Information we collect
We collect information you provide directly, information created while you use the service, and limited technical information needed to operate and secure Lummai.
- Account and authentication details, including your email address, password credentials handled through Supabase Auth, locale, theme, and basic account settings.
- Project details, including property and renovation metadata, budgets, rooms, expenses, change orders, milestones, plans, project members, and related notes you enter.
- Uploaded files, including floor plans, financial documents, receipts, invoices, quotes, photos, plan versions, and project library media.
- AI review data, including extracted suggestions, confidence notes, processing status, and user edits or confirmations.
- Technical and security data, such as IP address, device and browser information, cookies, session identifiers, and server logs needed to keep the service working.
How we use information
We use information to provide the renovation workspace and to keep project data consistent, private, and reviewable.
- Authenticate users, maintain sessions, and protect accounts.
- Create and manage renovation projects, rooms, budgets, expenses, change orders, milestones, plans, and project libraries.
- Upload, store, preview, sign, and delete private project files when the app workflow requires it.
- Run AI extraction or suggestion workflows for floor plans, financial documents, and timelines.
- Support project sharing, permissions, invitations, and collaboration between owners, editors, and viewers.
- Troubleshoot, prevent abuse, secure the service, comply with law, and respond to support requests.
AI processing and user confirmation
Lummai may send eligible uploaded content and project context to AI service providers such as OpenAI to extract rooms, financial fields, or timeline suggestions.
AI output is stored as unconfirmed review data. It does not directly create or change confirmed rooms, expenses, change orders, milestones, or financial reports until a user reviews and confirms it in the app.
How information is shared
We do not sell personal information or share it for targeted advertising in the current product. We share information only as needed to provide, secure, or legally operate the service.
- Project collaborators can see project data according to the role assigned by the project owner.
- Service providers process information for hosting, authentication, database storage, private file storage, AI extraction, and transactional auth email delivery.
- We may disclose information if required by law, to protect rights and safety, or to investigate abuse.
- If Lummai is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction.
Storage, security, and retention
Uploaded project files are stored in private Supabase Storage. Lummai stores private file paths in the database and generates time-limited signed links only when an authorized user needs to view or download a file.
The app uses server-side authentication checks, row-level security, role-based project access, validation, and private storage patterns to protect user-owned data. No internet service can guarantee perfect security.
- We keep project and account information while your account or projects are active, unless a shorter period is required by law or operational needs.
- Deleting a project is designed to remove its related project records and private files, subject to backup, log, legal, and operational retention.
- Server logs, failed upload traces, and backup copies may remain for a limited period after data is changed or deleted.
Cookies, analytics, and tracking
Lummai uses cookies and similar storage for authentication, session refresh, locale, theme, and app functionality. The reviewed application code does not include advertising SDKs, analytics SDKs, or third-party cross-site tracking tools.
Your choices and requests
- You can update account settings such as password, language, and appearance in the app.
- Project owners can invite, change, or revoke project member access.
- You can delete projects where the app exposes deletion controls and permissions allow it.
- You can contact us to request access, correction, deletion, or export of personal information. We may need to verify your identity and may retain information where required by law, security, backups, dispute resolution, or legitimate operational needs.
Children
Lummai is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this policy as Lummai changes. If changes are material, we will update the date on this page and provide additional notice when appropriate.
Privacy questions
For privacy questions or requests, contact Lummai support. Include the email address associated with your account so we can locate the relevant records.