Privacy & Security Statement.
Effective: 11 July 2026
The entity responsible for the personal information described here is Lumina Ventures Pty Ltd (ABN 47 690 766 459) of Brisbane, QLD, trading as Lunar8Ops. Privacy questions, access and correction requests, and complaints go to admin@luminaventures.com.au, whether or not you are a customer.
1. We never train AI models on your data
Your uploads, your Digital Twin and your generated outputs are never used to train, fine-tune, or improve any AI model, ours or anyone else's. We use AI providers (Anthropic, and, if you select them, OpenAI and Google) exclusively through their commercial APIs, under terms that contractually prohibit training on content submitted through the API. If you select a provider whose terms we cannot back with this guarantee, we require you to use your own API key and tell you so in the product.
2. Three kinds of data, and how long each one lives
Lunar8Ops handles your content in three deliberately different ways, and it is worth understanding the difference:
- Voice-training uploads (the writing you upload to build or update your Twin) are ephemeral. The raw file exists only long enough to be distilled into your Twin (typically minutes, never more than 24 hours), then it is automatically and irreversibly deleted. Deletion is enforced by our infrastructure at the end of every processing job (including failed jobs), with a scheduled sweep as a backstop. What remains is your Twin: a structured profile of how you think and write, not a copy of your source documents.
- Knowledge base content (documents you deliberately add as reference material, SOPs, or facts your Twin should look up) is retained, by design and with your consent, so it can be searched and cited when you generate. This is the intentional opposite of the ephemeral path above. The original uploaded file is still deleted immediately after processing; the extracted text chunks are the retained copy. You can view and delete any knowledge source at any time from the Knowledge page, which removes its stored content permanently.
- Data tables (structured business records you add, such as price lists, rate cards, catalogs) are retained like knowledge, for the same reason: your Twin quotes them exactly when you generate. They are commercially sensitive by nature, so note: rows relevant to a request are sent to your AI provider as part of that generation (see section 5), they are editable and deletable cell-by-cell or table-by-table from the Data page, and they are never used to train any model. The original uploaded file (PDF, spreadsheet) is deleted after the table is extracted; the table is the retained copy.
- Outbound action drafts and approvals (emails and calendar events your Twin drafts for a connected Google account, per section 10) are retained indefinitely as your record of what was proposed and what was actually sent or created. This is a permanent audit trail, not subject to automatic deletion, and it is not redacted the way automatically-ingested content is (see below), because it is content youchose to send. It can include personal information of people other than you (a recipient's email address, meeting attendees, or names and details you or your Twin included in the message), and by approving a send or calendar event you confirm you are authorised to disclose that information to those recipients. You can review this history at any time in Approvals, and it is deleted with your account.
Two smaller categories, for completeness: voice interview answers (the optional questionnaire) are retained so you can review and edit them at any time: they are folded into your Twin and deleted with your account; and automatically ingested content from connected accounts follows section 10 (relevance-filtered, PII-redacted before storage, deletable per connection).
We do not log the content of your uploads, chats, or generated outputs. For voice uploads we retain only filenames, cryptographic checksums, sizes and timestamps as a processing record.
We do keep a record of each job: which of your documents your Twin looked at, which version of your Twin wrote it, how long it took and what it cost. That record holds references and checksums, not the text. You can see it yourself for any job you run.
One exception, and it is off by default. If something your Twin writes comes out wrong and you want us to look into it, you can turn on troubleshooting in Settings. While it is on, the text you send your Twin is stored encrypted for up to 72 hours and then deleted automatically. Turning it off deletes it straight away, it switches itself off after three days, and it is never used to train any model. Separately, you can keep a job you were happy with as a quality check, so we can confirm your Twin still handles it properly after you teach it something. That one is per-job, it is your choice, and you can remove it in Settings whenever you like.
