본문으로 이동
Legal & trust
العربيةARDeutschDEEnglishENEspañolESFrançaisFRहिन्दीHIItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPTРусскийRUTürkçeTRУкраїнськаUK简体中文ZH
Lunume으로 돌아가기시작하기
LunumeLegal & trustSecurity and access

Preview edition · not yet effective Operator details are not yet confirmed. Registered particulars, provider locations and retention schedules must be confirmed before public launch.

Legal & trust
OverviewTerms of servicePrivacy noticeCookies and local storageAcceptable useSecurity and accessContact and requests

English edition
Lunume · preview edition

Security and access

Current safeguards, collaboration boundaries and vulnerability reporting.

Revision 2026-09-07EnglishPreview edition
On this page
01Accounts and sessions02Workspace and notebook access03Public links and attachments04Saving, conflicts and recovery05AI boundaries06Device and deployment responsibilities07Reporting a vulnerability08Coordinated investigation09Incident communications

01Accounts and sessions

Lunume stores password hashes rather than plaintext passwords and uses authenticated sessions. The device-management screen allows you to review and revoke sessions. Revocation prevents later authorised requests through that session; it does not remove files already downloaded. Use a unique password, protect your email account and report unexpected session activity.

02Workspace and notebook access

The service checks workspace membership and the permissions applicable to a notebook before returning protected material or accepting changes. Rights can come from a workspace role, direct permission or a group. Removing one grant may leave a separate inherited permission in place. Review effective access, group membership and the role of each participant. A board currently follows its associated notebook access; it does not provide an independent privacy boundary.

03Public links and attachments

Public links are a separate sharing mechanism. Review the note and its attachments before enabling one, and use expiry or revocation where appropriate. The service checks whether a link remains valid when serving protected shared material. Files are stored in object storage and supplied through authorised service routes. Link holders may forward content or retain copies; revocation cannot reverse that.

04Saving, conflicts and recovery

The editor reports save status. Version checks prevent a stale edit from silently overwriting a newer version, and recovery drafts preserve unsaved work for review. Resolve a save failure or conflict before closing the app. Concurrent edits are not automatically merged in real time. History and trash provide recovery options but are not an independent backup guarantee.

05AI boundaries

AI provider credentials remain on the server. The account control stops that user’s new AI requests; the workspace owner can disable AI for members in that workspace. Disabling AI cannot recall a request already transmitted. The assistant uses its selected note or permitted workspace excerpts and presents proposed changes for review before applying them. Provider output and quoted documents are not authority to bypass access checks.

06Device and deployment responsibilities

Protect devices, browser profiles and downloaded files. Unsent drafts can remain in local browser storage, including after sign-out. Content is not end-to-end encrypted. Production transport security, storage encryption, backups, administrator access and update procedures must be verified for the deployment. This page is a description of the current design, not a certification, penetration-test report or promise that all attacks can be prevented.

07Reporting a vulnerability

Contact the published support address with the affected feature, date, reproducible steps, likely impact and a minimal example using accounts and data you control. Do not send secrets or unrelated personal data in the initial message; request an appropriate channel first. If you encounter someone else’s information, stop testing, do not copy or alter it, and describe the exposure without including the material itself.

08Coordinated investigation

Do not carry out destructive tests, social engineering, physical attacks, denial-of-service testing or bulk collection. Obtain written scope before testing systems you do not control. We may ask for clarification and will coordinate investigation and disclosure where appropriate. This policy does not authorise access to third-party systems, promise a payment, establish a response-time guarantee or grant immunity from applicable law.

09Incident communications

An incident will be assessed for its effect on confidentiality, integrity and availability. Where required, affected organisations, individuals and authorities will receive the notices applicable to their roles and the circumstances. Customers acting as controllers remain responsible for their own obligations. Do not infer that a service interruption necessarily involves exposure of personal data.

All documents

노트와 프로젝트를 위한 공간.

Lunume 알아보기

기능사용 방법개인과 팀을 위해앱자주 묻는 질문

Legal & trust

Terms of servicePrivacy noticeCookies and local storageAcceptable use모든 문서

내 작업 공간

시작하기로그인Security & access문의 및 도움말
© 2026 Lunume
العربيةARDeutschDEEnglishENEspañolESFrançaisFRहिन्दीHIItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPTРусскийRUTürkçeTRУкраїнськаUK简体中文ZH
맨 위로