Lumemark — Internal Staging Test Privacy Notice

Version: staging-consumer-v1.

1. Scope And Responsible Operator

Nazar Pryimak, Heisfelder Straße 125, 26789 Leer, Germany, is responsible for this owner-controlled staging exercise. Contact accounts@lumemark.app about account information, privacy, copies or deletion.

This notice describes the internal agreement-confirmation and account-exit test. It is not the privacy notice for an external release. It does not authorize inviting other people or processing their operational records. The real accounts, messages, evidence and any later approved deletions are not simulated simply because the policies are test fixtures. Accepting the Terms is not blanket privacy consent, and a technical acceptance record is not by itself a legal basis for every processing operation.

2. Information Used

The exercise uses the account's authentication identifier, trusted email, supplied identity/name information where available, current access/Trial/funding state and immutable policy/acceptance history. These identify the selected account and verify that confirmation does not start or replenish a Trial.

Acceptance creates an exact confirmation snapshot, actual acceptance time, reference and bounded mail-delivery record. An exit declaration additionally records its action, confirmed name, account/agreement identification, destination and receipt time. Customer acknowledgements go to the frozen account address; a separate exit notice goes to the fixed operator mailbox. Provider acceptance is recorded for recovery and access control, not email-reading behaviour.

Approved cleanup can process the account's existing Projects, sources, saved work, messages and usage records. Those remain private application data, not content for the confirmation email or general operational logs. The first receipt test does not inspect source contents or authorize new uploads, fetches or AI calls. Any later content-processing exercise needs its own reviewed scope.

Necessary session cookies and browser-local state support sign-in, navigation and recovery. Technical monitoring uses bounded status, error and service information. Receipt text, postal addresses, source text, prompts, email addresses and private case details must not be placed in general logs or Sentry events. No advertising, marketing or model-training purpose is introduced by this exercise.

3. Providers And Access

The deployed test uses Google sign-in and Supabase authentication/database/private storage, Vercel frontend hosting, Render backend/background processing, Sentry error/operational monitoring and Google Workspace for correspondence. Sending uses the dedicated consumer mail configuration and the accounts@lumemark.app identity. The sender has no mailbox-reading or deletion authority merely because it can send.

The first confirmation test makes no AI request. Later approved staging AI work uses the enabled OpenAI path and can transmit relevant source/context material; it is not part of proving an email receipt. Existing provider processing and network/security metadata do not disappear when application mail is disabled.

The operator can access the minimum account and delivery evidence needed to perform the test and recover failures. Independently retained case records have restricted custody. Infrastructure is not asserted to be Germany-only or EU-only. This internal fixture does not certify external-release provider agreements, international-transfer safeguards or provider-copy disposal; those reviews remain required before the corresponding external use. It grants no waiver of applicable data-protection duties.

4. Retention And Deletion

Existing account/workspace data follows its ordinary lifecycle; Trial expiry and acceptance alone do not delete it. A declaration is followed by supervised case handling and authorized cleanup, not instantaneous deletion from every system.

Minimum agreement/acceptance evidence is kept while the account exists and then through the end of the third calendar year after termination under the current evidence schedule. Necessary rights/deletion/security case evidence follows the corresponding period after case closure, subject to a documented lawful hold. This does not justify keeping the whole workspace or treating all technical test data as legally necessary.

Exact consumer working copies remain available while delivery or case duties are unresolved. After verified independent handoff, redundant working copies are disposed of promptly and within seven days. Runtime database disposal does not prove deletion of Inbox, Sent, downloaded or provider-held copies; those require separate review and recorded completion. Uncertain delivery stays an active recovery task rather than being relabelled as sent or silently retried.

Account closure drains admitted work and authentication/token access before final removal. Eligible live content is permanently erased without an undo window. Recovery copies and provider records can have a separate disposal tail; the test must track relevant retained copies and prevent a restore from reviving completed deletion or repeating old mail. No unverified provider retention duration or immediate universal erasure is promised by this fixture.

5. Requests And Limits

Contact accounts@lumemark.app for access, correction, erasure, restriction, a qualifying data copy/transfer or an objection where applicable. Separately given consent, if any, can be withdrawn without changing the lawfulness of earlier processing. These rights do not require a new account, active Trial or acceptance of newer Terms. Authority is checked proportionately before disclosing data or deleting an account.

Applicable request deadlines, supervisory complaint rights and mandatory safeguards remain unchanged. This owner-controlled technical exercise is not a finding about every legal basis or duty of a future customer service. External release still requires its complete reviewed notice, actual provider/transfer and retention information, and operational acceptance.

Version staging-consumer-v1Effective September 29, 2026