
Lumo
Open SourcePublished September 28, 2026· By Juan Martinez
In This Article
Lumo is an AI chat assistant that runs its models on its operator’s own infrastructure rather than passing your prompt through to somebody else’s API, which changes what the privacy question even is. Launched in July 2025 by the Swiss company Proton AG, it inherits the encryption model the company built for its other products: saved conversations are stored under zero-access encryption, so the operator holds no key that would let it read them. The interesting tension in this product is not the architecture, which is unusually strong for the category, but the gap between how open the company says the whole thing is and how open it demonstrably is.
Privacy Architecture
The structural decision that matters most here is that there is no third party in the loop. The models — Lumo 2.0 Lite, Lumo 2.0 Max and Apertus 1.5 — run on servers the operator controls, so a prompt is not forwarded to an external model provider under a contract you cannot read. Most privacy-focused chat front-ends are essentially anonymizing proxies: they hide who you are from the company that actually runs the model. Lumo does not need that layer, because the company running the model is the company you already handed the prompt to.
That architectural difference is also why two of the usual measurements do not cleanly apply. The question “does the operator strip your IP before forwarding the request to the model provider?” has no answer here, because there is no forwarding step — the honest recording is that the mechanism this category normally measures does not exist in this product, not that the product failed the measurement. What is documented instead is broader: the support documentation states plainly that Lumo does not store metadata such as timestamps, IP addresses, or chat context. That is a stronger claim than IP-stripping, and a less verifiable one, since nothing external corroborates it.
Storage is where the design is most concrete. If you keep chat history, it is encrypted such that the operator cannot decrypt it: each conversation has its own key, those keys are encrypted by a master key, and that master key is encrypted by your PGP keypair, which only your password unlocks. The company’s published technical write-up describes the chain in detail. In transit, an AES session key is wrapped in asymmetric PGP encryption on top of the usual TLS. The practical meaning of zero-access is the one that survives a subpoena: a demand served on the operator for your stored conversations returns ciphertext it has no means to open.
An account is optional rather than required. There is a guest mode you can open without signing up, and in guest mode the conversation is erased when the session ends — nothing persists. An account, free or paid, is what buys you saved and synced history and the Projects feature. So the choice is explicit rather than assumed: you can have a session that leaves nothing behind, or a history that follows you between devices under encryption the operator cannot read, and you pick per use rather than once at signup.
On training, the stated policy is that conversations are not used to train the models, with one disclosed exception that deserves to be stated plainly rather than buried. If you press the feedback button, an anonymized copy of that prompt and response may be shared with the ETH Zurich and EPFL research teams to improve Apertus 1.5. That is opt-in and per-instance rather than a default, so it is not a hole in the no-training position — but it exists, it involves a party outside the company, and anyone relying on “nothing I type is ever used for training” should know where the one door is. It is also worth being precise about what kind of commitment the no-training policy is: because the company operates its own models, this is its own policy about its own infrastructure, not a contractual term you could hold a third-party provider to. Whether that is stronger or weaker depends on whether you trust contracts or you trust the absence of a counterparty.
Trust & Transparency
The operator is Proton AG, a Swiss company registered in Plan-les-Ouates, Geneva. Switzerland is the jurisdiction people come to this vertical looking for, and it is a real advantage over the alternatives — but it is worth keeping in proportion, because the encryption model is what actually limits what can be produced under legal compulsion, not the address on the filing.
Openness is where this review has to correct the marketing, and it is the most important paragraph in it. The application code is genuinely open source: the web client lives in a public repository with a real, populated source tree, and the iOS and Android clients are published separately. That is verifiable and it is not a token gesture. What is not open is the thing most people assume when they hear “open source AI” — the models. No weights, no training data, and no architecture documentation have been published for the in-house Lumo 2.0 Lite and Max models. The European Open Source AI Index, an independent academic project, examined exactly this claim and concluded the product is the least open “open” AI assistant it has indexed, a judgement it published alongside the company’s own public response. The one model in the roster that is genuinely open by that standard is Apertus 1.5, and it was built by ETH Zurich, EPFL and CSCS researchers — it is an outside model the product offers, not evidence about the operator’s own openness.
