01
Introduction
This Privacy Policy describes how Lumen (the "Application"), a software application developed and distributed by Kudige Panduranga Shenoy (the "Developer"), handles information when you (the "User") use it. By using the Application, you acknowledge the practices described in this Policy. The Developer is committed to a privacy-by-design approach in which the Application operates locally on your device by default.
02
No Lumen account or tracking
Lumen requires no account and includes no analytics, advertising or tracking. Its separate software-update request is described below.
03
On-device processing (default configuration)
In its default configuration, the Application processes documents entirely on your device using a locally installed artificial-intelligence model. Text extraction, optical character recognition, and document analysis are performed locally, and no document content is transmitted from your device. The local model files are downloaded on your instruction, from a third-party model distribution service; that transfer contains no document content and is subject to the distributor's own terms and privacy policy.
04
Optional third-party AI providers (user-supplied credentials)
The Application allows you to optionally enable one or more third-party artificial-intelligence providers by supplying your own application programming interface ("API") credentials for each provider. The available providers, their privacy policies, and — where the provider publishes separate terms for API use — the documents governing data sent through their APIs, are:
- Anthropic, PBC (Claude) — https://www.anthropic.com/legal/privacy — API use: https://www.anthropic.com/legal/commercial-terms
- OpenAI OpCo, LLC (OpenAI) — https://openai.com/policies/privacy-policy — API use: https://openai.com/enterprise-privacy/
- Google LLC (Gemini) — https://policies.google.com/privacy — API use: https://ai.google.dev/gemini-api/terms
- X.AI LLC (Grok) — https://x.ai/legal/privacy-policy — API use: https://x.ai/legal/terms-of-service-enterprise
- Ollama Inc. (Ollama Cloud) — https://ollama.com/privacy
Where you enable a provider and initiate an analysis, document data is transmitted directly from your device to that provider, authenticated using your own credentials. Such data is processed by the relevant provider — not by or on behalf of the Developer — under that provider's privacy policy and, where linked above, its API terms, which together with your account agreement govern that processing. The Developer is not a party to that transmission, does not receive the data, and exercises no control over the provider's processing of it.
4.1 Information transmitted
For each document analysed by a provider you have enabled, the Application transmits: (i) the name of the file; (ii) up to 300 of your saved name mappings; and (iii) text that the Application has extracted from the document, images having been read by optical character recognition and PDF text extracted on your device prior to transmission. The name mappings are the list of name variations and their corresponding canonical forms that the Application maintains on your device in order to spell personal names consistently in filenames. That set accompanies every document analysed, including documents in which the names concerned do not appear. In the following circumstances, additional data is transmitted:
(a) Large PDFs. For a PDF that the Application accepts for processing and that exceeds the inline size limit, the Application creates a temporary PDF containing up to the first five pages and performs text extraction and, where required, optical character recognition on that excerpt on your device. The original large PDF is not modified and is not transmitted through a provider's file-handling interface. The ordinary request to any enabled provider carries the extracted text described above. If that text produces a weak result on Anthropic or OpenAI, the temporary excerpt — not the whole large PDF — may also be transmitted inline as described in (b), provided it satisfies the separate request-size guard. A large preview PDF extracted from a Pages, Numbers, or Keynote file follows the same excerpt rule; where such a file embeds only a preview image, that image is read by optical character recognition on your device and only the extracted text is transmitted. The Application attempts to remove the temporary excerpt after the processing attempt and, if an interruption leaves one behind, attempts removal again when the Application next launches.
Earlier versions of the Application could instead upload an accepted large PDF in unmodified form to Anthropic's or OpenAI's file-handling interface. Where a usable cleanup record from such a version holds both the opaque provider upload identifier and a credential fingerprint matching the currently stored credential, the Application attempts at launch to send the provider an authenticated deletion request using that credential; if the request does not succeed, the record remains for a later launch. For an OpenAI cleanup record created more than 48 hours earlier, the Application instead attempts to remove the record from your device without sending a deletion request, on the basis of the corresponding upload's configured expiry. OpenAI uploads created by that route were configured to expire 24 hours after creation. If no usable record or upload identifier exists, the credential has been changed or removed, or deletion does not succeed, a provider-side copy may remain subject to the provider's expiry and retention practices, or until you delete it through that provider.
