Skip to content

Privacy Policy

Last updated: May 14, 2026

This Privacy Policy describes what information we collect from and about you when you use our messaging service (Lumo Concierge), API, or website at thinklumo.com (collectively, the "Services"), how we store and secure that information, who we share it with, and your choices regarding your data.

When we refer to "Lumo," "we," "our," or "us," we mean Resilient Ops, Inc. This Privacy Policy is incorporated into and subject to our Terms of Service.

Information We Collect

Information You Provide to Us

Account and Profile Information. When you sign up for Lumo Concierge or API access, we collect information such as your name, email address, and phone number. If you use Lumo Concierge, we also collect travel preferences you share with us — such as your home airport, preferred airlines, seat preferences, and communication preferences — to personalize your experience.

Content You Provide Through Lumo Concierge. When you send messages to Lumo Concierge via SMS or WhatsApp, we receive and store those messages, including flight details, trip information, questions, and any other content you share. This conversation history is stored to provide continuity across sessions and to improve the quality of our responses to you.

Content You Provide by Forwarding Emails. When you forward trip confirmation emails to trips@thinklumo.com or to your personal Lumo inbox address, we parse those emails to extract flight information. While we use only flight-related information to provide the Service, forwarded emails may contain other personal or financial data. We store these emails with encryption. If you prefer not to share the contents of full emails, you can register flights directly through Lumo Concierge instead.

Content from Connected Calendars. If you connect your calendar to Lumo Concierge, we receive calendar data to the extent needed to support flight tracking and travel planning.

Information You Provide Through Support

If you contact us for support or submit feedback through Lumo Concierge, we collect any information you provide, including descriptions of issues or feedback you share.

Information We Collect Automatically

Usage Information. We collect information about how you use the Services, including features used, message frequency, notification preferences, and usage patterns.

Device and Connection Information. We collect device type, device identifiers, IP addresses, and error or crash information to diagnose issues and maintain the Services.

Tracking Technologies. We use cookies, log files, and tracking scripts on our website to support session management, analytics, and product improvement. You can disable cookies in your browser settings, though this may affect site functionality.

Information We Receive from Third Parties

We work with businesses (such as employers, travel management companies, and airlines) that may provide us with information about you — including your name, email, phone number, and flight details — to enable flight tracking on your behalf. Third parties may only share your data with us if you have given them consent to do so.

How We Use Information We Collect

To Provide the Services. We use your information to authenticate you, track your flights, send alerts and updates via SMS and WhatsApp, respond to your messages through Lumo Concierge, and provide travel planning assistance.

To Power Lumo Concierge. Messages you send to Lumo Concierge are processed using large language model (LLM) AI services (see "Sharing with Service Providers" below for details). Your conversation history and profile information are used as context to provide personalized and accurate responses.

To Send Service Updates. We may contact you to inform you of changes to our Terms, Privacy Policy, or security practices.

For Research and Development. We use aggregated and anonymized information about how users interact with the Services to identify opportunities to improve our products.

For Customer Support. We use information you provide to resolve technical issues and respond to account or service questions.

With Your Consent. For any use not listed above, we will ask for your explicit consent before proceeding.

Legal Bases for Processing (EEA Users)

For users in the European Economic Area, we process personal data under the following bases:

  1. Legitimate interests — to operate and improve our Services, ensure security, and communicate with users, where those interests are not overridden by your rights.
  2. Contract performance — where processing is necessary to provide the Services you have signed up for.
  3. Consent — where we have specifically asked for and received your consent.
  4. Legal obligation — where we are required to process data to comply with applicable law.

How We Share Information We Collect

We do not sell or lease your personal information to any third party. However, we do share your information with third parties to provide our Services. We work with third-party service providers to provide website and application development, hosting, maintenance, backup, storage, infrastructure, payment processing, authentication, survey hosting, analysis and other services for us, which may require them to access or use information about you. A non-exhaustive list of third party service providers is listed below; all of our third party service providers abide by policies and procedures designed to protect your information. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Sharing with Service Providers

We share information with third-party service providers who help us operate the Services. All service providers are bound by policies and procedures designed to protect your information. Our current key service providers include:

Amazon Web Services (AWS). We use AWS to host our Services, store your data, and manage our infrastructure. All data is stored in the United States.

OpenAI. When you use Lumo Concierge (via SMS or WhatsApp), your messages — including message content, conversation history, and relevant profile context — are sent to OpenAI's API for processing by a large language model. We use OpenAI's API, not its consumer products. Under OpenAI's API usage policies, data submitted via the API is not used to train OpenAI's models by default. For more information, see OpenAI's privacy policy at openai.com/privacy.

