Privacy Policy
Last updated: April 20, 2026
This privacy policy (“Privacy Policy”) describes the privacy practices of Luma AI, Inc. (“Luma,” “we,” “our,” and/or “us”) and how we collect, use, disclose, and otherwise process personal information from users of our website, applications, and services that link to this Privacy Policy (collectively, our “Services”). By using our Services, you agree to the collection, use, disclosure, and procedures described in this Privacy Policy. Beyond the Privacy Policy, your use of our Services is also subject to our Terms of Service.
This Privacy Policy does not apply where Luma acts as a processor or service provider on behalf of enterprise customers. In that context, our processing of your personal information is subject to our agreements with the enterprise customer. In those cases, the enterprise customer is the data controller, and its privacy policies will apply to the processing of your personal information. We are not responsible for the privacy or data security practices of our enterprise customers, which may differ from those explained in this Privacy Policy. Please refer to the enterprise customer’s privacy policies if you have any questions about their processing of your personal information.
Personal information we collect:
We may collect a variety of personal information from or about you or your devices from various sources, as described below.
Where applicable, we indicate whether and why you must provide us with your personal data, as well as the consequences of failing to do so. If you do not provide your personal information when requested, you may not be able to use our Services if that personal information is necessary to provide you with our Services or if we are legally required to collect it.
Information you provide to us:
- Registration and account details. When you sign up for an account, Luma will collect your personal information, such as your first and last name and email address. We may also collect authentication credentials that let you access your accounts and your information via other service providers.
- Communications. If you contact us directly, we may receive your personal information. For example, when you contact us via our website, applications, or on Discord with questions, feedback, or otherwise, we may receive your name, email address, the contents of your messages or attachments that you may send to us, and other information you choose to provide.
- Payment information. If you make a payment on our Services, your payment-related information, such as credit card or other financial information, is collected by our third-party payment processor on our behalf.
- Careers. If you decide that you wish to apply for a job with us, you may submit your contact information, employment-related information, and your resume online. We will collect the information you choose to provide on your resume, such as your education and employment experience. You may also apply through a third-party service, such as LinkedIn. If you do so, we will collect the information you make available to us through that service.
Information we obtain from third parties:
- Social media information. We may maintain pages on social media platforms, such as Facebook, LinkedIn, Instagram, and other third-party platforms. When you visit or interact with our pages on those platforms, the platform provider’s privacy policy will apply to your interactions and their collection, use and processing of your personal information.
- Third-party login information. When you link, connect, or log into our Services with a third-party service (e.g. Google, Facebook, or Apple), you direct the service to send us information such as your registration, friends list, and profile information as controlled by that service or as authorized by you via your privacy settings at that service. If you wish to limit the information available to us, you should visit the privacy settings of your third-party accounts to learn about your options.
- Other Sources. We may obtain your personal information from other third parties, such as marketing partners, publicly available sources, and data providers, and combine it with other information we have about you.
Information we collect when you use our Services:
- Account data. When you create an account, we collect your name, email address, password, and profile information.
- User content. We collect images, videos, and other files you upload to our Services.
- Conversations. Our Services allow you to interact with AI agents through chat conversations, including by submitting text, images, video, and other materials ("Inputs"). These conversations generate responses based on your Inputs ("Outputs"). We collect the content of your conversations, including any information you choose to provide in your Inputs, and this information may be reproduced in the Outputs.
- Transaction data. We collect your purchase history and subscription plan. We do not collect or store payment card information or billing address; payments and billing details are processed and stored by our third-party payment processor, Stripe, under its own privacy policy.
- Device data. We receive information about the device and software you use to access our Services, such as your computer's or mobile device's operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers (including identifiers used for advertising purposes), language settings, mobile device carrier and manufacturer, radio/network information (e.g., WiFi, LTE, 4G), application installations, and push notification tokens.
- Location Information. When you use our Services, we may receive general location information such as city, state or geographic area. For example, we infer your location by using your IP address.
- Usage Information. We automatically receive information about your interactions with our Services, such as pages or screens you viewed, how long you spent on a page or screen, browsing history, navigation paths between pages or screens, information about your activity on a page or screen, access times, and duration of access, and whether you have opened our marketing emails or clicked links within them.
- Collaboration Data. When you communicate or collaborate with other users through our Services, we and our third-party partners receive the content of the messages you send and receive and information about those messages, such as when they were sent or received, as well as real-time activity data (e.g., cursor position, editing state, presence).