The company’s own comparison material does not draw that line. It marks the product as opening its source code to the public without qualifying which source code, which is the kind of claim that reads as covering the models when it covers the client. The distinction is not a technicality: open client code lets you check what the app sends, and it tells you nothing about what happens to the prompt after it arrives. Both facts are true at once, and a reader deserves both.
There is no independent audit. On the company’s own open-source page, every other product it lists carries a link to a published audit report; Lumo’s entry carries only repository links. This is not unique to this product — no AI chat assistant in this category currently has an independent third-party audit, and it would be dishonest to score one product down for a gap the entire vertical shares. But it does mean that the encryption chain, the no-metadata claim and the no-training policy all rest on the operator’s own description of systems nobody outside has inspected, and the strongest of those claims is the one with the least outside verification.
On product telemetry, the privacy policy states that the native apps may use mobile analytics, app-store statistics and self-hosted crash reporting. No user-facing toggle for that layer is documented, which is why it is recorded here as opt-out rather than something stronger. This concerns crash and usage diagnostics for the apps themselves, a separate question from the chat content covered by the encryption and retention terms above. No confirmed security incident affecting this product has been reported.
Features
Three models, which is a short list by the standards of this category. Lumo 2.0 Lite and Lumo 2.0 Max are the in-house pair; Apertus 1.5 is the externally built open model. Switching between them is a direct in-chat control rather than a setting buried in preferences, and all three are available on the free tier, with the usage caps landing on Max rather than locking it away entirely. Two reasoning modes, Fast and Thinking, give you a second axis to trade latency against depth.
Web search is available and optional, and the way it is implemented is worth a sentence. It can be turned off, and when it is on, the documentation states that only a simplified query rather than your full prompt is sent to the partner search APIs. That is a meaningful detail — the usual privacy cost of search-augmented chat is that your actual wording leaves the system to reach a search provider, and narrowing what crosses that boundary narrows the exposure.
File handling is the most developed feature. You can upload files manually or link them from the company’s own cloud storage, with a cap of 200 files per project. Documents up to 4,000 pages are handled through chunked retrieval rather than being loaded whole, which means long documents work but the model is reading selected passages rather than holding the entire text in view — expect good answers to specific questions and weaker ones to questions that require the whole document at once. Image generation is available on both tiers, with limits on the free one.
Projects, which group files and conversations into a persistent working context, are account-gated. That is the natural consequence of the storage model rather than an upsell: a project has to persist somewhere, and there is nowhere to persist it in a guest session.
Usability
Native applications exist for iOS and Android alongside the web client, which puts this ahead of the browser-tab-only norm in the category. The mobile apps are the same clients whose code is published, so the thing you install is the thing you can inspect.
Getting started has two doors. The guest mode opens with no signup at all — you land on the page and type, and the conversation disappears when the session ends. Creating an account, free or paid, turns on saved history that syncs across your devices, and Projects. That gradient is well designed: the no-commitment path is genuinely usable rather than a crippled demo, and the account buys capabilities rather than removing artificial obstacles.
The friction that does exist follows from the encryption. Zero-access encryption keyed to your password means the password is the only thing standing between you and your history, with the usual consequence for account recovery that any zero-access system carries. And the features most likely to make someone a daily user — accumulated history, Projects, files that stay put — are precisely the ones the guest mode cannot offer, so the frictionless entry point and the fully featured product are not the same experience.
Free-tier limits are real and unpublished. Messages, chat history, image generations and access to the larger model are all described as limited, with no numbers given for any of them. As with most products that do this, you learn where the ceiling is by hitting it.
Price & Value
The free tier is not a trial. It carries no credit card requirement and it includes every model in the roster, including the larger one, with caps rather than exclusions. For someone whose use is occasional, that may well be the whole product.
Lumo Plus is $9.99 a month billed yearly, which works out to $119.88 for twelve months, or $12.99 a month if you decline the annual commitment — a 23% difference for paying a year up front. There is a 30-day money-back guarantee. Notably, this is priced as a standalone AI subscription rather than bundled into a larger package, which makes it directly comparable to mainstream assistants at similar monthly prices.
That comparability is also the problem. At that price the market offers assistants with far broader model rosters and deeper tool ecosystems, and this product answers with three models, two of which come from the same in-house family. What you are paying for is not capability breadth but the architecture underneath it: models on the operator’s own servers, storage the operator cannot read, and a jurisdiction chosen deliberately. If that architecture is why you are here, the price is defensible. If you are comparing feature lists at $9.99, it will not win that comparison, and it is not really trying to.