Google (Gemini). When you use Lumo Concierge, your messages and relevant context may also be sent to Google's Gemini API for processing. We use Google's API, not its consumer products. Under Google's API usage policies, data submitted via the API is not used to train Google's models. For more information, see Google's privacy policy at policies.google.com/privacy.

What is sent to LLM providers. To give you accurate, personalized responses, the data sent to OpenAI and Google may include: the content of your messages, recent conversation history, your travel preferences and profile (such as home airport and communication preferences), and current trip tracking context (such as upcoming flight details). We do not send payment card information to LLM providers.

Stripe. We use Stripe to process subscription payments. Resilient Ops does not store your full payment card details. Stripe's privacy policy is available at stripe.com/privacy.

Google Mail. Our @thinklumo.com email addresses are hosted by Google.

Google Analytics. We use Google Analytics to track interactions with our website.

HubSpot. We use HubSpot to manage web pages, capture website usage data, and log communications.

International Data Transfers

We are based in the United States. If you are located outside the United States — including in the European Economic Area — your personal data will be transferred to and processed in the United States. We take steps to ensure that such transfers are made in accordance with applicable law, including through the use of Standard Contractual Clauses where required for transfers from the EEA. By using the Services, you acknowledge that your data may be transferred to and processed in the United States.

Compliance with Law and Enforcement of Rights

We may disclose your information as required by law or regulation, or where we believe in good faith that disclosure is necessary to: (1) comply with any applicable law, regulation, or legal process; (2) protect and defend our rights or property, or the rights of our users or third parties; (3) detect, prevent, or address fraud, security, or technical issues; or (4) enforce our Terms of Service.

Sharing with Partners or Corporate Customers

When our Services are made available through an organization (such as your employer, travel management company, or airline), we share relevant travel information and updates with that organization.

Merger or Acquisition

In the event of a merger, acquisition, or sale of all or part of Resilient Ops, your information may be transferred to the successor entity, subject to this Privacy Policy unless and until it is amended.

Conversation History and Data Retention

Conversation history. Messages exchanged through Lumo Concierge are stored in our infrastructure to provide continuity within and across sessions. Conversations older than 24 hours without activity may be archived. We retain conversation data for as long as your account is active, subject to the retention periods described below.

Account information. Retained until you delete your account. We may retain certain data after account deletion to comply with legal obligations or support business operations.

Usage information. Log data is anonymized where possible and archived within one year, with strict access controls.

Managed accounts. If your data is provided through an organization, we retain it as required by that organization.

How We Store and Secure Your Information

We host all data in the United States using AWS. We implement reasonable and industry-standard security safeguards to protect your information, including encryption of sensitive data at rest and in transit. However, no system is completely secure, and we cannot guarantee absolute security of your information.

Your Choices and Rights

You may decline to provide personal information, in which case we may be unable to provide some or all of the Services. You have the right to request that we:

  1. Delete your personal information
  2. Provide you with a copy of your personal information
  3. Correct or update inaccurate information
  4. Restrict or object to certain uses of your information

To make a request, contact us at privacy@thinklumo.com. We may be unable to fulfill requests in certain cases where our legal obligations or the privacy rights of others take precedence, and we will explain why if that is the case.

Other Important Privacy Information

Individuals Under 16

Our Services are not intended for individuals under 16. We do not knowingly collect personal information from anyone under 16. If we become aware that we have done so, we will delete that information promptly.

California Users

California Civil Code Section 1798.83 permits California residents who have provided personal information to request certain information about our disclosure of that information to third parties for direct marketing purposes. To make such a request, contact us at privacy@thinklumo.com.

Canadian Users

Canadian residents are entitled to access their personal information collected by Lumo, subject to certain legal exceptions. To request access, correction, or additional information about our data practices, contact us at privacy@thinklumo.com.

Notice to Users of Employer or Organization-Provided Services

When Lumo Concierge or our other Services are made available to you through an organization, that organization is responsible for managing your information privacy within its own policies. Please refer to that organization's privacy policy and direct privacy questions to them.

Updates to This Policy

We may update this Privacy Policy from time to time. If there are significant changes, we will notify you by posting a notice on the Site and, where appropriate, via the email address associated with your account.

Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: privacy@thinklumo.com
Postal address: Resilient Ops, Inc., 1 Broadway Fl 14, Cambridge MA 02142, USA
Phone: +1 (866) 452-1961