Skip to content
Cala
Download

Privacy policy

Last updated 2 August 2026. Lumino Solution LLC, trading as Cala. Version history.

This notice explains what Cala does with personal data, in plain language, with no exceptions hidden in a subclause. The short version: we hold an email address, a plan, some usage counters and a spend cap. Your documents, your chats and your investigations stay on your own machine.

1Who we are and what this covers

Lumino Solution LLC, trading as Cala, decides why and how your data is used.

The controller of your personal data is Lumino Solution LLC, trading as Cala. Our registered address is 5830 E 2nd St, Ste 7000 #25538, Casper, WY 82609, United States. For anything in this notice, write to privacy@calalayer.com.

This notice covers the Cala website at calalayer.com, the Cala account you sign in with, and the Cala desktop application. It does not cover the equipment documentation you keep on your own machine, because we never receive a copy of it.

We have not appointed a data protection officer, because our processing does not meet the threshold that requires one. Questions go to the address above and are answered by a person.

2What we collect

An email address, a plan, usage counters and a spend cap.

Your account

When you create an account we store your email address and the authentication identity our provider creates for it: an internal user id, a hash of your password, and the times you signed in. We never see your password in readable form.

Your subscription

We store which plan you are on, whether the subscription is active, when it renews, and an identifier that links your account to your billing record. Your name, billing address and payment method are given to Stripe at checkout and are held by Stripe, not by us. We never receive or store your card number.

Usage metering

To enforce plan limits and your spend cap we record metering events: a timestamp, your user id, the plan in force, and counters describing how much work was done. These counters describe the size of the work, not its subject. Nothing in a metering event says what machine you were working on or what you asked.

Messages you send us

Contact happens by email. What you send to our addresses lives in our mailbox, not in this database: your address, your message and the thread, kept for as long as the conversation needs and deleted when you ask.

Website requests

Our hosting provider keeps short-lived operational logs of requests to the website, including the IP address and browser type that made them. These exist so the site can be served and abuse can be stopped. The site sets only the cookies needed to keep you signed in, which is why you are not asked to dismiss a consent banner.

We do not run advertising or cross-site tracking. Traffic measurement uses Google Analytics in a cookieless, consent-denied configuration: it sets no cookies, carries no advertising identifiers, reports in aggregate, and never ties a visit to your account. That shape is what an earlier version of this policy promised any measurement would take, and it is listed in the subprocessor register.

3What we do not collect

Not your documents, not your chats, not your card number, and no advertising profile.

The following never reaches our database. This is an architectural property, not a promise of good behaviour.

  • Document content. The OEM manuals, drawings and specifications you read into Cala are not stored on our servers.
  • Chat content. Your questions and Cala’s answers are not stored on our servers.
  • Extracted knowledge, investigations and reports. The model Cala builds of your machine, and everything you produce from it, is not stored on our servers.
  • Card numbers. Payment details go directly to Stripe and never touch our systems.
  • Advertising profiles, location tracking and cross-site identifiers. We build none of these and sell nothing to anyone.
  • Special category data. We do not ask for it and you should not send it to us.

We also do not keep a record of what you troubleshoot. Nobody at Cala can look up which tool you were fixing, because that record does not exist on our side.

4The local-first invariant

Chat and document content never persists on our servers. It lives on your machine.

Cala is a desktop application. Extracted knowledge, chat history, investigations and exported reports live in a SQLite database on your own computer, under your control.

When you ask a question or read a document, the message and the specific part of the document being processed pass through our server to the inference provider. Our server acts as a stateless proxy: the content is held in memory for the length of the request and is never written to our database. The answer comes back and is saved on your machine.

The local-first invariant means exactly this: content transits our infrastructure, and it never persists there. What the inference provider then does with the request is governed by its own terms. We link those terms from the subprocessor register, so you can read them yourself rather than take our summary of them.

We cannot see what you loaded, and that is not permission to load it

Because your documents stay on your machine and are never stored on our servers, we have no way to see what you have loaded. Nobody here can list your documents, and no support request will produce them.

That is a security property, and it is not a licence. Cala does not encourage or condone loading material you have no right to use. You have to be entitled to load a document, and the agreements and policies that bind you at work bind you here too. The clause that sets this out is in the terms, under acceptable use.

The honest limits of this

Content does leave your machine while a request is being answered. If your site policy forbids document pages reaching an external inference provider at all, Cala does not meet that policy today, and we would rather you knew that now.

The local database is not separately encrypted by Cala. It is protected by your operating system, so full-disk encryption on the machine is what protects it if the machine is lost.

Because we never hold your content, we cannot recover it for you. If you delete the application and its data folder, that work is gone.

6Who else processes it

Four companies, each with a narrow job, all listed with their regions.

We use four companies to process data on our behalf. Each is bound by a data processing agreement and may only act on our instructions.

