Privacy policy
Last updated 2 August 2026. Lumino Solution LLC, trading as Cala. Version history.
This notice explains what Cala does with personal data, in plain language, with no exceptions hidden in a subclause. The short version: we hold an email address, a plan, some usage counters and a spend cap. Your documents, your chats and your investigations stay on your own machine.
1Who we are and what this covers
Lumino Solution LLC, trading as Cala, decides why and how your data is used.
The controller of your personal data is Lumino Solution LLC, trading as Cala. Our registered address is 5830 E 2nd St, Ste 7000 #25538, Casper, WY 82609, United States. For anything in this notice, write to privacy@calalayer.com.
This notice covers the Cala website at calalayer.com, the Cala account you sign in with, and the Cala desktop application. It does not cover the equipment documentation you keep on your own machine, because we never receive a copy of it.
We have not appointed a data protection officer, because our processing does not meet the threshold that requires one. Questions go to the address above and are answered by a person.
2What we collect
An email address, a plan, usage counters and a spend cap.
Your account
When you create an account we store your email address and the authentication identity our provider creates for it: an internal user id, a hash of your password, and the times you signed in. We never see your password in readable form.
Your subscription
We store which plan you are on, whether the subscription is active, when it renews, and an identifier that links your account to your billing record. Your name, billing address and payment method are given to Stripe at checkout and are held by Stripe, not by us. We never receive or store your card number.
Usage metering
To enforce plan limits and your spend cap we record metering events: a timestamp, your user id, the plan in force, and counters describing how much work was done. These counters describe the size of the work, not its subject. Nothing in a metering event says what machine you were working on or what you asked.
Messages you send us
Contact happens by email. What you send to our addresses lives in our mailbox, not in this database: your address, your message and the thread, kept for as long as the conversation needs and deleted when you ask.
Website requests
Our hosting provider keeps short-lived operational logs of requests to the website, including the IP address and browser type that made them. These exist so the site can be served and abuse can be stopped. The site sets only the cookies needed to keep you signed in, which is why you are not asked to dismiss a consent banner.
We do not run advertising or cross-site tracking. Traffic measurement uses Google Analytics in a cookieless, consent-denied configuration: it sets no cookies, carries no advertising identifiers, reports in aggregate, and never ties a visit to your account. That shape is what an earlier version of this policy promised any measurement would take, and it is listed in the subprocessor register.
3What we do not collect
Not your documents, not your chats, not your card number, and no advertising profile.
The following never reaches our database. This is an architectural property, not a promise of good behaviour.
- Document content. The OEM manuals, drawings and specifications you read into Cala are not stored on our servers.
- Chat content. Your questions and Cala’s answers are not stored on our servers.
- Extracted knowledge, investigations and reports. The model Cala builds of your machine, and everything you produce from it, is not stored on our servers.
- Card numbers. Payment details go directly to Stripe and never touch our systems.
- Advertising profiles, location tracking and cross-site identifiers. We build none of these and sell nothing to anyone.
- Special category data. We do not ask for it and you should not send it to us.
We also do not keep a record of what you troubleshoot. Nobody at Cala can look up which tool you were fixing, because that record does not exist on our side.
4The local-first invariant
Chat and document content never persists on our servers. It lives on your machine.
Cala is a desktop application. Extracted knowledge, chat history, investigations and exported reports live in a SQLite database on your own computer, under your control.
When you ask a question or read a document, the message and the specific part of the document being processed pass through our server to the inference provider. Our server acts as a stateless proxy: the content is held in memory for the length of the request and is never written to our database. The answer comes back and is saved on your machine.
The local-first invariant means exactly this: content transits our infrastructure, and it never persists there. What the inference provider then does with the request is governed by its own terms. We link those terms from the subprocessor register, so you can read them yourself rather than take our summary of them.
We cannot see what you loaded, and that is not permission to load it
Because your documents stay on your machine and are never stored on our servers, we have no way to see what you have loaded. Nobody here can list your documents, and no support request will produce them.
That is a security property, and it is not a licence. Cala does not encourage or condone loading material you have no right to use. You have to be entitled to load a document, and the agreements and policies that bind you at work bind you here too. The clause that sets this out is in the terms, under acceptable use.
The honest limits of this
Content does leave your machine while a request is being answered. If your site policy forbids document pages reaching an external inference provider at all, Cala does not meet that policy today, and we would rather you knew that now.
The local database is not separately encrypted by Cala. It is protected by your operating system, so full-disk encryption on the machine is what protects it if the machine is lost.
Because we never hold your content, we cannot recover it for you. If you delete the application and its data folder, that work is gone.
5Why we are allowed to use it
Mostly because we need it to run the service you paid for.
Under the UK and EU GDPR we need a legal basis for each purpose. Ours are set out below.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create your account and sign you in | Email address, authentication identity | Performance of a contract with you |
| Take payment and renew your subscription | Subscription record, billing identifier | Performance of a contract with you |
| Enforce plan limits and your spend cap | usage_events, usage_periods, spend cap setting | Performance of a contract with you |
| Send service emails, including the confirmation of what you bought | Email address, subscription record | Performance of a contract, and a legal obligation to confirm on a durable medium |
| Answer a message you send us | Your email address and message | Our legitimate interest in replying to you |
| Keep the service working and stop abuse | Request logs, metering counters | Our legitimate interest in the security of the service |
| Meet accounting and tax law | Invoices and payment records held by Stripe | A legal obligation |
Where we rely on a legitimate interest, we have weighed it against your interests and kept the data to the minimum that serves the purpose. You can object to that processing, and how to do so is in section 9.