(b) Quality escalation. Where an initial text-only analysis yields a low-confidence result, the Application may re-submit native document data to obtain an improved result (applicable to Anthropic and OpenAI only, and regardless of whether photo naming is enabled): the unmodified PDF data for an ordinary PDF that satisfies the inline request-size guard; the temporary up-to-five-page excerpt described in (a), never the whole original, for an accepted large PDF; or a re-encoded copy of an original image. Such an image is reduced in resolution only where its pixel dimensions exceed an internal limit and is JPEG-recompressed towards an internal byte-size target. If the applicable encoded payload still exceeds the separate request-size guard, the escalation is not sent.
(c) Photo and image naming. Where you enable the optional photo-naming feature (disabled by default), image files containing little or no readable text are transmitted to your selected provider so that it may generate a short visual description for use in the filename. Such an image is re-encoded before transmission, reduced in resolution only where its pixel dimensions exceed an internal limit, and JPEG-recompressed towards an internal byte-size target; the original file is not transmitted, and metadata embedded in it — including GPS coordinates, camera information and the embedded capture-date field — does not accompany it. The capture date, where recorded in the file, is separately transmitted as text. Of the information derived from the file, this request carries only the re-encoded image and that date: neither the name of the file nor your name mappings accompany it. This applies to any enabled cloud provider (Anthropic, OpenAI, Google, xAI, or Ollama). Images containing readable text are processed by optical character recognition on your device and are ordinarily transmitted as extracted text together with the file name and name mappings; where the quality escalation described in (b) applies, a re-encoded copy of the image may also be transmitted.
Except as described in (c), Google (Gemini), xAI (Grok) and Ollama (Ollama Cloud) receive no information derived from your files other than extracted text where available, file names, and name mappings. They do not receive original document files. Ollama Cloud runs open-weight models on infrastructure operated by or for Ollama, not on your device; its handling of transmitted data is governed by Ollama's privacy policy, linked above.
4.2 Consent
Prior to the first transmission of information derived from your files to any given provider, the Application presents a disclosure identifying the provider and the categories of information to be transmitted, and requests your express consent. Consent is obtained on a per-provider basis and, separately, in respect of the transmission of images under the photo-naming feature, so that enabling that feature presents a further disclosure before any image is transmitted. Consent is automatically revoked if the corresponding credentials are altered or removed. Consent is likewise treated as no longer current where the disclosure itself is materially revised: the revised disclosure is then presented once more, identified as updated, before the next transmission to that provider, so that your agreement is given against the current text. Separately, and only where you activate it, the credential-verification control in Settings sends a fixed authentication probe to the provider concerned using your credentials; that request contains a short fixed message and no information derived from your files.
4.3 Location lookup (Apple)
Photo naming (itself disabled by default) includes a location setting that defaults to Resolved. Under Resolved, the Application sends the GPS coordinates embedded in a photo to Apple's geocoding service to determine the city and country for the filename. These coordinates are transmitted to Apple only — not to the Developer and not to any AI provider — and are processed under Apple's privacy policy. Regardless of the default, no coordinates are sent until you have given your separate, explicit consent (you are asked once, before the first lookup). Photos with no embedded GPS coordinates, and the Off and Raw location settings, send nothing.
05
API credentials
API credentials that you supply are stored in the macOS Keychain on your device. Such credentials are used solely to authenticate requests to the provider for which they were supplied. They are not transmitted to the Developer and do not leave your device except as authentication to the applicable provider.
