1. Who we are
Lumi Support (“Lumi”, “we”, “us”) is run by CodeBridger LTD, a private limited company registered in England and Wales, company number 17152834. Registered office: 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom.
Contact for anything in this policy: info@codebridger.co.uk.
This policy covers:
- our websites:
lumi-support.com,app.lumi-support.com(the dashboard) andwidget.lumi-support.com(the chat widget and hosted chat pages); - the people who sign up and use the dashboard (our customers and their teammates);
- the people who chat with a customer’s Lumi widget or send one of its contact forms (visitors).
2. Two roles: when we are the controller, and when we are the processor
| Whose data | Our role | What that means |
|---|---|---|
| Customers and teammates (account, billing, team, support emails to us) | Controller | We decide why and how this data is used. This policy applies in full. |
| People who browse lumi-support.com | Controller | As above. |
| Visitors who chat with a customer’s widget or send one of its contact forms (their messages, any name or email they give, and any files they attach to a form) | Processor for our customer | The business whose website you chatted on, or whose form you sent, is the controller. It decides what its agent and its forms ask for, what it keeps, and who on its team reads it. We process these messages only to provide Lumi to that business. If you chatted with a business’s Lumi widget or sent its form, contact that business first; we will help them answer you. |
| Anonymous usage counts from widgets (§5.4) | Controller | We use them to run and improve Lumi. They contain no names, emails or message text. |
We do not yet offer a separate data processing agreement (DPA). Our terms of service (§5) describe how we process visitor data for our customers. If your business needs a DPA, email us.
3. Data about customers and teammates
| Data | Where it comes from | Why we use it | Legal basis (UK GDPR Art. 6) |
|---|---|---|---|
| Name, email address, profile picture and Google account id | Google sign-in (Lumi has no other way to sign in) | To create and secure your account | Contract |
| Workspace and agent settings: agent names, instructions (system prompt), chosen AI model, widget look, greeting | You, in the dashboard | To run your agents | Contract |
| Knowledge text you paste in, and the search index built from it | You | To answer your visitors. To build the index, the text goes through Vercel AI Gateway to a Google embedding model when you save it (§6). | Contract |
| MCP server addresses, and the tokens or OAuth credentials for them | You | To let your agent call the tools you chose | Contract |
| Teammate invitations: the invitee’s email, their access rights, starter message | You | To add people to your agent | Contract (for you); legitimate interests (for the invitee) |
| Online/Away status and notification choices | You and your teammates | To route handoffs and send alerts | Contract |
| Browser push tokens, with the browser’s user-agent text | Your browser, only if you turn push on | To send you handoff alerts | Contract |
| Billing records: Stripe customer and subscription ids, plan status, seats, credit balances and usage | Stripe and our metering | To bill you and show your balance | Contract; legal obligation (tax records) |
| Emails you send us and our replies | You | To support you | Legitimate interests |
Payment details. Card and bank details go to Stripe, not to us. We never see full card numbers.
4. Data about people who browse our websites
4.1 Analytics (Google Analytics 4)
We use Google Analytics on lumi-support.com and app.lumi-support.com to understand which pages and features are used.
- In the UK, the EEA and Switzerland, analytics stays off until you click Accept on the banner. Elsewhere it is on by default, and you can decline. A Global Privacy Control signal from your browser counts as a no.
- Advertising storage is denied everywhere. Google’s optional data sharing is off.
- We send page views by hand, with the page pattern only (for example
/agents/:id/embed), never the full address. Only campaign parameters (UTM tags and click ids) are kept from a link. - The events we send: button clicks on the site, sign-up and log-in, creating an agent, copying the embed code, and starting, finishing or cancelling a checkout.
- Your answer is saved in a first-party cookie,
lumi_analytics_consent, for six months. If you decline, we also delete Google Analytics cookies (_ga*).
Legal basis: consent where the banner asks for it; legitimate interests elsewhere.
4.2 Sign-in
When you sign in to the dashboard, Firebase Authentication keeps your session in your browser’s storage. It is needed for the dashboard to work.
5. Data about visitors to our customers’ widgets (we are the processor)
5.1 What the widget collects
| Data | When |
|---|---|
| The messages you send, and the replies from the AI and from the business’s team | Every chat |
| The address of the page you opened the chat on (without the query string) | When the chat starts |
| An anonymous visitor id (a random Firebase id) | When you first open the chat |
| Your name and email | Only if you type them into a form (before the chat, in the chat, when nobody is online, or when the business cannot reply), or if the business’s website passes them to the widget (data-user) |
| Tool calls the agent makes during your chat, with their inputs and results | Only if the business connected tools. These are shown to the business, never to you. |
| Which parts of the business’s knowledge an answer used | Every AI answer. Shown to the business, never to you. |
5.2 Nothing is stored on your device until you open the chat
The widget’s script shows only a button. The chat itself loads only when you click it. Before that click, the widget stores nothing on your device and sets no cookies.
