Cookie Policy
Last Updated: March 26, 2026
Luma AI, Inc. (“Luma,” “we,” “our,” and/or “us”) values the privacy of users of our website, applications, and services that link to our Privacy Policy (collectively, our “Services”). This cookie policy (“Cookie Policy”) explains how we use cookies, what types of cookies we use, and how you can block cookies. The Cookie Policy forms part of our Privacy Policy.
Our Use of Cookies
We and our third-party partners may collect personal data using cookies, which are small files of letters and numbers that we store on your browser or the hard drive of your computer and/or mobile device. They contain information that is transferred to your computer’s hard drive and your device’s storage. We and our third-party partners may also use pixel tags and web beacons on our website. These are tiny graphic images placed on web pages or in our emails that allow us to determine whether you have performed a specific action.
We use cookies, beacons, invisible tags, and similar technologies (collectively “Cookies”) to collect information about your browsing activities and to distinguish you from other users of our Services. This aids your experience when you use our Services and allows us to improve the functionality of our Services. Cookies can be used for performance management (i.e., collecting information on how our website is being used for analytics purposes). They can also be used for functionality management, enabling us to make your visit more efficient by, for example, remembering language preferences, passwords, and log-in details.
We additionally use Google Tag Manager to manage and deploy third-party tracking technologies on our Services. Google Tag Manager may load additional scripts and Cookies from third-party providers as described in this Cookie Policy. Below is an overview of the types of Cookies we and third parties may use to collect personal data.
Types of Cookies that We Use
Strictly Necessary Cookies
Some Cookies are strictly necessary to make our Services available to you. Disabling these Cookies may make certain features of our Services unavailable, and we cannot provide you with our Services without this type of Cookies.
| Name | Description | Retention | Domain |
|---|---|---|---|
| __cf_bm | Cloudflare places the cookie on end-user devices that access customer sites protected by Bot Management or Bot Fight Mode. | Session | .twitter.com, .apollo.io, .linkedin.com, .hubspot.com, .t.co |
| wos-session | Used to maintain the user's authentication session. Required for users to remain logged in and access their account. | Session | .lumalabs.ai |
| user-logged-in | Tracks whether the user has previously logged in to determine the appropriate authentication screen (sign-in or sign-up). | 1 year | .lumalabs.ai |
| render_token | Used to authenticate server-side rendering requests for shared board views. | Session | .lumalabs.ai |
| accessToken | JWT access token used to authenticate API requests in the Luma application. | Session (token lifetime) | .lumalabs.ai |
| refreshToken | Refresh token used for automatic token renewal to maintain user sessions. | Session (token lifetime) | .lumalabs.ai |
| user | Stores basic user profile data to support the authenticated experience. | 7 days | .lumalabs.ai |
| _geo | Stores the user's detected country code (from Cloudflare headers) to determine whether cookie consent is required under applicable law. | 24 hours | .lumalabs.ai |
| _consent | Stores the user's cookie consent preferences (analytics and marketing categories) so that consent choices persist across visits and subdomains. | 1 year | .lumalabs.ai |
Functional and Analytical Cookies
Functional and analytical Cookies allow us to understand how visitors use our Services. Functional Cookies do this by remembering information that changes the way our Services behave, such as visitors’ region. Analytical Cookies help us understand how visitors interact with our Services.
| Name | Description | Retention | Domain |
|---|---|---|---|
| _cfuvid | This cookie is set by Cloudflare to enhance security and performance. It helps identify trusted web traffic and ensures a secure browsing experience for users. | Session | .hubspot.com |
| s7 | Gather data regarding site usage and user behavior on the website. | Session | lumalabs.ai, .linkedin.com, analytics.twitter.com, .twitter.com, .t.co, aplo-evnt.com |
| _ga_# | Used to distinguish individual users by means of designation of a randomly generated number as client identifier, which allows calculation of visits and sessions. | Persistent | .lumalabs.ai |
| _ga | Records a particular ID used to come up with data about website usage by the user. | Persistent | .lumalabs.ai |
| __hssrc | Whenever HubSpot changes the session cookie, this cookie is also set to determine if the visitor has restarted their browser. | Session | .lumalabs.ai |
| hubspotutk | This cookie keeps track of a visitor's identity. It is passed to HubSpot on form submission and used when deduplicating contacts. | Persistent | .lumalabs.ai |
| __ptq.gif | Records page view data. | Session | track-na2.hubspot.com |
| __hstc | The main cookie for tracking visitors. | Persistent | .lumalabs.ai |
| __hssc | This cookie keeps track of sessions. | Session | .lumalabs.ai |
| D | Collects data on the user’s visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded with the purpose of generating reports for optimizing the website content. | Persistent | data.thoughtmetric.io |
| ph_*_posthog | Used by PostHog for product analytics, including tracking user interactions, session activity, and feature usage to help us understand how visitors use and improve our Services. | 1 year | .lumalabs.ai |
Advertising Cookies
Advertising Cookies are used to enhance user experience and facilitate Services-specific advertising activities. They help us measure the performance of our advertising campaigns to help us improve our campaigns and our Services’ content for those who engage with our advertising.
