Security FAQ
A detailed, plain-language overview of the controls LuminaOS currently uses—and the limits we do not hide.
TLS
Encrypted in transit
Encrypted
Database, files, backups
14 days
Database point-in-time recovery
EU
Primary storage and DR
Data protection and privacy
How LuminaOS protects, stores, and limits access to your information
Authentication and connected accounts
Account, session, multi-factor authentication, and Google integration controls
AI Coach and AI-assisted features
What is processed, retained, searched, and isolated when you use AI features
Infrastructure, backups, and deletion
Recovery controls, network boundaries, logging, uploads, and account deletion
Application security and assurance
How the service reduces web risk, validates changes, and communicates limitations
Have a security or privacy question?
For general security questions or responsible vulnerability reports, contact info@bright-minds.io. For privacy rights or legal questions, contact legal@luminaos.app.
Please do not send passwords, access tokens, private keys, or unnecessary personal data by email.
Last verified against the production security posture: July 19, 2026
