Last updated: August 2026
Lumio Studio ("Lumio", "we", "us") builds custom websites using AI. This policy explains what data we collect from you as a client, why, and what rights you have over it — written for an international audience, with specific attention to Australian privacy law since that's where Lumio operates from.
Solely to design, build, and deliver the website you've requested, to communicate with you about your project, to process payment, and to keep the service secure and working (e.g. preventing automated abuse of the AI chat on your site). We do not sell your data, and we do not use it to train any AI model beyond generating your own site.
Your submission is stored in a managed database (Upstash Redis, hosted on infrastructure that may be located outside your home country) while your project is active. Once your site is approved, we may export a complete offline copy of your record and remove it from the live database — see "Data retention" below.
Your business information is sent to Anthropic (the maker of the Claude AI models) to generate your website's design, copy, and layout, and to power your site's AI concierge chatbot if you enable it. This is a necessary part of how the service works. Anthropic processes this data under its own API terms and does not use API data to train its models.
We keep your submission record for as long as your project is active or your site is published through Lumio. Once your project is complete, we may retain only an archived copy of the final site's code (for our own record-keeping and in case you need it restored) and remove the working record from the live database. You can request a copy of everything we hold on you, or request deletion, at any time (see Section 8).
We share data only with the service providers needed to run Lumio:
We never sell your data to third parties or use it for advertising.
As an Australian-operated business, we handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), including collecting only what's reasonably necessary, being transparent about use, and giving you access/correction rights over your own information.
Regardless of where you're located, you can ask us at any time to:
If you're in the EU/UK, these map to your rights under GDPR (access, rectification, erasure, and data portability). If you're in California, these map to your rights under the CCPA. Contact us at the email below to exercise any of these.
Access to client data is restricted to the founder via a password-protected admin panel with brute-force protection. Payment details never touch our servers. We take reasonable technical measures to protect your data but no online service can guarantee absolute security.
Lumio is a business-to-business service and is not directed at children. We do not knowingly collect data from anyone under 18.
We'll update the date at the top of this page if this policy changes materially.
Questions about your data or this policy: lumiowebbuilder@gmail.com or 0413 136 686.