Skip to main content

Legal

Privacy Policy

Effective date: May 4, 2026

1. Information We Collect

Lumis is a compliance testing sandbox. We collect information necessary to provide the Service, including:

  • Account Information: When you sign up via Google or GitHub, we receive your name, email address, and profile picture.
  • Usage Data: We record simulation execution logs, DAG configurations, and API usage metrics to provide the Service and monitor for quotas.
  • Mock Data: Any data you input into the sandbox (e.g., in the Payload Editor) is stored in your workspace. Do not input real PII (Personally Identifiable Information) as this is a testing environment.

2. How We Use Your Information

We use the collected data for the following purposes:

  • To operate and maintain the Lumis Compliance Sandbox.
  • To manage your workspace, quotas, and billing subscriptions.
  • To provide customer support and respond to your inquiries.
  • To improve our simulation engine and developer experience.

3. Data Retention & Security

Your data is stored securely using industry-standard encryption. Data retention is governed by your workspace tier:

  • Free Tier: Simulation history is retained for 7 days.
  • Pro: Simulation history is retained for 90 days.
  • Business: Simulation history is retained for 365 days.

You may request deletion of your account and all associated data at any time via our support channels.

4. Third-Party Providers

We utilize trusted third-party services to deliver Lumis:

  • Convex: Our real-time database and backend infrastructure.
  • Google/GitHub: Authentication and identity management.
  • Lemon Squeezy: Payment processing and billing management.
  • Cloudflare: Global content delivery and security.
  • Custom Engine (customer-hosted Live Mode): Lumis provides the software (a container image) only. Evaluation runs on customer-controlled hosts, and Lumis does not receive or store live payloads. The only data Lumis receives from a deployed engine is usage counters (evaluations_count, period_seconds) and sync metadata (workspace id, ruleset id, version, timestamp).

Where you run the Live Mode engine on your own hosts, you remain the controller for any payloads you send to your own engine. Processing occurs on infrastructure you control, not Lumis infrastructure.

5. Contact Us

If you have any questions about this Privacy Policy, please contact us at legal@lumiscompliance.com.