Luumen connects straight from your machine to your servers. A small cloud workspace holds the things you want to keep and share. Here is what sits where.
What Stays on Your Machine
Terminal input and output. Your scrollback is written to a file on your own computer and is never uploaded. Each terminal keeps its most recent 256 KB and overwrites the oldest lines after that.
Your sign-in tokens. Encrypted with a key held in your operating system's keychain.
The SSH key already on your computer. A credential can point at it instead of storing a secret with us. The key itself is never uploaded.
What is Stored in Your Luumen Workspace
Your host list. Names, addresses, ports, connection type, tags, and groups.
Credentials saved to Luumen Cloud. Encrypted with AES-256-GCM before they are written. Luumen decrypts one only to make a connection for you.
Skills and snippets.
Luumen AI conversation history. Your messages, the commands the assistant proposed, your decisions on them, and the output it read.
The audit log. A record of product and AI activity in your organization. Owners and Admins can read it.
How a Session Works
Luumen dials the host directly using the credential attached to it. Session traffic goes from your machine to your server, and Luumen does not sit in the middle of it.
While you are connected to a host, Luumen AI is given that host's live state: its operating system, its public and private addresses, its current working directory, and whether it is still connected. A badge above the message box shows you exactly what it holds. With no session open the badge reads No active terminal context, and it can answer general questions but cannot inspect anything.
Your installed package list is not sent with every message. Luumen AI asks for it only when your question is about packages, and then it sends at most 50 that match what you asked about rather than the whole inventory.
Luumen AI can propose opening or closing a session on a host, and it can propose a command to run in one. Each of those is an approval card first. Nothing connects and nothing runs until you approve it, and what does run uses exactly the permissions of the account you connected as.
Asking Luumen AI is the one thing that leaves your machine. Your message, the host details it needs, and the output of any command you approve go to the Luumen AI service so it can answer, and they are kept with the conversation. That is what lets it read a log and tell you what broke. A terminal session you drive yourself sends nothing.
Nothing is Installed on Your Servers
Luumen needs no agent, no inbound access, and no new firewall rules. Terminal sessions, LuumenAI, and Skills all run over the same connection an ordinary SSH client would use.
One optional exception is worth knowing. If tmux 1.8 or later is already installed on a host, Luumen starts your shell inside a tmux session named luumen- plus an identifier, so your work keeps running when your connection drops. If tmux is absent, nothing is installed and the shell runs normally.
Privacy Settings
Open Settings, then Data & Privacy.
Allow AI model improvement. On by default. Luumen may use your prompts, responses, and approved actions to improve its models, with sensitive content stripped first. Turn it off and nothing from your conversations is used that way.
Allow product analytics. On by default. Anonymous, aggregated usage and stability data: which features are used, rough session activity, crashes. It is not used to track you personally.
Export data. Opens a message to [email protected] asking for an archive of your personal data. Send it and we put the archive together for you.
For more information on security visit our security page, for full privacy policy information view our privacy policy and How Luumen keeps your credentials secure.

