDPR), you may have rights to access, correct, delete, or receive a copy of your personal data, restrict or object to processing, and withdraw consent. To exercise them, email support@lumioguard.dev. If we process your data as a processor for your organization, we will refer your request to them and assist. You may also lodge a complaint with your local data protection authority. You can additionally disconnect any connected platform at any time, which revokes our access and deletes the stored credential.
10.Changes
We may update this policy from time to time. Material changes will be notified by email or in-app notice before they take effect. The effective date above always reflects the current version.
11.Contact
Lumio Software FZ-LLC (RAKEZ, Ras Al Khaimah, United Arab Emirates)
Email: support@lumioguard.dev