Legal

Privacy Policy

How Lumar GEO Studio collects, uses, shares, and protects personal data, and the rights and choices available to you.

Last updated: June 24, 2026

This Privacy Policy explains how Lumar ("Lumar", "we", "us", or "our") handles personal data in connection with Lumar GEO Studio — our generative engine optimization (GEO) platform for tracking, analyzing, and improving how brands appear in AI-generated search results (together with our websites and related applications, the "Services").

We act as a data controller for the personal data we process to operate our business and provide the Services to our customers, and as a data processor for the personal data contained in content and instructions that customers submit to the Services. Where we act as a processor, our processing is governed by our agreement with the relevant customer.

This Policy is provided for transparency and does not constitute legal advice. If anything here conflicts with a negotiated agreement between Lumar and your organization, that agreement controls.

1. Who we are

Lumar GEO Studio is operated by Written Byte Ltd, trading as Lumar (formerly Deepcrawl) — a company registered in England and Wales (registration number 05936299) with its registered office at 124 City Road, London, EC1V 2NX, United Kingdom. Lumar first launched in 2010 and provides enterprise website intelligence and optimization software.

We are the data controller for the personal data we process to operate our business and provide the Services. Our Data Protection Officer is Mike Smith, who can be reached at mike@lumar.io. For general privacy enquiries, contact info@lumar.io.

2. Personal data we collect

We collect the following categories of personal data:

CategoryExamplesSource
Account dataName, work email, password credentials, company, role, team membershipYou / your administrator
Billing dataPlan, billing contact, transaction history, partial card metadataYou and Stripe
Service contentDomains, URLs, prompts, brands, and content you submit for tracking and evaluationYou
Usage dataFeatures used, pages viewed, actions taken, log and diagnostic dataAutomatically
Device & technical dataIP address, browser type, device identifiers, cookie identifiersAutomatically
CommunicationsSupport tickets, emails, survey responses, sales enquiriesYou

We do not intentionally collect special categories of personal data (such as health or biometric data), and ask that you do not submit them to the Services.

Payment details. Card payments are processed by Stripe. We do not store full card numbers; Stripe handles that data as described in the Stripe Privacy Policy.

3. How we use personal data

We use personal data to:

  • Provide, operate, secure, and support the Services;
  • Authenticate users and manage accounts (via our identity provider, Auth0);
  • Query third-party AI engines on your behalf and return the results, scores, and analysis that make up the Services;
  • Crawl and evaluate the website content you submit for AI-readiness;
  • Process payments, manage subscriptions, and prevent fraud;
  • Communicate with you about the Services, including service notices and, where permitted, marketing;
  • Monitor, analyze, and improve the performance, accuracy, and reliability of the Services; and
  • Comply with our legal, tax, accounting, and regulatory obligations.

4. Service data, analytics, and AI model improvement

Operating a GEO platform generates a large volume of data — including the AI engine responses we collect, visibility and citation scores, content evaluations, benchmarks, and aggregated trends across queries, brands, and platforms (collectively, "Service Data").

To the extent permitted by applicable law and our customer agreements, Lumar retains all right, title, and interest in the Service Data and in any aggregated, de-identified, statistical, or derived data generated through your use of the Services. We use this data to operate, secure, benchmark, develop, and improve the Services and our other products, including to train, evaluate, and refine machine-learning models and scoring methodologies.

Where we use data for these purposes, we either:

  • Aggregate or de-identify it so that it no longer identifies you or any individual and we do not attempt to re-identify it; or
  • Rely on a lawful basis described in the "Legal bases" section below.

We do not sell your personal data, and we do not share identifiable customer content with third parties to train their models except as needed to provide the Services (for example, sending your prompts to an AI engine you have asked us to query). Customer content remains owned by the customer as set out in our Terms of Service.

This approach is consistent with Lumar's Responsible AI principles: we do not submit or process customer inputs through our own AI technologies except where you configure the Services to do so (for example, by selecting prompts, brands, or domains to track), and our model development and product improvement are based on synthetic, anonymized, aggregated, or internally generated data.

5. Third-party AI engines

A core function of the Services is querying third-party AI search and language engines — such as ChatGPT (OpenAI), Google AI, Perplexity, Claude (Anthropic), and Gemini — through their official interfaces, and capturing the responses, citations, and sources they return.

You control which prompts, brands, and domains are tracked. When you configure prompts for tracking, we transmit them to the relevant AI engines so they can generate responses. Those providers process the data under their own terms and privacy policies. We encourage you not to include personal data or confidential information within tracked prompts unless necessary.

Where the EU or UK GDPR applies, we rely on the following legal bases:

  • Contract — to provide the Services to you and our customers;
  • Legitimate interests — to secure, analyze, improve, and develop the Services, to benchmark performance, and for direct marketing to business contacts, balanced against your rights;
  • Legal obligation — to comply with tax, accounting, and other legal requirements; and
  • Consent — where required, for example for certain cookies or marketing. You may withdraw consent at any time.

7. How we share personal data

We share personal data with:

  • Sub-processors and service providers that help us run the Services — including cloud hosting and database providers, Stripe (payments), Auth0/Okta (authentication), AI engine providers (to fulfill your queries), analytics, error monitoring, and email delivery providers. These parties are bound by contractual confidentiality and security obligations and may only process data on our instructions.
  • Our group companies, for the purposes described in this Policy.
  • Professional advisers, auditors, and authorities, where necessary to comply with law, enforce our terms, or protect our rights, users, and the public.
  • A successor entity, in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy.

A current list of sub-processors is available on request.

8. Cookies and similar technologies

We and our providers use cookies and similar technologies to keep you signed in, remember preferences, measure engagement, and improve the Services. Where required by law, we request consent for non-essential cookies. You can control cookies through your browser settings; disabling some cookies may affect functionality. For more detail, see the Lumar Cookie Policy.

9. Data retention

We retain personal data for as long as needed to provide the Services. We generally retain information relating to your subscription for up to five years after your subscription ends, and information used for marketing for up to two years unless you opt out earlier. We keep data longer where necessary to comply with legal, tax, and accounting obligations, resolve disputes, or enforce our agreements. Aggregated and de-identified data may be retained indefinitely. When personal data is no longer required, we delete or anonymize it.

10. International data transfers

Lumar operates internationally and may transfer personal data to countries other than your own, including the United Kingdom, the European Economic Area, and the United States. Where we transfer personal data across borders, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful transfer mechanism.

11. Security

We maintain technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, and alteration — including encryption in transit, access controls, and monitoring. No system is completely secure; please use a strong, unique password and keep your credentials confidential. If you believe your account has been compromised, contact us immediately.

12. Your rights and choices

Depending on your location, you may have the right to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent. EEA/UK residents may lodge a complaint with their supervisory authority. US residents (including in California) may have rights to know, delete, correct, and opt out of "sale" or "sharing" of personal information — we do not sell personal data.

To exercise your rights, contact info@lumar.io or our Data Protection Officer at mike@lumar.io. Where we process data on behalf of a customer (as a processor), we will refer your request to that customer. We will not discriminate against you for exercising your rights.

13. Children

The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from any unsupervised individual under the age of 18. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date above reflects the latest revision. If we make material changes, we will provide notice as required by law, for example by posting the updated Policy or contacting you.

15. Contact us

For privacy questions or to exercise your rights, contact:

  • Data Protection Officer: Mike Smith — mike@lumar.io
  • General privacy enquiries: info@lumar.io
  • Post: Written Byte Ltd (trading as Lumar), 124 City Road, London, EC1V 2NX, United Kingdom. See also our contact page.