Privacy policy
Last updated: June 2026
This Privacy Policy explains how Nexora Group LLC ("Company", "we", "us", or "our") collects, uses, stores, and protects your information when you use the Lumi application ("App") and the Lumi website ("Website").
1. Information we collect
Information you provide directly
- Account information: email address, name, and payment information when you create an account or subscribe to a paid plan
- Voice input (not yet enabled): when real-time voice ships, the audio you capture by activating the microphone — see Section 3. Until then, all input to Lumi is text
- Text input: text commands you type into the App
- Preferences: language, notification settings, and feature preferences you configure
Information collected through service connections
When you connect Lumi to third-party services, Lumi accesses data from those services to fulfill your requests. This may include calendar data, contact data, email data, document data, messaging data, project data, and CRM data.
Lumi accesses this data only when you issue a command that requires it. Lumi does not continuously monitor or index your connected services unless you have enabled the Company Knowledge feature (Business and Enterprise plans only).
Information from your device (with your permission)
When you ask Lumi to do something that needs data stored on your device, and after you grant the matching Android or iOS permission, Lumi accesses: your device contacts (to find and reach the people you name, and to add a contact when you ask), your device calendar (to read your schedule and create or update events), and your photos, media, and camera (only the specific items you pick or capture, to attach them to a chat). Lumi accesses these only to carry out the specific request you make — it does not continuously scan, upload, or index them. You can revoke any of these permissions in your device settings at any time.
Information collected automatically
- Device information: device type, operating system version, app version, and device identifiers
- Usage data: which features you use, how often you use them, and general interaction patterns (not the content of your commands)
- Crash reports: technical logs when the App encounters an error, which may include device state information
Information we do NOT collect
- Biometric data: Lumi does not store voiceprints or use voice data for identification
- Location: Lumi does not access your device location
- Browsing history: Lumi does not access your web browsing history
- Photos or media: Lumi does not access your photo library unless you explicitly request a photo-related action
2. How we use your information
We use collected information to fulfill your requests, improve the service, provide customer support, process payments, send service communications, and maintain security. We do NOT use your information to train AI models without your explicit consent, sell it to third parties, target advertising, or profile you.
3. Voice data processing
Voice (real-time speech interaction) is not yet enabled in the shipping product. When the feature ships, this section will be updated to describe exactly how audio is captured, transcribed, processed, and deleted. Until then, all input to Lumi is text-based.
4. Data storage and retention
Conversation history
Your conversation history is stored on our servers so it can be resumed across devices. It is encrypted in transit (TLS 1.2 or higher). You can delete any individual conversation — or your entire history — at any time. To generate replies, your messages are processed by our LLM provider; see Service providers and sub-processors below for who that is and what they receive.
Connected service tokens
When you connect a third-party service, the OAuth access and refresh tokens issued by that service are stored on our servers, encrypted at rest. They are never returned to the App or exposed through our API, and Lumi uses them only to perform the actions you request — including background tasks you have scheduled, which run while the App is closed. You can revoke any connection at any time, which deletes the stored tokens.
Account data
Account information is stored on our servers, protected with access controls, and encrypted in transit (TLS 1.2 or higher).
Data retention periods
| Data type | Retention period | Where stored |
|---|---|---|
| Conversation history | Until you delete it | Our servers |
| Service access tokens | Until you disconnect the service | Our servers (encrypted at rest) |
| Account information | Until you delete your account | Our servers |
| Usage analytics | 24 months, then anonymized | Our servers |
| Crash reports | 90 days | Our servers |
| Payment records | As required by tax law (typically 7 years) | Payment processor |
Data deletion
You can delete your conversation history, disconnect any service, or request complete account deletion through the App or by emailing lumi-privacy@nexoragroup.dev. We will delete your account data within 30 days.
5. How we share your information
We share your information only with connected services (to perform actions you request), with service providers (under contract), for legal compliance, or in a business transfer. We do NOT share with advertisers, data brokers, AI model training providers, or any third party for marketing purposes.
Service providers and sub-processors
To run Lumi we rely on a small set of infrastructure and AI sub-processors. Vercel operates the AI Gateway that transports your chat messages (and any attached screen context) from our backend to a third-party large-language-model provider, which processes them under contract solely to generate Lumi's reply. We may change the underlying model providers that the gateway routes to; where a change introduces a new sub-processor or a new processing location, we will update this notice and inform you of material changes as described in Section 11.
Google user data and Limited Use
When you connect Google Workspace, Lumi accesses Google user data only to carry out the specific request you make in chat — it does not continuously sync, monitor, or index your Google account. The table below lists each Google scope Lumi may request, the data it covers, and why.
| Google scope | Data accessed | Why Lumi needs it |
|---|---|---|
Calendar events (calendar.events) | Your Google Calendar events | Read your schedule to answer questions, and create, update, or delete events when you ask |
Google Docs (documents) | The content of the Google Docs you reference | Read a document to answer questions or summarise it, and create or edit documents when you ask |
Drive file (drive.file) | Only the Drive files you open or create with Lumi | Open or save the specific files you use with Lumi — Lumi cannot see the rest of your Drive |
Access: Lumi calls these Google APIs only when a command you issue needs them, and only for the duration of that request. Lumi never reads your calendar or documents in the background, on a timer, or while the app is closed — other than scheduled tasks you set up yourself.