3. Your Twin lives in a vault only you can open
Your Twin and your knowledge base are stored as isolated records protected by database-level row security: our own application code cannot read one customer's data while serving another. You can export your Twin as JSON, or permanently delete your account and everything in it, instantly, from Settings.
4. Bring your own key: inference under your agreement
If you supply your own AI provider API key, your Twin's requests go directly to that provider under your agreement with them. We store your key encrypted with AES-256-GCM, never display it again after entry, and use it solely to perform generations you initiate.
5. Where your data is processed (overseas disclosure)
Lunar8Ops is operated from Australia, and we host our database and file storage in an Australian region. However, when you generate, chat, or build your Twin, the specific content needed for that request is sent to our AI processing providers: principally Anthropic, and OpenAI or Google if you select them, whose inference infrastructure is located outside Australia, primarily in the United States. By using the Service you consent to this overseas disclosure of your content for the sole purpose of producing the output you request. We disclose only what a request requires, under commercial API terms that prohibit training, and never sell or share your content for advertising or any unrelated purpose. If your organisation requires all processing to remain onshore, contact us before uploading regulated or client-confidential material.
What consenting to this means, stated plainly because the law requires us to state it. Where you consent to your content being disclosed to a processor outside Australia, Australian Privacy Principle 8.1 does not apply to that disclosure. In practice that means: if that overseas provider mishandles the information in a way that would breach the Australian Privacy Principles, we are not accountable for it under the Privacy Act, and you cannot seek a remedy for it under the Privacy Act. Your rights against us under our terms, the Australian Consumer Law and your contract are unaffected. We choose providers on commercial terms that prohibit training on your content and we tell you which countries are involved (currently the United States; and China if you select Moonshot or DeepSeek with your own key), but we cannot give you a Privacy Act remedy against a company we do not control. If that is not acceptable for the material you are handling, use your own API key or ask us about onshore-only processing before you upload it.
6. Your rights under Australian privacy law
We handle personal information in line with the Australian Privacy Principles (APPs). You may request access to, or correction of, the personal information we hold about you; export your Twin and knowledge base in machine-readable form at any time; and delete your account and all associated data immediately from Settings, with residual backups purged within 30 days. If you have a privacy concern we cannot resolve, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
7. Minimal collection
We collect your account email, subscription status (via Stripe, we never see card numbers), and anonymous usage counts (token totals, not content). We use only essential cookies for authentication: no advertising trackers, no third-party analytics scripts, no tracking pixels in our emails. The full list of services that process data on our behalf is in section 12.
8. A draft tool, with you in the loop
Lunar8Ops produces drafts for you to review, edit, and send. It does not make automated decisions with legal or similarly significant effects about you or anyone else, and it never sends, books, orders, or otherwise acts on your behalf without your explicit approval: every outbound action is drafted and held in an approval queue until a human releases it. You remain the author and decision-maker for every output. The full record of what was proposed and decided is retained as an audit trail. See section 2.
For completeness, routine service administration is automated: enforcing plan usage limits, screening sign-ups against disposable-email abuse, and sending you billing and lifecycle notifications. These are ordinary operational safeguards, not decisions made by profiling your content.
9. Teams and shared workspaces
If you join or create an organization, content you explicitly share with that organization (knowledge sources, data tables, skills) becomes visible to its members under that organization's administrators. Your personal Twin, and anything you do not share, remain private to you. Organization administrators can see an audit log of actions taken within the organization (who ran what, and what grounded it) for security and accountability. Removing yourself from an organization, or deleting it, reverts shared content to the uploader's personal space rather than destroying it.
10. Connected accounts (Gmail, Outlook, Google Drive, OneDrive)
Connecting an email or file account for ingestion (keeping your twin's knowledge current) is opt-in and uses read-only access. This connection can never send, modify, or delete anything in the connected account. When you connect one, we collect: encrypted access tokens (AES-256-GCM, revoked and deleted on disconnect), a decision record for every item scanned (title, source date, relevance verdict, visible to you in the decision log), and the content of items judged relevant, which is stored in your private knowledge base after personal identifiers are automatically redacted (email addresses, phone numbers, card and account numbers, TFNs, Medicare numbers are replaced with placeholders before storage; a redaction audit trail is kept). Items judged irrelevant are not stored; their content is processed transiently and discarded.
