Privacy Policy

Last updated: September 26, 2026

1. About this policy and who is responsible

This policy applies to oneaiguide.com and its related features (the “Site”). The controller operating the Site is Said el Moussaoui, a sole proprietor trading as LUMIVEX (Netherlands Chamber of Commerce number 42078200), based in the Netherlands. Business and postal address: Randveen 60s, 2544 RP Den Haag, Netherlands. He is responsible for the personal data processed to operate and improve the Site. Some services named below process data under their own terms and may have separate responsibilities.

This notice describes current processing based on the Site’s implementation. It is not a promise that every feature is available to every visitor, nor a substitute for the terms of a third-party provider.

2. Data we process

The data depends on how you use the Site. It may include:

3. Why we use data and our legal grounds

The legal basis for an activity depends on its purpose and the law that applies to you. For processing covered by the GDPR, the bases described below relate to the purposes indicated; different activities within one feature may have different bases.

4. Site measurement and browser storage

Analytics is opt-in. Before analytics consent is granted, and after it is rejected or withdrawn, the Site does not send first-party visit, page-view or outbound-click measurements and does not load/send Google Analytics 4 data. With analytics consent, first-party visit and page-view requests can include the page path, a random session identifier, browser user-agent and referrer where available. The API filters known bots and stores page paths/referrers/session IDs and user-agent information in its analytics records; these identifiers and records may be linkable and are not necessarily anonymous.

With analytics consent, outbound tool clicks can also send a first-party request to our API with the tool identifier and, where available, session identifier, referring page and source. The API ignores click requests without a valid analytics session. For consented click requests, the server uses and stores a truncated SHA-256 hash of the request IP for rate limiting and click analytics; it does not store the raw IP address in the click record.

The consent choice is saved in browser local storage under oag_cookie_consent_v2. The random analytics session identifier is stored separately under ai-guide.session.v1, and is created only when analytics is allowed. When analytics consent is withdrawn, the application removes that identifier and attempts to delete Google Analytics cookies whose names begin with _ga (including _ga_*). After opt-in, Google Analytics 4 may set first-party _ga and _ga_* cookies; their lifetime depends on Google/browser settings and may vary. Google also receives data under its own terms and privacy information.

Use the Cookie preferences control in the Site footer to review, grant, reject or withdraw optional analytics consent. The choice is stored locally; clearing the Site’s local storage also removes that choice. Necessary sign-in/security storage may still be used for features you request. Marketing consent only enables Google advertising-consent signals when analytics consent is also enabled; no separate advertising tag is currently installed.

5. AI features

If you use Lumi or the AI Project Consultant, the information needed to answer your request can include your prompts, conversation history, files or attachment content you provide, and relevant tool-catalog or project context. The service sends this information to the model provider used for that request. The current server implementation uses Google Gemini and Anthropic models, including provider integrations; the provider can vary by feature or fallback.

AI conversations and related project data may be stored by the Site to provide conversation history or saved-project features. Do not submit sensitive personal information unless it is necessary and you are comfortable with the applicable provider processing it. Provider retention, training and other use depend on the provider, product and applicable terms. We do not make a blanket claim that every provider does not retain or train on submitted data; consult the relevant provider terms for details.

Lumi and the AI Project Consultant can automatically analyze your question, conversation and relevant saved project context to personalize tool or workflow suggestions. This may involve profiling in the broad sense of evaluating your stated interests or needs. The suggestions are informational and do not themselves make solely automated decisions that produce legal or similarly significant effects for you. You can choose whether to use a suggested tool or workflow.

6. Service providers and data transfers

Recipients depend on the feature: Clerk handles sign-in; Google Analytics receives analytics only after opt-in; Google Gemini, Anthropic and Replit AI integrations receive prompts/context needed for AI requests; Stripe processes checkout and payment data for Lumi/Academy subscriptions, prepaid Lumi credits and tool sponsorships; Resend delivers contact-form messages and newsletter emails. Their own privacy notices, roles and terms also apply. Contact-form submissions are sent to our team inbox through Resend. If you follow a tool link, your browser connects directly to that tool or merchant, which receives ordinary connection/device data and any referral information in the link; affiliate links may identify the referral. That merchant is responsible for its own processing.

