Lumva / Administration

Privacy Policy

Effective date
August 18, 2026

Scope and operator

This Privacy Policy explains how Escalate Enterprises, LLC processes information through the Lumva iOS application and the administrative website at lumva.org. Escalate Enterprises, LLC is a California limited liability company with its principal place of business in Irvine, California. Its public mailing address is 15615 Alton Parkway, Suite 450, Irvine, CA 92618.

Lumva is an internal, work-based organization, drafting, tracking, and informational tool. It is adult-only and limited to individually assigned Lumva employees. Lumva is not open to public registration.

A separate Chicago, Illinois nonprofit is planned but has not been formed. Lumva is not owned, operated, sponsored, or administered by a nonprofit. Lumva is not a healthcare or treatment provider, financial institution, law firm, crisis service, or government service.

The reviewed build

The reviewed pre-release iOS build stores app records locally on the device and remains local-storage based. The published Lumva website provides a protected employee workspace using Lumva-only Microsoft Entra workforce authentication. Records created or changed through that website are stored in Lumva's Cloudflare-backed workspace. Protected synchronization from the iOS app is not active, and local iOS records are not uploaded unless a future reviewed release adds that feature.

Lumva authentication is separate from Comparsa and the Escalate employee portal. Microsoft processes website sign-in and returns identity and authorization claims to Lumva. Lumva requires a named workforce identity plus an explicit Lumva app-role or group assignment. Shared interactive accounts are not authorized.

Information the user may choose to store

Lumva may process the following information when the authorized user chooses to enter it:

  • Daily planning: priorities, habits, water entries, overviews, and quick notes.
  • Salon operations and client records: client labels and contact details, services, appointments, private notes, follow-ups, revenue, and inventory.
  • Navigation notes: pseudonymous case labels, categories, status, follow-up dates, notes, and saved public resources. “Navigation” refers to work and resource navigation, not device location tracking.
  • Manual financial information: manually entered account labels, balances, transactions, debts, categories, and marketplace income. Lumva does not connect to a bank or verify these entries.
  • Receipts: a receipt image selected by the user and related metadata, stored locally in iOS or in the protected website workspace when submitted there.
  • Tax-document organization: local tax year, document type or category, title, optional storage path, and status. Lumva does not prepare or file taxes.
  • Relocation planning: savings goals, checklists, research, milestones, captions, and source links.
  • Nonprofit launch planning: roadmap tasks, decision responses, board-role status, compliance items, grant opportunities, pilot planning, risks, records folders, sources, and verification results.
  • Wellness information: weight entries, habits, wellness wins, energy notes, and other optional notes. The reviewed build does not use HealthKit and is not designed to diagnose, treat, or manage a medical condition.
  • Message drafts: recipient labels, subjects, response templates, and message text. Lumva does not automatically send drafts.
  • Goals: goals, milestones, and future-self letters.
  • Account, assistant, or administrative information: local preferences, approval state, inactive integration settings, Qwen conversation text submitted during a signed-in browser session, local synchronization status, and working administrative references. Assistant conversations are not saved as workspace records or placed in browser storage by Lumva.

The authorized user should not enter unnecessary medical records, substance-use records, complete financial credentials, government identifiers, full tax records, employer-owned confidential information, patient information, or third-party client information that is not needed for the authorized work purpose.

How information is used

Lumva uses local iOS information and protected employee-workspace information to display, organize, draft, calculate, track, synchronize web sessions, and update the features selected by the authorized user. The reviewed build does not use records for advertising, behavioral profiling, sale, sharing for cross-context behavioral advertising, or automated eligibility decisions.

Lumva does not automatically send messages, contact providers, move money, file documents, create calendar events, or create records in an external service. Any output is a draft or organizational aid that the user must review.

When the in-product Qwen status shows ready, Lumva sends the user's conversation text and approved nonprofit planning context to Alibaba Cloud Model Studio to produce a streamed, proposal-only response. Lumva does not give Qwen authority to change a workspace record or take an external action.

Local and protected cloud storage

Structured records are stored in files inside the Lumva iOS app container. The reviewed local files use iOS complete file protection. Selected receipt images are stored in a separate protected folder.

