Privacy at Lumro
Last updated August 9, 2026
Lumro is a controlled Discord support pilot operated by Icon under the Lumro name. Questions or deletion requests begin on the Lumro support page.
What Lumro collects
We collect only the information needed to prepare a preview, run the pilot, secure the service, and manage billing:
- Account and authority data: Discord user and server identifiers, usernames, display names, roles, and the result of Discord administrator checks.
- Private-preview data: before Discord is connected, a sales preview may use a minimized operator-captured projection associated with the named community: a source tenant identifier, stable entry identifiers, timestamps, and support content. That projection is preview-only and can never authorize live delivery.
- Community data: during setup, Lumro temporarily reads the available Discord staff, role, category, and channel lists to show your choices; it does not persist the unselected roster. After you save, Lumro stores only the selected participant details, selected channel structure and necessary category names, plus the bounded message history you authorize Lumro to synchronize. Synchronized message evidence omits author identifiers; a tester's Discord identity is stored separately only after that selected person invokes Lumro.
- Questions and answers: staff pilot questions, generated answers, supporting excerpts, feedback, and operational records needed to diagnose a failed or unsafe answer. The short-lived signed Discord inbox erases its server, channel, user, names, question, and response credential as soon as admission is accepted, rejected, expired, or permanently failed; only a payload-free interaction identifier and outcome timestamps remain there for retry idempotency.
- Billing data: Stripe/Link customer, checkout, subscription, and entitlement identifiers and status. Stripe and Link—not Lumro—collect and store payment credentials.
- Technical data: signed session cookies, pseudonymous preview-viewer and request-lease digests, request and security logs, timestamps, error information, and coarse provider usage needed to operate the service. The application's preview-budget records do not contain the raw private-link token or requester IP address.
How the data is used
We use this information to authenticate administrators, enforce exact people and channel boundaries, retrieve relevant community evidence, generate and deliver private support answers, process subscriptions, prevent abuse, troubleshoot the service, and honor deletion requests.
We do not sell community data. We do not use payment status to expand who can interact with Lumro.
Services that process data
Lumro relies on a small set of providers. Discord supplies identity and community access; Stripe and Link provide merchant-of-record checkout, payment, tax, fraud/dispute, receipt, and transaction-support services; Vercel hosts the application; managed Postgres stores application and synchronized community data; and OpenRouter routes the bounded question and evidence needed to generate an answer to the configured model provider. Each provider processes information under its own terms and privacy commitments.
Retention and deletion
You can use the customer dashboard to disconnect Lumro and permanently delete synchronized Discord messages, synchronized member records, private-preview and customer conversations, agent runs, Discord-native support cases and linked thread records, approved guidance, Discord-native configuration, and integration health history. Imported preview content is deleted when that import belongs only to the community. Disconnecting also terminalizes and erases the payload of every queued or in-flight signed Discord question for that server. It revokes private-preview sessions and links, revokes the free-pilot grant, and retires the rollout, but retains minimal consent, deletion-audit, product-value, and billing records. It does not cancel a paid subscription through Link.
We retain account, authorization, security, deletion-audit, and billing records when needed to operate the service, document consent and access changes, resolve disputes, or meet legal and accounting obligations. Provider backups and logs may take additional time to expire under provider retention schedules.
Your choices
You decide whether to open a private preview, connect Discord, configure public support and private staff channels, change Lumro's autonomy, claim billing responsibility, or purchase a subscription. You may pause replies without deleting data, disconnect and delete product data, and manage or cancel paid renewal through Link.
Security and access
Lumro uses signed sessions, provider-signed webhooks, tenant-scoped database queries, explicit rollout checks, and server-held credentials. No internet service can promise absolute security; if you believe access is incorrect, pause or disconnect the pilot and contact us immediately.
Changes
We may update this notice as the pilot changes. The date at the top shows the current version. Material changes that affect an active customer will be communicated through the available account or operator contact.