Your store's data stays your store's data.
Powerful automation is only useful if you can trust it. This page is exactly how Lumnya earns that — with no claims we can't back.
Core guarantees
Eight things that are always true.
Per-store isolation
Your data — and the intelligence built on it — is scoped to your store. Never pooled, never shared.
Confirm-gated by default
Anything touching money or a customer is previewed and waits for your explicit yes. A store that sets nothing stays here forever.
Actions that never automate
Refunds, customer emails, return decisions and the security-sensitive settings can't run unattended at any autonomy level.
Undo that actually reverses
Reversible actions carry a stored inverse and replay through the same guarded path they were written by.
A journal, not just a log
Every write records what changed and how it was authorized — no gate needed, your yes, or a policy you set.
Least privilege
Agents and staff get the minimum access their job requires — nothing more.
Prompt-injection hardening
Untrusted content can't talk Lumnya into unauthorized actions — gates hold regardless of what a page or message says.
Only your storefront can call it
Every action the assistant takes carries a server-issued token minted when the widget loads on your store. A script that never loaded it — curl, a scraper, someone else's page — is turned away before it reaches your data.
A conversation belongs to one browser
A shopper's chat is bound to the browser that started it. The conversation id alone opens nothing: reading the transcript or writing to it needs a key that stays in that browser and never travels in a URL.
GDPR-aligned handling
Data minimization, purpose limitation, and retention designed around privacy from day one.
Before anything happens
It shows you the diff, then waits.
Lumnya renders the exact change before it makes it — the price before and after, the refund amount, the email it would send. One tap approves it, one dismisses it. Nothing is applied from a description you have to take on faith.
>refund order #1043 and email the customer an apology
… reading order #1043 · drafting refund + apology email
preview
Refund €42.00 (full) — order #1043
Email: “We’re sorry about the delay — your refund is on its way.”
Refunded & email sent · logged 14:32 · approved by you
Autonomy, on a dial you hold
Confirm is the default. Autopilot is a decision you make.
Independence isn't one global switch. It's set per area of your store — fifteen of them, from discounts and refunds to triggers, returns and FAQ — so trusting Lumnya with your FAQ never means trusting it with your money.
Suggest
Lumnya proposes; you make the change on the page yourself. It records no pending approval at all, so even a later “yes” can't execute from the chat.
Confirm
It asks, you approve, it acts. This is where every category starts — and a store that never opens the panel stays here permanently.
Autopilot, capped
Inside limits you set, Lumnya acts and tells you afterwards. You raise this per category, once an area has earned it.
The limits you set
Autopilot is never open-ended.
Unset limits fall back to deliberately tight defaults. You widen them on purpose, never by accident.
The line that never moves
Some things stay yours at every level.
Refunds, customer emails, messages sent as you in live chat, remarketing sends, return decisions, support tickets, emailed reports and the security-sensitive settings can never run unattended — no matter how high you turn any dial.
That list is enforced in the server, not in the model's instructions. Text smuggled into a product page or a customer message cannot talk its way past it, because the part that decides never reads it.
Autopilot is being switched on gradually while we watch it work. Until it's enabled for your store, every category simply behaves as confirm — which is also what happens the moment you pause it.
After it happens
Every write is reversible on record.
Each action Lumnya takes lands in a journal: what changed, and how it was authorized — no gate needed, your explicit yes, or a policy you set. Reversible ones store the inverse alongside them, so undo replays the same guarded path the original write used instead of poking the data directly.
Action journal
last 30 daysDiscount code SPRING10 created
Reorder threshold raised — Nordic Hoodie
Refund €62.00 — order #1043
every write · how it was authorized · what it changed
Isolation, not policy
Isolated by store, by architecture.
Separation isn't a promise in a policy document — it's how the system is built. Agents read a private snapshot of your store, memory is scoped per store, and nothing you teach Lumnya ever advises another merchant.
Data isolation — by architecture
per storestore-aurora
1,204 facts · 8.2k orders
store-nordic
312 facts · 1.9k orders
store-atlas
88 facts · 640 orders
cross-store reads: denied — always, for everyone, including us
Data & privacy
Two kinds of data, two lifespans.
Short-lived
Conversational data
Chats with the Customer AI are kept only as long as service quality and your own review windows require — then they age out. They exist to serve the customer, not to become a warehouse.
Long-lived
Business intelligence
Verified facts and agent findings about your store persist while your account is active — that compounding memory is the product. Delete your account and it goes with you.
Exact retention windows and lawful bases are published with counsel before general availability.
Compliance posture
Only what's true, nothing borrowed.
Security pages love logos and vague claims. Here's our actual status instead.
GDPR alignment
In place — minimization, per-store isolation, DPA template published
Data Processing Addendum
Template available now; counsel-reviewed signable version before GA
Penetration testing
Independent test scheduled before general availability
Sub-processor register
Published on this page before GA — hosting, models, email
SOC 2
Not yet pursued — on the radar post-GA. We won't claim what we don't hold.
Operational security
The unglamorous work, done daily.
No silver bullets — just the disciplines that keep systems boring.
Ownership & portability
Yours to keep. Yours to take.
Your store data and the intelligence Lumnya builds on it belong to you. Export what Lumnya knows about your store, or delete it — on request, without a retention fight.
Leaving should be as clean as arriving: uninstall removes the storefront widget immediately, and account deletion removes your data subject only to legal holds.
Responsible disclosure
Found something? Tell us first.
We take reports seriously, respond fast, and credit researchers who help us keep merchants safe. The same contact is published at /.well-known/security.txt (RFC 9116), on this site and on the app.
Private beta
Trust is a feature. Test it.
Join the private beta and be first in line when Lumnya opens to your store.