Who we are
Illumora (illumora.io) provides AI literacy content, a Prompt Studio for generating structured prompts, a Vault for saving them, tools like Model Match and Atlas, and Illumora Craft — an API and MCP product that compiles prompts for agents. This policy describes how we handle information when you use those services.
What we collect
- Account data. If you sign in, we store your email and authentication identifiers through Supabase Auth.
- Prompts and Vault entries. When you generate prompts in Studio or compile via Craft, we process your intent text to produce output. Free-tier Vault saves stay in your browser; Pro and Studio sync prompts to our database when you are signed in.
- Craft API & MCP. API keys (hashed at rest), OAuth client registrations, authorization codes, and access / refresh token hashes; compile and read-rate usage meters; optional Pulse webhook URLs you register.
- Usage data. We track daily Studio generation and Craft compile counts to enforce plan limits. We may log errors and basic request metadata to keep the service reliable.
- Payment data. Subscriptions (including Craft) are processed by Stripe. We receive your plan status and Stripe customer ID — not your full card number.
- Cookies and local storage. We use cookies for authentication sessions and local storage for anonymous usage keys and local Vault entries on the free tier.
How we use it
- Provide Studio generations, Craft compiles, Vault sync, MCP/OAuth connectors, and account features
- Enforce plan limits and process subscriptions
- Improve reliability and fix bugs
- Respond to support requests you send us
We do not sell your personal data. We do not use your prompts to train third-party AI models. Studio and Craft compose calls are sent to our inference provider only to produce your requested output. Host agents that call our MCP tools run their own models under their providers' terms.
OAuth and third-party agents
When you connect Claude or another MCP client via OAuth, you grant that client tokens to call Illumora Craft on your behalf. You can disconnect in the client or revoke access by contacting us. We do not receive your Claude password; consent is shown at illumora.io/oauth/consent.
Retention
Account and cloud Vault data remain until you delete your account or ask us to remove them. Local Vault data stays in your browser until you clear site data. Logs are retained for a limited period for security and debugging.
Your choices
- Use Illumora without signing in — with local Vault and tighter Studio limits
- Export prompts from Vault or delete entries at any time
- Cancel a paid plan through the Stripe customer portal; cloud Vault access follows your active subscription
- Request account deletion by emailing privacy@illumora.io
Changes
We may update this policy as the product evolves. Material changes will be noted on this page with a revised effective date.