Legal
Privacy Policy
Effective 14 September 2026. Adapted from GitHub's site-policy documents (CC0) and trimmed to the size of this service.
1. Controller
Calico AG, Riedmatt 2, 6300 Zug, Switzerland is the controller of the personal data described here. Reach us at hello@getluminaid.com. Where you use Luminaid for your company and put your own customers' or prospects' data into it, your company is the controller of that data and we process it on its behalf.
2. What we collect
- Account data — email address, name if you give one, the Google account identifier if you sign in with Google, workspace memberships and roles, sign-in events.
- Workspace content — the keywords, buyer personas, brand and competitor names, domains and pages you configure; the answers the answer engines returned, the sources they cited, the pages we read for you, and the analyses, recommendations and drafts the Service produced.
- Usage and billing data — runs started, credits consumed, provider and model usage per run (opaque workspace and run identifiers only), plan and payment status. Card details are held by our payment processor, never by us.
- Technical data — server logs with IP address, user agent, request path and timing, kept for security and operations. Logs never contain your keywords, the engines' answers or your content.
- Marketing site — if you request an audit through the form, the details you enter. The site sets no analytics or advertising cookies.
3. Why and on what basis
To provide the Service you asked for (performance of the contract): running analyses, storing results, billing. To keep the Service secure and reliable and to improve it (our legitimate interest): logs, alarms, aggregate usage. To meet legal obligations (accounting records). We do not sell personal data, do not use your content to train models, and do not profile you for advertising.
4. Sub-processors and where data is processed
The Service runs on Amazon Web Services in the EU (Ireland, eu-west-1) region: your workspace data, results and files are stored there. To produce an analysis, your keywords and personas — never your account data — are sent to the answer engines and search providers your workspace has selected, and pages you configure are read by our crawler. Model calls made through Amazon Bedrock use a global inference profile and may be served from AWS regions outside the EU. Our sub-processors:
- Amazon Web Services (hosting, storage, Amazon Bedrock model access, Cognito sign-in) — Ireland; Bedrock global inference profiles may route to the United States.
- Answer engines your workspace selects: OpenAI, Perplexity, Google (Gemini), Anthropic — United States.
- Search and crawl providers your workspace selects: Brave Search, Tavily, Exa, SerpApi, Firecrawl — United States.
- Google (optional "Sign in with Google") — the identifier and email of the Google account you choose.
- Stripe (payments) — card data and invoices; we hold only the payment status and references.
- GitHub (source hosting and deployment automation) — no customer data.
Transfers outside Switzerland and the EU rest on the recipients' standard contractual clauses or an adequacy decision. We update this list when a sub-processor changes and announce material changes in the Service.
5. How long we keep it
- Analysis results and raw provider answers — for the retention window of your plan: 90 days on Free and Starter, 365 days on Pro and Business, as agreed for contract plans. A nightly job deletes what is older; a storage-level rule removes anything it missed after 400 days.
- Workspace configuration (keywords, personas, brand details) and account data — while the workspace and account exist.
- Usage, credit and audit records — for the life of the organization plus the legal accounting period (ten years under Swiss law) in aggregate, identified by opaque identifiers.
- Server logs — 30 days.
- Deleted workspaces — every row and file of a workspace is deleted within 30 days of the deletion request, verified, and a deletion record with counts is kept; a data export is offered before deletion.
6. Your rights
Under the Swiss Federal Act on Data Protection and, where it applies, the GDPR, you may ask for access to, correction, export or deletion of your personal data, object to processing based on legitimate interest, and complain to a supervisory authority (in Switzerland, the FDPIC). Write to hello@getluminaid.com; we answer within 30 days. Workspace owners can export and delete their workspace's data from the Service directly.
7. Security
Data is encrypted in transit and at rest; each workspace's data is stored under its own key prefix and is reachable only with credentials scoped to that workspace; access by our staff is limited to support you request and is logged. We notify affected customers without undue delay if a breach affects their data.
8. Changes
We update this policy when the Service or our sub-processors change and announce material changes in the Service or by email. The current version is always at this address.