Data handling and procurement

Straight answers, including the ones that are a no.

This page is written for whoever has to assess Lumora before an organisation uses it. It covers what we hold, where it lives, who can see it, and what we have not got. The privacy policy and terms are the binding documents. Where this page and those disagree, those win.

The four answers most assessments want first

Data residency
Participant data is stored in the United States, not in Australia. Lumora is Australian-built and Australian-run, but it is not Australian-hosted.
Accreditation
None. No ISO, no IRAP, no Right Fit for Risk, and not on any government panel.
Minimum age
16 and over. Lumora is not built or approved for under-16 students, and there is no verified parental consent flow.
Encryption at rest
Lumora adds no encryption layer of its own on top of what the database provider applies. Data in transit is encrypted with TLS.

What Lumora holds

  • The resume text a user uploads or pastes, and any job ad text they choose to add.
  • The analysis, scores and documents Lumora generates from those.
  • An account email address and authentication record.
  • Product events: page views, feature use, scores and counts. Never resume or job ad text.
  • For an organisation lead: business contact details from the pilot application form.

The pilot application form deliberately asks for business contact details only. It does not ask for student names, case notes or documents, and organisations are told not to send them.

Who can see it

Can an organisation see a participant's resume or results?No.

There is no organisation-facing view of a participant's documents, diagnosis or score, and a pilot does not create a staff login that could reach one. Funding somebody's access does not create a right to read their work.

An organisation administrator can see that a place was used, when, and which feature consumed a credit. That is what a credit count is made of, and it is the limit of organisation visibility.

Row-level controlsEnforced in the database, not only in the application.

Postgres row level security is enabled on participant tables, and the policies allow a signed-in user to select their own rows only. The organisation-facing tables carry RLS with no policies at all, which means no browser session can read them under any circumstances; only server-side code holding the service role can.

Lumora staff accessOne person, for support and operations.

Lumora is a one-person business. The founder holds administrative access to the database in order to run it, investigate a support request and operate pilots. There is no support team, no offshore contractor and no third party with a login.

Subprocessors

The complete list. This is the same list as the privacy policy, and if the two ever disagree the privacy policy is the one that binds.

Supabase
Database, authentication and file storage. Hosted in a United States region.
Vercel
Application hosting and delivery.
Anthropic
Language model used to analyse a resume and write the improved wording.
OpenAI
Language model used for parts of the same work.
Stripe
Payment processing. Card details go to Stripe and never reach Lumora.
Resend
Transactional email, for example an approval or a password reset.
Canva
Only when a user chooses to open their resume in Canva. Receives that document.
Google
Analytics and advertising measurement. Event names, IP address and user agent.
Meta
Advertising measurement. Event names, IP address and user agent.
ElevenLabs
Speech for the voice interview practice, when a user starts one.

Resume text, job ad text, participant names and application content are never sent to Google or Meta. Those two receive event names, IP address and user agent only.

Payments

Payment card details are collected and stored by Stripe on Stripe-hosted pages and never reach Lumora's servers. During a pilot there is no card, no Stripe customer, no subscription object and no contract, and nothing converts automatically at the end.

Invoices and purchase orders are handled by a person, by email. Lumora does not have an automated purchase order workflow, and this page will not claim one until it does.

Retention and deletion

When a pilot ends, access pauses and unused credits are revoked. Nothing is deleted: participants keep their accounts and everything Lumora wrote for them, because that work is theirs rather than the organisation's.

Deletion is a manual process started by emailing support@lumoraapply.com. There is no self-service delete button today, and saying otherwise would be an overstatement of what exists.

What Lumora does not hold

  • ISO 27001 or any other ISO certification
  • An IRAP assessment
  • Right Fit for Risk (RFFR) accreditation
  • A place on any Commonwealth or state government panel
  • SOC 2

For a free pilot with 10 students this is usually not the deciding question. For a network-wide or funded deployment it may well be the blocking one, and it is better raised now than after somebody has committed to it.

Security and privacy contact

Security issues, privacy questions, deletion requests and vendor assessments all go to support@lumoraapply.com, and reach the founder directly.

Back to the education partners page or the employment providers page.