Is Lumo AI Safe for Client Data? A Freelancer Privacy Review — AI tool privacy review for freelancers

Is Lumo AI Safe for Client Data? A Freelancer Privacy Review

Transparency Notice: This article contains affiliate links. If you purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. Read our full disclosure.

Is Lumo AI Safe for Client Data? A Freelancer Privacy Review

Short answer: Lumo, Proton’s AI assistant, keeps no logs of your prompts, applies zero-access encryption to saved chats, and states it never trains on your conversations — our verdict is SAFE for client work, and it is one of the rare AI assistants we can say that about. As of July 2026, with the Lumo 2.0 release reviewed this month, the tool now handles text and images, live web search, and encrypted project spaces while keeping that privacy model intact. For a solo freelancer who pastes contracts, client emails, or draft proposals into an AI chat every day, the difference between “we don’t log this” and “we may use this to improve our models” is the difference between a confidential workflow and a slow data leak. Lumo sits firmly on the confidential side. This review explains why, where the limits still are, and how to run it safely for paid client work. See how we vet privacy claims for the process behind this verdict.

What Lumo does with your data

Privacy dimensionLumo’s answer
Trains on your data?No — states conversations never train the model
Training opt-outNot needed; no-training is the default
Data retentionNo server-side chat logs; saved chats stored client-side
Third-party sharingNone with advertisers, governments, or brokers
Storage regionEuropean infrastructure, Swiss-headquartered
Enterprise-team tierYes — Proton for Business “confidential AI”

Lumo is built by Proton, the Swiss company behind Proton Mail and Proton VPN, and its privacy model is the opposite of most mainstream assistants. Proton states that it keeps no logs of what you ask or what Lumo replies, and that nothing is saved on its servers by default (per Lumo’s privacy page, retrieved 2026-07-08). If you choose to save a conversation, it is protected by zero-access encryption, meaning it can only be decoded on your own device — Proton says it cannot read your stored chats, and neither can anyone else.

The training question, which sinks most AI tools for client work, is answered directly: Proton states your conversations are never used to train the model, and Lumo’s code is open source so that claim can be independently checked (per Lumo’s privacy documentation, retrieved 2026-07-08). On the corporate side, Proton AG is domiciled in Geneva and governed by Swiss law, describes itself as GDPR compliant, and names an EU representative in Luxembourg (per Proton’s master privacy policy, retrieved 2026-07-08). Uploaded and generated images in Lumo 2.0 fall under the same zero-access encryption as text (per Proton’s Lumo 2.0 announcement, 2026-06-30). The company’s own framing is minimal collection: gather as little as technically possible.

It is worth being precise about what “no account required to try it” means for data. You can start chatting without creating an account, which keeps your identity out of the picture entirely for casual use. If you do register — necessary for saved chats, Memory, and Projects — Proton’s stance is that no personal information is strictly required; an external recovery email is optional (per Proton’s master privacy policy, retrieved 2026-07-08). Where Proton does collect something, it tends to be operational rather than behavioral: anti-spam verification during signup may temporarily touch an IP address, email, or phone number, and Proton states that if such data is stored at all it is kept as a cryptographic hash rather than a readable value. For a freelancer, the meaningful line is that none of this is your chat content — the substance of your client work is never in the collection scope in the first place.

Two structural facts reinforce the policy language. First, Proton is owned by a Swiss nonprofit foundation, so its stated business model does not depend on monetizing user data — a different incentive structure from ad-funded or usage-mined assistants. Second, the open-source codebase means the “we don’t log, we don’t train” claims are not purely a promise you have to accept on faith; they are auditable in principle. That does not mean you personally will audit them, but it does mean independent researchers can, which is a meaningfully stronger position than a closed tool that asks for trust and offers no way to verify it.