Separately, you may connect a Google account for actions: sending email or creating calendar events on your behalf. This is a distinct, separately consented connection (its own OAuth grant, its own encrypted tokens) that can send or create, but every send and every new event is queued for your approval and only actually reaches Google after you review it and click Approve. Nothing fires automatically, and this connection never reads or scans your mailbox or calendar beyond what you ask it to look up. Disconnecting revokes and deletes these tokens immediately, same as the read-only path.
Per-item AI processing on this path — deciding whether an item is relevant, pulling the useful content out of it, and learning how you write — runs on the model API key you supply, under your agreement with that provider. Without a key of your own, none of those run and nothing is indexed. See section 5. Indexing runs on our account, not yours. To make a kept item findable we turn its text into a numerical index (an embedding), and that step uses our own OpenAI account, which processes outside Australia. It is listed as a subprocessor in section 12 for that reason. Your mailbox naturally contains information about other people; the redaction step exists to minimise what of theirs is retained, and by connecting an account you confirm you are authorised to grant that access. Disconnect any time in Train → Connected sources: tokens are deleted immediately (and revoked with Google), and you choose whether imported material is kept or purged.
Lunar8Ops's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Google user data is used only to provide the connected-ingestion feature you requested, is never used for advertising, and is never transferred except as necessary to provide the feature (to your own chosen AI model provider, and to the indexing provider named above and in section 12), for security, or to comply with law. Data received from Microsoft services is handled to the same standard.
11. Emails we send
We send service emails required to operate your account: billing, security, approvals you requested. Reminder emails (like a nudge to finish your voice interview) are optional and sent in line with the Spam Act 2003 (Cth): every one identifies us as the sender and carries a one-click unsubscribe that works without logging in and takes effect immediately. You can also manage reminder emails in Settings → Account & privacy. We use no tracking pixels.
12. Subprocessors & DPA
Our current subprocessors (the services that process personal information on our behalf) are: Vercel (application hosting), Supabase (database and file storage, Australian region), Stripe (payments), Resend (transactional and inbound email), and Anthropic (AI inference), plus OpenAI and/or Google only where you select those models or where OpenAI embeddings index your knowledge base. Anthropic is the only AI provider we send content to on our own account; every other provider is reachable only with an API key you supply. Providers you connect with your own API key or your own MCP servers are governed by your agreement with them, not ours. Businesses that require a signed Data Processing Agreement can request one via the address below before uploading regulated or client-confidential material.
13. Industry benchmarks: off unless you turn it on
We would like to be able to tell you whether your payment terms and insurance limits are in step with other contractors your size. Doing that means combining numbers from many businesses, so it is off by default and nothing is contributed unless you switch it on in Settings. Turning it off again stops all future contribution.
If you do switch it on, three kinds of number can be included, and nothing else: payment terms expressed in days, insurance and cover limits, and prequalification thresholds. Specifically not included: your rates, your margins, your prices, any excerpt of any document, your project names, your clients, or the identity of anyone you contract with. We never name a head contractor, a principal or a client, and we never publish anything that identifies you.
Anything published is a range or a median across a minimum of eight contributing businesses, with no single business making up more than a quarter of it, and never fresher than six months old. Contributors can see the benchmark; businesses that have not contributed cannot. We do not sell it.
The honest limit: if you turn this on and later turn it off, a figure that has already been blended into a published range cannot be pulled back out of it. Everything after that point stops. We mention this because most companies do not.
14. Contact
Privacy questions, DPA requests, or data-access/deletion requests: reply to any email from us or use the support address in your account.