LuHm OS is designed to minimize data collection. The public MCP tool surface is anonymous and read-only. It returns bounded project source-truth, role, routing, scope-validation, and proof-contract information.
Tool requests may contain task kinds, routing flags, and source or scope identifiers supplied for the request. The current public tools do not request passwords, payment data, signing keys, provider credentials, private Google Drive files, or user account data.
The public MCP candidate is hosted on Render over HTTPS. Hosting infrastructure may retain ordinary service and request metadata for reliability, abuse prevention, and debugging. LuHm OS is designed not to log secrets or unnecessary personal data.
The public plugin exposes no write or destructive tools. If private data or write actions are added in a future version, that version requires a new privacy review plus appropriate authentication and authorization before release.
The service may rely on OpenAI/ChatGPT, Render, GitHub, and their infrastructure. Those services operate under their own privacy terms.
Material privacy-impacting architecture changes require a new evidence review before publication.