Contents
1. Who we are
Bloom Corp Ltd ("Bloom", "Lumo", "we", "us") is the data controller for the personal data collected through the Lumo app and this website (the "Service"). We are registered in England and Wales.
We process personal data in line with the UK GDPR and the Data Protection Act 2018. This policy explains what we hold, why we hold it, and what you can do about it. Because Lumo acts on your behalf by writing to companies, claiming refunds and negotiating prices, section 5 sets out exactly what leaves us and when.
2. What we collect
2.1 What you give us
- Account details: name, email address, password (stored hashed), and your app settings and preferences.
- Task information: what you're claiming and why, account or reference numbers with the company concerned, the price you're prepared to accept, and anything else you tell the agent so it can make your case.
- Documents you upload: bills, invoices, receipts, letters, order confirmations and photographs used as evidence.
- Facts you ask us to remember: reusable details such as an account number or a standing preference ("never sign me into a new contract"), so the agent doesn't ask twice.
- Support messages: anything you send us directly.
2.2 Bank data, if you connect an account
- Accounts: account name, type, balance, currency, sort-code and account identifiers as provided.
- Transactions: date, amount, description, merchant and category.
- Connection details: bank name, connection status and consent expiry.
This access is read-only. We receive it through a regulated open banking provider and never see your banking credentials.
2.3 Email, if you connect an account
- Permission to send from your address, and the messages we send for tasks you have authorised.
- Replies received at the Lumo-controlled reply address, including whatever the company chooses to put in them.
We ask for send-only permission. We do not request access to read your mailbox, and we do not scan your inbox.
2.4 What the agent produces
- Opportunities: what we think is worth acting on, and why.
- Task records: every step the agent took, the channel it used, what it sent and what came back.
- Evidence: confirmations, screenshots and parsed replies that show what a task achieved. This is what a fee is based on.
2.5 Payment and technical data
- Payment: fees are processed by Stripe. We keep a record of amounts, dates and the outcome charged for, and a token identifying your card. We do not store full card numbers.
- Device and usage: device type, operating system, app version, screens used, timestamps.
- Technical: IP address, error logs and performance data.
3. Why, and on what legal basis
| Running your account and carrying out tasks you authorise | Performance of our contract with you. |
|---|---|
| Reading your transactions and documents to find opportunities | Performance of our contract, on the basis of the consent you give when connecting each source. |
| Corresponding with companies in your name | Performance of our contract, under the authority you give for that task. |
| Charging our fee and keeping financial records | Performance of our contract; legal obligation. |
| Keeping the Service secure and preventing fraud or misuse | Our legitimate interests, and legal obligation. |
| Fixing faults and improving how well the agent works | Our legitimate interests in providing a service that works. |
| Service messages you can't opt out of (a task needs you, a fee was charged) | Performance of our contract. |
| Marketing and product updates | Your consent, withdrawable at any time. |
4. Who we share it with
We do not sell your personal data, and we do not share it for advertising. We share it in four situations:
4.1 Companies we contact for you
See section 5. This is the one that matters most, and it only ever happens for a task you approved.
4.2 Providers who help us run the Service
| Open banking provider | To connect to your bank and retrieve balances and transactions. |
|---|---|
| Amazon Web Services | Hosting, storage and authentication of the Service, in European regions. |
| Anthropic | The AI models the agent runs on. Content sent for processing is not used to train their models. |
| Google (Gmail API) | Sending messages from your address, where you have connected an email account. |
| Browser automation provider | Completing forms and processes on company websites where no email or API route exists. |
| Stripe | Processing success-fee payments. |
| Analytics and error reporting | Understanding faults and how the app is used. |
Each is bound by a data processing agreement, may only act on our instructions, and may only use your data to provide their service to us.
4.3 Where the law requires it
We may disclose data if required by law, court order or a regulator, or where necessary to protect our rights or someone's safety.
4.4 If the business changes hands
In a merger, acquisition or sale of assets, data may transfer to the acquirer. We will tell you, and this policy continues to apply until you are given a new one.
5. Acting on your behalf: what leaves us
To claim a refund, negotiate a price or cancel a service, we have to identify you to the company concerned. When you authorise a task, we may disclose to that company:
- your name and email address;
- your account, order, booking or policy reference with them;
- the details of the matter: dates, amounts, what happened and what you want;
- supporting evidence you have provided, such as a receipt, invoice or photograph;
- where relevant to a negotiation, the price you currently pay and comparable prices we have researched.