Structured records may be included in an Apple device backup when the user enables backup. Apple controls the backup service, its security, retention, and restore behavior under the user's Apple settings and agreements. Lumva marks saved receipt image files to be excluded from device backup. Excluding receipt files does not exclude the structured records that may refer to them.

Removing Lumva from the device ordinarily removes its local app container, but structured records may remain in an Apple backup and could be restored according to Apple's settings. Preserve any needed information before removing the app.

The employee website stores structured workspace records in a private Cloudflare D1 database. Private receipt images uploaded through the website are stored in Cloudflare R2, with ownership metadata and server-generated object paths scoped to the signed-in employee's Microsoft tenant ID and object ID. Lumva does not place workspace records, receipt images, Microsoft access tokens, or passwords in browser storage.

Device permissions and user-initiated actions

Lumva uses Apple's system photo picker only after the user chooses to add a receipt image. The picker gives Lumva access only to the image the user selects. Lumva does not request broad photo-library access.

The employee website may request microphone access only after the user taps the voice control. Compatible browsers may use their own speech-recognition service to convert speech into text under the browser or operating-system provider's terms. Lumva receives the resulting text and does not intentionally record or store microphone audio. The reviewed build does not request camera, contacts, calendar, HealthKit, location, notification, Bluetooth, email, or biometric permission. It does not collect device geolocation.

Technical logging

The app uses Apple unified logging for reviewed allowlisted technical metadata. The reviewed logging implementation did not verify logging of private app-record content. No external crash-reporting or analytics SDK is active.

No security method can guarantee that information will never be lost, accessed, or disclosed. The user should protect the iPhone with a strong passcode, keep iOS current, limit physical access, and choose backup settings appropriate for the sensitivity of the records.

Active service providers and external recipients

The following services have an active or planned role:

  • Apple: provides iOS, the app sandbox, file protection, the system photo picker, unified logging, optional device backup, and later private beta distribution if approved. Apple receives information according to the user's Apple settings and Apple's privacy terms.
  • OpenAI Sites and Cloudflare: OpenAI Sites packages and manages the website deployment. Cloudflare registers the lumva.org domain, provides authoritative DNS, hosts and delivers the website through Cloudflare Workers, stores structured employee-workspace records and operational rate-limit counters in D1, and stores private receipt images in R2. Lumva stores limiter scope keys only as HMAC values, not raw IP addresses or identity keys. Cloudflare may process workspace content, receipt images, Microsoft tenant and object identifiers, IP address, request method, requested URL, browser or user-agent information, timestamps, response status, and security events as needed to provide those services.
  • Microsoft: Microsoft Entra processes assigned-employee website sign-in and authorization claims. Microsoft 365 and Outlook process support and privacy correspondence, including sender and recipient addresses, message content, headers, attachments, and response history.
  • Alibaba Cloud Model Studio: When the Lumva assistant status shows Qwen ready and the user submits a message, Alibaba processes the submitted conversation text, approved planning context, and technical request metadata to generate the response. Lumva requests no provider-side response storage and disables DashScope session caching, but Alibaba's service terms, security practices, and operational processing still apply.
  • Browser and operating-system speech services: if the user chooses voice input or spoken output, the browser or operating system may process microphone input or synthesized speech under its own terms. Availability and processing vary by device and browser.
  • External websites selected by the user: a public resource or reference link may open in the browser only when selected. The external site's terms and privacy practices then apply.

Cloudflare Worker invocation logs, if enabled for the published site, will be limited to Cloudflare's maximum retention period of seven days. Escalate will not enable Web Analytics, Logpush, advertising analytics, tracking pixels, or custom logging of employee-workspace content. Access to operational logs and cloud storage will be limited to operator-authorized administrators who need it for security, support, maintenance, legal compliance, or a verified privacy request. These settings are reviewed as part of each deployment and material hosting change.

Inactive integrations

Firebase, Google Calendar, Gmail integration, Microsoft 365 Copilot, analytics, advertising, external crash reporting, bank connections, payment processing, synchronization from the iOS app, and automatic message sending are not active. The Qwen interface remains unavailable unless its in-product status shows ready. OpenAI Sites is used for website deployment and does not itself provide Lumva's Qwen responses. Future-facing interfaces, example configuration, integration seams, or mock controls do not mean that these services receive information.

