Privacy Policy

Last updated on 30 June 2026

Your data belongs to you. Lumini is the custodian of the prompts, files, chats, organisational settings, Private Library documents and outputs you create in Lumini. We use that data only to provide, secure, support and improve the Services for you.
We do not share it with any other customer.
We do not use it to train AI models.
We do not sell it.

In Brief

  • What we collect: your contact and account details, information about your organisation, what you type or upload into Lumini, and general usage analytics.
  • What we do with it: run the platform, support you, improve the service, and deliver the alerts and analysis you ask for.
  • Who we share it with: a small, named set of service providers who help us run Lumini. We do NOT sell your personal information.
  • Where it lives: in secure cloud infrastructure hosted in Australia (AWS, Sydney), encrypted in transit and at rest.
  • AI processing: we use OpenAI to power search and to generate answers. When you work over documents you have uploaded into your Private Library, the relevant content is sent to OpenAI under terms that prohibit training on it. We name every provider in section 7.
  • Your control: you can request access to, correction of, or deletion of your personal information at any time by contacting us.

All personal information we collect, hold, and handle is done so in accordance with the New Zealand Privacy Act 2020. This policy explains, in plain terms, what information we handle, why, who we share it with, where it is stored, how long we keep it, and the choices you have.

1. About this Privacy Policy

This policy applies when you visit our website, use Lumini ("our Services"), connect Lumini to an AI assistant through our connector, or otherwise interact with us. Lumini is operated by Lumini Works Limited, a New Zealand company.

We may update this policy by publishing a revised version on our website. The change applies from the date the revised version is uploaded. This policy may be supplemented by other terms or notices agreed between us.

2. Information we collect

We collect information about you when you use our Services, including:

  • Contact details: such as your name and email address.
  • Authentication credentials: such as usernames and securely managed login credentials.
  • Organisation information: the organisation you belong to and your role within it.
  • Your input into our tools: the prompts, search queries, documents, and files you enter or upload, and the chats you create.
  • Usage and analytics data: general, mostly non-identifiable information about how the Services are used.
  • Cookies and similar technologies: see Cookies below.

3. How we use your information

We use your information to:

  • manage your access to our Services;
  • provide support;
  • operate, maintain, and improve the Services so they better fit your needs;
  • respond to your enquiries;
  • send you the alerts, briefings, and analysis you have set up or requested;
  • notify you about changes or additions to the Services;
  • keep the Services secure and prevent misuse; and
  • comply with our legal obligations and enforce our agreements.

We may use aggregated or de-identified usage information to understand and improve Lumini. We do not use your Private Library content, prompts, chats or generated outputs to train AI models or to build profiles for other customers.

4. Information you upload

Information about others

If you upload documents or enter information that contains personal information about another person, you are responsible for ensuring you have the right to do so and that your use of Lumini is consistent with your own privacy obligations. Lumini processes that information on your behalf to provide the Services.

Official information and confidential organisational material

Lumini may be used by organisations that handle official information, confidential policy material, legal, commercial, or stakeholder information. We treat uploaded customer documents and customer-generated content as confidential customer data, whether or not it contains personal information. Customers remain responsible for deciding what material is appropriate to upload to Lumini, including any obligations they have under the Official Information Act, Local Government Official Information and Meetings Act, Public Records Act, confidentiality obligations, legal privilege, or internal information-classification policies.

5. AI Processing

Some Lumini features rely on third-party artificial-intelligence services. We are deliberate about what is sent to them, and what is sent depends on which data you are working with.

Lumini search and chat can run over the Lumini Library (publicly available government and parliamentary material, together with selected publicly available and licensed third-party sources), over your organisation's Private Library (documents your organisation has uploaded), or over both.

Search. When you search, your search query text is sent to OpenAI to generate a numerical representation (an "embedding") used to find relevant matches. OpenAI processes this query under its API terms and does NOT use it to train its models.

Working over the Lumini Library. When you generate reports, briefings, or answers from the Lumini Library, the source material is not customer-provided personal information, although public records may contain personal information about people in public roles or submitters. Lumini uses OpenAI's models for this generation.

Working over your Private Library. When you upload a document to your Private Library, its content is sent once to OpenAI's embedding API, at upload, to build your searchable index. When you then ask Lumini to search or answer questions over those documents, the relevant parts are sent to OpenAI to generate your answer. In both cases OpenAI processes the content under its API terms and does NOT use it to train its models. Your Private Library content is isolated to your organisation and is never used to answer another customer's questions.

Transcription. Lumini transcribes publicly available material in the Lumini Library, such as parliamentary and select committee hearings. Our transcription engine processes publicly available content only; your personal information and Private Library content are NOT sent to our transcription engine.

We do not use AI to make automated decisions that have a legal or similarly significant effect on you.

6. Connected AI Assistants

You can choose to connect Lumini to an AI assistant, such as Anthropic's Claude, Microsoft’s Copilot, or OpenAI's ChatGPT, using our MCP connector.

  • When you connect Lumini to an external AI assistant, Lumini only responds to authorised requests from your account. The information Lumini returns in response to your requests is shared with that assistant's provider so it can answer you. This happens only after you sign in and authorise the connection.
  • Once information is returned to the connected assistant, that assistant provider’s own privacy, security and data-retention terms apply.
  • By default the connector can draw on both the Lumini Library and your organisation's Private Library. An individual request can be scoped to one or the other. This means that, where your request uses your Private Library, your uploaded content may be returned to the connected assistant's provider. We do not retrieve your conversations, chat history, or files from the connected assistant beyond what is needed to fulfil your request.
  • We recommend using enterprise, work, government or commercial versions of AI assistants rather than personal consumer accounts.
  • You can disconnect the connector at any time.

7. Who we share your information with

We share your information only where necessary to run Lumini and deliver the Services, with the providers below. They may use your information solely to provide their service to us, and are bound by confidentiality and data-protection obligations. We do NOT sell your personal information.

Hosting and database: Supabase and Vercel (application hosting, authentication, and data storage), operating on Amazon Web Services infrastructure in Sydney, Australia.

Email delivery: Resend (transactional email, such as the alerts and notifications you have set up) and MailerLite (product updates and newsletters). We share your name and email address with these providers to send these emails. You can unsubscribe from product updates and newsletters at any time using the link in those emails or by contacting us.

AI processing: OpenAI receives your search queries (as embeddings), your Private Library content (once at upload to build your index, and again when you search or ask questions over it), and the publicly available and licensed Lumini Library material used to generate reports and briefings. See AI processing above for the details.

Connected AI assistants: where you choose to use our connector, Anthropic (Claude), Microsoft (Copilot), and/or OpenAI (ChatGPT), which receive what Lumini returns in response to your authorised request. By default this can include Private Library content; see AI processing above.

Product analytics: Google Analytics and Mixpanel, to understand how the Services are used and improve them.

Your organisation: where applicable, information may be shared with the organisation through which you access Lumini (for example, with an administrator on your account).

We may also disclose personal information where required or permitted by law, to protect our rights or the safety of others, or in connection with a sale or restructure of our business (in which case we will handle your information consistently with this policy).

8. Information about public figures and published submissions

The Lumini Library includes information drawn from public sources about people in public roles. This may include:

  • statements made by Members of Parliament, Ministers, and officials in parliamentary proceedings, select committee hearings, and other public forums;
  • posts from a bounded, defined set of official ministerial and party-leader social media accounts; and
  • submissions made to government, which we copy only after the relevant government body has published them into the public domain. Where a published submission names an individual or organisation, that information is reproduced from the public record.
  • We process this public-domain information to provide policy intelligence to our customers. If you are a public figure, or have made a submission that appears in our library, and you have a question about the information we hold, please contact us at privacy@lumini.nz.

9. Where your data is stored

Lumini is operated by a New Zealand company and is governed by the New Zealand Privacy Act 2020.

Your data is stored with our cloud infrastructure providers on Amazon Web Services infrastructure located in Sydney, Australia. Because the data is hosted in Australia, Australian law may apply to the stored data, to our hosting sub-processors, and to any lawful request for access by Australian authorities in relation to data held there. We chose an Australian region because it keeps your data within Australasia close to New Zealand, and subject to a comparable privacy framework (rather than transferring it further offshore).

Some of the AI service providers described in section 5 may process the content sent to them outside Australia, under the API terms and protections referred to above.

10. How long we keep your information

We keep personal information only as long as we need it:

  • Content you can delete: your prompts, files, and chats are kept for as long as you want them. When you delete them, they are removed from active systems.
  • Operational logs: logs we use to support customers and keep the Services secure are automatically deleted after 30 days. Some service providers may also retain the inputs we send them for a short period (up to 30 days) for abuse-monitoring purposes only.
  • Account and organisation data: retained while your account is active, and automatically deleted 90 days after your account is closed, except where we are required to keep it longer to meet legal, accounting, or security obligations.
  • When a file is deleted, the file and associated searchable index entries are removed from active systems. Backup copies may persist for a limited period before being overwritten in the normal backup cycle. We retain limited billing, security and audit records where required for legal, accounting, fraud-prevention or security purposes.

You can request deletion of your account data at any time by contacting us.

11. How we protect your information

We use practical technical and organisational safeguards to keep your personal information safe from loss, unauthorised access, and misuse, including:

  • storage with our cloud infrastructure provider in AWS, Sydney, encrypted in transit and at rest;
  • access restricted through authentication, organisation-level data isolation and database row-level security, so users can only access data belonging to their own organisation;
  • role-based access controls and logging of administrative activity; and
  • incident investigation processes that include prompt investigation of any suspected incident, with clear communication to affected customers in the unlikely event of exposure.

If we become aware of a privacy breach that has caused, or is likely to cause, serious harm, we will notify the affected individuals and the Office of the New Zealand Privacy Commissioner as required by the Privacy Act 2020. We will also take reasonable steps to contain the breach, assess its impact, and reduce the risk of recurrence.

A more detailed description of our security controls is available on request for procurement and due-diligence reviews.

12. Cookies

We use cookies, (small identifiers stored on your device) to recognise your browser, keep you signed in, and understand how the website is used (including through Google Analytics and Mixpanel). You can disable cookies in your browser settings, although some features of the website may then not work properly.

13. Your Privacy rights

Under the Privacy Act 2020, you have the right to request access to, correction of, or deletion of the personal information we hold about you. To make a request, or to be removed from our mailing list, contact our Privacy Officer at privacy@lumini.nz. We may need to verify your identity before responding to a privacy request. We will respond within a reasonable time and be consistent with timeframes required by the Privacy Act 2020. If we cannot comply with a request, we will explain why. If you are not satisfied with how we have handled your request or your personal information, you may contact the Office of the New Zealand Privacy Commissioner (privacy.org.nz).

14. Changes to this policy

We may update this policy from time to time to reflect changes in our business, our Services, the law, or best practice. When we make material changes, we will update the "Last updated" date above and, where appropriate, let you know.

15. Contact us

For any question, request, or complaint about this policy or how we handle your personal information, contact our Privacy Officer, at:

Lumini Works Limited
Email: privacy@lumini.nz
Website: lumini.nz

Contact our Privacy Officer

For any question, request, or complaint about this policy or how we handle your personal information, contact our Privacy Officer at Lumini Works Limited.

Email: privacy@lumini.nz

Website: lumini.nz