Privacy Policy
What we collect, why we collect it, who touches it, and how you get rid of it.
Effective 3 August 2026
Who we are
Lumo ("we", "us") is an AI character chat app published by Ratera Yazılım ve Bilişim Anonim Şirketi. This policy explains what we collect when you use the Lumo iOS app, why we collect it, who we share it with, and what you can ask us to do about it.
It applies to the app and to this website. It does not apply to anything you do on a third-party service we link to.
Ratera Yazılım ve Bilişim Anonim Şirketi is the data controller for the information described here.
Information you give us
- Account details. You sign in with Apple or Google; we never see or store a password. From your provider we receive an account identifier and, where you allow it, your email address. If you use Sign in with Apple's private relay, the relay address is the only address we ever see.
- Profile details. The display name and date of birth you enter when you set up your account, and optionally your gender. You may later add a nickname, a short bio and a profile picture.
- Personas. If you write a persona — a short description of who you want to be in a conversation — we store it and include it in the request that generates a reply.
- Your conversations. The messages you send, the replies generated for you, the images generated in a conversation, and anything you ask a conversation to remember.
- Characters you create. The name, description, greeting, artwork and settings of any character you make, and whether you chose to publish it.
- Reports and support messages. What you write when you contact support or report a character, a reply or another person's profile, including which item the report is about.
- Settings. Your language, notification, appearance and content settings, and your time zone — which we use so a notification does not arrive in the middle of your night.
Information we collect automatically
- Usage data. Which screens you open and which features you use, collected through Firebase Analytics, so we can see what works.
- Crash and diagnostic data. Stack traces and device state when the app crashes, through Firebase Crashlytics.
- Device identifiers. A device-scoped identifier used to group analytics and crash reports.
- Push token. If you allow notifications, the token Apple issues for your device, so we can deliver them.
- Activity counts. How many times you opened the app and how many messages you sent on a given day, stored on our own servers so we can measure whether people come back.
- Experiment assignment. Which variant of a feature or price you were shown, so a test can be read honestly.
- Purchase state. Whether you hold an active subscription, and your gem balance and its history, from Apple and RevenueCat.
We do not track you across other companies' apps or websites, and we do not ask for the App Tracking Transparency permission. Our iOS privacy manifest declares this data as not linked to your identity and not used for tracking.
We do not collect your location, your contacts, your photo library or your microphone. The app only reads a photo you deliberately pick.
Your conversations and the AI
This is the part most people want to understand, so we will be direct about it.
Your conversations are stored against your account so you can pick them up again later. Access rules enforced by the database, not merely by the app, restrict every conversation and message to the account that created it. Nobody else using Lumo can read them.
To generate a reply, the message you send — together with recent messages from the same conversation, anything that conversation remembers, your persona if you wrote one, and the character's hidden instructions — is passed to the AI infrastructure that produces the reply. Some of that infrastructure is operated by specialist providers on our behalf. We do not send your name, your email address or your date of birth with it.
When an image is generated in a conversation, a description of the scene and, where needed, the character's reference artwork are passed to the image generation infrastructure. Your messages are not sent as-is, and part of that work runs on software we operate ourselves.
We do not use your conversations to train AI models, and we do not publish them or sell them.
Staff do not read conversations as a matter of course. We may access a specific conversation only where it is necessary to investigate a report, a suspected breach of our Terms, or a legal obligation.
Notifications
If you allow notifications, we send them for three reasons: a reply or an image you were waiting for has arrived, support has answered your ticket, or a conversation you left has something waiting in it. We keep a record of what we sent and whether it was delivered, so you are not sent the same thing twice.
You can turn notifications off in iOS Settings or in the app at any time. Doing so does not affect anything else.
Purchases, subscriptions and gems
Purchases are made through the Apple App Store. Apple processes the payment; we never receive your card details.
RevenueCat validates the receipt and tells us which subscription you hold, and Superwall decides which paywall design you are shown. We keep a record of your gem balance and of each grant and spend, because that ledger is what protects you if something is charged and not delivered.
The parts of Lumo other people can see
Most of Lumo is private. These parts are not, and it is worth being clear about which:
- Your profile — your nickname, bio and picture — is visible to anyone who opens it.
- A character you publish is visible to everyone, along with statistics such as how many people have chatted with it.
- Who you follow, and who follows you.
Your conversations, your messages, your personas, your date of birth, your email address and your purchases are never visible to another user.
How we use what we collect
- To run the service: create your account, show you characters, generate replies and images, and keep your history.
- To enforce the age limit. This is the only thing your date of birth is used for.
- To sell and manage subscriptions, to keep your gem balance correct, and to decide which paywall to show you.
- To send the notifications you asked for.
- To fix crashes, understand which features get used, and run product experiments.
- To keep the service safe: investigate reports, prevent fraud and abuse, and enforce our Terms.
- To meet legal obligations.
Where the law asks for a lawful basis, we rely on the performance of our contract with you for the parts needed to run the service, on your consent for notifications, and on our legitimate interest in a working, safe and financially sound product for measurement, fraud prevention and safety.
Where your data is held
Our servers are in Frankfurt, Germany, inside the European Union. If you use Lumo from elsewhere, your information is transferred to and processed there.
Some of the service providers named above process data in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses or an equivalent transfer mechanism.
How long we keep it
Your account, profile, personas, characters and conversations are kept for as long as your account exists. When you delete your account they are permanently deleted, along with the images generated in your conversations.
A report you filed about someone else remains readable to our safety team after your account is gone, without your identity attached, because that is the case where the record matters most.
Crash and analytics records are retained on a rolling basis by the providers named above and are not tied to your identity. Records we are legally required to keep — transaction records for tax purposes, for example — are kept for as long as the law requires.
Security
Traffic between the app and our servers is encrypted in transit. Access to conversations, personas and purchases is enforced at the database level rather than in the app, so a flaw in the client cannot expose another person's data. Access to production systems is limited to the people who need it.
No service can promise perfect security and we will not pretend otherwise. If a breach affects your personal data we will notify you and the relevant authority as the law requires.
Age limit
Lumo is for adults. You must be 18 or older to create an account. We ask for your date of birth at sign-up for that reason and refuse accounts that do not meet the limit.
We do not knowingly collect information from anyone under 18. If you believe someone under 18 has created an account, write to us at the address below and we will delete it.
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it. You can delete your account and everything in it from inside the app at any time — Settings, then Delete account.
If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the right to object to or restrict certain processing, the right to data portability, and the right to complain to your local data protection authority. Where we rely on your consent you can withdraw it at any time.
If you are in Türkiye, you hold the rights set out in Article 11 of the Personal Data Protection Law (KVKK No. 6698) and may apply to us using the contact details below.
If you live in a US state with its own privacy law, you have the rights that law gives you, including the right to know, to delete and to correct, and to opt out of sale or sharing — we do not sell or share personal data as those laws define it.
We answer requests within the period the applicable law sets, and we may need to verify your identity first.
Changes to this policy
If we change this policy we will update the date at the top of the page, and for material changes we will tell you in the app before the change takes effect.
Contact us
Write to support@lumochat.ai for anything in this policy, including access and deletion requests. The data controller is Ratera Yazılım ve Bilişim Anonim Şirketi.