Privacy policy
What we store, where it lives, and what we will never do with it. Written to be read, not to be survived.
01The short version
This policy explains what Lumural (lumural.com) does with your personal data.
- We store your account and your boards, because that is what the Service is for.
- Everything is hosted in the EU: Finland, Germany and France. No US providers.
- No advertising, no marketing trackers, no third-party analytics. Only strictly necessary cookies.
- We do not read your boards, sell your data, or use it to train models.
- Delete your account and your data is gone from live systems within 30 days and from backups within 60.
02Who we are
CA Systems, based in Sweden, operates Lumural and is the data controller for the Service. Contact: support@lumural.com. Organisation number and postal address are available on request.
If you use a Team workspace on behalf of an organisation, that organisation is the controller for personal data inside the workspace, and we process it on their behalf under our Data Processing Agreement.
03What we collect, and why
- Account
- Your email address, password (hashed, never stored in plain text), display name and profile details you choose to add. We need these to run your account. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Content
- Boards, slides, images you upload, version history and anything else you create. We store it so you can use it. We do not inspect it except to serve it, generate previews, respond to a report, or investigate abuse. Legal basis: performance of a contract.
- Published
- When you publish a board, it becomes public along with your display name and the board's process history. Anyone on the internet can see it, fork it, and search engines may index it. Your public profile page lists your published boards. Templates we publish ourselves carry no user data.
- Sharing
- When you invite someone to a board or a workspace, we store their email address and send them an invitation from you. Unaccepted invitations are deleted after 30 days. Board owners can see who has access to their board. Workspace owners can see who is in the workspace and what has been created there.
- We email you for things like sign-in links, invitations, password resets and billing. We do not send marketing email. Legal basis: performance of a contract.
- Payments
- If a workspace is on a paid plan, [PAYMENT PROVIDER] handles payment. We never see or store card numbers. We keep billing records for as long as accounting law requires. Legal basis: performance of a contract; legal obligation.
- Analytics
- We run our own instance of Umami on our own server in Germany. It records page views and feature events without cookies. IP addresses are used only to derive a short-lived, salted visitor hash and are not stored. We use this to understand which features get used and to spot abuse. Legal basis: legitimate interest (Art. 6(1)(f)).
- Logs
- Our servers and our self-hosted error monitoring (GlitchTip) record request logs and error reports. These can include your IP address, browser details and account ID. We use them to keep the Service running and secure. Logs are kept for at most 30 days. Legal basis: legitimate interest.
- Support
- If you email us, we keep the conversation to handle your request and for a reasonable time after.
04Cookies
We use only strictly necessary cookies: a session cookie that keeps you signed in, and a security token that protects forms. No consent banner is needed for these and we set nothing else. Umami does not use cookies.
05Where your data lives
- Database
- Application servers and the database. Hetzner, Finland and Germany.
- Assets
- Uploaded assets and board images. Scaleway, France.
- Transactional email. Scaleway, France.
- Backups
- Encrypted backups. Scaleway, France.
- Telemetry
- Analytics and error monitoring, self-hosted. Hetzner, Germany.
All providers are EU companies operating EU data centres. We do not transfer personal data outside the EU/EEA. The full list is at /legal/subprocessors.
06Who we share data with
Only the providers above, who process data under our instructions, and public authorities when the law requires it. We do not sell personal data or share it with advertisers.
Content you publish is, by definition, shared with everyone.
07How long we keep data
- Account
- Account and content stay for as long as your account exists. After deletion, removed from live systems within 30 days and from backups within 60 days.
- Forks
- Published boards that others have forked: the forks remain, attributed to your display name at the time of forking where the licence requires it.
- Invitations
- 30 days if not accepted.
- Logs
- Up to 30 days.
- Billing
- As long as Swedish accounting law requires (currently seven years).
08Your rights
Under GDPR you can ask us to access, correct, delete or restrict your personal data, object to processing based on legitimate interest, and receive your account data in a portable format. You can delete your account, and export boards to PDF or PNG, from settings. For anything else, email support@lumural.com. We answer within a month.
You can also complain to the Swedish Authority for Privacy Protection (IMY, imy.se) or your local supervisory authority.
09Security
Data is encrypted in transit (TLS) and at rest. Passwords are hashed. Access to production systems is limited to the operator and protected by key-based authentication. Backups are encrypted and stored in a separate provider from the live system.
No system is perfectly secure. If a breach affects your data we will tell you and the supervisory authority as the law requires.
10Children
Lumural is not for anyone under 16. If we learn we hold data about a child under 16 we will delete it.
11Changes
We may update this policy. Material changes are announced by email or in the Service before they take effect.