LumenMe
Privacy Policy
In short. LumenMe uses your email, calendar and chat messages only to do what you ask. It does not sell your data, show you ads, or use your data to train AI models. Nothing is sent or changed in your accounts until you approve it.
1. Who we are
LumenMe is a private assistant, used through Telegram, that helps you manage your email, calendar and tasks. It is operated by BYC Ventures ("we", "us"). This policy explains what LumenMe accesses, why, and how it is protected.
2. What we access
LumenMe only accesses accounts you connect yourself, through Google's or Microsoft's own sign-in screen. We never see your passwords.
| Data | Source | Why |
|---|---|---|
| Email messages: sender, recipients, subject, date, content, read status | Gmail or Microsoft Outlook | To search, summarize and show your email; to draft, send and reply when you approve; to mark messages read or unread when you approve; to alert you about important messages |
| Calendar events: title, time, location, attendees, description, your response | Google Calendar or Microsoft Outlook | To show your schedule, find free time and prepare meeting briefs; to create, move or answer events when you approve |
| Your basic profile: email address | Google or Microsoft sign-in | To confirm which account you connected |
| Messages and voice notes you send the assistant | Telegram | To understand and answer your requests. Voice notes are transcribed and then handled as text. |
| Tasks, notes, saved preferences and people notes | You, or an assistant you authorize | To remember what you ask it to remember |
| Your Telegram user ID | Telegram | To make sure only you (and anyone you authorize) can use your assistant |
3. How we use it
- Only to provide the features you use: answering your questions, preparing briefs and reminders, and carrying out actions you approve.
- Every action that changes something (sending or replying to email, saving a draft, marking email read, creating or changing an event, answering an invite, changing a task or note) is shown to you on an approval card first, and happens only if you tap Approve.
- To keep the service secure, for example to detect hidden instructions in incoming email and block them.
We do not sell your data, use it for advertising, build advertising profiles, or use it to train or improve AI models.
4. Google user data
If you connect a Google account, LumenMe requests access to Gmail (read, send, compose drafts, and change read status) and Google Calendar events, plus your email address.
LumenMe's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- Google user data is used only to provide and improve the user-facing features described here.
- It is not transferred to others except as needed to provide those features (see section 5), to comply with law, or as part of a merger or acquisition with notice to you.
- It is not used for advertising, and it is not used to develop, improve or train generalized AI or machine-learning models.
- People do not read it, except with your explicit permission for a specific message, when needed for security (for example investigating abuse), or to comply with law.
5. Who processes your data
To provide LumenMe we use these service providers, which process data on our behalf:
- Google Cloud hosts LumenMe (Cloud Run, Secret Manager, Firestore, Cloud Storage, Cloud Logging). It also runs the language model that understands your requests (Vertex AI Gemini) and the content screening (Model Armor). Under Google Cloud's terms, this data is not used to train Google's models.
- Telegram carries the messages between you and the assistant.
- Google and Microsoft, as the providers of the accounts you connect.
Data is processed mainly in Singapore (asia-southeast1), with content screening in the United States (us-central1). Language model requests use Google's global endpoint.
6. Storage and retention
- Sign-in tokens for your accounts are kept in Google Cloud Secret Manager until you disconnect the account. Only the service that connects to that account can read them.
- Email and calendar content is fetched when needed and is not copied into a separate database. Parts of it can appear in your recent conversation history.
- Conversation history with the assistant is stored so you can follow up, trimmed to recent messages, and deleted when you send /reset.
- Tasks, notes and people notes are kept until you or your assistant remove them, or until you ask us to delete them.
- An activity log records which actions were proposed, approved, rejected or blocked. It records tool names, not message content.
- System logs in Google Cloud Logging are kept for up to 30 days by default and are used for operations and security.
When you ask us to delete your data, we delete your tokens, stored conversation, tasks and notes within 30 days, except where we must keep something to comply with law.
7. Security
- Each part of LumenMe runs as a separate service with its own restricted permissions. The services that read your accounts are not reachable from the internet.
- Actions you approve are signed by a separate approval service using a key held in Google Cloud KMS. The services that act on your accounts refuse unsigned requests.
- Incoming email and calendar content is screened for hidden instructions before the assistant reads it.
- Data is encrypted in transit and at rest by Google Cloud.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify you without undue delay.
8. Your choices
- Disconnect an account at any time from your Google account permissions or Microsoft apps page. LumenMe loses access immediately.
- Clear your conversation by sending /reset to the assistant.
- Access, correct or delete your data by emailing us (section 11).
- Decline any action by tapping Reject, or by ignoring the approval card. Requests expire after 30 minutes.
9. Children
LumenMe is not intended for anyone under 18, and we do not knowingly collect data from children.
10. Changes to this policy
If we change this policy, we will update the effective date above. If we make material changes to how we use Google or Microsoft data, we will tell you in the assistant before they take effect.
11. Contact
BYC Ventures, operator of LumenMe. Email paul@bayanichain.io.