Legal

Privacy Policy

PerLucemAI LLC · Last updated: September 2, 2026

This Privacy Policy describes how PerLucemAI LLC (“PerLucem,” “we,” “us”) collects, uses, and protects information in connection with perlucem.ai, app.perlucem.ai, the Perlucem TBPI platform, the Perlucem MCP Connector, and the Perlucem Data Room (the “Services”). The Services are business tools for financial institutions; we act primarily as a service provider to the institutions (“Customers”) that authorize their personnel to use them.

1. Information We Collect

Account information. Name, work email address, mobile phone number (for SMS verification), role, and institution affiliation — typically provided by you or by your institution’s administrator when you are invited.

Institution data. Data about your institution used to provide analytics:

  • Public regulatory data — FFIEC Call Report and UBPR data, FDIC BankFind data, and similar publicly available regulatory filings. This data is public by nature.
  • Customer-provided data — files and data your institution chooses to upload (for example, through the Data Room) or connect. What may be provided is controlled by your institution’s written agreement with PerLucem.

Usage and technical information. Sign-in events, pages and features used, queries submitted to analytical tools and AI chat (including through the MCP Connector), tool-call and generation telemetry (timings, token counts, error states), device and browser information, IP address, and logs necessary to operate and secure the Services.

We do not collect consumer financial account data, cardholder data, protected health information, or consumer credit reports, and our terms prohibit submitting them to the Services.

2. How We Use Information

  • Provide, operate, secure, and support the Services;
  • authenticate users (including SMS verification codes) and enforce institution-scoped access controls;
  • generate analytics, benchmarking, scores, and reports for your institution;
  • process natural-language questions with AI models and return answers grounded in your institution’s data;
  • monitor performance, investigate incidents, and maintain audit trails;
  • communicate service information (e.g., invitations, security notices); and
  • improve the Services, including as authorized by your institution’s written agreement. Where benchmark datasets are created, they are anonymized as provided in that agreement, and we do not publicly attribute data to any institution by name without its written consent.

We do not sell personal information, and we do not use it for third-party advertising.

3. AI Processing

  • Analytical AI processing of institution data runs on Anthropic Claude models via Amazon Web Services (AWS) Bedrock inside PerLucem’s AWS environment; in this architecture your institution’s data is processed within AWS and is not sent to Anthropic’s consumer services.
  • Financial scores and the figures in tables and charts are computed by deterministic (non-AI) systems from source data; AI is used for narrative analysis and conversation.
  • Text embeddings for document search are generated using OpenAI’s API and are limited to framework and methodology content — never customer financial records.

MCP Connector. If you connect a third-party AI assistant (such as Claude or ChatGPT) to PerLucem, that assistant sends your questions to our connector and receives the responses; your prompts and the assistant’s handling of responses are governed by that provider’s privacy policy. Our connector authenticates you, is scoped to your institution only, exposes read-only analytical tools, and logs tool calls for security and audit purposes.

4. Service Providers (Subprocessors)

We use a small set of infrastructure providers to run the Services:

ProviderPurpose
Amazon Web Services (US regions)Hosting, storage, databases, AI model inference (Bedrock)
TwilioSMS delivery for verification codes
MailgunTransactional email (e.g., invitations)
PineconeVector search for framework/methodology content
OpenAIText embeddings (framework/methodology content only)

Each provider processes only what its function requires, under its own security and privacy commitments.

5. Security

Security is foundational to the Services: single-tenant-style institution scoping enforced at the API layer; encryption in transit (TLS) and at rest; multi-factor authentication; VPC-isolated databases with no public endpoints; secrets management and key management via AWS services; immutable, checksummed data snapshots for auditability; activity logging; and a security-gated software delivery pipeline (secret scanning, static analysis, dependency and container scanning). PerLucem maintains a SOC 2-aligned security program. No system is perfectly secure; report suspected issues to info@perlucem.ai.

6. Data Retention

  • Account and institution data are retained while the Customer relationship is active and as needed for legal, audit, and security purposes.
  • Data Room uploads and analytical snapshots are retained per the Customer’s agreement (snapshots are immutable by design for auditability).
  • Upon termination, Customer Data is deleted or returned as provided in the Customer’s agreement, subject to backup cycles and legal holds.
  • Operational logs and telemetry are retained for 12 months by default.

7. Your Choices and Rights

Most user accounts exist under a Customer’s administration; requests to access, correct, or delete account information can be made to your institution’s administrator or to us at info@perlucem.ai, and we will respond consistent with our role as the institution’s service provider and applicable law. You may not opt out of security-essential processing (e.g., authentication logs) while maintaining an account. Depending on your jurisdiction, you may have additional rights; contact us and we will honor those that apply.

8. Cookies and Similar Technologies

The application uses cookies and browser storage strictly for authentication, session state, and security. We do not use advertising or cross-site tracking cookies.

9. Other Disclosures

We may disclose information: to comply with law or valid legal process; to protect the rights, safety, and security of PerLucem, our Customers, or others; in connection with a merger, acquisition, or sale of assets (with notice); or with your institution’s direction or consent.

10. Children

The Services are business tools and are not directed to anyone under 18.

11. International Users

The Services are operated in the United States. If you access them from elsewhere, your information is processed in the U.S.

12. Changes

We will post updates here with a revised “Last updated” date and notify Customers of material changes.

13. Contact

PerLucemAI LLC
info@perlucem.ai