LearnLumina Logo
    InsightLumina

    Privacy Policy

    InsightLumina — AI Analytics Agent for E-Commerce · Last updated: January 2025

    1. Overview

    This Privacy Policy describes how InsightLumina (operated by LearnLumina) collects, uses, stores, and protects information when you use our AI analytics service. We are committed to transparency and data minimization — we only collect what we need to deliver insights, and we never sell, share, or use your data to train AI models.

    2. Information We Collect

    Account Information

    When you create an account, we collect your email address, name, and payment information (processed securely through Stripe — we never store credit card numbers).

    Business Metrics (Aggregated)

    When you connect platforms like Shopify, Google Analytics, or Meta Ads, we sync and store aggregated business metrics only — revenue trends, conversion rates, product performance statistics, traffic breakdowns, and similar summary data.

    What We Do NOT Collect

    • • Individual customer names, emails, or phone numbers from your store
    • • Individual order details or transaction logs
    • • Payment or credit card information from your customers
    • • Shipping addresses or personal identifiers
    • • Any raw PII from your connected platforms

    Connection Credentials

    We store OAuth tokens and API credentials needed to connect to your platforms. These are encrypted at rest using separate key material and are used solely to sync your business metrics.

    3. How We Use Your Information

    • • To deliver insights: We analyze your aggregated metrics using AI to generate actionable business insights and recommendations.
    • • To send reports: We deliver insight digests via email, Slack, or your dashboard based on your preferences.
    • • To improve the service: We may use anonymized, aggregated usage patterns (not your business data) to improve InsightLumina's analysis quality.
    • • To process payments: We use Stripe to handle subscription billing securely.

    4. AI & Data Processing

    InsightLumina sends only aggregated, anonymized statistics to AI models for analysis. The AI never receives raw data, customer PII, or individual transaction details.

    Our LLM vendor's API terms prohibit training on data submitted through their API. Your business metrics are not used to train, fine-tune, or improve any AI model.

    5. Data Storage & Security

    • • All data is encrypted at rest (AES-256) and in transit (TLS 1.2+)
    • • Each customer has an isolated data partition — no commingling
    • • OAuth tokens are encrypted with separate key material
    • • We conduct regular security reviews and dependency audits

    6. Data Retention

    Data retention is configurable based on your plan: 30 days (Starter), 60 days (Growth), or 90 days / custom (Enterprise). Data that reaches the end of its retention period is automatically and permanently deleted. You can change your retention setting at any time from your dashboard.

    7. Data Deletion

    You can request full deletion of all your data at any time from your account dashboard. Upon request, we permanently delete all aggregated metrics, connection credentials, generated insights, and reports. Backups are purged within 48 hours. No data is retained after deletion.

    8. Third-Party Services

    We use the following third-party services to operate InsightLumina:

    • • Stripe — Payment processing
    • • AI/LLM Provider — Insight generation (receives only aggregated statistics)
    • • Email/Slack — Insight delivery

    We do not sell or share your data with any other third parties.

    9. Your Rights

    Depending on your jurisdiction, you may have the following rights:

    • • Access: Request a copy of the data we hold about you
    • • Correction: Request correction of inaccurate data
    • • Deletion: Request deletion of all your data (one-click from dashboard)
    • • Portability: Request your data in a machine-readable format
    • • Objection: Object to specific processing of your data

    To exercise any of these rights, use the controls in your dashboard or contact us.

    10. GDPR & CCPA

    InsightLumina is designed to be GDPR and CCPA compliant by design. We practice data minimization (only aggregated metrics, no raw PII), offer configurable retention controls, support full deletion rights, and provide a Data Processing Agreement (DPA) for Enterprise customers.

    11. Changes to This Policy

    We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before they take effect.

    12. Contact

    For privacy-related questions, contact us at our support page.

    InsightLumina
    Terms of ServicePrivacy PolicyData Processing AgreementSecurity