This policy covers the hosted Illumina service at app.illumina.sh and api.illumina.sh, the MCP server, the SDKs, and this website. It explains what we collect, why, who processes it on our behalf, and what you can do about it.
What we collect
Account information. Your email address, the name you give us, and the name of your workspace. Sign-in works by a link we email you, so we also keep a short-lived sign-in token until you use it. If a teammate invites you, we store the invitation and who sent it.
Content you save. Everything you commit into a namespace: text, uploaded files, and the context and tags you attach. From that content the service derives facts, entities, links between them, embeddings, signals, community summaries, automation output, and decision history. All of it lives in your workspace and belongs to you.
Usage records. Counts of commit, search, and illuminate operations, bytes of file storage, and model token usage, recorded per workspace so we can enforce plan limits and bill Pro usage.
Audit logs. Every operation a namespace serves, over HTTP or MCP, with its outcome, duration, and the API key or user behind it. On the hosted deployment these are kept for 90 days by default.
Billing details. Stripe handles payment. We store your Stripe customer id, plan, and plan status. Card numbers never reach our systems.
Messages you send us. Anything you submit through the contact form or send to support.
How we use it
We use this information to run the service, meter and bill usage, keep accounts secure, prevent abuse, answer support requests, and send service emails such as sign-in links, invitations, and billing notices.
We do not sell your information. We do not run advertising. We do not use your content to train our own models.
Who processes it for us
We rely on a small number of providers. Each one receives only what it needs for the job described.
| Provider | What it does |
|---|---|
| Amazon Web Services (us-east-1) | Hosts the database, file storage, and application servers. Amazon Bedrock computes embeddings and reranks search results. Amazon Textract reads uploaded documents. Amazon SES sends service email. |
| DeepSeek | Runs the language model calls that extract facts from your content and write illuminate answers, automation output, and consolidation signals. |
| Temporal Cloud | Orchestrates background work such as extraction, consolidation, and automation refreshes, so an accepted write survives restarts. |
| Stripe | Processes payments and holds card details. |
| Vercel | Hosts this website and counts its page views. |
Content sent to a model provider is limited to what that request needs, and comes back as the extracted facts or answer you asked for.
How long we keep it
Content stays in your workspace until you delete it. You can delete individual memories, documents, or whole namespaces at any time, and erasing a workspace removes every namespace, memory, file, and configuration it holds. Audit logs age out after their retention window. Backups expire on a rolling schedule after the data they contain has been deleted.
Enterprise deployments can set their own retention windows and data residency.
Your choices and rights
- Read it back. Every memory and document in your workspace is available through the API, the SDKs, and the dashboard.
- Delete it. Delete memories, documents, or namespaces from the dashboard or the API. Erase the whole workspace from workspace settings.
- Ask us. For access, correction, deletion, or portability requests under GDPR, UK GDPR, CCPA, or similar laws, use the contact page. We respond to verified requests within the time the applicable law allows.
- Data processing agreement. Enterprise customers can request a DPA that covers the providers listed above.
Cookies and browser storage
The dashboard sets a cookie to keep you signed in. This website stores your light or dark theme preference in your browser and counts page views with Vercel Web Analytics, which sets no cookies and does not follow you to other sites. Neither the dashboard nor this website uses advertising trackers.
Security
Traffic to and from Illumina is encrypted in transit with TLS. Uploaded files are encrypted at rest in object storage. API keys are scoped to the namespaces you choose at creation, shown once, and can be revoked at any time. Every workspace is isolated from every other workspace at the database layer.
Children
Illumina is not directed at children under 16, and we do not knowingly collect their information.
Changes
When this policy changes we update the date at the top of this page. For material changes we also email workspace owners.
Contact
Questions about this policy go to the contact page.