06
Information stored on your device
The Application stores the following within its sandboxed application container on your device. None of this information is transmitted to the Developer:
(a) name mappings and excluded-name entries used to compose filenames consistently (as to transmission of the name mappings to a provider you have enabled, see Section 4.1);
(b) rename-history records that enable renaming operations to be reversed;
(c) locally installed model files;
(d) optional diagnostic logs, as described in Section 7;
(e) operational records, including your settings and preferences, bookmarks recording the folders to which you have granted access, counts of tokens used with each provider, entries retained from earlier versions that track provider uploads awaiting deletion, and warning records retained from earlier versions for PDFs that those versions prepared to upload to Anthropic but for which no provider identifier was saved. A cleanup entry for an upload with a saved provider identifier holds that opaque identifier and may also hold a non-reversible cryptographic fingerprint of the credential used for the upload; when present, the fingerprint allows deletion to be retried only against the same credential. The entry does not hold the credential itself. A warning record instead holds only the provider, a locally generated identifier, the time the upload was prepared for transmission, and whether the warning has been offered. It cannot be used to locate or delete a provider-side copy, and it holds no credential, credential fingerprint, filename, or document content; and
(f) session-recovery snapshots that allow analysis and review work to be restored after the Application is closed or interrupted. A snapshot records the names and file-system locations of the files involved; proposed or manually entered filenames; analysis and review state, including file sizes and reasons a file could not be processed; fields extracted from your documents — which may include personal names, identification numbers, organisation names, document types, countries, and dates — and notes or descriptions produced for those files; names awaiting your review; and records of the folders to which you have granted access, together with the local model or provider, relevant settings, progress and summary information retained for the run, including token counts, and the time the snapshot was saved and the version of the Application that wrote it. A snapshot holds no credential, credential fingerprint, or document content. The current snapshot is periodically replaced as work proceeds and is ordinarily removed after a successful discard, once a later run supersedes it, or when no restorable work remains. A snapshot that the Application cannot read, or that was written by a different version of the Application, is left in place rather than deleted, and an unreadable snapshot is retained as a separate diagnostic copy. Such a snapshot, and any snapshot the Application fails to delete, may remain in the Application's container indefinitely, until a later write or clearing operation succeeds. The Application does not transmit snapshot files or include them in the share-safe diagnostic-log export.
07
Diagnostic logging
The Application provides an optional diagnostic-logging feature, which is disabled by default. When enabled by you, the Application records locally the names and file-system locations of the files processed, the text extracted from them, the fields returned by the AI provider — which may include personal names, identification numbers, and organisation names — the filenames composed from those fields, and the provider's responses. A further option restricts the log to operational events, omitting that extracted content while retaining file names and locations. These logs remain on your device, are not transmitted to the Developer or any third party, and may be disabled and deleted by you at any time. A separate export produces a share-safe copy in which file names, folder names, and paths are replaced with tokens and extracted content is always omitted.
08
File-system access
The Application is sandboxed and may access only those files and folders that you expressly select or provide to it. It scans only those selected locations and does not browse storage outside them. Renaming a file in place requires your authorisation for the folder containing that file.
09
Children's privacy
The Application is not directed to children and does not knowingly collect personal information from any individual.
10
Changes to this Policy
The Developer may update this Policy from time to time. Any revised version will be published at this location and within the Application, identified by a revised effective date. Your continued use of the Application following publication constitutes acknowledgement of the revised Policy.
11
Contact
Enquiries regarding this Policy may be directed to:
Kudige Panduranga Shenoy
Email: kudige@icloud.com
12
Software update checks
Automatic update checks are on by default in Lumen 1.2.1. The control is in Settings → Advanced → Software Updates.
When on, Lumen contacts lumen-ai.eu after launch when a daily check is due. The request identifies Lumen and its version; the server also receives your IP address and the time. No document data or Mac system profile is sent. Available updates download from GitHub Releases. Turn this off to stop automatic checks; you can still use Lumen → Check for Updates… at any time.