Privacy Policy
Last updated: October 6, 2026
Lumen reads the screen you tell it to read. That is the whole product, which makes it the part of our system that matters most to explain. This policy describes what leaves your machine, what gets stored, and who can see it.
1. The short version
- Screenshots you capture stay on your machine unless you send a request, and when you send one they travel to our server only long enough to produce an answer.
- We do not sell data, we do not run advertising, and we do not build profiles of your screen activity.
- Your API key lives on our server and never in the app. Your OpenRouter key is not something you hand to us.
- You can delete your account and associated data at any time by emailing us.
2. Information we collect
Account information. If you create an account we store your email address, the display name you choose, your subscription plan, and your account creation date. If you sign in with Google we receive the email address and profile name Google returns, and nothing else unless you grant more.
Usage records. We record how many requests you make per day and roughly how many tokens those requests consumed. This is used to enforce daily limits and to understand aggregate cost. We do not store the text of your prompts or the content of your answers in these records.
Content you submit for processing. When you use Select, Screen, Solve, Code, Read, or Listen, we receive that request in order to generate a response: your instruction, and for visual modes a downscaled screenshot of the region you selected. This is the only way the feature can work.
Local session history. Conversations are stored on your device so they survive a restart. You can turn this off in Settings.
3. How screen content is handled
This is the part worth reading carefully, because screen captures can contain anything that happens to be on your display.
- Nothing is captured until you ask. There is no ambient recording, no background screenshotting, and no telemetry of what is on screen.
- A capture happens only after you trigger it, by global shortcut or by selecting a region. Read mode can also scroll and re-capture the foreground window while you hold the control, but only then.
- Captures are downscaled before upload to reduce cost and bandwidth.
- Screenshots are sent to our server, passed to the model provider for that request, and held in memory only for the duration of the call. We do not write screenshots to disk on our servers.
- If you have a subscription, your subscription plan governs the model used. Model providers process requests under their own terms; we do not use your content to train their models and have no arrangement that would allow it.
- You should avoid capturing material that is confidential or regulated unless you have the authority to do so. That is your responsibility, not ours, but we cannot process content you are not entitled to share.
4. Who can see your data
- Our processors.
- We use Supabase for authentication and database storage, Vercel for hosting, and OpenRouter as the model gateway. Each receives only what it needs to do its job.
- Model providers.
- For a request to be answered, the relevant provider processes the prompt and image. Their handling is governed by their own privacy policies.
- Nobody else.
- We do not sell, rent, or share personal information with third parties for their own benefit. We will disclose information if we are legally compelled to, and will tell you unless prohibited from doing so.
5. How long we keep things
- Screen content and prompts: not stored on our servers after the request completes.
- Usage records: retained while your account is active, for billing and limit enforcement.
- Account data: retained until you delete your account, then removed within 30 days.
- Local history on your device: retained until you delete it or disable history.
6. Security
Credentials live exclusively on the server. The desktop application contains no API key and authenticates as you through a token held in the application's main process, so there is nothing for a user of the installed app to extract. Requests between the app and our server are made over TLS.
No system is perfect. If a security breach affects your data we will notify you and any relevant authority as required by law, without undue delay.
7. Your rights
Depending on where you live you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can exercise most of these by emailing us rather than through a formal process.
If you are in the EEA or UK and are unhappy with how we have handled your data, you also have the right to complain to your local data protection authority.
8. Children
Lumen is not directed at children under 13 and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.
9. International transfers
Our processors operate globally, so data may be transferred outside your country. Where that happens we rely on standard contractual clauses or an equivalent safeguard.
10. Changes to this policy
We may update this policy as the product changes. The date at the top always reflects the current version. For material changes affecting how we use your data we will notify you through the product or by email before the change takes effect.
11. Contact
Questions, requests, or concerns about this policy can go to privacy@lumenoverlay.com. If you are in the EEA or UK, you may also reach us at the postal address provided in our Terms of Service.