Lumee Privacy Policy

Effective 2026-09-08

This policy describes what data Lumee collects, where it goes, how long it is kept, and how to reach us. It is written to be specific. Where a connected platform is treated differently from another, this policy says so.

Lumee is operated by Each Ember Inc. ("Each Ember"). In respect of the business data Lumee copies from your connected systems, you are the controller and Each Ember is your service provider and processor, acting on your instructions.

1. What information we collect through connected platforms

Lumee copies business records from systems you authorise. The exact set is determined by the narrowest authorisation the platform allows for the purpose, and it differs by platform. Where a platform's response includes a field we do not need, that field is removed before anything is stored.

QuickBooks Online. Chart of accounts, journal entries, invoices, bills, payments, credit memos, items, classes and locations, and the Profit and Loss, Balance Sheet, and Cash Flow reports. Customer and vendor records are collected as display names only. Email addresses, phone numbers, and billing or shipping addresses on customer and vendor records are not collected.

Shopify. Orders, including totals, line items, discounts, taxes, fulfilment status, and sales channel; products and variants; inventory levels; and shop configuration such as currency and timezone. No customer records are collected. Customer names, email addresses, phone numbers, and addresses are not requested, and where an order payload carries them they are removed before storage.

Amazon Selling Partner. Orders as financial records, inventory, catalog listings, and settlement and financial event reports. No buyer information is collected. Lumee requests no restricted data roles, and buyer names, addresses, email addresses, and phone numbers are never requested.

Square. Payments, orders, catalog, inventory, and locations. The Customers API is not used and no customer records are collected.

Other systems connected during an Each Ember engagement. Some clients connect systems that are not part of the connector platform described above, such as a CRM (GoHighLevel), an ERP (Odoo), a workspace (Notion), or spreadsheets. Those systems can include personal information about the client's own customers and contacts, such as names, email addresses, and phone numbers, because that information is the working substance of a CRM or ERP and the client has asked us to include it. Such connections are set up individually with the client, are documented in the client's engagement, and are governed by this policy in every other respect.

2. What information we collect directly from you

The Google Workspace identity (email address and name) of each person you authorise to use Lumee, used to sign them in and to record who asked what. The identity of the person who connects each platform, and when. Feedback you choose to submit about an answer.

3. What information we collect from your customers

None directly. Lumee has no interface for your customers and does not collect information from them. The only route by which information about your customers could reach Lumee is through a system you connect, as described in section 1.

4. How we use the information

To provide Lumee to you: to answer the questions your authorised users ask, to show changes over time, and to display connection status. To operate and secure the service: to detect failures, to audit access, and to enforce the isolation between clients. To improve the service: we record the text of questions asked and the queries run against your data, and use them to improve how Lumee answers questions across all clients. That record identifies your business and the person who asked, and access to it is limited to the Each Ember staff who operate Lumee. We do not use your data to train AI models, we do not sell it, and we do not share it with any other client.

The assistant your team uses. Lumee is reached through an assistant your business already licenses. That assistant is your vendor, not ours, and its handling of your questions and answers is governed by your agreement with it rather than by this policy. Lumee sends it the data needed to answer the question and nothing else.

5. Where the data lives and how long we keep it

Business data from connected systems is stored in a Google Cloud project dedicated to your business and to no other client, in the us-central1 region. Raw records are kept in that project for the duration of the engagement so that questions about history can be answered. The project is operated by Each Ember on your behalf.

Connection credentials (the tokens a platform issues when you authorise Lumee) are stored encrypted in Google Cloud Secret Manager in an Each Ember project, one secret per client per platform, accessible only to the process that synchronises your data. No credential can be read across clients.

Usage records (who asked what, when, and which tables were read) are kept in your dedicated project. A copy of question and query text is also kept in an Each Ember project, so we can find and fix the questions Lumee answers badly. That copy identifies your business and the person who asked. Query results are never copied there and are never logged anywhere. Logs are retained for 360 days.

Coverage metadata for scheduled synchronisation (which source, which resource, which time window, whether it loaded) is kept in a Neon Postgres database dedicated to your business. It contains no business records.

Deletion. When you disconnect a platform, Lumee revokes its access at the platform, deletes that platform's data from your project, and destroys the stored credential. When your engagement ends, everything above is deleted. BigQuery retains deleted data for up to 7 days for recovery and Cloud Storage soft-delete retains deleted objects for up to 7 days; after that the data is gone. We keep no separate backup beyond those two recovery windows.

6. International processing

Each Ember is established in the United States. Your business data is stored and processed in the United States. If you are established in Europe, or your connected systems hold personal information about people in Europe, contact us before connecting so the appropriate transfer terms can be put in place.

7. How to contact us

Privacy questions and requests: info@eachember.com Support: info@eachember.com Postal: Each Ember Inc., 19284 W. Osborn Rd., Litchfield Park, AZ 85340

8. Requests about personal information

If your customers exercise rights over their personal information under a platform's privacy programme (for example a Shopify customer data request or erasure request), Lumee receives that request from the platform and acts on it. For the connector platforms in section 1, Lumee holds no customer personal information, so the response is that none is held. For other connected systems that do hold contact information, Each Ember acts on your instruction as your processor.

9. Sub-processors

Sub-processor Purpose
Google Cloud Platform Hosting, storage (BigQuery, Cloud Storage), identity, secret storage, logging
Neon Synchronisation coverage metadata, one database per client, no business records
Anthropic Automated evaluation of Lumee before a deployment. Test questions are run against your data, and the answers, including the figures those queries returned, are sent to Anthropic's API for grading. Evaluation only, never in normal use.
Slack Feedback notifications, where enabled for your engagement. A notification carries your business name, the person who submitted the feedback, and a short paraphrase of the question they asked.

The assistant your team signs into is your own vendor under your own agreement, not our sub-processor.

10. Changes

We will notify the connecting account of material changes before they take effect, and this page states its effective date.