Pros and Cons
- Models run on the operator's own servers rather than being proxied to an external model provider, so there is no third party receiving your prompts under terms you cannot read
- Saved chat history is held under zero-access encryption — conversation keys wrapped by a master key wrapped by your own PGP keypair — so the operator cannot decrypt stored conversations even under legal compulsion
- Guest mode works with no account at all, and the conversation is erased when the session ends
- The support documentation states that no metadata such as timestamps, IP addresses or chat context is stored
- The web, iOS and Android client code is genuinely published and populated on public repositories, so what the app sends can be inspected
- Swiss jurisdiction with a named legal entity registered in Geneva
- Native iOS and Android apps rather than a web interface alone, with history that syncs across devices once you have an account
- Optional web search sends only a simplified query to partner search APIs rather than your full prompt, and can be turned off entirely
- Every model including the larger one is available on the free tier, with usage caps rather than paywalls, and no credit card is required
- File handling is substantial — up to 200 files per project and documents up to 4,000 pages via chunked retrieval
- The "open source" claim covers the application code only; the in-house models have no published weights, training data or architecture documentation, and an independent academic index concluded this is the least open "open" AI assistant it has examined
- The vendor's own comparison material marks the product as opening its source code to the public without distinguishing client code from models, which overstates the case
- No independent third-party audit of this product exists — the vendor's own open-source page links audit reports for its other products and only repository links for this one
- Every architectural claim, including the no-metadata statement, rests on the operator's own description of systems nobody outside has inspected
- The no-training policy is the operator's own policy about its own infrastructure rather than a contractual term binding a third party, so there is no external counterparty to hold to it
- Opting into feedback shares an anonymized prompt and response with the ETH Zurich and EPFL research teams for Apertus 1.5 improvement — consent-gated, but the one route by which your text can reach model training
- Only three models, two of which come from the same in-house family, which is a narrow bench at this price point
- Saved history, Projects and persistent files all require an account, so the frictionless guest entry point is not the full product
- Free-tier limits on messages, history, image generation and the larger model are real but the numbers are not published
- Native apps may use mobile analytics and crash reporting with no documented user-facing toggle for that layer
- Zero-access encryption keyed to your password carries the account-recovery consequences that any zero-access design does
- $9.99/month yearly or $12.99 monthly is priced against general-purpose assistants that offer considerably more model breadth for the same money
Our Rating
Lumo suits the person for whom the storage question outranks the capability question: conversations encrypted so the operator cannot read them, models running on that operator’s own hardware rather than a third party’s API, a Swiss entity behind it, and a guest mode for the sessions you would rather leave no trace of. It suits you less if you want a wide bench of models, if you need a full-document context window rather than chunked retrieval, or if you want the openness claim to hold for the models and not only the client — that last one is the honest limit here, and it is the gap between what the marketing implies and what has actually been published.
- Privacy Architecture8.8/10
Models run on the operator's own servers rather than being proxied to a third party, saved history is held under zero-access encryption the operator cannot unwrap, guest mode needs no account at all, and no identifying metadata is stored — held back from a higher score only by the absence of any hardware attestation claim and by the fact that no third party has verified any of it
- Trust & Transparency6.5/10
Swiss jurisdiction, a named legal entity, genuinely open application code, and a detailed public technical description of the encryption model — against an openness claim that independent researchers dispute for the models themselves, no published audit, and a consent-gated training exception that has to be found in the documentation rather than the marketing
- Features6.8/10
Three models with in-chat switching, two reasoning modes, optional web search that sends a simplified query rather than the full prompt, and file handling up to 4,000 pages through chunked retrieval — but a roster of three is a narrow bench, and two of the three come from the same in-house family
- Usability7.8/10
Native iOS and Android apps alongside the web client, a guest mode that starts with no signup, and history that syncs across devices once you do sign in — the friction is that the interesting parts, saved history and Projects, are the ones an account gates
- Price & Value6.5/10
A free tier with every model on it, though with unpublished caps on messages, history, image generation and the larger model; the paid tier at $9.99/month yearly or $12.99 monthly is priced against general-purpose assistants without matching their model breadth
Privacy Architecture 30% · Trust & Transparency 20% · Features 20% · Usability 20% · Price & Value 10%