Privacy Policy
Last updated: July 30, 2026
1. What We Collect
When you use Lumora, we collect:
- Account data — email address, name, and hashed password (if you register via email).
- GitHub data — repository metadata, code files (source, structure, dependencies), and OAuth token scope.
- Usage data — feature interactions, AI chat queries, generated documents, security scans.
- Analytics — page views and interactions via Google Analytics. You can opt out via the cookie banner.
2. How We Use Your Data
We use your data solely to provide and improve Lumora's services:
- Analyze your codebase to generate documentation, architecture diagrams, and health scores.
- Power AI chat responses based on your repository content.
- Detect secrets and security issues in your code.
- Send service-related emails (verification, password reset, security alerts).
- Improve the product through anonymous usage analytics.
3. Data Sharing
We do not sell your data. We share data only with trusted third-party services necessary for operation:
- Groq — AI inference (code snippets sent for analysis, not stored).
- Resend — email delivery.
- MongoDB Atlas — database hosting.
- Google Analytics — anonymous usage tracking (opt-out available).
- Ko-fi — payment processing (no payment data stored by Lumora).
4. Data Retention
We retain your data for as long as your account is active. If you delete your account, all associated data is permanently removed within 30 days. Shared reports are automatically deleted after 7 days.
5. Your Rights (GDPR)
If you are in the European Economic Area, you have the following rights:
- Right to access — download all your data via Settings → Export My Data.
- Right to rectification — update your profile information in Settings.
- Right to erasure — delete your account and all data via Settings → Delete Account.
- Right to restrict processing — contact us to restrict how your data is processed.
- Right to data portability — your data export is in standard JSON format.
- Right to object — opt out of Google Analytics via the cookie banner.
6. Cookies
We use a minimal set of cookies:
- Authentication — JWT and refresh tokens stored in localStorage (not cookies).
- Analytics — Google Analytics cookies for page view tracking. You can accept or decline via the cookie banner.
- Preferences — theme preference and cookie consent status stored in localStorage.
7. Security
We encrypt sensitive data (passwords, GitHub tokens) at rest using AES-256 and bcrypt. All traffic is served over HTTPS. We perform regular security scans on your repositories to detect exposed secrets.
8. Contact
For privacy-related inquiries, email privacy@lumora.app.