Privacy Policy
Lumaion is experimental continuity infrastructure for AI agents. This page describes the current privacy boundary of the developer preview and the production service behind its public integrity surfaces.
Continuity data
Server-managed encryption is the default compatibility mode, and Lumaion can decrypt those vaults. In opt-in client-managed AES-256-GCM mode, the continuity key stays connector-side, Lumaion does not receive plaintext continuity payloads and does not have decrypt capability for those client-managed payloads.
Early-access requests
The developer-preview form stores the email address and profile details you submit, plus request timestamps, review status and limited campaign attribution. It is used only to review preview access, contact the requester about that preview and measure the preview funnel. Early-access requests are retained for up to 180 days by default; privacy-minimal product events are retained for up to 90 days by default.
Submitting the form does not create an account, owner credential or pairing token. Pairing remains a separate owner-controlled action.
Public integrity
Public integrity surfaces expose verification metadata such as hashes, signatures and status. Prompts, private memory, credentials and continuity content are not intentionally published there. Public Bitcoin anchoring contains a cryptographic integrity hash, not conversations or identity data.
Recovery and witness
A verified off-device recovery copy is not a completed restore drill. A separate witness signing key can attest an audit head, but key separation alone does not prove physical custody on another computer.
Accounts and payments
The current public website has no signup or purchase flow. Early access is a manual request, not registration. Real-money payments remain disabled.
Retention and deletion
There is no self-serve deletion control on this site yet. Security and operational logs may be retained as needed to investigate failures, detect abuse and maintain audit integrity. Early-access request records have a default 180-day retention period and privacy-minimal product events have a default 90-day retention period.
To request access to, correction of, or deletion of personal data associated with an early-access request, email hello@lumaion.world, preferably from the address used for the request. We aim to acknowledge privacy requests within 7 days and complete verified requests within 30 days, subject to applicable security, audit-integrity, abuse-prevention or legal retention requirements.
Operator, contact and jurisdiction
Lumaion is currently a developer preview. A commercial operating entity and governing jurisdiction for paid public service have not yet been designated. Public project and privacy contact is hello@lumaion.world; developer early-access mail may be sent to access@lumaion.world.
Source and live service
Canonical source may contain accepted changes that are not yet deployed. Production changes require a separate release gate, so source status and live service status should not be treated as identical.