Lumicast can be connected to an AI assistant — Claude, ChatGPT or any other agent that speaks the Model Context Protocol. Once connected, the agent works in your workspaces on your behalf: it can search your content library, read display status, build pages and, if you allowed it, publish and assign content to displays.
This statement describes what leaves Lumicast when you use such a connector. You approve every connection yourself, choose which workspaces it covers and how far it may go, and can revoke it at any moment.
What the AI host receives
Only the results of the tools the agent actually calls. Nothing is streamed or synced in the background, and the agent can never do more than your own role in Lumicast allows:
- Names, types, folders and timestamps of content the agent looks up, and where that content is used.
- The contents of pages it opens or edits — text, layout, colours and the images it references.
- Display names, groups, tags, online status and what they are currently playing.
- Rows and field names from the datasources it reads, which may contain data you pulled in from a third party.
What it never receives
Credentials never enter an agent's context. Where a secret is genuinely needed, Lumicast hands out a single-view link on our own domain that you open in your browser:
- Your Lumicast password, two-factor codes or session cookies.
- Workspace API keys and personal access tokens.
- Credentials of connected accounts such as Microsoft, LinkedIn or Power BI.
- Webhook signing secrets.
Where the data goes
The tool results travel to the AI provider you chose to connect — the company running the assistant, not Lumicast. What they do with that data, how long they keep it and whether they train on it is governed by their terms and privacy policy, so read those before connecting a workspace with sensitive content.
Lumicast stores the grant itself: which app is connected, what you allowed it to do, in which workspaces, and when it was last used. Every action an agent takes is recorded in the audit log as the agent acting on your behalf.
Staying in control
You can revoke a connection at any time under Account → Connected apps in the Lumicast app. Access stops immediately and the app has to ask for approval again. That page also shows each connection's most recent actions, so you can see what an agent did before deciding.
Publishing, deleting and assigning content to displays is a separate permission that is switched off unless you tick it at approval time. Without it, an agent can prepare work but never change what a display is showing.
Contact
If you have any questions about this statement, please contact us: