Privacy Policy
What we collect, why, and what we never do. Last updated 4 August 2026.
What we collect
Account data (name, email, organization), the operational data you send (automation definitions, run events and their metadata, cost and rate assumptions), and product telemetry about feature usage (signups, plan changes, ingestion volume). For AI workloads we receive token counts, model identifiers, and costs; the ingestion paths do not accept prompt or completion content. Billing card details go directly to Stripe; we never see or store them.
What we use it for
Running the service, computing your value ledger, sending the emails you configure (value packs, alerts, invitations), and improving the product. We do not sell your data, we do not advertise, and we never use one customer's data to benefit another.
Sharing
Report links and shared analytics views are visible to anyone who has the URL until you revoke them; that is their purpose, and you control creation and revocation.
Service providers and customer-directed connections
We run on Render (hosting) and Stripe (payments), and send email through our email delivery provider. If you enable AI spend import, we use the provider admin keys you supply to fetch billing totals from OpenAI or Anthropic on your behalf (keys encrypted at rest; remove them any time). Webhook deliveries and report links go to destinations you configure; those are your connections, under your control. We disclose data only when legally compelled, and we will tell you unless prohibited.
Managed service providers
When an MSP creates a managed organization for a client, the MSP is our customer and administers that organization; the client's users see only their own organization's data. Questions about a managed organization's data go first to the MSP that manages it.
Retention and deletion
Run history is retained per your plan's retention window. On account deletion we remove your organization's data, including feedback text and marketing-list entries, within 30 days; backups age out within 90.
Your rights
Export is self-serve and needs no request: the ledger, run events, automations, and value figures download as CSV from inside the app on every plan, and the same records read over the API. See the export guide. For a single bundle of everything your organization holds, or for correction or deletion, email support@lumatrack.io. We answer within 30 days.