Privacy Policy
Last updated: 9 May 2026
LumiLens is operated by Livana Group Ltd (company number 16955382), a company registered in England and Wales. We take your privacy seriously and are committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy explains what data we collect, why we collect it, how we store it, and your rights regarding that data. This policy applies specifically to LumiLens at lumilens.io.
What data we collect
Account information
When you create an account, we collect your name and email address. If you sign in with Google, we receive your name, email, and profile image from Google. If you subscribe to a paid plan, payment details are processed directly by Stripe and are never stored on our servers.
Accessibility preferences
During onboarding, you may choose to share your assistive technology preferences (e.g., screen reader type, primary concerns, experience level). This data is used solely to personalise your accessibility insights and is never shared with third parties or used for advertising.
Scan and insights data
We store the website URLs you submit for scanning, along with the scan results (accessibility scores, issues found, and AI-generated insights). This data is necessary to provide the service, show your insights history, and populate the site directory.
Community contributions
If you leave a review on a website, we store your review text, star rating, and your display name alongside your assistive technology profile. Reviews are publicly visible on the site directory. You can request removal of your reviews at any time.
Saved sites
If you save websites for monitoring, we store the URLs and your monitoring preferences. We use this data to send you email alerts when a site's accessibility changes.
Usage and analytics
With your consent, we collect anonymous usage data via Vercel Analytics to understand how the product is used and to improve it. This includes pages visited, feature usage, and general device information. Analytics are only enabled after you accept cookies. We do not use this data to identify individual users.
Cookies
We use the following types of cookies:
- Essential cookies are required for authentication, session management, and cookie consent preferences. These cannot be disabled.
- Analytics cookies (Vercel Analytics) are only loaded after you accept cookies via our consent banner. You can change your preference at any time by clearing your browser's local storage.
Site directory and public data
LumiLens maintains a public directory of websites that have been scanned. This directory displays automated accessibility scores, community reviews, and aggregate data. The directory contains information about publicly accessible websites, not personal data about individuals.
Accessibility scores are automated estimates generated by scanning publicly available web pages. They do not constitute a professional audit or legal assessment. Website owners who wish to dispute their listing or request removal can contact us at hello@livana.io.
Data retention
- Paid accounts:Insights and account data are stored for the duration of your active subscription. After cancellation, data is retained for 30 days before permanent deletion.
- Free accounts:Insights history is retained while your account is active.
- Anonymous scans:Results from scans without an account are automatically deleted after 7 days.
- Account deletion:You can request deletion of your account and all associated data at any time by contacting us. We will process your request within 30 days.
Third-party services
We use the following third-party services to operate LumiLens. Each has their own privacy policy and data handling practices:
- MongoDB Atlas — Database hosting and data storage
- Railway — Scan worker hosting (processes website URLs and generates insights)
- Anthropic (Claude) — AI-powered insights generation. Website content is sent to Claude for analysis but is not stored by Anthropic for training purposes.
- Stripe — Payment processing. We never store your card details directly.
- Resend — Transactional email delivery (monitoring alerts, account verification)
- Vercel — Application hosting, deployment, and analytics
- Google — OAuth authentication (optional sign-in method)
International data transfers
Some of our third-party service providers process data in the United States and other countries outside the United Kingdom. Where your data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office, or equivalent mechanisms that provide an adequate level of data protection.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Withdraw consent at any time (for analytics and marketing)
- Request a portable copy of your data
- Request removal of your community reviews
- Lodge a complaint with the Information Commissioner's Office (ICO) if you believe your rights have been violated
To exercise any of these rights, contact us at hello@livana.io. We will respond within 30 days.
Legal basis for processing
We process your personal data on the following bases:
- Contractual necessity — to provide the accessibility scanning and insights service you signed up for
- Legitimate interest — to improve the product, maintain the site directory, prevent abuse, and ensure service security
- Consent — for analytics cookies, marketing communications, and assistive technology preferences, which you can withdraw at any time
Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, as required by UK GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
Contact us
If you have any questions about this privacy policy or how we handle your data, please contact us at hello@livana.io.
Livana Group Ltd (company number 16955382), registered in England and Wales.