What this means for solo freelancers

The practical upside is that the usual AI-privacy risks mostly do not apply here. Consider three scenarios that would be dangerous with a logging, model-training assistant:

  • Pasting a client’s signed contract to summarize the scope. With a training assistant, fragments of that contract could surface in a future model output. Based on the policy as written, Lumo does not retain the text server-side and does not train on it, so this specific leakage path is closed.
  • Uploading a client PDF or screenshot for analysis. Lumo 2.0 is multimodal, and image content is covered by the same zero-access encryption, so the vendor states it cannot read what you uploaded.
  • Working for EU clients under a processor arrangement. Swiss jurisdiction plus a stated EU representative reduces the controller-processor ambiguity you get with US-only tools — though you should still confirm a data processing agreement for formal client work.
  • Using web search inside a client research task. Lumo 2.0 can pull live results and cite sources. That is convenient, but remember a search query itself can reveal a client’s name, a competitor, or a confidential project theme; keep queries generic where the topic is sensitive, the same way you would with any search engine.

There is also a positive framing that matters for how you sell your own service. If a client asks whether you use AI tools and how you protect their data, “I use a Swiss, zero-access, no-training assistant and keep each client in a separate encrypted space” is a credible, specific answer. Compare that to the vague reassurance most freelancers can offer about mainstream tools, where the honest answer is often “their policy lets them use my inputs to improve their models.” Lumo lets you turn a privacy liability into a small trust signal, which is quietly valuable when you compete for privacy-conscious clients such as lawyers, therapists, accountants, or anyone handling regulated data.

The honest caveats: Lumo is still a hosted cloud service, not a local model, so during a live chat your prompt does travel to Proton’s servers to be processed before the no-logging and encryption guarantees take over. You are also trusting Proton’s implementation — the open-source code helps, but you are not auditing it yourself. And a free-tier account has usage limits that can interrupt a long client session. None of these turn Lumo into a risky tool; they are the normal trust boundaries of any hosted assistant, and Lumo’s are unusually narrow. For a broader view of how we weigh these trade-offs, see [INTERNAL_LINK_TO_CLUSTER_ai-privacy-reviews].

How to use it safely

Even with a strong default posture, a few concrete settings keep client work clean:

  • Decide per chat whether to save it. Unsaved conversations leave nothing behind; only save a chat when you genuinely need the history, and delete saved chats once a project closes.
  • Turn Memory on deliberately, not by habit. Lumo 2.0’s user-controlled Memory stores your preferences and context to improve answers. That is useful, but for sensitive client work, keep Memory off or scoped to a dedicated encrypted Project so client details do not bleed across engagements.
  • Use a separate Project per client. Encrypted Projects let you wall off each client’s context; this also makes deletion clean when a contract ends.
  • Redact where you can. Zero-access encryption is strong, but replacing a client’s real name with a placeholder before you paste is free insurance and good habit.
  • Confirm a DPA for formal EU work. For regulated or contractual client data, check Proton for Business terms and get the processing agreement on file rather than relying on the consumer tier.
  • Keep your account itself locked down. The encryption model only protects you if nobody else reaches your logged-in session. Set a strong unique password, turn on two-factor authentication, and if you handle high-value client data, a hardware security key such as a YubiKey raises the bar on account takeover well beyond an app-based code.

None of these steps are heavy. The point of a tool with a strong default posture is that safe use is mostly about not undoing the defaults — not saving what you do not need, not letting Memory quietly accumulate client details, and not leaving your account itself weakly protected. Get those three habits right and Lumo’s guarantees actually hold in your day-to-day workflow rather than only on paper.

Privacy-friendlier alternatives

Lumo is already the privacy-friendly pick in its category, so the “alternatives” here are complements — the rest of a confidential solo stack, plus one option if you want to remove the cloud entirely:

  • Proton (the wider suite). What it adds that Lumo alone doesn’t: encrypted mail, calendar, drive, and a password manager under the same Swiss, zero-access model — so your AI assistant and your client files share one trust boundary. Free tier available; paid Proton Unlimited runs in the roughly $10/month band. Best for freelancers who want their whole workflow, not just chat, off Big Tech.
  • Bitwarden. What it adds: open-source, end-to-end encrypted password and secret management to keep client logins out of your chats entirely. Free for individuals; premium around $10/year. Best for anyone still pasting credentials into notes or AI tools.
  • A local LLM (Ollama or LM Studio) for maximum control. What it adds over any hosted tool, Lumo included: nothing leaves your machine at all, because the model runs on your own hardware. Free software; you supply the computer. Best for the security-strict freelancer handling the most sensitive client data who can accept weaker capability than a frontier hosted model.