Public approved reviews and stacks are visible to Site visitors. A certificate verification page reveals the limited fields described above to anyone with the unique link; it is marked no-index/no-cache but is not private from link holders.

The Site is operated from the Netherlands, but providers and their systems may process data in other countries. Where personal data is transferred outside the European Economic Area, the transfer mechanism and safeguards depend on the provider and service configuration, and may include an adequacy decision or contractual safeguards. Contact us if you need information about the safeguards applicable to a particular service.

7. How long we keep data

We keep information for as long as needed for the purpose for which it was collected, to provide a feature you use, to handle a request or dispute, and to meet legal, accounting or security requirements. Retention varies by data type and feature. We do not publish a fixed expiry period for every session, conversation, content record, analytics record or support email; those records may not be deleted at the same time. Where a feature offers deletion controls, you can use them; you can also contact us to ask about deletion. Some records may need to be retained where the law permits or requires it.

More specifically, enrollment/progress data is kept while needed to provide and support the course; certificate and verification records while needed to issue, validate or revoke credentials and maintain integrity. Newsletter details are kept while subscribed and as needed to honor unsubscribe choices and maintain subscription records; Resend may retain delivery records under its own terms. Subscription, sponsorship, credit and payment records are kept as needed to provide entitlements, handle billing/refunds/disputes, and meet legal or accounting duties; Stripe may retain its own payment and tax records. Reviews and public stacks may remain available while published or needed to operate the community, subject to available controls, moderation and applicable law.

8. Security

We use technical and organizational measures intended to protect data, including access controls and safeguards in our service integrations. No website, transmission or storage system can be guaranteed completely secure. Please use a unique password with your sign-in provider and contact us promptly if you believe your account or data has been compromised.

9. Your privacy rights

Depending on your location and the circumstances, you may have rights to request access to, correction of, deletion of or a copy of your personal data; to object to or request restriction of certain processing; and to withdraw consent where processing relies on consent. These rights are subject to legal conditions and exceptions. For a correction request that is not available in your account controls, contact us with the information to correct; we may need to verify your identity. We do not promise a particular correction workflow or deadline beyond applicable law.

Signed-in users can download a JSON account export from the Account page. It covers the current application database’s account-linked records; it is not a complete copy of every item about you. It excludes records held solely by Clerk, Stripe, email and other external providers, non-account-linked analytics, database backups and historical versions. Lumi file bytes are not included (the export includes file metadata); files remain available through the signed-in vault before deletion.

Signed-in users can request account deletion from the Account page. The current deletion process removes supported account-linked application records and indexed account-owned Lumi files, but it does not erase non-account-linked analytics, database backups, logs, Stripe payment/accounting records or all records held by Clerk and other providers. It attempts to delete the Clerk identity, but provider failure can leave deletion incomplete. A recurring Stripe subscription must be retrieved and canceled before local deletion proceeds; if that step fails, local deletion is refused. Public tool listings may be retained with submitter attribution cleared. These implementation limits mean we cannot promise complete erasure from every system.

To make a request, use our contact page and tell us enough to understand and verify it. We will respond within the period required by applicable law (ordinarily one month under the GDPR); complex requests may lawfully take longer, and we will explain if an extension applies.

If you are in the European Economic Area, you may also complain to your local data-protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens. You may also have the right to seek a judicial remedy.

10. Children and policy changes

The Site is not designed for children under 16, and we do not knowingly seek to collect their personal data. If you believe a child has provided personal data, contact us so we can review the request.

We may update this policy when our processing or legal requirements change. The date at the top shows the latest update. Material changes will be reflected on this page; please review it periodically.

Privacy questions or requests

To exercise a right or ask about this policy, contact us through our

Owner's digital acknowledgment

Approved for publication at the owner's request: /s/ Said el Moussaoui, owner of LUMIVEX — Den Haag, September 26, 2026.

This typed name records the owner's instruction to publish this notice. It is not an independently verified or qualified electronic signature, a supplier agreement, or evidence of a particular international-transfer safeguard.