After you open the chat, the widget stores on your device, under widget.lumi-support.com:
- an anonymous sign-in session (so you can continue your chat);
- the id of your current conversation, and your contact id if you gave an email.
These are needed for the chat you asked for to work.
5.3 How the AI answers
To write a reply, we send the AI model:
- the business’s instructions for its agent;
- the most relevant parts of the business’s knowledge;
- up to the last 10 messages of your conversation, and your new message;
- the results of any tools the agent called.
To find the relevant knowledge, your message is also turned into a search vector by a Google embedding model.
These requests go through Vercel AI Gateway to the provider of the model the business chose (§6). Vercel’s documentation says AI Gateway deletes prompts and responses once each request completes.
We do not use chats to train AI models ourselves.
5.4 Usage counts we keep for ourselves
Our servers send Google Analytics a count of widget events: the widget loaded, a chat started, a message was sent, a handoff was requested, a lead was captured, a follow-up email was sent. Each event carries the agent’s id, the hostname of the site (for example example.com), and a one-way hash of the anonymous visitor id. It never carries a name, an email, a message, a page path or a conversation id. No Google tag runs inside the widget. An owner’s preview chats are not counted.
5.5 Emails to visitors
If you give an email, the business’s team can reply to you by email. When they do, we send you an email with a link back to the conversation. The link works for 7 days. If the business has turned on outreach, its team can also send you a message later, by email, with a link back to the chat on its website.
These emails, and replies to a contact form (§5.6), carry the business’s name and look: the sender name, logo, colour and footer it chose. They are sent from Lumi’s own sending address.
5.6 Contact forms
[Draft for legal review, added on 1 October 2026: this section, and the contact-form rows in §2, §6 and §8, are not reviewed yet.]
A business can put a Lumi contact form on its website, or share it as a link. When you send one, we keep:
- the fields the business chose to ask for. There is always an email address; often a name and a message; it can add others, such as a list to choose from or a checkbox;
- any files you attach, if the business allows files: up to 5 files, 10 MB in total;
- the address of the page you sent the form from, and the time.
The form page loads with the page it is on, but it signs nobody in and stores nothing on your device. The AI agent does not read or answer form messages.
Where it goes. Your message is stored for the business in our database, and your files in Google Cloud Storage (§6). The business’s team is alerted by email, in the dashboard and by browser push; the alert shows your name (if you gave one), your email address and the start of your message. Your name and email are also added to the business’s contacts in Lumi, unless the business has no active plan or trial at that moment (then the message is kept locked, and the alert shows none of it).
Replies. The team can answer you by email from Lumi. We send the reply to the email address you gave, with your message quoted. If you answer that email, your answer goes to the reply-to address the business set. If it set none, your answer reaches us, at info@codebridger.co.uk.
Abuse limits. To stop a form being flooded, we count the messages sent to it from each IP address. We store only a one-way hash of the address together with the business’s agent id, never the address itself.
6. Who we share data with (sub-processors)
We use these companies to run Lumi. Each gets only what it needs for its job.
| Company | What it does for us | Data it handles | Where |
|---|---|---|---|
| Google Cloud / Firebase (Google LLC) | Database (Firestore), servers (Cloud Functions), hosting, sign-in (Firebase Authentication), push alerts (Firebase Cloud Messaging), secret storage, file storage for contact-form attachments (Cloud Storage) | All the data in this policy | United States (us-central1) |
| Vercel (Vercel Inc.) | AI Gateway: routes each AI request to the model provider | Prompts and replies (§5.3), and the knowledge text you index (§3), for the length of each request | See Vercel’s privacy policy |
| Model providers: Google (Gemini models, and the embedding model for knowledge search); OpenAI (GPT models); Anthropic (Claude models); other providers in Vercel AI Gateway’s catalogue | Generate replies and search vectors. Google is used by default; the others only if the business picks one of their models. | Prompts and replies (§5.3); for Google’s embedding model, also the knowledge text you index (§3) | Depends on the provider |
| Stripe | Payments, invoices and tax, as the merchant of record (Stripe Managed Payments; see below) | Your billing details, your account email and our account id | See Stripe’s privacy policy |
| Resend (Resend, Inc.) | Sends our emails: handoff and contact-form alerts, invitations, trial notices, follow-ups to visitors, replies to contact forms | Recipient email addresses and the email content | See Resend’s privacy policy |
| Google Analytics (Google LLC) | Website analytics (with consent) and widget usage counts | §4.1 and §5.4 | United States |
Stripe sells to you as the merchant of record. When you pay for Lumi, Stripe (through Stripe Managed Payments) is the seller of record for that payment: it takes the payment, charges the tax and issues the invoice. For that sale, Stripe also decides for itself how it uses your payment and billing details, for example to meet its own legal and tax duties, under its own privacy policy. It does not act only on our instructions. We receive the billing records listed in §3.
