跳转到正文
Legal & trust
العربيةARDeutschDEEnglishENEspañolESFrançaisFRहिन्दीHIItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPTРусскийRUTürkçeTRУкраїнськаUK简体中文ZH
返回 Lunume开始使用
LunumeLegal & trustPrivacy notice

Preview edition · not yet effective Operator details are not yet confirmed. Registered particulars, provider locations and retention schedules must be confirmed before public launch.

Legal & trust
OverviewTerms of servicePrivacy noticeCookies and local storageAcceptable useSecurity and accessContact and requests

English edition
Lunume · preview edition

Privacy notice

What we process, why and how to exercise your rights.

Revision 2026-09-07EnglishPreview edition
On this page
01Controller and team content02Data you provide03Data generated by use04Purposes and legal bases05Recipients and public links06AI and connections07Providers and international transfers08Retention and deletion09Browser storage and the public demo10Your rights11Complaints, children and automated decisions12Security and changes

01Controller and team content

The service operator identified on the Contact page is the proposed controller for account administration, service operations and its own communications. Its particulars appear on the Contact page. For content processed solely on an organisation’s instructions, the organisation may be controller and Lunume processor. A data processing agreement must define these responsibilities before organisational processing begins. This preview is not a signed processing agreement.

02Data you provide

Account information includes email, display name, password hash, language and time zone. Workspace content includes documents, revisions, tasks, comments, dates, assignments, files, tags, templates and sharing choices. Support requests contain the details you submit. A payment provider may collect billing details if paid access is enabled; its identity and data flow must be disclosed before checkout launches. Do not send support passwords or complete card details.

03Data generated by use

The service records session identifiers and expiry, browser or device information, IP address, timestamps, access changes and audit events. These support account protection, troubleshooting and requested workspace actions. Some supported attachments have text extracted for search. Shared activity may identify who changed content or permissions.

04Purposes and legal bases

Account administration and requested features rely on performance of our contract with you. Security, fraud prevention, support and diagnostics rely on legitimate interests in operating a reliable service, balanced against your rights. Statutory record-keeping and lawful disclosure rely on legal obligations. Optional marketing and non-essential technologies require an appropriate separate basis, including consent where required. Organisational controllers determine the legal basis for their workspace content.

05Recipients and public links

Authorised participants can see content and account information made available by their permissions, such as names and assignments. Public links expose the shared material to their holders. Operational personnel and contracted providers may access data where needed to run, secure or support the service. We may disclose information where required by law or necessary for legal claims. A public link is not a private invitation.

06AI and connections

A requested AI action processes its prompt and selected context. Provider identity, locations, retention and any training use must be disclosed before production AI is enabled; this preview makes no unverified promise about provider training. Telegram or other connections you enable receive the content, identifiers or reminders required for the feature. Review their scope. Disconnecting does not delete information already transferred.

07Providers and international transfers

Hosting, object storage, email and any AI or payment processors depend on deployment. A current processing schedule identifying recipients, locations and purposes must be published before this notice takes effect. Transfers outside the EEA require an applicable adequacy decision or appropriate safeguards, such as approved contractual clauses and necessary supplementary measures. You may request information about relevant safeguards from our privacy contact.

08Retention and deletion

Active content is retained for the requested service. In the current implementation, trashed items remain recoverable until permanently deleted. Final deletion removes the live item and its linked history. Files referenced by another item remain; unreferenced file deletion may be retried after a storage failure. Logs, backups, billing records and legal holds require separate retention periods. The operator must establish and disclose these in the processing schedule before launch.

09Browser storage and the public demo

The current landing demonstration animates fictional examples; it does not accept note editing or create account records. The signed-in editor stores unsent drafts locally to recover interrupted saves. Account-specific drafts may remain after sign-out on that browser. Clear site data on shared devices when appropriate, after saving needed work. The Cookies and local storage policy explains these controls.

10Your rights

Subject to applicable conditions, you can request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. Consent can be withdrawn without affecting earlier lawful processing. Contact the privacy address from your account email and describe your request; proportionate verification may be necessary. GDPR requests are normally answered within one month. A permitted extension of up to two further months requires notice and reasons within the first month.

11Complaints, children and automated decisions

You may complain to the Cyprus Commissioner for Personal Data Protection or the competent authority where you live or work and seek a judicial remedy. The current service does not use AI to make decisions about you with legal or similarly significant effects. A future change would require separate assessment and notice. The service is not marketed to children.

12Security and changes

Controls include password hashing, authenticated sessions, permission checks and editing version checks. Files use object storage with authorised service routes. Content is not end-to-end encrypted. Production infrastructure encryption, backups, operational access and incident handling must be verified for the deployment. Email and authentication data are required for an account; submitting other content is your choice. We will update this notice and provide further notice where processing changes require it.

All documents

存放笔记与项目的地方。

探索 Lunume

功能使用方式个人与团队应用常见问题

Legal & trust

Terms of servicePrivacy noticeCookies and local storageAcceptable use全部文档

你的工作区

开始使用登录Security & access联系与支持
© 2026 Lunume
العربيةARDeutschDEEnglishENEspañolESFrançaisFRहिन्दीHIItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPTРусскийRUTürkçeTRУкраїнськаUK简体中文ZH
返回顶部