Skip to content

Effective August 26, 2026

Your financial records are private by default.

This notice explains the information Lumio handles during its controlled beta, why it is needed, who else can see it, and the controls available to you.

Information Lumio handles

  • Account information: your name, email address, authentication method, and the session data needed to keep you signed in.
  • Financial records you provide: plans, transactions, categories, accounts, budgets, savings goals, contributions, emergency funds, bills and debts, and related preferences. Informal debts may include a creditor name and contact details if you choose to enter them.
  • Households you create or join: the household name, its membership, and the records shared inside it.
  • Life events, such as a wedding: the event details, budget categories and amounts, vendors and their contact details, tasks, milestones, and recorded payments.
  • Documents you upload: PDF, PNG, or JPEG files up to 10 MB and 20 pages, plus the text extracted from them.
  • Spreadsheets you import: CSV or Excel (.xlsx) files up to 5 MB. The file name and the parsed contents of its rows are stored so the review step can show you what will be created before anything is written to your records.
  • Service and security data: limited request, import, export, restore, notification, and email-delivery status needed to operate the product and prevent abuse.

When other people can see your records

Most of Lumio is private to your account. There are exactly two ways another person can see your records, and both require your action:

  • Household members. When you create a household and invite someone, records you place in that household are visible to its members. Your personal records stay outside it — a household is a deliberate boundary, not a merge of two accounts.
  • A life-event planner. If you invite a planner to a wedding, their access is scoped to that one event. They can see its vendors, tasks, milestones, and budget amounts, and can update vendors and tasks. They cannot record or change payments, cannot reach any other part of your household, and cannot see documents you mark as restricted unless you grant them individually. Removing a planner takes effect on their next request.

These limits are enforced in the database itself, not only by hiding controls in the interface.

How the information is used

Lumio uses this information to authenticate your account, calculate and display your plans and balances, keep shared households in sync, read text from documents you upload, read the rows of spreadsheets you import, send reminders and essential account messages when email is configured, complete exports or restores you request, and protect the service from misuse.

Lumio does not use financial records for advertising, sell them to data brokers, or provide automated financial advice.

Error tracking and product analytics

Lumio uses Sentry to capture application errors and PostHog Cloud to record a small set of named product events — for example, that a monthly plan was created, not what it contains. Both are third-party services, so both are configured deliberately narrowly:

  • Sentry never receives request bodies, query parameters, or the breadcrumb trail leading up to an error — only the error itself: its type, message, and where in the code it happened.
  • PostHog never receives amounts, category names, free text you entered, or any other financial record. Autocapture and session replay are both off — PostHog only receives the specific named events Lumio explicitly sends it, never a recording of what happened on your screen.

Error reports and analytics events are retained for 90 days, then deleted automatically.

You can switch product analytics off. In Settings, under Appearance, turning on “Don't include me in product analytics” stops Lumio sending any event at all for your account. Error reports are not affected, because they carry no account identity in the first place — there is nothing in them to tie back to you.

Documents you upload

When you upload a bill, statement, or contract, Lumio reads text from it to suggest values you can review before anything is saved. That processing happens on Lumio's own infrastructure: PDF text is parsed directly, images are read with an optical-character-recognition library that runs on our servers, and the fields are matched with pattern rules. Uploaded documents are not sent to a third-party AI or document-processing provider.

Extraction is deliberately limited and often imperfect. Lumio always shows you what it read and waits for you to confirm or correct it — no record is created from a document without your review.

Spreadsheet imports are processed the same way and on the same infrastructure: the file is parsed on Lumio's servers, never sent to a third party, and every row is shown to you before anything is written. Lumio also matches each description against a fixed list of pattern rules to suggest a category — that matching is local, uses no outside service, and builds no profile of you. Suggestions are only shown, never applied, unless you tick the box asking for the confident ones to be used, and any category can be changed afterwards.

Files are stored in private storage that is not publicly reachable. Access is checked on every request, and links used to view a file are short-lived.

Your bank

Lumio does not connect to your bank account. It cannot see your balance, read your bank transaction history, or move money on your behalf. Everything in Lumio is information you entered, imported, or scanned yourself.

Service providers

Lumio relies on Supabase for authentication, database, and file storage; Vercel for application hosting; Resend for limited transactional email when configured; Sentry for error tracking; and PostHog Cloud for product analytics.

Lumio does not connect to your bank, and does not use a bank-data aggregation provider. You choose what financial records to enter or import.

Account isolation and security

Lumio uses authenticated access and database row-level controls designed to isolate each account's records, and the same controls govern who may read or change shared household and life-event records. Private application routes are not rendered for anonymous visitors, and sensitive API responses are not stored in shared caches. Application logs are written so that request and response bodies — including document contents and imported spreadsheet rows — cannot reach them. No online service can promise absolute security, so please use a strong, unique password and keep access to your sign-in method secure.

How long information is kept

  • Account and financial records are kept until you delete them or delete your account.
  • Uploaded documents are given a 30-day retention window by default, so files nobody links to a record do not accumulate indefinitely. You can delete a document yourself at any time.
  • Imported spreadsheets keep their parsed rows only while the import can still be completed — 24 hours. After that a daily sweep empties them, leaving the file name, the date, and how many records were created, so you can still see that the import happened without Lumio holding a second copy of your statement. The transactions it created are yours and stay until you delete them.
  • Completed or archived life events remain readable and exportable until you delete them; archiving is not deletion, and nothing in an archived event is removed.
  • Error reports and analytics events are retained for 90 days, then deleted automatically.

Lumio does not currently maintain database backups, so deletion — of a document, a record, or your account — is immediate, with nothing kept afterward for Lumio to use for any other purpose. The same absence also means Lumio has no way to restore records lost to an unexpected technical failure on its own infrastructure, rather than a request you made. Backup coverage is under evaluation for a future update to this notice.

Your controls

  • Review and correct your profile and preferences in Settings.
  • Export your transactions, export a life event, or download an account backup.
  • Leave a household, remove a member, or revoke a planner's access at any time.
  • Delete an uploaded document without deleting the record it informed.
  • Permanently delete your account and its live application records from Settings after recent authentication.

Cookies and local browser storage

Lumio uses essential authentication cookies and browser storage to maintain your session and remember product state. The current beta does not use advertising cookies.

If something goes wrong

If a security issue affects your records, Lumio will investigate, contain it, and notify affected accounts by email with what happened, what information was involved, and what to do next. To report a suspected issue, use the route described on the support page.

Children's privacy

Lumio is intended for adults managing their own finances and is not designed for children under 18. If you believe a child has provided personal information, use the route described on the support page.

Changes and questions

This notice may change as the beta and its providers evolve. Material changes will be reflected here with a new effective date. For privacy questions or account-access help, visit Support.