If your risk profile is high enough that even a no-log hosted assistant feels like too much, pairing a local LLM with the Proton suite gives you a fully self-contained setup. For most solo freelancers, though, Lumo plus Proton is the pragmatic balance of capability and confidentiality. The distinction to keep in mind: a local model wins on data control but usually loses on raw capability and convenience, while Lumo gives you frontier-class features with a privacy model far closer to local than to the mainstream cloud assistants. Choosing between them is a question of how sensitive your typical client data is, not a question of which one is “more private” in the abstract. For most consulting, writing, design, and admin work, Lumo’s guarantees are more than sufficient; reserve the local-only route for the genuinely regulated edge cases. You can also mix the two — draft and brainstorm in Lumo, and drop only the most sensitive documents into a local model — so the choice is not strictly either-or.

The verdict

ATP Privacy-Vetted: SAFE

Lumo is SAFE for client work, including paid engagements, because Proton states it keeps no server-side chat logs, applies zero-access encryption to saved conversations, and never trains its model on your data — a combination almost no mainstream assistant offers. The residual limits (a hosted service you must trust to implement its own claims, plus free-tier usage caps) are normal and narrow, not disqualifying. Use encrypted Projects per client and confirm a Proton for Business processing agreement for formal EU work, and Lumo is a genuinely confidential AI assistant for solo freelancers.

Frequently asked questions

Does Lumo train on my prompts?

No. Proton states that Lumo does not use your conversations to train its model, and it points to Lumo’s open-source code as a way to verify that claim independently. This is the default behavior, so there is no opt-out toggle you need to find and switch. That single fact is the main reason Lumo clears the bar for client work where most assistants do not.

Is Lumo GDPR-friendly for EU client work?

Based on the policy as written, Lumo is well positioned: Proton AG is Swiss, describes itself as GDPR compliant, and names an EU representative in Luxembourg. For informal work that is reassuring. For formal or regulated client data, sign a data processing agreement through Proton for Business rather than relying on the consumer tier, so your controller-processor relationship is documented.

Can I use Lumo for HIPAA-covered client data?

Treat HIPAA as a contract question, not a feature question. Proton offers HIPAA-relevant business agreements across parts of its suite, but you must confirm coverage and a business associate agreement specifically for the AI assistant before putting protected health information into it. Based on the policy as written, the encryption model is strong, but the paperwork is what makes a workflow defensible.

Are my saved Lumo chats readable by Proton?

Proton states that saved conversations use zero-access encryption, meaning they can only be decoded on your own device and cannot be read by Proton or any third party. Unsaved chats leave nothing on the servers at all. The practical takeaway: delete saved chats when a project ends, and unsaved sessions are the most private default.

Does Lumo share my data with advertisers?

No. Proton states that Lumo data is not shared with advertisers, governments, or other third parties, and that the company is owned by a Swiss nonprofit whose stated model does not depend on monetizing user data. This is a structural difference from ad-funded assistants, where your prompts can feed profiling systems.

Sources

  • Lumo privacy page — https://lumo.proton.me/privacy (retrieved 2026-07-08)
  • Proton master privacy policy — https://proton.me/legal/privacy (retrieved 2026-07-08)
  • Proton Lumo 2.0 announcement — https://proton.me/blog/lumo-2 (published 2026-06-30, retrieved 2026-07-08)

Reviewed by Jérémy, founder of AidTaskPro and GreenBudgetHub. Based in central France. Privacy posture sourced from public policies and vendor documentation as of 2026-07-08.

Get Your Free Cybersecurity Checklist

Protect your digital life in 5 minutes. Free checklist + weekly productivity & security tips.

Similar Posts