Privacy Policy

Privacy Policy

Lumen Flow Privacy Policy: local architecture, data encryption, zero tracking, and user privacy commitment.

Last updated: August 2026

This Privacy Policy (“Policy”) describes the principles and practices regarding data processing within the Lumen Flow application (“Software” or “Application”), the raylyt.com website, and communications sent to RAYLYT DESIGN SYSTEMS LTDA, Brazilian corporate taxpayer ID (CNPJ) 68.516.965/0001-75, with its registered office in Anápolis, Goiás, Brazil (“raylyt”, “we”, or “Controller”).

We are committed to respecting user privacy through an architecture built on data minimization and local processing. For privacy matters or to exercise rights relating to personal data, contact us at support@raylyt.com.


1. Fundamental Principles

1.1. Local Processing: The Software is designed to operate primarily offline (offline-first). Your work data belongs exclusively to you and remains on your device.

1.2. No User Registration: Use of the Software requires no account creation, registration forms, prior authentication on our servers, or provision of personally identifiable information.

1.3. Zero Tracking: The Software contains no third-party Software Development Kits (SDKs), telemetry tools, analytics trackers, or advertising networks.

1.4. Website and Communications: This Policy also applies to personal data voluntarily provided when you write to support@raylyt.com, including in relation to the waitlist, support, feedback, or partnerships.


2. Data Collection, Storage, and Encryption

2.1. Work Data: All request flows (“Flows”), workspaces (“Spaces”), configuration profiles (“Profiles”), and execution histories created or managed in the Application are stored in a local database on the User’s device, and are additionally synchronized only where User enables Git Sync or iCloud Sync, as described in Section 4.

2.2. Credential Encryption: Sensitive information and secrets (API keys, passwords, authentication tokens, OTP seeds) are stored with support from the operating system’s native Keychain and/or encrypted using the AES-256-GCM algorithm, with key derivation via PBKDF2-HMAC-SHA256 (600,000 iterations).

2.3. No Proprietary Storage Servers: Licensor does not maintain or operate its own cloud infrastructure, central databases, or intermediate servers to receive or copy User content. Where iCloud Sync is enabled, data is transmitted to and stored within Apple’s own iCloud infrastructure, as described in Section 4.

2.4. Messages Sent to Raylyt: When you write to us, we may process your name, email address, message content, and metadata normally associated with the communication. We use this data solely to respond to your request, manage the relationship initiated by you, and, when requested, keep you informed about the Lumen Flow waitlist. Messages are received directly by raylyt in its support inbox; they are not used for behavioral advertising or sold to third parties.


3. Network Communications and Request Execution

3.1. Request Execution: The Software enables Users to design, run, and automate flows that make HTTP/HTTPS calls. Requests dispatched by the Application are sent directly from the User’s device to destination endpoints explicitly configured by the User, without interception, routing, or inspection by Licensor.

3.2. Artificial Intelligence Features: Artificial intelligence assistant features operate entirely on-device, without transmitting data, payloads, or responses to external AI servers or cloud services.


4. Synchronization Features (Git Sync and iCloud Sync)

4.1. Git Sync: If User chooses to enable this local synchronization feature, the Software exports workspace structures in JSON format to a local directory selected by User.

4.2. The Software makes no automatic connections to external code hosting platforms. Control, committing, and pushing these files to remote repositories rests solely with User via User’s own git tools.

4.3. Credentials and secrets contained within exported files remain encrypted or omitted according to security settings configured by User.

4.4. iCloud Sync: If User enables iCloud Sync, the Software uses Apple’s iCloud service (via CloudKit) to synchronize workspace data — such as Spaces, Flows, and Profiles — across devices signed in to the same Apple ID.

4.5. Data synchronized through iCloud Sync is transmitted to and stored within Apple’s own iCloud infrastructure, tied exclusively to User’s personal Apple ID, and is governed by Apple’s own privacy and security practices, independent of Licensor.

4.6. Licensor does not operate, access, or have visibility into iCloud infrastructure or its contents. Credentials and secrets included in synchronized data remain encrypted according to the standards described in Section 2.2.

4.7. International Transfers: raylyt does not operate its own infrastructure to transfer personal data abroad and does not transfer messages sent to its support channel on its own initiative. iCloud Sync is an optional feature operated on Apple’s infrastructure and is subject to Apple’s practices described in Sections 4.4 through 4.6. If raylyt begins to make international transfers of personal data through its own means, we will update this Policy before adopting that practice, with the applicable information and safeguards.


5. Financial Transactions and Billing Data

5.1. Processing of subscriptions, licenses, and purchases in the Application is conducted exclusively through official distribution platforms (such as the Apple App Store via StoreKit).

5.2. Licensor does not collect, view, or store bank details, credit card numbers, or financial information. All transactions are governed by the privacy policies and operational terms of respective app stores.


6. Diagnostics and Crash Reports

6.1. Licensor does not collect automated crash reports or usage metrics independently.

6.2. Any diagnostic data collected and transmitted by the operating system occurs solely under User option and consent within device settings, governed by the operating system provider’s privacy policy.


7. User Control, Retention, and Data Rights

7.1. Because User data resides on User’s device — and, where iCloud Sync is enabled, within User’s own iCloud account — retention and deletion of information remain under full User control. User may enable or disable iCloud Sync at any time.

7.2. Permanent data deletion is performed directly by User by deleting application files, local database files, uninstalling the Software, or, where applicable, removing synchronized data through iCloud settings.

7.3. We retain messages sent to raylyt only for the period necessary to respond and manage the relationship initiated by the sender, unless retention is necessary to comply with a legal obligation or defend legal rights. You may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability where applicable, or information about the sharing of your data at support@raylyt.com, subject to applicable law.


8. Changes to this Privacy Policy

8.1. Licensor reserves the right to update this Policy periodically to reflect technical improvements or new Software features.

8.2. Any changes will be published on this page accompanied by an updated revision date. Periodic review of this document is recommended.


9. Contact Channels

9.1. For inquiries regarding this Policy, Software security practices, or the processing of personal data, contact us at: support@raylyt.com.

Questions about our legal terms?
support@raylyt.com