We disclose the minimum needed to make your case. We do not send your bank statements, your balances, your transaction history or details of any unrelated account, and we do not disclose one company's information to another.
Once your details are with that company, their own privacy policy governs what they do with them. We cannot control or delete data held by them, though you can exercise your rights with them directly.
Correspondence about your task returns to a Lumo-controlled reply address, and the agent reads it in order to act on it. You can see it all in the app.
6. Google API Services Limited Use
Lumo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, for the one Google permission we ask for:
- We request a single scope,
gmail.send, and use it only to send messages for a task you have authorised. We do not request permission to read, search or download your mailbox, and we cannot do so. - We do not use Google user data for advertising, and we do not sell it or transfer it to data brokers or information resellers.
- We do not transfer it to others except as necessary to provide or improve the Service, to comply with applicable law, or as part of a merger or acquisition with your notice.
- No human at Lumo reads it, except with your explicit consent, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and de-identified.
- We do not use it to train generalised artificial-intelligence or machine-learning models.
You can revoke this permission at any time in the app, or from your Google account's security settings.
7. AI and automated processing
Lumo is built on large language models. They are used to interpret your transactions and documents, decide what is worth acting on, draft correspondence, read replies and choose the next step.
Approval stays with you. We do not make decisions producing legal or similarly significant effects on you by automated means alone: consequential actions are shown to you and require your approval, and a task pauses and asks rather than proceeding beyond what you authorised. You can ask a person at Lumo to review anything the agent did.
Training. We do not train models on your identifiable personal or financial data, and our AI providers do not train on the content we send them. Where we use information to improve how the agent performs, it is aggregated and de-identified first.
Content we receive is treated as untrusted. Emails, web pages and documents are processed as information, never as instructions. Content arriving from outside cannot change what the agent has been authorised to do.
8. How long we keep it
| Account data | Until you delete your account, plus up to 30 days to complete deletion. |
|---|---|
| Bank transactions | A rolling 24 months, and deleted when you disconnect the account and ask us to remove it. |
| Task records, correspondence and evidence | Up to 6 years where they support a fee we charged or a matter that could be disputed. Otherwise deleted with your account. |
| Documents you upload | Until you delete them, or with your account. |
| Payment records | 6 years, as required for UK financial and tax records. |
| Usage analytics | Aggregated and anonymised after 12 months. |
9. Security
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
- Access tokens for banks and email accounts are encrypted, and decrypted only at the moment they are used.
- Least-privilege access controls, structured logging with sensitive fields redacted, and audit trails on every action the agent takes.
- Automation runs in isolated sessions, separated per task.
- Multi-factor authentication support, regular security review and an incident response process.
No system is perfectly secure, but if a breach affects your data and creates a high risk to you, we will tell you and the ICO without undue delay.
10. Your rights
Under UK data protection law you have the right to:
- Access the personal data we hold about you, and export it from the app;
- Correct anything inaccurate;
- Delete your data (deleting your account in settings does this), subject to records we must keep by law;
- Restrict or object to processing based on our legitimate interests, and to object to direct marketing at any time;
- Portability: receive your data in a structured, machine-readable format;
- Withdraw consent where processing relies on it, including by disconnecting a bank or email account;
- Human review of anything the agent decided or did on your behalf.
Contact us through the app or by email and we will respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk, though we'd rather you gave us the chance to put it right first.
11. Managing your connections
Every data source is optional and removable. Lumo works without any of them, because you can simply tell the agent what you pay for.
- Bank: disconnect in the app or through your bank's open banking portal. We revoke the token and stop receiving data; ask us and we'll delete what was already synced. Open banking consent expires roughly every 90 days anyway.
- Email: disconnect in the app, or revoke Lumo's access in your Google account settings. We can then no longer send on your behalf.
- Documents: delete any file individually.
- Card: remove it once you have no outstanding fees.
12. International transfers
Our infrastructure is hosted in European AWS regions. Some providers, including AI processing, may process data outside the UK or EEA. Where they do, we rely on UK adequacy regulations or on Standard Contractual Clauses with the UK Addendum, together with appropriate technical safeguards.
13. Children
Lumo is for adults. It is not intended for anyone under 18 and we do not knowingly collect their data. If we discover that we have, we will delete it promptly.
14. Changes and contact
If we change this policy in a way that materially affects you, we'll tell you in the app or by email before it takes effect, and update the date at the top.
Data protection enquiries
Bloom Corp Ltd
United Kingdom
Email us