Use and sharing: Data returned by Google APIs is passed transiently to our LLM provider (via the Vercel AI Gateway described above) solely to generate Lumi's reply, then discarded. Google user data is never stored beyond the chat session it belongs to, never sold, never used for advertising, and never used to train AI or machine-learning models.
Storage and revocation: The OAuth tokens for your Google connection are stored encrypted at rest and are deleted when you disconnect Google in the app. You can also revoke Lumi's access at any time at myaccount.google.com/permissions.
Limited Use: Lumi's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Business and enterprise data handling
Business and Enterprise plans include a Company Knowledge feature, audit logging, and data residency controls. Company Knowledge respects source-system permissions, is admin-controlled, and excludes personal content unless owners opt in.
7. Security measures
We protect your information with encryption in transit (TLS 1.2 or higher), secure token storage, access controls, regular audits, and an incident response plan.
8. Your rights
Depending on your location, you may have rights of access, correction, deletion, portability, objection, restriction, and consent withdrawal. To exercise these rights, contact lumi-privacy@nexoragroup.dev. California residents have CCPA/CPRA rights. EEA residents have GDPR rights and may lodge a complaint with their local data protection authority.
9. Children's privacy
Lumi is not intended for children under 16. We do not knowingly collect personal information from children under 16.
10. International data transfers
We ensure appropriate safeguards for international transfers, including Standard Contractual Clauses where required by GDPR.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the App or via email at least 30 days before the changes take effect.
12. Contact us
For questions about this Privacy Policy or to exercise your privacy rights, email lumi-privacy@nexoragroup.dev. For data protection inquiries in the EU, our Data Protection Officer can be reached at lumi-dpo@nexoragroup.dev.
13. Accessibility service data
Lumi for Android uses Android's accessibility service so that, with your explicit permission, Lumi can read what is on your screen and act on your behalf in other apps. This section describes exactly what Lumi captures via the accessibility service, when it captures it, where it goes, and how long we keep it.
What we collect
When you send a message in the Lumi mini-chat overlay — and only then — Lumi captures a single bundle from your foreground app:
screen_tree— a structured, DOM-style description of every visible UI element on the app you are currently using. For each element we record the on-screen text, its accessibility description, its view identifier, its class name, its position on screen, and whether it is tappable, editable, or scrollable. We do not record what you type unless that text is already visible on screen at the moment of capture.screenshot— a single image of the screen as it appears at the moment of capture, produced by Android's standard accessibility screenshot API.focused_app— the package name of the app that is currently in the foreground (e.g.com.google.android.calendar).
Lumi does not capture, store, or transmit:
- Your keystrokes. Lumi's accessibility service does not intercept hardware key events or text input as you type.
- Notification contents, clipboard contents, biometrics, or location.
- Anything from any app while the screen is off, or while Lumi is in the background, or while you have not initiated a chat turn.
When we collect it
Only when you send a message to Lumi from the mini-chat overlay, or when the assistant calls one of the on-device action tools (tap, tap_at, input_text, scroll, swipe, back, home, capture_screen_context) in direct response to your chat turn. Each capture is initiated by a user action; Lumi does not capture screen content proactively, in the background, on a timer, or while the device is locked.
If you have not enabled Lumi in Settings → Accessibility → Installed services → Lumi, no capture occurs at all. Disabling Lumi in that settings screen stops every form of accessibility-backed capture immediately.
Why we collect it
So the Lumi assistant has enough context to (a) understand what you are asking about ("what's on this page?", "summarise this email"), and (b) act on your instruction in other apps ("tap Reply and type 'on my way'") when standard typing or pointing on the device is not practical. The accessibility service is the only Android API that provides both halves of this experience for a non-system app.
Where it goes
Lumi sends each capture, attached to your chat message, to the Lumi backend at https://lumi-api.nexoragroup.dev/api/chat/ over TLS. The backend forwards the relevant slice to our LLM provider so the model can ground its reply in your screen context. No part of the capture is shared with any other third party, sold to anyone, or used for advertising.
Sub-processors
- Vercel operates the AI Gateway that transports your chat message and its attached screen context from our backend to the model provider.
- Our third-party LLM provider receives the
screen_tree, thescreenshot, thefocused_app, and your chat message text for the duration of the inference call needed to answer your turn, solely to generate Lumi's reply.
Retention
Accessibility-service captures are attached to the chat session record they belong to. We keep that record until you delete it: deleting the chat session from your in-app history removes its captures, and deleting your account purges every accessibility-service capture we hold for you (see Data deletion elsewhere in this policy). We do not retain these captures on any separate timer.
User control
You control the accessibility service in three places:
- In Lumi — the Accessibility row in Settings opens an in-app rationale screen that explains what the permission allows Lumi to do, and offers both an "Open Accessibility settings" button (to grant or revoke) and a "Not now" button (to dismiss without granting).
- In Android Settings — Settings → Accessibility → Installed services → Lumi. Toggle off to revoke. Lumi cannot re-enable the service on your behalf; only you can.
- By deleting your account — see Data deletion. Deleting your account purges every accessibility-service capture we hold for you.
How to ask us about your data
Email lumi-privacy@nexoragroup.dev. We respond to access and deletion requests within 30 days, sooner where required by local law.