Who is responsible
Monosphere Pte Ltd (UEN 202612963C), Singapore, operates Lomus and is responsible for the personal data described here. Contact our privacy team at support@lomus.ai for questions, access requests, or concerns.
Information we process
- Account information, such as your email, display name, profile image, password hash where applicable, and linked sign-in providers.
- Session and security information, such as timestamps, IP addresses, browser information, authentication credentials, and security events.
- Workspace and product content you provide, including agent configurations, instructions, conversations, attachments, skills, and service credentials.
- Usage and operational records, including model usage, cost records, agent activity, errors, and billing references. Payment card details are handled by Stripe.
- Community posts, comments, reactions, and other participation. Public contributions can be seen by other visitors and indexed by search engines.
- Support correspondence and, only after consent, marketing website analytics.
Why we use information
We use information to provide accounts and agents, process content through selected services, manage payments and usage, protect the service, respond to support requests, and meet legal obligations. Optional analytics helps us understand how the marketing website is used. We do not sell personal data. We do not use your content to train our own foundation models; processing by your selected AI providers is governed by the applicable provider arrangements.
Who receives information
Authorised personnel and service providers may access information as necessary to operate, support, and secure Lomus. These include infrastructure, payment, authentication, AI, and optional analytics providers. Connected services receive the information needed for the features you enable. Workspace roles control administrative access; Studio conversations are not automatically shared with all workspace members. See Service providers. We may disclose information when required by law or to protect legal rights and service security.
Where processing happens
Core Lomus infrastructure is hosted on AWS in Singapore. External providers may process information in other countries according to their services and terms. A region label in an interface does not establish a contractual data-residency commitment. Contact us before providing data subject to particular residency requirements.
Retention and deletion
We retain data as needed for the service, security, support, and legal or accounting obligations. Usage-log retention varies by plan. Records held by external providers follow their applicable retention arrangements.
Requesting account deletion disables account access and schedules deletion after a 30-day grace period. Contact support during that period if you need help reversing the request. This is not a promise that all workspace content, billing records, public contributions, backups, or provider-held copies are erased on day 30. Shared workspace data and records that must be retained may remain. Ask us for help with a specific deletion request.
Your choices and requests
You can edit available account details, revoke sessions, manage sign-in security, and request account deletion in Settings. The account export provides the account records supported by that feature; it is not a complete export of all agent, workspace, or provider-held data. Contact support@lomus.ai to request access, correction, deletion, withdrawal of consent, or other rights available under applicable law. We may need to verify your identity and explain applicable limits.
Cookies and optional analytics
The app uses necessary authentication and security cookies. The marketing website uses Google Analytics only if you choose to allow it. It measures page views and selected interactions, such as pricing choices and clicks to the app or community. We do not intentionally send form text, account identifiers, or sensitive URL parameters. Declining analytics does not prevent using the site. Change your choice through Cookie preferences in the footer. See the Cookie policy.
Children and sensitive information
Lomus is not directed at children who cannot legally enter the service agreement. Contact us if you believe a child has provided personal data without the required authorisation. Avoid providing sensitive information that is unnecessary for your task; no special regulated-data arrangement is included unless separately agreed.
Changes and contact
We update this policy when our practices change and provide appropriate notice of material updates. The current version is available here. For questions or privacy complaints, contact support@lomus.ai. You may also contact the relevant data protection authority where applicable.