Privacy Policy

Effective 1 August 2026

Lumora (lumoraapply.com) helps job seekers understand why their applications aren't converting, and fixes their application documents. Doing that requires you to trust us with your resume. This page explains exactly what we collect, why, and what we will never do with it.

The short version

  • Your resume is used to generate your diagnosis and documents. That's it.
  • The free resume fix is genuinely free. No card details are asked for or collected.
  • We never sell your personal information, and we never share your resume with employers, recruiters or advertisers.
  • Payments are handled by Stripe. We never see or store your card number.
  • If you use the free fix without making an account, the resume is not saved at all. It is processed, shown to you, and then it is gone.
  • If an organisation paid for your access, they can see that you used Lumora, never what your resume says. Section 6 has the detail.
  • You can delete your account and everything in it yourself, from your account page. It happens straight away. If you would rather we did it, email support@lumoraapply.com and we will.

1. What we collect

  • Account information: your email address and password (stored as a hash), managed through our authentication provider, Supabase.
  • Content you provide: your resume, job ads you paste, your selected industry, and any details you add (for example, application outcomes you track). If you run the free fix without creating an account, none of that content is written to our database. It is processed in memory, returned to your browser, and held only by your own browser until you close the tab or create an account to save it. We do still record the usage events described below, which cover the industry you picked and the score you were given, never the words in your resume.
  • Referral information: if you arrive via a friend's referral link, we store their referral code as the source of your signup and any purchase. That's the whole mechanism: we never scan contacts and never access anyone's address book.
  • Payment information: processed entirely by Stripe. We receive confirmation of payment, the product purchased, and a customer reference, never your card details.
  • Usage information: product events (for example: page viewed, diagnosis started, purchase completed), device/browser type, and approximate location derived from IP. Used to measure and improve the funnel and product.
  • Cookies and similar technologies: session cookies to keep you signed in, and (where enabled) analytics/advertising pixels described below.

2. How we use your information

  • To generate your diagnosis, scores, and (if purchased) rewritten documents.
  • To operate your account: sign-in, purchase fulfilment, receipts and support.
  • To understand how the product is used and improve it, using aggregated usage events.
  • To measure the performance of our advertising (see “Analytics and advertising” below).
  • To meet legal, accounting and tax obligations.

We do not use your resume for advertising, and we do not build advertising profiles from its contents.

3. AI processing of your resume

Your resume text and the job ad you provide are processed by third-party AI providers to generate your diagnosis and documents. Anthropic is our primary provider, and OpenAI is the failover when Anthropic is unavailable. We use these providers' commercial APIs, which under their terms do not use API data to train their models. Your resume is sent for processing only. It is not published, listed, or shared beyond what is required to produce your results.

If you upload a PDF or a photograph of a printed resume, the file itself is sent to Anthropic so the words can be read off the page. Where a feature reads text aloud, only the words to be spoken are sent to ElevenLabs, or to OpenAI if ElevenLabs is unavailable. Section 5 names every provider that receives anything at all.

Two things about the voice features are worth saying plainly, because they are not obvious. First, the audio generated for you is saved in a private storage area tied to your account, so that replaying it does not have to be paid for a second time. It is never given a public or shareable link, it is served back only to you while you are signed in, and it is part of the account content covered by section 8. Second, when you practise an interview out loud, the speech-to-text is done by your own web browser rather than by us. Depending on the browser, that may happen on your device or the audio may be sent to the browser maker to transcribe, which is a matter between you and your browser. Lumora never receives the recording. We receive only the text your browser produces, we send that text to our AI provider so the answer can be graded, and we do not store it.

4. Where your data lives

Your account data and content are stored with Supabase, our database, authentication and file storage provider, and the site is served by Vercel, our hosting provider. All transmission between you, Lumora and our providers is over TLS. To be precise about what that does and does not mean: Lumora does not add its own encryption layer at rest. Supabase encrypts the storage volumes your data sits on. Access within Lumora is restricted to what is needed to operate and support the service.

Lumora is an Australian business, but it is not hosted only in Australia and we would rather you read that here than assume otherwise. Our Supabase project runs in the United States, so your account, your resume and everything generated from it are stored there. Vercel serves the site from a global network, and our AI, voice, payment, email and analytics providers are also outside Australia. Where your information is handled overseas we rely on the protections in our agreements with those providers, and the Australian Privacy Act 1988 (Cth) still governs how we handle it. We hold no certification or accreditation of any kind, and we do not claim one.

