← Back to Lumen
Privacy

Your relationship is not our inventory.

Lumen is designed around user ownership. This page separates the protections available now from the stronger privacy architecture still being built.

Updated September 29, 2026

The short version

Lumen is local-first, has no advertising business, does not sell private user data, and does not use private user data for model training by default. Local-first does not mean every enabled capability is offline.

What can stay under your control today

  • Core model inference can run on owner-controlled hardware.
  • Reviewed memories and corrections can be inspected, changed, or deleted.
  • Higher-impact actions can require explicit approval.
  • Cloud capabilities can be left disabled when they are not wanted.

When information can leave the device

If the owner enables and authorizes an external capability, the minimum information needed for that request may be sent to the configured provider. Examples include model providers, web research, synchronization, email, SMS, voice, and image services.

Lumen should identify those paths plainly. A local foundation is not permission to describe an external request as local.

What Lumen may hold

  • Conversation history and user-approved memory.
  • Preferences, corrections, and relationship context.
  • Tool inputs, outputs, approvals, failures, and receipts.
  • Device and account information needed to authenticate an owner-controlled connection.

Roadmap—not yet claimed as shipped

The Identity Vault is intended to add user-held encryption keys, stronger retention and deletion controls, export, and privacy receipts that make each turn’s data path easier to inspect. These protections remain roadmap work.

Questions or deletion requests

Email lumen@talklumen.com. Until automated account controls exist, Lucas reviews external requests and approves any action Lumen prepares.