- Cookies. We and our third-party partners collect information about your activities on our Services using cookies, pixel tags, SDKs, or other tracking technologies. Our third-party partners, such as analytics, advertising, and security partners, may also use these technologies to collect information about your online activities over time and across different services. You can manage your cookie preferences through your browser settings. For more information on the types of cookies in use on our Services, please see our Cookie Policy.
How we use your personal information:
We use the information we collect to:
- Provide, maintain, operate, support, and improve our Services;
- Train, develop, and improve the artificial intelligence, machine learning, and models that we use to support our Services;
- Process your payments and complete transactions with you;
- Communicate with you about our Services, including by sending announcements, updates, security alerts, and support and administrative messages;
- Provide support, and respond to requests, questions, and feedback;
- Personalize your experience on our Services;
- Facilitate the connection of third-party services or applications;
- Analyze and improve our Services and to develop new products, services, features and functionality;
- Conduct marketing or advertising activities as permitted by law, including, but not limited to, notifying you of special promotions, offers and events via email and in-app notifications;
- Comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities;
- Prevent fraud, promote safety, and enforce our legal rights, including to: (a) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (b) enforce the terms and conditions that govern our Services; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity; and
- Generate anonymous or aggregate data, containing only de-identified, non-personal information, that we may use for any lawful business purpose, including to analyze and improve our Services, conduct research, and promote our business.
We may also use the information we collect for other purposes for which we provide notice at the time the information is collected.
Legal Bases for Processing European Personal Information:
If you are located in the European Economic Area or the United Kingdom, we only process your personal information when we have a valid “legal basis,” including as set forth below.
- Consent. We may process your personal information where you have consented to certain processing of your personal information. For example, we may process your personal information to use cookies where you have consented to such use.
- Contractual Necessity. We may process your personal information where required to provide you with our Services. For example, we may need to process your personal information to respond to your inquiries or requests.
- Compliance with a Legal Obligation. We may process your personal information where we have a legal obligation to do so. For example, we may process your personal information to comply with tax, labor and accounting obligations.
- Legitimate Interests. We may process your personal information where we or a third party have a legitimate interest in processing your personal information. Specifically, we have a legitimate interest in using your personal information for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of our Services. We only rely on our or a third party’s legitimate interests to process your personal information when these interests are not overridden by your rights and interests.
How we share your personal information:
- Vendors and Service providers. We may share your personal information with third-party companies and individuals that provide services on our behalf or help us operate our Services (such as customer support, hosting, analytics, email delivery, marketing, payment processing, and database management services).
- Third-Party Integrations. If you connect a third-party service or application to our Services, we may disclose information to that third party.
- Partners and Affiliates. We may disclose information we receive to our current or future partners and affiliates for any of the purposes described in this Privacy Policy.
- Analytics Partners. We use analytics services such as Google Analytics to collect and process certain analytics data. These services may also collect information about your use of other websites, apps, and online resources. You can learn more about Google’s practices by visiting https://www.google.com/policies/privacy/partners/.
- Professional advisors. We may disclose your personal information to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.
- For compliance, fraud prevention and safety. We may share your personal information for the compliance, fraud prevention and safety purposes described above. For the avoidance of doubt, the disclosure of your information may occur if you post any objectionable content on or through our Services.
- Business transfers. We may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business transaction (or potential business transaction) such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution.
- Consent. We may also disclose your information with your permission.
Your choices:
- The public. You may choose to export output based on the pictures you submit to us and use it for any purpose, including for display on the website of an online retailer or on social media.
- Location Information. You can prevent your mobile device from sharing precise location information at any time through your device’s operating system settings.
- Access or update your information. To keep your information accurate, current, and complete, please contact us as specified below. We will take reasonable steps to update or correct information in our possession that you have previously submitted via our Services.
- Opt out of marketing communications. You may opt out of marketing-related emails or texts by following the opt-out or unsubscribe instructions at the bottom of the marketing communication we send you, or by contacting us at hello@lumalabs.ai. Even if you opt out of marketing-related communications, you may continue to receive service-related and other non-marketing communications.
- Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. There is no accepted standard on how to respond to “Do Not Track” signals, and we do not respond to such signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
- Your European Privacy Rights. If you are located in the EEA or the UK, you have additional rights described below. You may request access to the personal information we maintain about you, update and correct inaccuracies in your personal information, restrict or object to the processing of your personal information, have your personal information anonymized or deleted, as appropriate, or exercise your right to data portability to easily transfer your personal information to another company. In addition, you have the right to lodge a complaint with a supervisory authority, including in your country of residence, place of work or where an incident took place.