Tools our customers connect. When a business connects its own MCP server (for example its bug tracker), the agent sends that server the tool inputs the AI writes, which can include what a visitor said. That server belongs to the business, not to us, and the business decides what it receives.
We do not sell personal data. We do not share it for advertising.
We may disclose data if the law requires it, or to protect our rights, our users or the public.
7. International transfers
Our database and servers are in the United States (Google Cloud region us-central1). Some of our sub-processors are also in the United States. So your data leaves the UK and the EEA.
[To confirm before this page is published: the legal safeguard used for each transfer, for example the UK Extension to the EU–US Data Privacy Framework, or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.]
8. How long we keep data
We have not built automatic deletion by age. Today:
| Data | How long |
|---|---|
| Your account, agents, knowledge and settings | Until you delete them, or ask us to (§9) |
| Conversations of an agent: the messages, and the tool calls made in them | Until the business deletes that agent or uses “reset” on it, or asks us to delete them |
| Contacts and leads of an agent: the names and emails visitors gave | Until the business deletes that agent, or asks us to delete them. “Reset” does not delete them. |
| Contact-form messages of an agent, and the team’s replies to them | Until the business deletes that agent, or asks us to delete them. Deleting a form, or using “reset”, keeps its messages; there is no way to delete a single message in the dashboard. |
| Files attached to contact-form messages (Google Cloud Storage) | Until the business asks us to delete them. Deleting the agent does not delete them yet; ask us, and we delete them by hand. |
| Contact-form abuse counts (a one-way hash of an IP address and an agent id) | Marked to expire when their ten-minute window ends. Until automatic deletion is switched on for them, they can stay longer. |
| Anonymous sign-in accounts of chat visitors (Firebase Authentication): a random id, and when it was created and last used | Not deleted today; we have not built a clean-up for them. They hold no name, email or message. |
| Records of the emails we send | Marked to expire one month after sending. Until automatic deletion is switched on for them, they can stay longer. |
| Server logs (Google Cloud) | Google Cloud Logging’s default period, 30 days. Our logs avoid message text. |
| Billing and tax records | As long as tax law requires (in the UK, generally six years), held by us and by Stripe |
| Analytics | The data-retention period set in our Google Analytics property (Google’s default for event data is 2 months) |
Deleting an agent permanently deletes everything stored under it in our database: its knowledge, conversations, contacts, leads, contact forms and form messages. The files attached to those messages are the exception (see above). “Reset” deletes its knowledge and conversations, and keeps its contacts, leads and form messages.
There is no self-serve data export or account deletion in the dashboard yet. Email us, and we will do it by hand (§9).
9. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- correct it;
- delete it;
- restrict or object to how we use it;
- receive it in a portable form;
- withdraw consent at any time, where we rely on consent. For analytics: choose Cookie settings at the bottom of any page on lumi-support.com and click Decline; the change applies straight away, and the dashboard uses the same answer.
To use any of these rights, email info@codebridger.co.uk. We reply within one month. We may ask you to prove who you are.
If you chatted with a business’s widget, that business controls your chat. Ask it first. If you write to us instead, we will pass your request to the business and help it respond.
You can also complain to the UK Information Commissioner’s Office (ICO): ico.org.uk, or 0303 123 1113. We would like the chance to fix things first.
10. Security
- All connections use HTTPS.
- Access rules in our database keep each workspace’s data to its own members.
- Tokens for connected tools are kept in a store only our servers can read; they are never sent to a browser.
- Tool servers on private networks and cloud-metadata addresses are blocked.
- Card details are handled by Stripe.
We do not hold a security certification such as SOC 2 or ISO 27001.
11. Children
Lumi is a service for businesses. It is not meant for children, and we do not knowingly collect children’s data. Businesses must not use Lumi on services aimed at children.
12. Automated decisions
Lumi’s replies are written by AI. Lumi does not make decisions about you that have legal or similarly significant effects.
13. Changes to this policy
We will post any change on this page and update the date at the top. If a change is significant, we will also email customers.
14. Contact
CodeBridger LTD · 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom · info@codebridger.co.uk