Privacy & data security
What data LumaiScope collects, the providers we rely on, how we protect your Amazon Seller Central connection, and the controls you have.
What we collect and why
We collect what we need to run your research and your account — nothing more. That breaks down into three buckets.
- Account data: your name, email, and sign-in identity, handled by our authentication provider (Clerk).
- Research data: the products, keywords, watchlists, pipelines, and listings you create inside the app.
- Your Amazon Seller Central data: only the data you authorize us to read through the Amazon Selling Partner API, used to power Performance, Reimbursements, and Forecasts.
We use Stripe for payments. Your full card number is handled by Stripe and never touches LumaiScope's servers.
Where your data comes from
The numbers in LumaiScope are grounded in real sources. Lumai AI reads measured data and explains it — it doesn't fabricate figures.
- Oxylabs and Rainforest API — public Amazon product data (prices, BSR, reviews, the seller landscape).
- DataForSEO — keyword search-volume and seasonality.
- Reddit API — social signals for Social Trends.
- Amazon Selling Partner API — your own Seller Central data, read only with your OAuth authorization.
Supporting services: Clerk for sign-in, Resend for email, and Sentry for error monitoring so we can catch and fix problems quickly.
Your Amazon connection is read-scoped and revocable
When you connect Seller Central, you grant access through Amazon's own OAuth flow. We only read the data needed to power the tools you use — we don't change your listings, prices, or inventory.
- You authorize the connection from Settings, through Amazon's consent screen.
- We store the access token securely and use it only to fetch your reports and metrics.
- You can revoke access at any time — disconnect in LumaiScope's Settings, or remove the app from Seller Central under Apps & Services → Manage Your Apps.
How we protect it
- Traffic between your browser and LumaiScope is encrypted in transit (HTTPS).
- Sign-in is handled by a dedicated identity provider with industry-standard token security — we don't store your password.
- Access to your data is scoped to your account; your research isn't shared with other users.
- We use a small set of vetted subprocessors (listed above) and only share the minimum data each one needs to do its job.
We don't sell your data, and we don't use your private Seller Central numbers to train models.
Controls you have
- Export your research data from the data tools at any time (see Manage your account).
- Disconnect your Amazon account whenever you want.
- Request a full data export or deletion by emailing support.
- Delete your account entirely — see the guide below.