You may withdraw any consent you previously provided to us regarding the processing of your personal information at any time and free of charge. We will apply your preferences going forward and this will not affect the lawfulness of the processing before you withdrew your consent.
You may exercise these rights by contacting us using the contact details at the end of this Privacy Policy. Before fulfilling your request, we may ask you to provide reasonable information to verify your identity. Please note that there are exceptions and limitations to each of these rights, and that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain information for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so.
Other sites, mobile applications and services
Our Services may contain links to other websites, mobile applications, and other online services operated by third parties. These links are not an endorsement of, or representation that we are affiliated with, any third party.
In addition, our content may be included on web pages or in mobile applications or online services that are not associated with us. We do not control third party websites, mobile applications or online services, and we are not responsible for their actions or their privacy practices. Other websites and services follow different rules regarding the collection, use and sharing of your personal information. We encourage you to read the privacy policies of the other websites and mobile applications and online services you use.
Data Retention
We take measures to delete your personal information or keep it in a form that does not permit identifying you when this personal information is no longer necessary for the purposes for which we process it, unless we are required by law to keep this personal information for a longer period. When determining the retention period, we take into account various criteria, such as the type of products and services requested by or provided to you, the nature and length of our relationship with you, the impact on our Services we provide to you if we delete some personal information from or about you, mandatory retention periods provided by law, and any relevant statute of limitations. In certain cases, we also keep your information for legal reasons, including after your account has been deleted, for example to respond to a legal request or to comply with applicable law when we have a legal obligation to retain information, and to deal with and resolve requests and complaints related to data rights.
Following the relevant retention period, personal information is deleted from storage. Copies of personal information may also remain for a limited time in the backup storage that we use to recover lost information in the event of an information loss event.
Security practices
We use reasonable organizational, technical and administrative measures designed to protect against unauthorized access, misuse, loss, disclosure, alteration and destruction of personal information we maintain. Unfortunately, data transmission over the Internet cannot be guaranteed as completely secure. Therefore, while we strive to protect your personal information, we cannot guarantee the security of personal information.
Children
Our Services are not intended for use by children under 13 years of age, and no part of our Services is directed to children. If you learn that a child has provided us with personal information in violation of this Privacy Policy, then you may alert us at hello@lumalabs.ai.
Regional Disclosures
Depending on where you live, you may have specific privacy rights that apply to you. Where applicable under local law and subject to applicable exceptions, you have the following rights regarding your personal information:
- To request access to and/or a copy of certain information we hold about you (including in a portable and/or machine-readable format);
- To object to how we process your personal information;
- To update or correct your personal information;
- To request that we delete certain personal information we hold about you;
- To restrict how we process certain personal information about you;
- To request that we transfer your information to a third-party provider of services;
- To opt out of the sharing of your personal data for targeted advertising; and
- To withdraw your consent at any time (where you have provided consent for the processing of your personal information).
To exercise your rights, you or an authorized agent may submit a request by emailing us at hello@lumalabs.ai or by writing to us via postal mail at 380 Hamilton Ave, P.O. Box 102, Palo Alto, CA, 94301. After receiving your request, we may need to verify your identity before processing your request.
International Visitors
Our Services are hosted in the United States (“U.S.”) and intended for visitors located within the U.S. If you choose to use our Services from the EEA, the UK or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your personal information outside of those regions to the U.S. for storage and processing. We may transfer personal information from the EEA or the UK to the United States and other third countries based on European Commission-approved or UK Government-approved Standard Contractual Clauses, or otherwise in accordance with applicable data protection laws. We may also transfer your personal information from the U.S. to other countries or regions in connection with storage and processing of data, fulfilling your requests, and operating our Services. By providing any information, including personal information, on or through our Services, you consent to such transfer, storage, and processing. For more information about the tools that we use to transfer personal data, or to obtain a copy of the contractual safeguards we use for such transfers (if applicable), you can contact us as described below.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on our Services.
How to contact us
We are the data controllers responsible for the processing of your personal data. Please direct any questions or comments about this Policy or privacy practices to hello@lumalabs.ai. You may also write to us via postal mail at: 380 Hamilton Ave, P.O. Box 102, Palo Alto, CA, 94301