| Name | Description | Retention | Domain |
|---|---|---|---|
| _ttp | Used by TikTok to track and measure the effectiveness of advertising campaigns and to identify users across devices and sessions. Helps optimize ad delivery. | Persistent | .tiktok.com, .lumalabs.ai |
| bcookie | Used to optimize the range of advertising on LinkedIn. | Persistent | .linkedin.com |
| lidc | These cookies are associated with a B2B marketing platform, formerly known as Bizo. This sub-domain is connected with LinkedIn's marketing services that enable website owners to gain insight into types of users on their site based on LinkedIn profile data, to improve targeting. | Persistent | .linkedin.com |
| UserMatchHistory | These cookies are associated with a B2B marketing platform, formerly known as Bizo. This sub-domain is connected with LinkedIn's marketing services that enable website owners to gain insight into types of users on their site based on LinkedIn profile data, to improve targeting. | Persistent | .linkedin.com |
| lastExternalReferrerTime | Detects how the user reached the website by registering their last URL-address. | Persistent | lumalabs.ai |
| ri-* | Tracks referral and marketing attribution. | Persistent | .lumalabs.ai |
| test_cookie | A session cookie used to check if the user's browser supports cookies. | Session | .doubleclick.net |
| _fbp | Facebook tracking pixel used to identify visitors for personalized advertising. | Persistent | .lumalabs.ai |
| _gcl_au | Used by Google Ads for experimenting with advertisement efficiency across websites using their services. | Persistent | .lumalabs.ai |
| _fbc | Facebook Click ID cookie. Stores the Facebook click identifier from inbound ad links to measure the effectiveness of advertising campaigns. | 90 days | .lumalabs.ai |
| luma_ad_context | Stores UTM parameters and advertising click identifiers (such as gclid, fbclid, ttclid, msclkid, and li_fat_id) from the landing page URL to support marketing attribution. | 1 hour | .lumalabs.ai |
| ps_xid | Used by PartnerStack to store an affiliate tracking identifier for conversion attribution. | 90 days | .lumalabs.ai |
| faved_user_id | Used by Faved to assign a persistent user identifier for affiliate conversion tracking and attribution. | Persistent (localStorage) | .lumalabs.ai |
| faved_affiliate | Used by Faved to store the affiliate session data, including referral code and session identifier, for conversion attribution. | 365 days (localStorage) | .lumalabs.ai |
Session Recording and Behavioral Analytics
We use session recording tools to understand how users interact with our Services, including mouse movements, clicks, scrolling, and page navigation. This helps us identify usability issues and improve the user experience.
| Name | Description | Retention | Domain |
|---|---|---|---|
| _clck | Used by Microsoft Clarity to store a unique user identifier for session recording and heatmap analytics. | 1 year | .lumalabs.ai |
| _clsk | Used by Microsoft Clarity to connect multiple page views by a user into a single Clarity session recording. | 1 day | .lumalabs.ai |
| CLID | Used by Microsoft Clarity to identify the first-time Clarity saw this user on any site using Clarity. | 1 year | .clarity.ms |
Email and Messaging Technologies
We use messaging platforms to communicate with users about their account and product activity.
| Name | Description | Retention | Domain |
|---|---|---|---|
| Braze Web SDK | We use Braze to deliver email and push notifications related to your account and product usage. The Braze SDK may set its own cookies and local storage entries to identify your browser session and associate it with your account. | Session / Persistent | .lumalabs.ai |
Local Storage Technologies
Local storage technologies, like HTML5, provide cookie-equivalent functionality but can store larger amounts of data, including on your device outside of your browser in connection with specific applications. We use the following local storage technologies:
- X-Client-Context: A randomly generated unique identifier stored in localStorage and sent with API requests to help us identify and troubleshoot client sessions.
