Privacy policy
Last updated 4 September 2026
Who we are
[LEGAL COMPANY NAME] Ltd (company number [COMPANY NUMBER]), trading as Lumvi, of [REGISTERED ADDRESS, including postcode], is the data controller for the personal data described here. Contact us at [A WORKING EMAIL ADDRESS].
What we collect
- Account data — name, email address, and the password hash held by our authentication provider. We never see your password.
- Business data — your trading name, address, postcode, phone, VAT and company numbers, and who you invite to your account.
- Content — the briefs you write, and the copy and images generated for you.
- Connected accounts — access tokens for services you connect. These are stored encrypted, server side, and are never sent to your browser.
- Leads — publicly visible posts from public social media groups you ask us to watch, including the author’s display name where it is public.
- Billing data — subscription status and identifiers from Stripe. We do not store card numbers.
- Usage data — a record of each AI operation and its cost, so we can apply your plan’s limits.
Why, and on what basis
- To provide the service — performance of our contract with you.
- To take payment — performance of our contract, and our legal obligations for accounting records.
- To keep the service secure and working — our legitimate interests in preventing abuse and diagnosing faults.
- Lead discovery — our legitimate interests, and yours, in identifying publicly posted enquiries. Only public groups are read, only posts, and never through a logged-in account.
Who we share it with
We use these processors, and share only what each needs: Supabase (database, sign-in and file storage, hosted in the UK), Vercel (application hosting), Stripe (payments), Anthropic (text generation), OpenAI (image generation), Apify (reading public social posts), and the platforms you choose to connect, such as Netlify, Meta and LinkedIn.
Some of these are outside the UK. Where that is so, transfers are covered by the UK International Data Transfer Agreement or equivalent safeguards. We do not sell personal data, and we do not use your business data to train AI models.
How long we keep it
- Account and business data — while your account is open, then up to 90 days.
- Content and websites — while your account is open.
- Leads — automatically deleted 90 days after they are found.
- Billing records — six years, as tax law requires.
Your rights
Under UK GDPR you may request a copy of your data, ask us to correct or delete it, object to or restrict processing, or ask for it in a portable format. Email [A WORKING EMAIL ADDRESS] and we will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk.
Cookies
We set only the cookies needed to keep you signed in and to keep your session secure. We do not use advertising or third-party analytics cookies, so there is no consent banner to click through.
Security
Data is separated per business at the database level, so one customer cannot read another’s. Access tokens for connected services are held in a store that no browser session can read. Access to production systems is limited to people who need it.