Core Commitments
What we measure, what we never do, and the mechanism that stops us changing our minds quietly. Last updated August 16, 2026.
The distinction this page is about
There are two different things a software company can know about you.
The first is how the product is used — which features you opened, how often, how long something took, whether it failed. The second is what you wrote, uploaded and stored — the text of a message, the contents of a file, the name of a client.
These are routinely bundled together as "your data", and the bundling is convenient for whoever is doing the collecting. We keep them apart, because the first is how a product gets built and the second is not ours.
We measure the first. We do not read the second for our own purposes.
What we record
Every action you take in the product, as it happens, attached to your account and your workspace. Not a sample, not a rounded-off monthly total. We would rather say that plainly than hide it under "usage data".
In Baselumen that means every component you copy or generate: which component, which library, which surface you took it to, and whether a generation succeeded. Component names come from our own catalogue, or from what you named your own work — never from anything about you.
Each record holds the action and when it happened, which product, what kind of object it touched, how long it took, whether it worked, and a single headline number where the action produces one. Failed actions are kept too — something breaking for you is exactly what we want to see.
Why. It is what makes the product work as one thing rather than a pile of disconnected screens. Your history, your dashboard, your limits, and the shared view your colleagues see are all read back out of these records. It is also how we find out what is broken before you have to tell us.
What we never do
- No advertising technology. No pixels, no conversion tags, no retargeting — not on the marketing site, not in the app.
- No third-party analytics. No Google Analytics, Tag Manager, Segment, PostHog, Hotjar, Plausible, Mixpanel or Meta pixel. Anywhere.
- No cross-site tracking. We do not follow you off our own products.
- No selling, renting or sharing your records for anyone else's purposes.
- No enrichment. We do not buy information about you and append it to your account.
- No training AI models on your content.
What is on our servers — and when we look
We will not claim a blindness we do not have.
If you upload a file to us, it sits on infrastructure we operate, and our staff hold credentials that can read it. Any company telling you otherwise is either using end-to-end encryption — which we do not — or is being imprecise with you. An operator who genuinely could not see what was stored on their own servers would be unable to act on an abuse report, remove illegal content, respond to a malware notice, answer a court order, or tell you what became of your upload. That is not a protection. It is an inability to take responsibility.
So the question is not whether we can. It is when we do, and what stops it being casual.
We look when: someone reports abuse; we are notified of malware or illegal content; we are compelled by valid legal process; you ask us to, in support of a request you have made; or a fault cannot be reproduced any other way.
We do not look: out of curiosity; to build a profile of you; to train a model; to find sales leads; or because an internal dashboard happened to put it on the screen in front of someone.
How this is enforced
A policy is a sentence. It holds right up until someone is in a hurry. So the boundary is built into the database rather than written down and hoped for.
- Internal monitoring reads a redacted view. Message text, project names, task and ticket titles are stripped by the database before any application code receives them. A bug in our own software cannot put them on a screen, because they never arrive.
- It is an allowlist, not a blocklist. A new kind of event is hidden by default. Making one visible requires a database migration — a reviewed change with a name on it, not a setting someone can toggle.
- Entry into the cross-customer area is logged to an append-only record of who looked, when, and at what. The log cannot be edited or deleted by our applications; the database refuses the attempt.
- File names, types and sizes are deliberately visible to our staff, for the reasons in the section above. We would rather tell you which parts we can see than imply we see none of it.
We are describing the mechanism in this much detail because the mechanism is the commitment. Anyone can write that they respect your privacy.
What this has already cost us
A commitment that has never cost anything is a preference.
In August 2026 we removed the messaging feature from Hublumen entirely. Part of the reason was that it was not good enough. The other part is that running a messaging product meant being the custodian of private correspondence between an agency and their clients — the most sensitive material on our servers, and a thing we had no business holding in order to sell project management software.
We removed the feature rather than get better at storing it. We think that is the right instinct to have, and we would rather be judged on decisions like that one than on this page.
Where the limits are
The honest edges, because a commitments page without them is marketing:
- We rely on third parties — Clerk for authentication, Stripe for payments, Supabase for the database, Cloudflare for delivery, Resend for email. We choose them carefully and hold them to contracts. Their commitments are theirs, not ours.
- We comply with valid legal process. If lawfully compelled, we will produce data, and we will tell you unless we are prohibited from doing so.
- Aggregate, non-identifying figures — how many workspaces use a feature — inform what we build next. That is exactly what the first section permits, and we do not consider it an exception.
- Security is a practice, not a state. We can be breached. If we are, you will hear it from us.
- We can change this page. Material changes will be dated and described, not quietly edited. The commitment is not to be perfect; it is to be legible.
Holding us to it
Ask us what we hold about you and we will tell you. Ask us to delete it and we will. If you believe we have crossed a line described here, write to apps@stacklumen.com and say so plainly — we would rather hear it from you than not hear it.
The mechanics of your rights, retention periods and our processors are set out in the Privacy Policy. This page is what sits behind them.