Legal
Security
Effective 13 July 2026. Security matters even before we launch. Lumienzo, Inc. is pre-launch: the product is not yet available to the public, and there are no live accounts, payments, escrow, dashboards, or social integrations today. This page is candid about exactly where we are now and where we are going. Questions or reports go to [email protected].
What is true today
Right now, lumienzo.com is a static marketing website. The only personal data we collect is the email address you give us when you join the waitlist, and that address is held by Buttondown, our reputable email provider, not in a database we run. We do not sell or share your personal information. Concretely, today:
- HTTPS everywhere. All traffic is encrypted in transit, with HSTS enabled (max-age of two years, includeSubDomains, and preload) so browsers refuse to connect over plain HTTP.
- Strict security headers. We serve a strict Content-Security-Policy locked to our own origin plus a small number of named sources, along with X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and Referrer-Policy: strict-origin-when-cross-origin.
- Locked-down browser permissions. Our Permissions-Policy disables geolocation, microphone, and camera, and opts out of FLoC cohort tracking.
- Minimal attack surface. The marketing site is static, with no database and no server-side application behind it, so there is very little to attack.
- No tracking. We set no analytics or advertising cookies and run no ad pixels or cross-site trackers. Only strictly necessary technical state, if any, is used.
- The third parties involved today. The site is hosted on Netlify, whose edge network writes standard request logs (such as IP address, user agent, and timestamp) that are inherent to serving any website. Some decorative photos load from Unsplash's image CDN, which receives your IP address when those images load. Alongside Buttondown for waitlist email, these are the only third parties involved today.
How we are building the product
The items below describe how we intend to build the product. They are commitments for launch, not controls operating today. We will update this page as each one goes live.
- Encryption in transit and at rest. Data will be encrypted in transit with TLS 1.2 or higher, and encrypted at rest.
- Hardened cloud hosting. The application, database, and storage will run on Google Cloud.
- Least-privilege access. We will operate on least-privilege access with multi-factor authentication on the accounts and tools we use.
- Secure Instagram connection. When a creator connects their own Instagram account through official OAuth, they authorize us through Meta's own consent screen to read professional-account insights. Access tokens will be stored encrypted, never returned in API responses, and never logged in plaintext. Creators can disconnect and revoke access at any time in their Instagram or Facebook settings or by disconnecting within Lumienzo, and can request deletion of ingested Instagram data. We will not sell this data and will not use it to train external or third-party AI models, and our use will comply with the Meta Platform Terms and Developer Policies.
- Payments we never touch. Payments will be handled by Stripe, a PCI DSS compliant processor, so we never store or see full card numbers. We receive only tokenized identifiers and metadata.
- Escrow with a regulated partner. Brand funds will be held in escrow with Stripe, a regulated third-party payment processor. Lumienzo does not hold funds directly.
- Address masking. Blind shipping will mask creator home addresses so brands never see street-level creator addresses.
- Password storage. Account passwords will be stored only as bcrypt hashes, never in plaintext.
Compliance roadmap
We are honest about certifications: we hold none today, and we will not claim any we have not earned.
- SOC 2. We are not SOC 2 certified. We intend to pursue SOC 2 as we grow and scale, and we are building our controls with that framework in mind.
- Privacy rights. At launch we will support data-subject rights under GDPR, UK GDPR, and CCPA, including access, correction, and deletion. Our Privacy Policy sets out the lawful bases we rely on, our international transfer safeguards, and the full detail of how we handle connected-account data.
- Data Processing Agreement. A DPA is available on request. Contact [email protected] and we will provide it.
Reporting a vulnerability
If you believe you have found a security issue, please tell us at [email protected]. We are committed to acknowledging good-faith reports quickly and working with you in good faith to understand and fix the issue.
Safe harbor. We will not pursue or support legal action against researchers who make a good-faith effort to follow this policy: test only against your own data and accounts, avoid privacy violations and service disruption, and give us a reasonable chance to remediate. Please do not publicly disclose an issue before we have released a fix. We do not offer cash bounties, but we may recognize and thank researchers at our discretion.
Contact
Lumienzo, Inc. Reach us at [email protected].