The current subprocessor register. Changes are announced before they take effect.
SubprocessorWhat it doesWhat it receivesRegion
Anthropic, PBCModel inference for chat answers and document readingThe message and the part of the document being processed, in transit onlyUnited States
SupabaseAuthentication, account database and the server-side proxy functionsEmail address, authentication identity, plan, usage counters, spend capUnited States
StripeSubscription billing and payment processingName, email address, payment method, invoices, metered usage totalsUnited States
VercelHosting for this website and the account pagesThe network requests that serve the site, including IP address and browser type in short-lived logsUnited States

The full register, including what each provider is contractually held to, is published at /subprocessors and kept in version control, so you can see when it last changed.

We do not sell personal data, and we do not share it with anyone for their own purposes. We would disclose data if the law required it, and we would tell you unless we were forbidden from doing so.

7International transfers

Processing happens in the United States, under standard contractual clauses.

Lumino Solution LLC is a United States company and all four subprocessors process data in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, your data is therefore transferred outside your own country.

Those transfers rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved. The clauses are incorporated into the data processing agreement we hold with each provider.

We have assessed the transfers and applied the measures available to us: encryption in transit, and a strict minimum of data leaving the account database. The local-first architecture also keeps your engineering content out of storage entirely. You can ask us for the transfer mechanism that applies to a specific provider.

8How long we keep it

Metering records go at 24 months. Email threads are kept only as long as needed. Backups roll off after that.

We keep personal data only as long as it has a purpose. The schedule below is the policy we hold ourselves to, and it is the same schedule recorded in our internal security baseline.

DataHow long we keep itWhy that period
Account record: email address and authentication identityLife of the account, deleted when you delete the accountWe need it to sign you in
Subscription record (subscriptions)Life of the account, then only as long as accounting law requiresIt is the record of what you bought
Metering events (usage_events)24 monthsA metering input, not a tax record
Current period counters (usage_periods)Life of the account, plus a short tail for billing correctionsThey describe where you are this month
Email you send to our addressesAs long as the thread needs; deleted on requestReplying, and keeping track of the conversation
Chat, documents, extracted knowledge, investigations and reportsNot held by us at allThey live on your machine, under your control

Why 24 months, and not seven years

Stripe is the financial system of record for Cala. Invoices, charges and tax records live there and are kept for the period the law requires of them.

That makes our usage_events and contact_messages tables inputs to metering and support, not books of account. No tax minimum binds them. Storage limitation under Article 5(1)(e) argues for the shortest period that still works, and 24 months is what a billing dispute or a year-on-year usage question actually needs.

Backups

Our account database is backed up. A record can be deleted by the retention schedule, or because you deleted your account. Either way, a copy can survive in an encrypted backup until that backup expires. Backups expire after no more than 30 days.

Backups are only ever used to restore the service after a failure, never to bring back a deleted account. If a restore ever did reinstate deleted records, we would delete them again.

9Your rights and how to use them

You can see it, correct it, export it and delete it, from your account page.

If the UK or EU GDPR applies to you, you have the rights below. Comparable rights exist under other privacy laws, and we apply the same process to everyone rather than sorting people by jurisdiction.

  • Access. Ask for a copy of the personal data we hold about you.
  • Rectification. Have anything inaccurate corrected.
  • Erasure. Have your account and its data deleted.
  • Restriction. Ask us to pause processing while a dispute is resolved.
  • Portability. Receive your account data in a machine-readable file, or have it sent to another provider.
  • Objection. Object to processing we base on a legitimate interest.
  • Withdraw consent. Where we rely on consent, withdraw it at any time, without affecting what was lawful before.

How to exercise them

Your account page shows what we hold, offers an export, and offers deletion behind a typed confirmation. That is the fastest route and it needs no correspondence with us.

You can also write to privacy@calalayer.com. We answer within one month, and tell you if a complicated request needs longer. There is no charge unless a request is manifestly unfounded or excessive, and we would explain before charging anything.

What deleting your account does not reach

Deleting your account removes your profile, subscription record and metering events from our servers, and cancels your subscription so it does not renew. Tell the privacy contact if you also want our email threads with you deleted.

It does not touch the knowledge base, investigations or reports on your own machine, because we cannot reach them. Delete the application and its data folder to remove those. It also does not delete the invoice and tax records Stripe is required by law to keep.

10Complaining to a supervisory authority

You can go to your data protection regulator without asking us first.

If you think we have handled your data badly, tell us first if you are willing, at privacy@calalayer.com. We would rather fix it than argue about it.

You do not have to come to us first. You have the right to complain to the data protection supervisory authority in the country where you live, where you work, or where you think the problem happened. In the United Kingdom that is the Information Commissioner’s Office.

11Age limit

Cala is a professional tool and is not for anyone under 18.

Cala is a professional tool sold to working engineers. It is not intended for anyone under 18, and we do not knowingly create accounts for children.

If you believe someone under 18 has an account with us, write to privacy@calalayer.com and we will delete it and the data attached to it.

12Changes to this notice

Every version is dated and kept in a public changelog.

When this notice changes, the date at the top changes with it, and the change is recorded in the legal changelog so you can see what moved and when.

If a change materially affects how we use your data, we will tell account holders by email before it takes effect rather than relying on you to check this page.