Privacy Policy
This Privacy Policy explains how Luma collects, uses, stores, shares, and protects information when you use the Luma mobile application, luma-app.space legal website, and related services.
1. Scope
This Policy applies to the Luma Android app, its cloud-backed features, AI processing flows, optional rewarded advertising, optional subscription features, the luma-app.space legal website, and support or legal communication related to Luma.
2. Information we collect
2.1 Account and profile data
- email address and Firebase Authentication account metadata
- sign-in provider information such as email or Google Sign-In
- first name, last name, age-confirmation status, gender selection, profile image
- language, timezone, notification settings, and personalization choices
- selected AI personality and Pro or tariff status
2.2 Content users create
- chat messages and recent conversation context
- voice-call transcripts or speech-derived text where voice features are used
- organizer events, notes, plans, dictionaries, memories, and growth workspaces
- custom AI personalities, feedback, support tickets, bug reports, and feature requests
- images users attach to chat or profile flows
Chat history is stored locally on the user's device by default. Luma does not store chat history as server-side chat history unless the user chooses a feature that syncs, shares, backs up, imports, or otherwise uploads chat content or related context. However, when a user sends a message to Luma AI, the message and relevant context are transmitted to Luma's backend and cloud AI providers for processing so a response can be generated.
Feature-specific data
- For voice interaction, microphone audio is processed temporarily on the device to create a transcript. The transcript is sent to Luma's backend and cloud AI services; when text-to-speech is used, response text, selected voice, and language are sent to Microsoft Edge speech services.
- For Nearby, navigation, and travel tools, we may process precise or approximate location, location searches, destinations, route information, and venue details only when the user starts the relevant feature. Luma does not create a continuous location history.
- Nearby collects profile, age-confirmation, optional profile image and bio, interests, meetup, participant, chat, review, block, and report data. Selected profile and meetup information is visible to other eligible Nearby users or meetup participants as described in the feature.
- Travel workspaces may contain destination and accommodation details, selected coordinates, dates, saved places, budget, party, language, food, dietary, and mobility preferences. They are private to the account and are not shared with Nearby.
- Screen capture is initiated by the user through Android's MediaProjection flow. Captures and crops are stored temporarily on the device; a selected image is sent to Luma AI only when the user attaches and sends it in chat.
- When a Pro user shares a synced chat snapshot, Luma stores the selected chat messages and metadata, the sender's display name and email, and an access code. The link can be imported for 24 hours unless the owner revokes or replaces it; recipients receive a local copy.
- Dictionary and image lookup may send the search word or image query, language, and ordinary request metadata directly to DictionaryAPI.dev, Wiktionary or Wikimedia Commons, Pixabay, or Pexels. Optional Pixabay and Pexels API keys entered by the user are stored locally in Android SharedPreferences and sent only to the selected provider.
- Security Agent processes the target URL or Git repository, ownership confirmation, scan metadata, and resulting findings. If GitHub is connected, Luma requests
repo,user, andread:userscopes to read the GitHub profile and repository list, including private repositories the user authorizes. A GitHub access token may pass through Firebase, Cloud Tasks, and the isolated worker for the requested scan.
2.3 Billing, rewards, and verification records
- Google Play subscription product identifiers, purchase tokens, token hashes, and expiry states
- purchase verification records and subscription history metadata
- Luma Coin balances, redemptions, and purchase history
- rewarded ad verification records, response identifiers, reward statuses, timestamps, and anti-fraud metadata
We do not receive or store full payment card numbers. Payments are processed by Google Play.
2.4 Device, app, and security information
- Firebase Cloud Messaging token for push notifications
- app integrity signals such as Firebase App Check or Google Play Integrity results
- request metadata and security logs generated by Google Cloud and related infrastructure
- an app-scoped installation identifier stored locally for anti-abuse, reward verification, and limit enforcement
- basic encrypted local cache used for app continuity and performance
Luma does not receive or store raw fingerprint templates, face templates, or similar biometric templates. Biometric matching is handled by the device or operating system.
3. How we use information
- create and secure user accounts
- provide chat, organizer, planner, dictionary, memory, and Growth Hub features
- process AI requests through our backend and cloud AI providers
- apply personalization and AI personality settings
- deliver notifications and reminder flows selected by the user
- verify subscriptions and maintain Pro access
- verify rewarded ads, credit rewards, and prevent abuse or duplicate rewards
- debug, maintain, improve, and secure the app
- respond to support, deletion, and legal requests
4. When information may be shared
We do not sell personal or sensitive user data for money.
