LlumoRequest access

Privacy policy

Last updated 7 September 2026.

Who we are

Llumo operates the Llumo platform at llumohq.com and is the controller of the personal data described here. Reach us at support@llumohub.com.

What we collect

Everything below is collected because the service cannot run without it. We do not buy data about you, and we do not sell or rent what we hold.

What you tell us when you sign up

Your organisation and workspace name, the name and email address of the person requesting it, the brand and website to be tracked, any competitors and additional domains you list, an optional logo, and any notes you add. If you bring your own model provider keys, we store them encrypted and use them only to run your own workspace.

What your workspace produces

The prompts you track, the answers the AI models return for them, the citations and competitors found in those answers, and the analytics derived from them. This is your content; see the terms of service.

Google Analytics and Search Console data, if you connect them

Connecting Google is optional and separate from having a workspace. When you connect it, we ask Google for read-only access to Analytics and Search Console, plus your email address so the workspace can show which account is linked. We store a refresh token so the connection survives, encrypted and bound to your organisation; we never receive your Google password. Reports and search statistics are fetched when a question needs them and are not copied into a separate store.

Assistant conversations

If you use the in-app assistant, the messages you send, the answers it gives and the steps it took are stored against your organisation so the thread survives a reload. Credentials are stripped before a message is stored.

Billing

Payments are handled by Dodo Payments. We never see or store card numbers. We keep the customer and subscription identifiers they give us, the record of what was charged and when, and your usage totals so invoices can be explained.

Technical records

Server logs, the IP address a request came from (used to rate limit abuse), and the session cookie that keeps you signed in. Our public pages load Google Tag Manager, which may set cookies for site analytics; the signed-in application does not use it for advertising.

How we use Google user data

Data received from Google APIs is used for one purpose: answering the questions you ask inside your own workspace about your own traffic and search performance. It is never used for advertising, never sold, never shared with another customer, and never used to train a general model.

Llumo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

You can disconnect Google from the assistant page at any time, which revokes our access at Google and deletes the stored token. You can also revoke it yourself from your Google account’s third-party access page.

Why we are allowed to hold it

For workspace and billing data, because we need it to perform the contract you entered into. For the Google connection, because you consented, and you may withdraw that consent at any time. For security logs and abuse prevention, because we have a legitimate interest in keeping the service standing up.

Who else touches it

These are the processors the service depends on. Each receives only what its job requires.

We disclose data to anyone else only where the law requires it, and we will tell you unless we are forbidden to.

Where it lives and how long we keep it

Data is held on servers in the European Union. Workspace content is kept while your workspace exists and is deleted when it is closed. Billing records are kept for as long as tax and accounting law requires. Google tokens are deleted the moment you disconnect. Server logs are short-lived.

How it is protected

Traffic runs over TLS. Provider keys and Google refresh tokens are encrypted at rest with AES-256-GCM and tied to the organisation that owns them, so a record copied elsewhere cannot be read. Access to production is limited to the people who operate it. No system is perfect, and we will tell you promptly if a breach affects you.

Your rights

You may ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to a particular use, or ask for it in a portable form. Write to support@llumohub.com and we will answer within thirty days. If you are in the European Economic Area or the United Kingdom and we have not resolved your concern, you may complain to your national data protection authority.

Children

The service is for businesses. It is not directed at anyone under 16, and we do not knowingly collect their data.

Changes

If we change this policy in a way that matters, we will email the contact on your account before it takes effect. The date at the top always reflects the current version.