← Back to home

Privacy policy

Effective 5 August 2026 · Last updated 5 August 2026

Bank access is read-only, so we can never move your money
We never sell your personal data
We only share your details with a company when you approve that task
We ask for permission to send email, not to read your mailbox
Your data is encrypted in transit and at rest
Delete your account, and your data, whenever you like

1. Who we are

Bloom Corp Ltd ("Bloom", "Lumo", "we", "us") is the data controller for the personal data collected through the Lumo app and this website (the "Service"). We are registered in England and Wales.

We process personal data in line with the UK GDPR and the Data Protection Act 2018. This policy explains what we hold, why we hold it, and what you can do about it. Because Lumo acts on your behalf by writing to companies, claiming refunds and negotiating prices, section 5 sets out exactly what leaves us and when.

2. What we collect

2.1 What you give us

2.2 Bank data, if you connect an account

This access is read-only. We receive it through a regulated open banking provider and never see your banking credentials.

2.3 Email, if you connect an account

We ask for send-only permission. We do not request access to read your mailbox, and we do not scan your inbox.

2.4 What the agent produces

2.5 Payment and technical data

3. Why, and on what legal basis

Running your account and carrying out tasks you authorisePerformance of our contract with you.
Reading your transactions and documents to find opportunitiesPerformance of our contract, on the basis of the consent you give when connecting each source.
Corresponding with companies in your namePerformance of our contract, under the authority you give for that task.
Charging our fee and keeping financial recordsPerformance of our contract; legal obligation.
Keeping the Service secure and preventing fraud or misuseOur legitimate interests, and legal obligation.
Fixing faults and improving how well the agent worksOur legitimate interests in providing a service that works.
Service messages you can't opt out of (a task needs you, a fee was charged)Performance of our contract.
Marketing and product updatesYour consent, withdrawable at any time.

4. Who we share it with

We do not sell your personal data, and we do not share it for advertising. We share it in four situations:

4.1 Companies we contact for you

See section 5. This is the one that matters most, and it only ever happens for a task you approved.

4.2 Providers who help us run the Service

Open banking providerTo connect to your bank and retrieve balances and transactions.
Amazon Web ServicesHosting, storage and authentication of the Service, in European regions.
AnthropicThe AI models the agent runs on. Content sent for processing is not used to train their models.
Google (Gmail API)Sending messages from your address, where you have connected an email account.
Browser automation providerCompleting forms and processes on company websites where no email or API route exists.
StripeProcessing success-fee payments.
Analytics and error reportingUnderstanding faults and how the app is used.

Each is bound by a data processing agreement, may only act on our instructions, and may only use your data to provide their service to us.

4.3 Where the law requires it

We may disclose data if required by law, court order or a regulator, or where necessary to protect our rights or someone's safety.

4.4 If the business changes hands

In a merger, acquisition or sale of assets, data may transfer to the acquirer. We will tell you, and this policy continues to apply until you are given a new one.

5. Acting on your behalf: what leaves us

To claim a refund, negotiate a price or cancel a service, we have to identify you to the company concerned. When you authorise a task, we may disclose to that company:

We disclose the minimum needed to make your case. We do not send your bank statements, your balances, your transaction history or details of any unrelated account, and we do not disclose one company's information to another.

Once your details are with that company, their own privacy policy governs what they do with them. We cannot control or delete data held by them, though you can exercise your rights with them directly.

Correspondence about your task returns to a Lumo-controlled reply address, and the agent reads it in order to act on it. You can see it all in the app.

6. Google API Services Limited Use

Lumo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice, for the one Google permission we ask for:

You can revoke this permission at any time in the app, or from your Google account's security settings.

7. AI and automated processing

Lumo is built on large language models. They are used to interpret your transactions and documents, decide what is worth acting on, draft correspondence, read replies and choose the next step.

Approval stays with you. We do not make decisions producing legal or similarly significant effects on you by automated means alone: consequential actions are shown to you and require your approval, and a task pauses and asks rather than proceeding beyond what you authorised. You can ask a person at Lumo to review anything the agent did.

Training. We do not train models on your identifiable personal or financial data, and our AI providers do not train on the content we send them. Where we use information to improve how the agent performs, it is aggregated and de-identified first.

Content we receive is treated as untrusted. Emails, web pages and documents are processed as information, never as instructions. Content arriving from outside cannot change what the agent has been authorised to do.

8. How long we keep it

Account dataUntil you delete your account, plus up to 30 days to complete deletion.
Bank transactionsA rolling 24 months, and deleted when you disconnect the account and ask us to remove it.
Task records, correspondence and evidenceUp to 6 years where they support a fee we charged or a matter that could be disputed. Otherwise deleted with your account.
Documents you uploadUntil you delete them, or with your account.
Payment records6 years, as required for UK financial and tax records.
Usage analyticsAggregated and anonymised after 12 months.

9. Security

No system is perfectly secure, but if a breach affects your data and creates a high risk to you, we will tell you and the ICO without undue delay.

10. Your rights

Under UK data protection law you have the right to:

Contact us through the app or by email and we will respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk, though we'd rather you gave us the chance to put it right first.

11. Managing your connections

Every data source is optional and removable. Lumo works without any of them, because you can simply tell the agent what you pay for.

12. International transfers

Our infrastructure is hosted in European AWS regions. Some providers, including AI processing, may process data outside the UK or EEA. Where they do, we rely on UK adequacy regulations or on Standard Contractual Clauses with the UK Addendum, together with appropriate technical safeguards.

13. Children

Lumo is for adults. It is not intended for anyone under 18 and we do not knowingly collect their data. If we discover that we have, we will delete it promptly.

14. Changes and contact

If we change this policy in a way that materially affects you, we'll tell you in the app or by email before it takes effect, and update the date at the top.

Data protection enquiries
Bloom Corp Ltd
United Kingdom