Security FAQ

A detailed, plain-language overview of the controls LuminaOS currently uses—and the limits we do not hide.

TLS

Encrypted in transit

Encrypted

Database, files, backups

14 days

Database point-in-time recovery

EU

Primary storage and DR

This page describes the verified production posture as of July 19, 2026. Security is a continuing process, and no online service can guarantee zero risk. We update this FAQ when material architecture, provider, retention, or access-control changes are verified.

Data protection and privacy

How LuminaOS protects, stores, and limits access to your information

Authentication and connected accounts

Account, session, multi-factor authentication, and Google integration controls

AI Coach and AI-assisted features

What is processed, retained, searched, and isolated when you use AI features

Infrastructure, backups, and deletion

Recovery controls, network boundaries, logging, uploads, and account deletion

Application security and assurance

How the service reduces web risk, validates changes, and communicates limitations

Have a security or privacy question?

For general security questions or responsible vulnerability reports, contact info@bright-minds.io. For privacy rights or legal questions, contact legal@luminaos.app.

Please do not send passwords, access tokens, private keys, or unnecessary personal data by email.

Last verified against the production security posture: July 19, 2026