1. The short version
To match you to funding, Lumina has to hold a fairly complete picture of you: your grades, your finances, your CV. We treat that as what it is — sensitive. We do not sell it, we do not rent it, and we do not hand it to advertisers. There are no advertising or third-party analytics trackers on this site.
Two things we would rather you learn here than discover later: your CV and profile text are sent to an outside AI provider whenever you run parsing or matching , and you can export or erase everything yourself from your settings without asking us.
This policy covers the Lumina website and product. Cookies are covered separately in our Cookie Policy, and the terms of the service itself in our Terms of Usage.
2. Who we are
Lumina is an independent product operated by its founding team, which is not yet incorporated. The founding team is the controller of the personal data described here. For anything about your data, write to legal@mylumina.tech. To report a vulnerability, use security@mylumina.tech and give us a chance to fix it before disclosing it.
3. What we collect
Almost all of it comes from you, because you typed or uploaded it. We do not buy data about you, and we do not build a profile of you from other sites.
- Account details
- Your name, email address, and profile photo, created when you sign up. Sign-in is handled by Clerk; the account row on our side is written from Clerk's signed webhook and holds your name and email.
- Your scholarship profile
- Everything you enter to be matched — country, field of study, level, grades, financial need, achievements, and the essay text you write.
- Documents you upload
- Your CV and profile photo, stored as files. We also keep the structured profile our parser reads out of your CV.
- What you save and apply to
- Scholarships and universities you save, the status you set on them, your notes, and the match runs behind your results.
- Product usage
- Which scholarships you open, save, and click through to apply for, recorded against your account so we can tell whether Lumina is actually getting people to funding.
- Feedback you send
- Anything you submit through the feedback form, including a bad-match report.
- Technical records
- Ordinary server and security records — request rate limits keyed to your account, and cached AI results so the same work is not repeated.
We ask for your grades and financial situation because scholarship eligibility turns on them. If you would rather not give a particular detail, leave it out — you will still get matches, just less precise ones.
4. AI, and what leaves our systems
Reading your CV and scoring your matches is done by a large language model we do not host. When you run a parse or a match, the relevant text — your CV contents and profile details — is sent to that provider over the network. Today that is OpenRouter, or DeepSeek where the deployment is configured for it.
Once your text reaches them, what they do with it is governed by their data policy, not ours. We cannot promise on their behalf that it will never be used to improve their models, and we would rather say that plainly than imply a guarantee we are not in a position to give. If that matters to you, do not upload a document you would not want processed by a third-party AI service.
On our side, we cache AI results against your account so the same document is not sent twice, and we count usage to keep costs and abuse in check. Both are deleted with your account.
5. Who else touches your data
These are the services Lumina runs on. Each is given only what its job needs, and none of them are permitted to use your data for their own purposes.
| Service | What it does | What it receives |
|---|---|---|
| Clerk | Sign-in and account management | Your name, email, photo, and session |
| Supabase | Database and file storage | Everything listed above, at rest |
| OpenRouter | AI parsing and matching | CV text and profile details, at the moment of a run |
| Upstash | Rate limiting | A per-account counter, no profile content |
Beyond these, we disclose personal data only where the law requires it, where it is needed to protect someone’s safety, or where you ask us to. Scholarship providers do not receive your profile from us — when you apply, you apply on their site, under their policy.
6. How long we keep it
Your profile and documents are kept while your account is open, because that is the thing the account is for. Delete a document and it goes; delete your account and the whole record goes with it.
What survives a deletion is a single log line recording that the deletion happened: an account identifier and a count of the rows and files removed. No profile content, no documents, no essay text. Data is stored in Frankfurt.
7. Your rights, and the buttons for them
You can see, correct, export, and erase your data. Two of those do not need us at all — your settings page has both:
- Export my data — downloads your profile, your parsed CV profile, your saved scholarships and universities, and the paths of your uploaded files as one file. Files themselves are downloadable from your documents page.
- Delete my account — removes your uploaded files first, then every row we hold against you including cached AI output and usage records, and only then the login itself. If any part of that fails, the deletion stops and your account is left intact rather than leaving orphaned data behind a dead login.
Correcting your profile is just editing it. For anything else — restricting or objecting to processing, or a question about what we hold — write to legal@mylumina.tech. If you are in a country with a data protection authority and you are unhappy with our answer, you can complain to that authority.
8. Security
Data is encrypted in transit and at rest. Uploaded documents live in per-account folders in private storage, not on a public URL. Internal access to student records is limited to what is needed to operate and support the service. No system is perfect, and we would rather tell you that than claim otherwise.
9. Children
Lumina is for students applying to university and is not directed at children under 16. If we learn we are holding data for someone below that age without the consent their country requires, we delete it. A parent or guardian who believes this has happened should write to legal@mylumina.tech.
10. Changes
If what we collect or who we send it to changes, this page and its effective date change with it, and we will tell you before a material change takes effect rather than after.