Skip to main content

Last updated · 2026-05-08

Privacy Policy

This is what LumaShift does with your data. We’ve written it in plain English. The legal basis is Malaysia’s Personal Data Protection Act 2010 (amended 2024) plus the GDPR-aligned obligations in our standard contractual clauses for international users.

Who we are

LumaShift is a cybersecurity career coaching platform run by Mukesh Vijaian + Lavanyah Prabu, operated under Moovela Ventures (SSM Reg. No. 202603210826), a business registered in Malaysia. Email lumashift@outlook.com for any data-protection question.

What we collect

From you, directly

  • Account info: email, name (only what you give us at signup), and OAuth provider id if you sign in via Google.
  • Profile content: target roles, current skills, certifications obtained / planned, career stage, years of experience, and anything else you fill in on the profile page.
  • Tool inputs: resume text, job descriptions, mock-interview answers, salary-coach negotiation context — whatever you paste into the AI tools to get back an analysis.
  • Quiz + assessment responses: your answers to the career quiz, cert-readiness assessment, and skill-gap analysis.
  • Saved items: blog posts, resources, and tools you bookmark.

Automatically

  • Usage events: which pages you visit, which tools you run, how long sessions are. Anonymous until you sign up.
  • AI call metadata: for every AI tool you use, we record the prompt id, model, latency, token count, and pass/fail outcome — see “AI tools” below.
  • IP + user-agent: for rate-limiting and abuse prevention only. Discarded after 30 days unless tied to a security investigation.

How we use it

  • Run the tools you use. Resume analyzer needs the resume text. Salary coach needs the negotiation context. We can’t do the work without these inputs.
  • Personalise your dashboard + recommendations. Your profile + activity is what makes recommendations relevant.
  • Improve the AI prompts. AI call metadata (latency, token count, error rate, optional quality flags from you) feeds an internal eval set. We don’t use the content of your inputs to train any model.
  • Send you what you asked for. Welcome email, payment receipts, your purchased reports, optional weekly digest if you opt in.
  • Operate the business. Payments are made via DuitNow/bank transfer to Moovela Ventures and confirmed manually; we mirror order metadata for you to download your reports.

What we never do

  • We don’t sell your data. Not to brokers, not to hiring platforms, not to anyone.
  • We don’t train AI models on your inputs. Our AI provider (Groq running Meta’s Llama) doesn’t retain your prompts beyond the API call. Their policy: groq.com/privacy-policy.
  • We don’t share your career details with employers, recruiters, or third-party vendors without your explicit consent (e.g. when you book a coaching session, the assigned coach sees your profile).

AI tools — what the “Generated by Llama” footer means

Every AI-generated artifact (chatbot reply, cert plan, resume analysis, etc.) renders a small footer: Llama 3.3 via Groq · prompt: <id> · Used: <your inputs> · Inputs not retained beyond this session.

What that means precisely:

  • “Inputs not retained” = the prompt + your input text are not stored after the AI call returns. Groq doesn’t persist them; we don’t persist them.
  • What we DO log: the prompt id, model name, latency, token count, success/failure, and (when you’re signed in) your user id. We don’t store the prompt or the response text. This is for cost and quality observability — see ai_call_logs in our schema.
  • If you click “Inaccurate?” or “Suggest a question” on an AI output, we DO record your comment + question. This goes into a separate table (ai_output_feedback) reviewed weekly by a coach.

Sharing

Career Snapshot share links

When you generate a Career Snapshot you can mint a public share link at /r/<token> from your reports page. Share links:

  • Expire automatically 90 days after creation.
  • Can be revoked any time from the same page.
  • Show only your first name and the report’s public highlights — never email, never last name, never user id, never subscription tier.
  • Are rate-limited per IP to prevent enumeration.

Coaches

When you book a coaching session, the assigned coach can read your profile, quiz results, recent activity, and AI tool history within the admin panel. This is necessary for them to do the work. Coaches sign confidentiality agreements.

Data processors

The third-party services we use as data processors:

  • Supabase — database + auth (Frankfurt region for EU users, US East for everyone else)
  • Vercel — hosting + edge runtime
  • Resend — transactional email
  • Stripe — payment processing
  • Groq — AI inference (no retention of prompts or responses)
  • PostHog — anonymous usage analytics (opt-in via “analytics cookies” consent — see cookie note below)

How long we keep things

DataRetention
Account + profileUntil you delete the account
Tool inputs (resume, JD, etc.)Not retained — see AI section above
AI call metadata (prompt id, latency, tokens)1 year, then deleted
AI feedback (your flags + suggestions)1 year, then deleted
Activity logs1 year, then aggregated + raw rows deleted
Email events (delivery, open)2 years for transactional; 90 days for marketing
Career Snapshot PDFsUntil you delete them or the account
Stripe invoices7 years (Malaysian tax law)
Database backupsUp to 7 days (rolling)
IP addresses (rate-limit)30 days

Your rights (PDPA 2010 amended 2024 + GDPR-aligned)

  • Access — see what we have on you. Visit your data page.
  • Correction — fix anything that’s wrong via the profile page.
  • Deletion — request account deletion via lumashift@outlook.com. We action within 30 days, except where we’re required to retain for tax law (Stripe invoices).
  • Objection / withdrawal of consent — opt out of marketing emails any time via the unsubscribe link.
  • Portability — export your data as JSON, request via the email above.
  • Complaint — Malaysia’s Personal Data Protection Commissioner (JPDP) at pdp.gov.my.

Breach notification

Per PDPA 2024 amendments, if we suffer a data breach that creates a significant harm risk to you, we will notify the Personal Data Protection Commissioner AND you within the prescribed regulatory timeline. Our internal target is much shorter — within 72 hours of confirmed scope.

Security posture

  • Row-level security (RLS) on every database table that contains user data.
  • HTTPS everywhere; no plain HTTP listeners.
  • OAuth + magic-link auth via Supabase (no passwords stored on our side).
  • Service-role keys held in environment variables, never in code.
  • Per-user AI usage caps to prevent runaway abuse + cost.
  • Rate-limited public share endpoints to prevent enumeration.

Refund policy

Payment and refund terms (including the 7-day refund window on paid digital products) now live in our Terms of Service, so they stay in one place rather than two documents drifting out of sync.

Cookies

We use a small number of essential cookies (auth session, sidebar collapse preference, referral tracking on the homepage). We do not serve advertising cookies. Analytics cookies (PostHog) are enabled only with your explicit opt-in.

Changes

We’ll bump the “Last updated” date at the top of this page when this policy changes substantively. If a change materially affects your rights or the way we handle your data, we will email registered users.

LumaShift Career Advisor

Cybersecurity career guidance

Hi! I'm LumaShift's Career Advisor. I can help you find the right coaching service, understand cybersecurity career paths, or answer questions about certifications and salaries.


What can I help you with today?

Or email lumashift@outlook.com

Chat on WhatsApp