← PriviNet Lumra
Privacy Policy
PriviNet Inc · Version 1.0, July 2026 · privacy contact: brad@privinet.net
What we collect on this website
- Pilot signups and chat: if you submit the pilot form or talk to our assistant, we store what you send (name, work email, device count, your questions) to respond to you. Chat requests are processed by our AI provider to generate the reply.
- We do not run advertising trackers on this site.
What the Lumra service processes for customers
- Event metadata your systems send us: timestamps, device identifiers, event types, locations, readings, and content hashes. This is the product: we sign it and keep it as tamper-evident records for your account.
- What we deliberately do not take: raw video, audio, or media files. Lumra receives hashes of media, not the media itself. If your events describe people (for example a resident wearable alert), that data is yours; we process it only to provide the service to you, under your instructions.
- Access: records are scoped to your account and reachable only with your access key. PriviNet operators access customer records only to run the service or at your request.
Retention and deletion
- Signed records are kept for the life of your account so their evidentiary chain stays intact.
- On account closure you have 30 days to export; after that we delete your live-service records within 60 days of the window closing. Exported records remain verifiable on your side forever.
- Immutable evidence archives. When you export a court-ready ProofPack, an immutable copy may be written to retention-locked storage so it cannot be silently altered or deleted; that immutability is part of its evidentiary value. Archived ProofPacks are retained for a fixed period (currently up to seven years) and cannot be deleted before that period expires, even on request, except as the law requires or permits. We disclose this so immutable retention is never a surprise. Self-serve pilots default to sandbox ProofPacks that are not placed in immutable retention. See Regulated Data and Retention for the full detail.
- Website leads that never become customers are deleted on request: email brad@privinet.net.
Sharing
We do not sell personal information. We share data only with the infrastructure providers that run the service (hosting, database, AI chat processing), each bound to process it only for us, or when the law requires it.
Your choices
Email brad@privinet.net to access, correct, export, or request deletion of information we hold about you, or to ask anything this page does not answer. We acknowledge within one business day. We delete what we can from the live service; where information sits in an immutable evidence archive under an active retention lock, we cannot delete it before the lock expires and will tell you so, and the reason, rather than claim a deletion we did not perform.
California Privacy Notice (CCPA/CPRA)
Last updated July 6, 2026. This notice is for California residents. PriviNet handles two kinds of data.
- 1. Account data we collect from you. Categories: identifiers and contact details (name, work email, phone, company, IP address); professional information (title, role); commercial information (plan, pilot status, ProofPacks generated, billing records on paid plans); internet activity (log-ins, pages viewed, device and browser data, security logs). Sources: you, your company, your devices, our logs. Purposes: to provide, secure, support, bill for, and improve the service, communicate with you, prevent fraud and abuse, and meet legal obligations.
- 2. Customer event data your company's systems send (timestamps, device IDs, event types, sensor readings, content hashes). Some of it may identify your personnel or clients. We process it only on your company's instructions to provide the service, as a service provider under the CCPA. We never take custody of raw video or audio, and we do not use event data for advertising or to train models.
- Selling and sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done either in the preceding 12 months. For that reason we do not post a "Do Not Sell or Share My Personal Information" link. We do not knowingly collect personal information of anyone under 16. We do not use or disclose sensitive personal information except to provide the service. We disclose personal information only to service providers (hosting, email, payments) under contracts limiting their use.
- Retention. Account data: life of the account plus any legally required period. Event records in the live service: life of the account, then a 30-day export window after closure, then deletion within 60 days. Immutable ProofPack archives: retained for their fixed retention period (currently up to seven years) and deleted after it expires; they cannot be deleted earlier except as the law requires or permits. Security logs: 12 months. We keep live-service data no longer than reasonably necessary for the purposes above.
- Your rights. California residents may request access, correction, deletion, and a portable copy of their personal information, and will not be discriminated against for asking. Email brad@privinet.net from the address on the account, or use an authorized agent with written permission. We verify requests against account records and respond within 45 days (extendable once by 45 days). We honor deletion for live-service data; personal information held in an immutable evidence archive under an active retention lock is retained until the lock expires, as permitted for information kept to comply with a legal obligation or to establish, exercise, or defend legal claims, and we will tell you when that applies. If your information sits inside a customer's event data, we will refer the request to that customer and assist them, as the CCPA requires of service providers.
Plain-English v1 policy for pilot-stage service; it will be expanded as the service and its jurisdictions grow.