5. Who we share information with

Only the service providers needed to run Lumora. This is the complete list, and it says what each one actually receives:

  • Supabase: our database, authentication and file storage. Holds your account and your content.
  • Vercel: hosting. Serves the site and runs our server code.
  • Stripe: payment processing. Receives your payment details directly. We never see your card number.
  • Anthropic: text generation, and reading the text off uploaded resume files. If you upload a PDF or a photo of a printed resume, the file itself is sent.
  • OpenAI: text generation when Anthropic is unavailable, and speech.
  • ElevenLabs: voice. Receives only the words to be spoken aloud.
  • Canva: design editing, and the one worth reading twice. If you choose to open your resume in Canva, the full tailored resume document is uploaded to Canva so it can become an editable design in your own Canva account. This only happens when you choose it. If you never open Canva, Canva never receives anything.
  • Resend: transactional email, such as sign-in links and receipts. Receives your email address and the contents of that email.
  • Adzuna: salary range lookups. Receives a job title only, never your resume, your name or your email.
  • Google Analytics and Google Ads, and the Meta Pixel: where enabled, they receive event names, your IP address and your browser user agent. They never receive your resume contents.
  • Authorities, where disclosure is required by law.

We never sell your personal information. We never share your resume contents with employers, recruiters, data brokers or advertisers. If you share your referral link, the only thing recorded is that your code referred a signup or purchase. The people you refer never see your resume or results, and we never see their contacts.

That list covers the service providers we send information to. If an organisation referred you and paid for your place, section 6 sets out separately what that organisation can and cannot see.

6. If an organisation referred you

Some people reach Lumora through a link from an employment services provider, a school or a similar organisation that has paid for their place. If that is you, this section says exactly what your organisation can and cannot see. It adds to everything above and takes nothing away from it.

What your organisation cannot see. Your resume, your diagnosis, your scores and your generated documents. There is no screen, export or report anywhere in Lumora that shows an organisation a participant's content, and the database has no path that would allow one. If you want someone at your organisation to read your resume, you export it and give it to them yourself, exactly as you would with any other document.

What your organisation can see. That it invited you, whether you took the invitation up, when you used the place it paid for, and which Lumora feature you used it on. That is how a paid place is accounted for, so we would rather you read it here than assume otherwise. At the end of a pilot we review results with the organisation at cohort level, against measures agreed with them before the pilot begins.

The account is yours. A place paid for by an organisation still creates your own Lumora account, in your name. Your rights over your information in section 9 are the same as any other user's. Your organisation cannot delete your account, and it cannot take your documents.

7. Analytics and advertising

Where enabled, we use Google Analytics, Google Ads and the Meta Pixel to understand how visitors reach and use the site and to measure our advertising (for example, that a purchase occurred after clicking an ad). These tools use cookies or similar identifiers and receive event names such as pages viewed and purchases made, along with your IP address and browser user agent. They never receive your resume contents. You can limit ad tracking through your browser settings, and through Meta and Google's own ad preference tools.

8. Retention and deletion

We keep your data while your account is active so your history (diagnoses, documents, tracked applications) keeps working for you. You can request deletion of your account and associated content at any time by emailing support@lumoraapply.com. You can also do it yourself, immediately, from your account page. That removes your resume, every diagnosis, every generated document and your account. Two things survive it, and we would rather say so: anonymous usage counts that contain nothing pointing back to you, and payment records held by our payment provider, which we are required to keep. If you email us instead, we'll action it within 30 days and confirm when it is done.

9. Your rights

We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may request access to, correction of, or deletion of your personal information, or complain about our handling of it, by contacting us at support@lumoraapply.com. If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).

10. Security

The measures we actually have: all traffic runs over TLS, passwords are stored as hashes by our authentication provider, our database enforces row-level access controls, and payment handling is delegated entirely to Stripe so we never hold a card number. We do not claim to encrypt your data at rest ourselves. Our database provider encrypts the storage volumes your data sits on. No system is perfectly secure. If we become aware of a data breach likely to result in serious harm, we will notify affected users and the OAIC as required by law.

11. Children

Lumora is not directed at children and must not be used by anyone under 16.

12. Changes to this policy

If we make material changes, we'll update the effective date above and, for significant changes, notify you by email or in the product.

Contact

Questions about privacy: support@lumoraapply.com