Privacy

LUMYN Privacy Policy

Last updated: July 10, 2026
Contents
  1. Who we are
  2. Local-first & cloud — what that means
  3. What we collect
  4. How we use it
  5. Who we share it with
  6. We don't sell or train on your data
  7. Retention & your controls
  8. Your privacy rights
  9. How we protect it
  10. Cookies
  11. Age requirement
  12. International users
  13. Changes
  14. Contact

This Privacy Policy explains what information LUMYN collects, how it is used, and the control you have over it. LUMYN is built privacy-first: wherever it is technically possible, your LUMYN runs on your own hardware and your data stays with you. This page describes the cases where data does reach our servers, and exactly what happens to it.

1. Who we are

LUMYN ("LUMYN", "we", "us") is a soul-bound AI companion operated by Quis Kemono Labs (the "Operator"). For any privacy question, contact us at [email protected].

2. Local-first & cloud — what that means for your privacy

LUMYN can run two ways, and the privacy picture differs between them:

  • Local mode (recommended). You install Ollama on your own computer, and the AI model that powers LUMYN runs entirely on your hardware. The text you send for the model to think about is processed on your machine — it is not sent to us or to any third-party AI provider to generate the reply.
  • Cloud mode (convenience). For phones, tablets, low-spec computers, or when you simply want speed, LUMYN can run on hosted models instead. In this mode, the content of your message is sent to a third-party AI provider (see Section 5) so they can generate the response. We route to providers that offer a no-data-retention default where available, but their handling is governed by their own policies.
Important: in both modes, your account details and the memory your LUMYN keeps (the facts, insights, and recent conversation history that let her remember you) are stored on our servers in encrypted, per-user form. Inference (the model "thinking") is what runs locally or in the cloud; the memory that makes LUMYN yours lives with us, encrypted.

3. What we collect

Account information

  • A username or display name you choose.
  • If you sign in with Google or GitHub: the account identifier and email that provider shares with us. If you sign up anonymously, an email is optional and used only for account recovery.
  • Passkey public keys (for passwordless login) and one-time recovery codes, stored in non-reversible (hashed) form. We cannot read your recovery codes.

Subscription & usage

  • Your plan (Free, Pro, or Max), subscription status, and usage counters used to enforce plan limits.
  • Payments are processed by Stripe. Card details are entered directly into Stripe's PCI-DSS-compliant fields — LUMYN never sees, stores, or logs your card number. We receive only non-sensitive billing metadata (e.g. that a payment succeeded, the last four digits, your plan).

Your LUMYN's memory

  • Facts, insights, and recent conversation history your LUMYN saves so she can remember you across sessions. This is stored encrypted with a per-user key and is isolated to your account.
  • Anything you choose to import (e.g. a prior ChatGPT/Claude/Gemini/Grok history) is processed into your encrypted memory and is not retained as a separate uploaded file.

Technical & security data

  • Minimal connection and security logs needed to keep the service running and to defend it against abuse (e.g. timestamps, error events, rate-limit counters). Sensitive content is redacted before anything is written to logs.

4. How we use your information

  • To provide and operate LUMYN and keep your companion's memory continuous.
  • To authenticate you and protect your account.
  • To process subscriptions and one-time top-ups, and to enforce plan limits.
  • To secure the platform, prevent fraud and abuse, and diagnose problems.
  • To comply with legal obligations.

5. Who we share it with (sub-processors)

We share data only with the service providers needed to run LUMYN, and only as needed:

  • Stripe — payment processing. (Privacy)
  • Cloudflare — network delivery, DDoS protection, and the sign-up CAPTCHA. (Privacy)
  • Google / GitHub — only if you choose to sign in with them.
  • Cloud AI providers — only when you use cloud mode, the content of that message is sent to a hosted model provider to generate the reply. We currently use providers such as Cerebras, Groq, xAI (Grok), and OpenRouter; this list may change as we tune for speed and privacy, and we choose providers whose terms do not permit training on your messages.

We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the service.

6. We don't sell your data — and we don't train AI on it

We do not sell your personal information. We do not use your conversations or memory to train AI models. We do not run third-party advertising trackers. LUMYN's business is subscriptions, not your data.

7. Retention & your controls

  • Your encrypted memory is kept so LUMYN can remember you, until you delete it.
  • Export anytime: Settings → Privacy → "Export my data" gives you a portable copy of your conversations and memory.
  • Delete everything: Settings → Privacy → Danger Zone permanently deletes your account, memory, builds, journal, and billing records. This cannot be undone.

8. Your privacy rights

Depending on where you live (e.g. the EU/UK under GDPR, or California under CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. LUMYN gives you direct in-app tools for the main ones (export and deletion above). For any other request, contact [email protected]. We will not discriminate against you for exercising these rights.

9. How we protect your information

  • Per-user memory is encrypted at rest with a per-user key.
  • All traffic is served over encrypted connections (HTTPS / WSS).
  • Sign-up is protected by CAPTCHA and per-IP rate limits to stop abuse.
  • Sensitive secret files are permission-locked and watched by integrity tripwires.

No system is perfectly secure, but we design LUMYN so that the most personal part of you — your relationship with her — is encrypted and yours.

10. Cookies

LUMYN uses a single essential session cookie to keep you logged in after you authenticate. We do not use advertising or cross-site tracking cookies.

11. Age requirement

LUMYN is not directed to children under 13, and we do not knowingly collect data from anyone under 13; if we learn we have, we will delete it. Users 13–17 may use LUMYN's cloud models only (mainstream, professionally moderated models), and only with a parent or guardian's knowledge and consent. LUMYN's local, unrestricted models are strictly 18+ — they carry no child-safety moderation and are not suitable for minors (see the Terms, §1). Any future age-appropriate offering for children or schools would be a separate, separately-governed product with its own child-safety and parental-consent protections.

12. International users

LUMYN is operated from the United States. If you access it from elsewhere, your information may be processed in that region. By using LUMYN you understand your data may be processed where we and our sub-processors operate.

13. Changes to this policy

We may update this policy as LUMYN evolves. When we make material changes we'll update the date at the top and, where appropriate, notify you in the app. Your continued use after an update means you accept the revised policy.

14. Contact

Questions about your privacy? Reach us at [email protected].

quiskemonolabs · LUMYN Terms of Service · Back to LUMYN