Legal

Privacy Policy

How ConceptMem, operated by LumenLabs Development, collects, uses, and protects information when you create a workspace, sign in, and use the product.

Last updated September 9, 2026

Who we are

ConceptMem is operated by LumenLabs Development LTDA (CNPJ 48.155.438/0001-75), referred to here as “LumenLabs,” “we,” “us,” or “our.” This policy explains how we handle personal data when you visit our website, create an account, or use the ConceptMem console, API, SDK, or MCP server (together, the “Service”).

This policy is written to align with Brazil’s Lei Geral de Proteção de Dados (LGPD) and with common international privacy practice, since the Service is available to users outside Brazil as well.

Information we collect

We collect information in three ways:

  • Account information. When you create an account we collect your email address and password (handled by our authentication provider). During signup you may also give us your full name, company, job role, and phone number; these fields are optional and are only used to set up your workspace and to reach you about your account.
  • Workspace content. Observations, entities, facts, relations, and other records you or your connected agents submit to a workspace (“Workspace Content”). Workspace Content may include personal data about third parties if you choose to record it — for example, information about your own contacts or teammates. You control what is submitted, and you are responsible for having a lawful basis to record any personal data about others.
  • Usage and technical data. Log data such as IP address, browser or client type, pages and API routes accessed, timestamps, and error diagnostics, collected automatically to operate and secure the Service.

How we use information

  • To create and maintain your account and workspace.
  • To operate the Service: consolidating observations, enforcing your ontology and policy, and serving retrieval, review, and export requests.
  • To send account, security, and service-related communications.
  • To respond to support requests sent to maximiliano.veiga@lumenlabs.dev.
  • To detect, investigate, and prevent abuse, fraud, or security incidents.
  • To improve the Service’s reliability and features.

How information is shared

We do not sell personal data. We share information with:

  • Infrastructure providers that host the application, database, and authentication (including our authentication and database providers), acting as our data processors under contract.
  • LLM providers (OpenAI, Anthropic, or Google, depending on what your workspace or agent is configured to use) — only when a feature you invoke requires sending data to a model, and only the content necessary for that request.
  • Legal and safety exceptions — when required to comply with applicable law, enforce our Terms of Use, or protect the rights, property, or safety of LumenLabs, our users, or others.
  • A successor entity in the event of a merger, acquisition, or sale of assets, subject to this policy or one offering equivalent protection.

International data transfers

LumenLabs is based in Brazil, and our infrastructure and service providers may process data in other countries, including the United States. Where personal data leaves Brazil, we rely on our providers’ standard contractual safeguards to protect it in transit and at rest.

Data retention

We retain account information for as long as your account is active. Workspace Content follows the retention and history rules configured in your workspace’s ontology and policy — current facts, superseded values, and the changelog are kept until you retract them or request deletion. We retain usage and technical logs for a limited period needed for security and troubleshooting. When you close your account, we delete or anonymize personal data within a reasonable period, except where we must keep it to meet a legal obligation.

Security

We use industry-standard measures — encryption in transit, access controls, and API key authentication — to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at maximiliano.veiga@lumenlabs.dev.

Your rights

Subject to applicable law, including the LGPD, you may request to: confirm whether we process your data; access it; correct incomplete, inaccurate, or outdated data; request anonymization, blocking, or deletion of unnecessary or excessive data; request portability; obtain information about entities we shared your data with; revoke consent; and request deletion of data processed with your consent.

To exercise any of these rights, email maximiliano.veiga@lumenlabs.dev. We may need to verify your identity before acting on a request.

Cookies and similar technologies

We use only the cookies necessary to keep you signed in and to protect the login and OAuth flows (session and CSRF-protection cookies set by our authentication provider). We do not use advertising or cross-site tracking cookies.

Children's privacy

The Service is not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us so we can remove it.

Changes to this policy

We may update this policy as the Service evolves. We will update the “Last updated” date above and, for material changes, provide additional notice such as an email or an in-product notification.

Contact us

Questions about this policy or your data can be sent to maximiliano.veiga@lumenlabs.dev, or see our contact page. Our Terms of Use are available at /terms.