We may share information with service providers and platforms needed to operate Luma, including:
- Google Firebase and Google Cloud, including Firestore, Cloud Functions, Storage, App Check, and Messaging
- Google Cloud Vertex AI for AI generation or moderation workflows
- Google Play and Google Play Billing for subscription purchases and verification
- Google Sign-In if the user chooses that sign-in method
- Google AdMob and related Google systems for optional rewarded advertising
- Resend for verification and password reset emails
- regulators, authorities, advisers, or successors where legally required or operationally necessary
- Microsoft Edge speech services for selected text-to-speech requests; DuckDuckGo or Yahoo for user-requested web lookup; and OpenStreetMap, Nominatim, or OSRM for mapping, geocoding, venue, or route requests
- Firebase Crashlytics for crash diagnostics and Google Cloud Run and Cloud Tasks for Security Agent processing
- OpenAI for selected AI requests and safety moderation only when a server-controlled production rollout enables that route
- GitHub for authorized repository access; DictionaryAPI.dev, Wiktionary and Wikimedia Commons for dictionary or media lookup; Pixabay and Pexels when selected by the user; and Hugging Face or GitHub Releases for downloading on-device speech models
5. AI processing
When users send chat prompts, use voice interactions, attach images, work in Growth Hub, or ask Luma to create structured content, relevant information may be transmitted to Luma's backend and cloud AI services so the feature can function.
By default, Luma does not keep full chat history on our servers as a synced server-side conversation archive. Individual AI requests may be processed transiently by Cloud Functions and cloud AI providers to generate responses, enforce limits, protect the service, and support the specific feature requested. Server-side storage of chat content or chat-derived context happens only when the user chooses a cloud-backed feature such as sync, sharing, Growth Hub import, memory saving, support submission, or another feature that requires uploading or saving that content.
AI output may be inaccurate, incomplete, outdated, or unsuitable for high-risk decisions, even when it sounds confident. Users are responsible for reviewing AI output before acting on it.
Luma does not use user prompts, images, Travel context, or Security Agent findings to train a Luma general-purpose model. Google Vertex AI is the default cloud AI provider. A fail-closed, server-controlled rollout may route selected eligible requests to OpenAI and may fall back to verified Gemini models after retryable failures.
Requests sent through the OpenAI route use API storage controls that disable model-response storage for the request. AI providers may still retain limited security or abuse-monitoring records under their applicable enterprise or API terms. Luma sends a pseudonymous, hashed safety identifier where supported instead of the user's email address.
5.1 Security Agent and code-audit privacy
For a Security Agent scan, Luma sends the authorized public HTTPS website or Git repository target and scan parameters to an isolated Google Cloud Run worker. A GitHub token may be included temporarily for an authorized private-repository scan. Repository working files are kept in a temporary worker directory and removed when that scan finishes; Luma does not intentionally store raw cloned repository files as persistent user content.
Luma stores scan jobs, verified-domain records, authorization and audit confirmations, report metadata, target references, usage telemetry, and vulnerability findings in Firestore so the account holder can view results and Luma can prevent abuse. GitHub and Firebase Authentication may retain account-linking or authorization records under their own terms.
AI output may contain hallucinations, fabrications, false facts, false citations, incorrect dates or reminders, invalid plans, code errors, or other mistakes. AI output is generated automatically and may not be independently verified by Luma before it is shown. Disclaimers and liability limits for AI output are described in the Terms of Service.
6. Ads, ad-request data, and reward verification
Luma includes optional rewarded ads. If a user chooses to watch one, Google AdMob and related Google systems may process ad-request, device, diagnostic, measurement, and advertising-related information according to Google's own policies.
For rewarded ads, Luma also stores and processes reward-verification metadata needed to:
- validate that a reward callback is legitimate
- prevent duplicate rewards or reward fraud
- apply per-user and per-install anti-abuse limits
- credit the correct reward outcome
This reward-verification metadata may include app-scoped installation identifiers, pseudonymous user linkage, reward callback identifiers, ad verification timestamps, and anti-fraud signals used by our backend.
