Trust by design

Your store's data stays your store's data.

Powerful automation is only useful if you can trust it. This page is exactly how Lumnya earns that — with no claims we can't back.

Core guarantees

Eight things that are always true.

Per-store isolation

Your data — and the intelligence built on it — is scoped to your store. Never pooled, never shared.

Confirm-gated by default

Anything touching money or a customer is previewed and waits for your explicit yes. A store that sets nothing stays here forever.

Actions that never automate

Refunds, customer emails, return decisions and the security-sensitive settings can't run unattended at any autonomy level.

Undo that actually reverses

Reversible actions carry a stored inverse and replay through the same guarded path they were written by.

A journal, not just a log

Every write records what changed and how it was authorized — no gate needed, your yes, or a policy you set.

Least privilege

Agents and staff get the minimum access their job requires — nothing more.

Prompt-injection hardening

Untrusted content can't talk Lumnya into unauthorized actions — gates hold regardless of what a page or message says.

Only your storefront can call it

Every action the assistant takes carries a server-issued token minted when the widget loads on your store. A script that never loaded it — curl, a scraper, someone else's page — is turned away before it reaches your data.

A conversation belongs to one browser

A shopper's chat is bound to the browser that started it. The conversation id alone opens nothing: reading the transcript or writing to it needs a key that stays in that browser and never travels in a URL.

GDPR-aligned handling

Data minimization, purpose limitation, and retention designed around privacy from day one.

Before anything happens

It shows you the diff, then waits.

Lumnya renders the exact change before it makes it — the price before and after, the refund amount, the email it would send. One tap approves it, one dismisses it. Nothing is applied from a description you have to take on faith.

lumnya console confirm-gated

>

… reading order #1043 · drafting refund + apology email

preview

Refund €42.00 (full) — order #1043

Email: “We’re sorry about the delay — your refund is on its way.”

Cancel Approve refund

Refunded & email sent · logged 14:32 · approved by you

Autonomy, on a dial you hold

Confirm is the default. Autopilot is a decision you make.

Independence isn't one global switch. It's set per area of your store — fifteen of them, from discounts and refunds to triggers, returns and FAQ — so trusting Lumnya with your FAQ never means trusting it with your money.

level 0

Suggest

Lumnya proposes; you make the change on the page yourself. It records no pending approval at all, so even a later “yes” can't execute from the chat.

level 1 · default

Confirm

It asks, you approve, it acts. This is where every category starts — and a store that never opens the panel stays here permanently.

level 2 · opt-in

Autopilot, capped

Inside limits you set, Lumnya acts and tells you afterwards. You raise this per category, once an area has earned it.

The limits you set

Autopilot is never open-ended.

A ceiling on what a single action may be worth — and a monthly one
A maximum number of unattended actions per day
A discount ceiling on top of your store-wide maximum
Quiet hours, in your store's own timezone
Pause every category instantly — one switch, no arguing

Unset limits fall back to deliberately tight defaults. You widen them on purpose, never by accident.

The line that never moves

Some things stay yours at every level.

Refunds, customer emails, messages sent as you in live chat, remarketing sends, return decisions, support tickets, emailed reports and the security-sensitive settings can never run unattended — no matter how high you turn any dial.

That list is enforced in the server, not in the model's instructions. Text smuggled into a product page or a customer message cannot talk its way past it, because the part that decides never reads it.

Autopilot is being switched on gradually while we watch it work. Until it's enabled for your store, every category simply behaves as confirm — which is also what happens the moment you pause it.

After it happens

Every write is reversible on record.

Each action Lumnya takes lands in a journal: what changed, and how it was authorized — no gate needed, your explicit yes, or a policy you set. Reversible ones store the inverse alongside them, so undo replays the same guarded path the original write used instead of poking the data directly.

Undo is itself gated — a smuggled instruction can't silently revert a fraud block
A racing double-undo refuses instead of replaying twice
Irreversible actions journal honestly with no inverse — nothing is faked
Journal entries are scrubbed on the same 30-day retention as the rest

Action journal

last 30 days

Discount code SPRING10 created

your yesUndo

Reorder threshold raised — Nordic Hoodie

policy · triggersUndo

Refund €62.00 — order #1043

your yesnot reversible

every write · how it was authorized · what it changed

Isolation, not policy

Isolated by store, by architecture.

Separation isn't a promise in a policy document — it's how the system is built. Agents read a private snapshot of your store, memory is scoped per store, and nothing you teach Lumnya ever advises another merchant.

Data isolation — by architecture

per store

store-aurora

1,204 facts · 8.2k orders

isolated

store-nordic

312 facts · 1.9k orders

isolated

store-atlas

88 facts · 640 orders

isolated

cross-store reads: denied — always, for everyone, including us

Data & privacy

Two kinds of data, two lifespans.

Short-lived

Conversational data

Chats with the Customer AI are kept only as long as service quality and your own review windows require — then they age out. They exist to serve the customer, not to become a warehouse.

Long-lived

Business intelligence

Verified facts and agent findings about your store persist while your account is active — that compounding memory is the product. Delete your account and it goes with you.

Exact retention windows and lawful bases are published with counsel before general availability.

Compliance posture

Only what's true, nothing borrowed.

Security pages love logos and vague claims. Here's our actual status instead.

GDPR alignment

In place — minimization, per-store isolation, DPA template published

active

Data Processing Addendum

Template available now; counsel-reviewed signable version before GA

in progress

Penetration testing

Independent test scheduled before general availability

planned

Sub-processor register

Published on this page before GA — hosting, models, email

in progress

SOC 2

Not yet pursued — on the radar post-GA. We won't claim what we don't hold.

not yet

Operational security

The unglamorous work, done daily.

No silver bullets — just the disciplines that keep systems boring.

Encryption in transit for every connection
Least-privilege access controls, reviewed regularly
Secrets managed centrally — never in code
Audit logging on by default, product-wide
Incident response runbook with merchant notification
Backups and tested recovery for critical data

Ownership & portability

Yours to keep. Yours to take.

Your store data and the intelligence Lumnya builds on it belong to you. Export what Lumnya knows about your store, or delete it — on request, without a retention fight.

Leaving should be as clean as arriving: uninstall removes the storefront widget immediately, and account deletion removes your data subject only to legal holds.

Responsible disclosure

Found something? Tell us first.

We take reports seriously, respond fast, and credit researchers who help us keep merchants safe. The same contact is published at /.well-known/security.txt (RFC 9116), on this site and on the app.

Private beta

Trust is a feature. Test it.

Join the private beta and be first in line when Lumnya opens to your store.