We do not make automated decisions that produce a legal effect for you. Cala produces engineering guidance for a person to judge, and a person is always the decision maker.
6Who else processes it
Four companies, each with a narrow job, all listed with their regions.
We use four companies to process data on our behalf. Each is bound by a data processing agreement and may only act on our instructions.
| Subprocessor | What it does | What it receives | Region |
|---|---|---|---|
| Anthropic, PBC | Model inference for chat answers and document reading | The message and the part of the document being processed, in transit only | United States |
| Supabase | Authentication, account database and the server-side proxy functions | Email address, authentication identity, plan, usage counters, spend cap | United States |
| Stripe | Subscription billing and payment processing | Name, email address, payment method, invoices, metered usage totals | United States |
| Vercel | Hosting for this website and the account pages | The network requests that serve the site, including IP address and browser type in short-lived logs | United States |
The full register, including what each provider is contractually held to, is published at /subprocessors and kept in version control, so you can see when it last changed.
We do not sell personal data, and we do not share it with anyone for their own purposes. We would disclose data if the law required it, and we would tell you unless we were forbidden from doing so.
7International transfers
Processing happens in the United States, under standard contractual clauses.
Lumino Solution LLC is a United States company and all four subprocessors process data in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, your data is therefore transferred outside your own country.
Those transfers rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved. The clauses are incorporated into the data processing agreement we hold with each provider.
We have assessed the transfers and applied the measures available to us: encryption in transit, and a strict minimum of data leaving the account database. The local-first architecture also keeps your engineering content out of storage entirely. You can ask us for the transfer mechanism that applies to a specific provider.
8How long we keep it
Metering records go at 24 months. Email threads are kept only as long as needed. Backups roll off after that.
We keep personal data only as long as it has a purpose. The schedule below is the policy we hold ourselves to, and it is the same schedule recorded in our internal security baseline.
| Data | How long we keep it | Why that period |
|---|---|---|
| Account record: email address and authentication identity | Life of the account, deleted when you delete the account | We need it to sign you in |
| Subscription record (subscriptions) | Life of the account, then only as long as accounting law requires | It is the record of what you bought |
| Metering events (usage_events) | 24 months | A metering input, not a tax record |
| Current period counters (usage_periods) | Life of the account, plus a short tail for billing corrections | They describe where you are this month |
| Email you send to our addresses | As long as the thread needs; deleted on request | Replying, and keeping track of the conversation |
| Chat, documents, extracted knowledge, investigations and reports | Not held by us at all | They live on your machine, under your control |
Why 24 months, and not seven years
Stripe is the financial system of record for Cala. Invoices, charges and tax records live there and are kept for the period the law requires of them.
That makes our usage_events and contact_messages tables inputs to metering and support, not books of account. No tax minimum binds them. Storage limitation under Article 5(1)(e) argues for the shortest period that still works, and 24 months is what a billing dispute or a year-on-year usage question actually needs.
Backups
Our account database is backed up. A record can be deleted by the retention schedule, or because you deleted your account. Either way, a copy can survive in an encrypted backup until that backup expires. Backups expire after no more than 30 days.
Backups are only ever used to restore the service after a failure, never to bring back a deleted account. If a restore ever did reinstate deleted records, we would delete them again.
9Your rights and how to use them
You can see it, correct it, export it and delete it, from your account page.
If the UK or EU GDPR applies to you, you have the rights below. Comparable rights exist under other privacy laws, and we apply the same process to everyone rather than sorting people by jurisdiction.
- Access. Ask for a copy of the personal data we hold about you.
- Rectification. Have anything inaccurate corrected.
- Erasure. Have your account and its data deleted.
- Restriction. Ask us to pause processing while a dispute is resolved.
- Portability. Receive your account data in a machine-readable file, or have it sent to another provider.
- Objection. Object to processing we base on a legitimate interest.
- Withdraw consent. Where we rely on consent, withdraw it at any time, without affecting what was lawful before.
How to exercise them
Your account page shows what we hold, offers an export, and offers deletion behind a typed confirmation. That is the fastest route and it needs no correspondence with us.
You can also write to privacy@calalayer.com. We answer within one month, and tell you if a complicated request needs longer. There is no charge unless a request is manifestly unfounded or excessive, and we would explain before charging anything.
What deleting your account does not reach
Deleting your account removes your profile, subscription record and metering events from our servers, and cancels your subscription so it does not renew. Tell the privacy contact if you also want our email threads with you deleted.
It does not touch the knowledge base, investigations or reports on your own machine, because we cannot reach them. Delete the application and its data folder to remove those. It also does not delete the invoice and tax records Stripe is required by law to keep.
10Complaining to a supervisory authority
You can go to your data protection regulator without asking us first.
If you think we have handled your data badly, tell us first if you are willing, at privacy@calalayer.com. We would rather fix it than argue about it.
You do not have to come to us first. You have the right to complain to the data protection supervisory authority in the country where you live, where you work, or where you think the problem happened. In the United Kingdom that is the Information Commissioner’s Office.
11Age limit
Cala is a professional tool and is not for anyone under 18.
Cala is a professional tool sold to working engineers. It is not intended for anyone under 18, and we do not knowingly create accounts for children.
If you believe someone under 18 has an account with us, write to privacy@calalayer.com and we will delete it and the data attached to it.
12Changes to this notice
Every version is dated and kept in a public changelog.
When this notice changes, the date at the top changes with it, and the change is recorded in the legal changelog so you can see what moved and when.
If a change materially affects how we use your data, we will tell account holders by email before it takes effect rather than relying on you to check this page.