7. Local storage and sync
Some content remains locally on the device by default. Selected features may also sync data to cloud storage or cloud-backed databases when the user chooses to use those flows.
Chat history is local-only by default unless the user chooses a feature that uploads or syncs it. Even when chat history remains local-only, individual messages sent to online AI features are transmitted to our backend and AI providers for processing and response generation.
The legal website uses browser local storage to remember language, theme, and the cookie-notice choice. We do not currently use behavioral advertising or analytics on these legal pages. Hosting and security providers may still create ordinary request and security logs.
8. Retention and deletion
We retain data for as long as reasonably necessary to operate, secure, and support the app, comply with law, prevent abuse, resolve disputes, and maintain billing or reward integrity.
- account and user content are generally retained while the account is active
- verification codes are short-lived and expire automatically
- reward and anti-fraud records may be retained for operational or dispute windows
- purchase and subscription verification records may be kept for billing, tax, fraud prevention, and compliance
- limited pseudonymous anti-abuse records may remain when necessary to protect the service
- chat history that remains local-only is not retained by Luma as server-side chat history, although individual AI requests may pass through our backend and AI providers for processing
- shared chat snapshots stop being importable after 24 hours, revocation, or replacement; residual records may remain until scheduled cleanup, backup expiry, or account deletion
- user-scoped web-search cache entries expire after no more than 10 minutes; provider security logs may follow the provider's own retention terms
In-app account deletion is scheduled first. The account enters a 3-day deletion window, and the user can restore it by signing in again during that period. If the account is restored, another deletion request cannot be made for 1 day as an anti-abuse measure. After the 3-day window, we generally delete or de-identify the associated app-account data unless some categories must be retained for fraud prevention, billing, legal compliance, dispute handling, or service security.
After the recovery window, the deletion workflow is designed to delete or de-identify the primary account record, user-owned cloud content, Travel workspaces, Nearby profiles and owned meetups, and Security Agent jobs, reports, verified-domain records, and usage data. Content involving other users may be detached, de-identified, or retained where necessary to preserve their content, handle safety reports, prevent fraud, resolve billing disputes, or comply with law. Deleting the Luma account does not automatically erase copies already imported or saved by another user or records independently held by a third-party provider.
9. User choices and rights
Depending on the user's location and applicable law, the user may have rights to access, correct, delete, restrict, or object to processing; receive portable data; withdraw consent where processing relies on consent; and lodge a complaint with a competent supervisory authority.
Users can manage or delete parts of their content directly in the app, revoke device permissions in Android, and revoke connected-provider access in that provider's settings. For broader requests, portability, consent withdrawal, or deletion issues, contact support. Exercising a legal right will not result in discriminatory treatment.
Legal bases and international processing
Where applicable law requires a legal basis, Luma relies on performance of the user agreement for account and requested features; consent for optional permissions and processing where required; legitimate interests in service security, fraud prevention, diagnostics, moderation, and improvement; and legal obligations for billing, tax, accounting, or lawful requests.
Service providers may process data outside the user's country. Where required, Luma relies on appropriate contractual safeguards, including standard contractual clauses or equivalent mechanisms, together with technical and organizational safeguards. Contact support to request more information about the safeguards relevant to a transfer.
Luma uses automated systems for AI output, spam and abuse prevention, integrity checks, moderation support, rewards, quotas, and security findings. Luma does not intentionally make solely automated decisions that produce legal or similarly significant effects about a user without the safeguards required by applicable law.
10. Children
Luma is not intended for children under 13, or a higher age where local law requires parental consent. If a child is believed to have provided data in violation of this rule, contact us and we will review the case.
Luma Nearby is available only to users aged 18 or older. We may restrict or remove Nearby access if age information is inaccurate or this requirement is not met.
11. Security
We use reasonable safeguards such as authenticated access controls, HTTPS/TLS, server-side validation, App Check, anti-abuse controls, and encrypted local storage where supported. No service can guarantee absolute security.
12. Changes to this Policy
We may update this Privacy Policy from time to time. If a change materially affects how personal data is used, we will provide notice through the app, website, email, or another appropriate channel before or when the change takes effect, as required by applicable law.
13. Contact
For privacy questions, account deletion requests, or data-related
requests, contact:
support@luma-app.space
https://luma-app.space