Data handling and procurement
Straight answers, including the ones that are a no.
This page is written for whoever has to assess Lumora before an organisation uses it. It covers what we hold, where it lives, who can see it, and what we have not got. The privacy policy and terms are the binding documents. Where this page and those disagree, those win.
The four answers most assessments want first
- Data residency
- Participant data is stored in the United States, not in Australia. Lumora is Australian-built and Australian-run, but it is not Australian-hosted.
- Accreditation
- None. No ISO, no IRAP, no Right Fit for Risk, and not on any government panel.
- Minimum age
- 16 and over. Lumora is not built or approved for under-16 students, and there is no verified parental consent flow.
- Encryption at rest
- Lumora adds no encryption layer of its own on top of what the database provider applies. Data in transit is encrypted with TLS.
What Lumora holds
- The resume text a user uploads or pastes, and any job ad text they choose to add.
- The analysis, scores and documents Lumora generates from those.
- An account email address and authentication record.
- Product events: page views, feature use, scores and counts. Never resume or job ad text.
- For an organisation lead: business contact details from the pilot application form.
The pilot application form deliberately asks for business contact details only. It does not ask for student names, case notes or documents, and organisations are told not to send them.
Who can see it
Can an organisation see a participant's resume or results?No.
There is no organisation-facing view of a participant's documents, diagnosis or score, and a pilot does not create a staff login that could reach one. Funding somebody's access does not create a right to read their work.
An organisation administrator can see that a place was used, when, and which feature consumed a credit. That is what a credit count is made of, and it is the limit of organisation visibility.
Row-level controlsEnforced in the database, not only in the application.
Postgres row level security is enabled on participant tables, and the policies allow a signed-in user to select their own rows only. The organisation-facing tables carry RLS with no policies at all, which means no browser session can read them under any circumstances; only server-side code holding the service role can.
Lumora staff accessOne person, for support and operations.
Lumora is a one-person business. The founder holds administrative access to the database in order to run it, investigate a support request and operate pilots. There is no support team, no offshore contractor and no third party with a login.
Subprocessors
The complete list. This is the same list as the privacy policy, and if the two ever disagree the privacy policy is the one that binds.
- Supabase
- Database, authentication and file storage. Hosted in a United States region.
- Vercel
- Application hosting and delivery.
- Anthropic
- Language model used to analyse a resume and write the improved wording.
- OpenAI
- Language model used for parts of the same work.
- Stripe
- Payment processing. Card details go to Stripe and never reach Lumora.
- Resend
- Transactional email, for example an approval or a password reset.
- Canva
- Only when a user chooses to open their resume in Canva. Receives that document.
- Analytics and advertising measurement. Event names, IP address and user agent.
- Meta
- Advertising measurement. Event names, IP address and user agent.
- ElevenLabs
- Speech for the voice interview practice, when a user starts one.
Resume text, job ad text, participant names and application content are never sent to Google or Meta. Those two receive event names, IP address and user agent only.
Payments
Payment card details are collected and stored by Stripe on Stripe-hosted pages and never reach Lumora's servers. During a pilot there is no card, no Stripe customer, no subscription object and no contract, and nothing converts automatically at the end.
Invoices and purchase orders are handled by a person, by email. Lumora does not have an automated purchase order workflow, and this page will not claim one until it does.
Retention and deletion
When a pilot ends, access pauses and unused credits are revoked. Nothing is deleted: participants keep their accounts and everything Lumora wrote for them, because that work is theirs rather than the organisation's.
Deletion is a manual process started by emailing support@lumoraapply.com. There is no self-service delete button today, and saying otherwise would be an overstatement of what exists.
What Lumora does not hold
- ISO 27001 or any other ISO certification
- An IRAP assessment
- Right Fit for Risk (RFFR) accreditation
- A place on any Commonwealth or state government panel
- SOC 2
For a free pilot with 10 students this is usually not the deciding question. For a network-wide or funded deployment it may well be the blocking one, and it is better raised now than after somebody has committed to it.
Security and privacy contact
Security issues, privacy questions, deletion requests and vendor assessments all go to support@lumoraapply.com, and reach the founder directly.
Back to the education partners page or the employment providers page.