Privacy at PromoLuma
Last updated September 2026
PromoLuma is currently an early-access product. This page explains how the current website handles information and how that changes when optional services are connected.
Demo Mode
In Demo Mode, project details, Brand Kit information, recent work, plan selection, and demo credit values are stored locally in your browser using local storage. They are not sent to PromoLuma servers because a PromoLuma database is not connected in this build.
When AI is connected
If the server-side AI integration is enabled, the information you submit to an AI workflow is sent to the configured backend and AI provider so the requested output can be generated. API keys are intended to remain on the server and should never be exposed in the public website code.
When accounts are connected
If Supabase authentication is enabled, account information and saved product data may be stored in the configured Supabase project. Access should be protected with row-level security and appropriate authorization rules.
Payments
Payments are not enabled in the current public build. If Stripe is connected later, payment information should be handled by Stripe rather than stored directly by PromoLuma.
Third-party services
Connected providers may process data under their own privacy terms. Before a production launch, PromoLuma should publish a final privacy policy that accurately lists every live provider, retention period, analytics service, and user right.
Your choices
You can clear Demo Mode information by clearing this site's browser storage. Once cloud accounts are enabled, production controls should include account deletion and data-export options.
This early-access notice should be reviewed and updated before accepting paid customers.