- color-scheme: Stores the user’s preferred color theme (light, dark, or system) in localStorage so that the chosen theme persists across visits.
- cookie-consent: Stores your cookie consent preferences in localStorage so they persist across page loads and browser sessions.
- posthog-distinct-id: Stores the PostHog analytics identifier in localStorage to maintain a consistent identity for product analytics across page loads.
- vespa-settings: Stores application preferences (such as layout and display options) in localStorage so they persist across visits.
- vespa-sidebar-width: Stores the user’s preferred sidebar width in localStorage for interface personalization.
- vespa-camera-{realmId}: Stores the canvas camera position per project in localStorage so users return to their previous view.
- activeConversationId-{realmId}: Stores the currently active conversation per project in localStorage to preserve navigation context.
- LUMA_GENIE_{id}: Tracks which user-generated creations you have already rated to prevent duplicate submissions.
- _fbc_backup: A temporary backup of the Facebook Click ID stored in sessionStorage to preserve attribution data during page redirects within a single browsing session.
- luma_ad_context: A session-scoped backup of advertising attribution parameters stored in sessionStorage as a fallback when the corresponding cookie is unavailable.
- last_event_id-{realmId}: Stores the last server-sent event ID in sessionStorage to resume real-time data connections after brief interruptions.
- vespa-err: Stores recent error information in sessionStorage to support debugging and error reporting during your current browsing session.
- mobile-email-gate-dismissed: Stores in sessionStorage whether you have dismissed the mobile access prompt during your current browsing session.
Web Beacons
Also known as pixel tags or clear GIFs, web beacons are used to demonstrate that a webpage or email was accessed or opened, or that certain content was viewed or clicked.
Third-Party Service Providers
In addition to the technologies described above, the following third-party services may process data in connection with your use of our Services:
- Vercel Analytics: We use Vercel Analytics for privacy-preserving website performance measurement. Vercel Analytics does not use cookies or fingerprinting.
- Mixpanel: We use Mixpanel for product analytics to understand how users interact with specific features of our Services. Mixpanel may set its own cookies and local storage entries to track user sessions.
- Stripe: We use Stripe for payment processing. When you interact with payment features, the Stripe JavaScript library may set its own cookies and collect device information to support fraud prevention and payment authentication.
- Freshworks: We use a Freshworks support widget to provide customer support. When you interact with the support widget, your name and email address may be shared with Freshworks to facilitate your support request.
How to Block Cookies
You can block Cookies by setting your internet browser or device to block some or all Cookies. However, if you use your browser or device settings to block all Cookies (including essential Cookies) you may not be able to access all or parts of our Services.
By using our Services, you consent to our use of Cookies and our processing of personal data collected through such Cookies, in accordance with our Cookie Policy and Privacy Policy. You can withdraw your consent at any time by deleting placed Cookies and disabling Cookies in your browser or device.
You can change your browser settings to block or notify you when you receive a Cookie, delete Cookies, or browse our Services using your browser’s anonymous usage setting. Your device may also offer settings to allow you to block or delete Cookies. Please refer to your browser or device instructions or help screen to learn more about how to adjust or modify your browser or device settings.
If you do not agree to our use of Cookies or similar technologies which store information on your device, you should change your browser or device settings accordingly. Please note that if you delete or choose not to accept Cookies from our Services, you may not be able to utilize the features of our Services to its fullest potential. Where required by applicable law, you will be asked to consent to certain Cookies and similar technologies before we use or install them on your computer or other device.
Changes to this Cookie Policy
We will post any adjustments to the Cookie Policy on this page, including if we add or remove any Cookies from our Services, and the revised version will be effective when it is posted.
Contact Us
If you have any questions or concerns about this Cookie Policy or our privacy practices, please email us at hello@lumalabs.ai or write to us via postal mail at 380 Hamilton Ave, P.O. Box 102, Palo Alto, CA, 94301.