Other Escalate products, including Comparsa, do not share Lumva authentication or app records merely because they may have a common operator or affiliation.

Website privacy

The published lumva.org website uses Lumva employee sign-in and a protected session cookie. The protected employee workspace allows an authorized employee to create, edit, synchronize, and tombstone records and to upload or download supported receipt images. The site also contains a proposal-only Qwen conversation interface for assigned employees. The site has no public account creation, public contact form, advertising, analytics, tracking pixel, marketing cookie, or general client-side record storage. Lumva does not save assistant messages in browser storage or the employee-record database. It does not load third-party scripts for the legal pages. Fonts are bundled with the site.

The website does not track visitors over time across unrelated websites. Because it does not engage in cross-site tracking, it does not respond differently to browser Do Not Track signals or Global Privacy Control signals. Escalate does not knowingly permit third parties to collect personally identifiable information about a visitor's activities over time across different websites through lumva.org. If these practices change, this Policy will be updated before the change is activated.

Support and privacy correspondence

A person who emails Escalate chooses to provide an email address, message content, headers, attachments, and any other information included in the request. Escalate uses that information to authenticate the request when appropriate, troubleshoot, respond, maintain security, document compliance, and protect legal rights.

Do not email passwords, authentication codes, financial account numbers, payment-card numbers, complete medical or substance-use records, complete tax records, government identifiers, full receipt collections, or unnecessary client information.

Escalate will generally retain support and privacy correspondence for up to 24 months after the last substantive interaction. It may delete information sooner when it is no longer needed or retain it longer when reasonably necessary for security, fraud prevention, a legal hold, dispute handling, or another legal obligation. Deleted messages may remain temporarily in Microsoft's recoverable systems and backups according to Microsoft 365 settings and service terms.

Retention, deletion, export, and recovery

Local iOS records remain on the device until the user changes them, uses an available local deletion control, removes the app container, or restores a different local state. Available deletion controls vary by record type. The reviewed build has no complete erase-all or export-all feature. A local deletion control may update the saved record state without immediately overwriting every byte in a serialized file or an Apple backup.

Escalate cannot remotely inspect, recover, export, correct, or delete local iOS records because it does not receive those records. Employee identity lifecycle and assignment changes are administered in Lumva's Microsoft tenant.

Website record deletion creates a synchronization tombstone and does not immediately erase prior record versions from the append-only D1 history. Cloud records and receipt objects are retained while needed for the authorized workspace, security, recovery, compliance, dispute handling, or legal obligations. Lumva does not currently provide a complete export-all or erase-all control. A verified request may require operator-assisted export, correction, or deletion from D1 and R2. Provider backups or recoverable systems may retain deleted data temporarily under provider terms.

Choices and requests

The California Consumer Privacy Act does not currently apply to Escalate based on the verified size and processing facts. This Policy does not claim that a person has CCPA rights against Escalate when the statute does not apply.

A person may nevertheless ask Escalate to provide, correct, or delete support, privacy, website, or employee-workspace information that Escalate controls. Escalate will evaluate a request in good faith, verify identity when appropriate, and comply with applicable nonwaivable law. A request cannot give Escalate access to local app records that it does not receive. Escalate may retain information when reasonably necessary for security, legal compliance, dispute handling, or another lawful purpose. This does not give Escalate access to local iOS records that were never uploaded.

To make a privacy request, contact: support@lumva.org. Postal requests may be sent to Escalate Enterprises, LLC, 15615 Alton Parkway, Suite 450, Irvine, CA 92618.

Adults only

Lumva is restricted by policy to authorized adults and is not directed to children. Escalate does not knowingly permit a child to register for Lumva because Lumva has no public registration. Contact Escalate if you believe a child has provided information through the website or support channel.

Changes to this Policy

Escalate will review this Policy when Lumva's data practices, permissions, integrations, distribution, website hosting, or support services change. Material changes will be communicated by updating the effective date and posting a prominent notice on lumva.org or, when available and appropriate, providing an in-app or direct notice before the change takes effect.

Contact

Escalate Enterprises, LLC
15615 Alton Parkway, Suite 450
Irvine, CA 92618
Privacy contact: support@lumva.org