Last updated 25 August 2026
Privacy Policy
Current LumicSec operating policy. Mandatory rights under applicable law continue to apply, and any enterprise or jurisdiction-specific commitment must be expressly agreed in writing.
1. Who this policy covers
This policy describes personal and service data processed through LumicSec. For paid contracting, the applicable invoice, payment instruction or written order should identify the legal or business service provider accepting payment. Questions about the responsible service provider or privacy handling can be raised through the LumicSec contact channel.
2. Data we process
LumicSec may process account identifiers, website URLs, scan metadata, security findings, reports, remediation/retest state, ownership-verification state, scheduled-scan state, support messages, payment-reference information, payment-proof files where submitted, client-report-link metadata and service/security logs needed to operate the product.
3. Why we process data
We use this information to authenticate users, run authorized security workflows, generate and retain reports, compare remediation and retests, operate scheduled scans with explicit authorization, enforce plan limits, review assisted payments, investigate abuse or reliability problems, maintain service security and provide support.
4. Security-token minimization
Verified Scan Access is designed so the raw Scan Access token is not persisted as the server-side credential record; the service retains a cryptographic hash and a short non-secret prefix/state needed to verify or identify the configured access. The raw token is treated as a secret and must not be sent to unrelated origins. Ownership-verification tokens are public proofs and are handled differently from Scan Access secrets.
5. Client report links and access telemetry
Secure Client Report Links use bearer-style share tokens. The raw share token is presented to the authorized user for sharing, while the service stores a cryptographic hash and short prefix rather than the raw bearer token. Link records can include the source scan snapshot, expiry/revocation state and last-accessed telemetry. Revoking or expiring a share link does not by itself delete the underlying source scan/report from the customer account.
6. Payment and support data
Assisted billing may process payer identity, plan, amount, payment method, transaction/reference information, review status and a payment-proof file if the customer chooses to submit one. Support messages may contain information necessary to investigate account, billing or security issues. Never submit card numbers, CVVs, OTPs, UPI PINs, bank passwords, private keys, session cookies or unrelated customer secrets.
7. Service providers and processing locations
Current core service categories include Google-based authentication, Vercel-hosted application infrastructure and Supabase-backed authentication/database services. These providers may process limited account or technical data in locations where their services operate under their applicable terms. LumicSec does not promise a specific data-localization region unless a separate written agreement expressly provides one.
8. Retention, deletion and account requests
Retention is based on the purpose of the record rather than a promise that all data is deleted on a single fixed date. Account, scan and report history may be retained while needed to provide the workspace and evidence history; billing/payment and security records may be retained for reconciliation, fraud prevention, dispute handling or legal obligations. Customers may request deletion through the contact/support channel after identity and account checks. Where an infrastructure provider keeps recovery copies, removal from those copies may follow that provider's recovery cycle rather than immediate deletion from every backup copy.
9. Data access and export
Customers can use available product report/export features and may request reasonable access, correction, export or deletion assistance through support. Requests can be limited where disclosure would expose another person's data, weaken service security, conflict with fraud-prevention needs or violate a legal recordkeeping requirement.
10. Data you should not submit
The standard workflow is designed around public website signals and does not require passwords, private keys or confidential production datasets. Do not upload credentials, OTPs, card data, session cookies, confidential customer records or production secrets unless a future written enterprise agreement expressly supports that data type and workflow.
11. AI and model-training use
The current LumicSec service does not use customer scan reports, payment-proof files, support messages, Scan Access secrets or Secure Client Report bearer tokens as a training dataset for a general-purpose AI model. If a future optional AI feature sends customer content to an AI provider or introduces a materially different model-data use, that processing must be disclosed in the product or applicable policy before customers are expected to rely on it. Standard authorized security-review scoring does not depend on training a model on customer reports.
12. Operational retention schedule
Operational retention follows the record purpose: active account, website, scan, report and remediation history may remain while the workspace is active or until the customer deletes it or completes a verified deletion request; active share-link records remain until revoked, expired or deleted, while the underlying source report can remain in the workspace; payment, fraud-prevention, security and audit records may be retained for reconciliation, disputes, accounting/tax or other legal requirements; support and demo records are retained only while reasonably useful for the request, follow-up, abuse prevention or legal needs. After a verified account/data deletion request, LumicSec targets removal of deletable primary-service records within 30 days. Records subject to a legal, billing, fraud or security hold are excluded until that need ends, and provider recovery copies may age out on the provider's recovery cycle rather than disappearing immediately.