Privacy Policy
Who we are
Luma ("we", "our", "us") is an AI photography companion for Fujifilm, Canon, Nikon, and Sony shooters, built and operated by CraftedPxl, LLC as an independent product. You can reach us at info@craftedpxl.com.
Information we collect
We collect the minimum necessary to provide the service:
- Account data — email address and password (or OAuth token) when you create an account.
- Profile data — display name and avatar you optionally provide.
- Usage data — which features you use, recipes you save, gear you add, and AI tools you interact with, so we can personalise your experience and improve the product.
- Device data — device type, OS version, and app version, for crash reporting and compatibility.
- Payment data — billing is handled entirely by Polar, which acts as the merchant of record for your purchase. We store the customer and subscription identifiers Polar returns to us, together with your subscription tier; we never see or store your card details.
- Location — only if you use the “find spots near me” search in Photo Spots. Your browser asks your permission first, and the coordinates it returns are sent to our server and on to Anthropic, our AI provider, to generate shooting suggestions for that area. We cache the resulting suggestions against a coordinate pair rounded to roughly a kilometre; that cache is shared and is not linked to your account. The coordinates you searched also appear in our server logs alongside your account ID for a limited period, so that we can diagnose failures. We do not otherwise build a history of where you have been.
- Photos — images sent to AI tools for analysis are forwarded to our AI provider for the duration of that request and are not retained by us afterwards. Images you choose to save are stored: your photo vault and journal are private to your account, while images attached to community posts and published recipes are served from publicly accessible URLs so they can be displayed to other users. Anyone holding such a URL can view that image without signing in. Deleting the post or recipe removes the stored image.
How we use your information
- Authenticate you and keep your session secure.
- Personalise your feed, recipe recommendations, and AI tool results.
- Process subscription payments via Polar.
- Send optional push notifications about new recipes, community activity, or product updates (you can opt out at any time in Settings → Notifications).
- Monitor service health, diagnose errors, and improve performance.
- Comply with legal obligations.
We do not use your data to train third-party AI models, sell it to advertisers, or share it with data brokers.
Third-party services
Luma integrates the following sub-processors. Each governs its own data under its own privacy policy:
- Cloudflare — hosting, database, file storage, sign-in, image resizing, and DDoS protection (privacy policy). Your account, profile, recipes, gear, journal, vault, community posts, and the images you upload are all stored with Cloudflare, and your password is checked there, never stored in readable form. Images you attach to community posts and published recipes are resized with Cloudflare Images before they are stored.
- Resend — sends account emails, such as password-reset links (privacy policy). Resend receives your email address and the message we send you.
- Polar — payment processing and merchant of record (privacy policy). Polar is the seller of record for your subscription: it takes payment, calculates and remits any sales tax or VAT, and issues your receipt. We identify you to Polar by your Luma account ID, and Polar tells us which plan you hold.
- Web Push (browser vendor) — if you enable notifications, your browser registers a push subscription with its own vendor's push service. We store that subscription: its endpoint, plus the browser-supplied keys required to encrypt messages to it. That push service belongs to your browser vendor, not to us — for Chrome and other Chromium browsers it is operated by Google, and for Firefox by Mozilla — so delivering a notification to you means sending it to your vendor’s endpoint. We use the Web Push standard directly and do not use Firebase Cloud Messaging or any other Google messaging product of our own.
- Anthropic — AI features send only the minimum context required to generate a response (privacy policy). Under Anthropic's standard API terms, inputs and outputs are not used to train their models by default.
- Google (Gemini API) — some illustrative images in the app, such as daily recipe artwork and composition examples, are generated on demand. We send Google a short text prompt describing the image we want; we do not send your photos (API terms).
- Sightengine — automated content moderation (privacy policy). When you attach an image to a community post, that image is sent to Sightengine to be checked against our content rules before it is published.
- Google (Sign-In) — if you choose “Continue with Google”, Google authenticates you and tells us your email address, name, and profile picture. Google therefore knows you have an account with us. Your profile picture continues to be served from Google’s servers, so your browser contacts Google when it is displayed (privacy policy).
- Google Fonts — the typefaces used across Luma are loaded from Google’s font servers when a page opens, so your browser contacts Google and Google receives your IP address and browser details on each visit (privacy policy).
- Unsplash — we no longer source imagery from Unsplash ourselves, but an article in the news feed may link to an image hosted there. When one does, your browser loads it directly and Unsplash receives your IP address (privacy policy).
- Sentry — error and crash reporting (privacy policy). When something goes wrong in the app we send Sentry the technical details of the failure along with your account ID, so we can tell whether a problem affects one person or everyone.
We do not use advertising networks, analytics SDKs, or data brokers. Cloudflare Web Analytics runs at the edge and is cookieless — it does not build a profile of you across sites.
Product milestones. To understand how people get from signing up to subscribing, we record — in our own database, with no analytics provider involved — the first time your account reaches each of five steps: creating the account, getting your first recipe, seeing an upgrade prompt, starting a checkout, and a subscription becoming active. Each record holds your account ID, the step, when it happened, and one short label (for example, whether you signed up with email or Google, or which plan you chose). Nothing else about your activity is recorded this way. Turning on Settings → Analytics opt-out stops these records for your account from that point on, and deleting your account deletes them.
Where your data is processed
The services Luma depends on are located in several countries. If you use Luma from the European Economic Area, the United Kingdom, or elsewhere, your personal data will be transferred to and processed in countries outside your own — including the United States.
- Your account and content — your account, profile, recipes, gear, journal entries, and community posts are stored in a Cloudflare database located in Western Europe.
- Your files — vault photos, journal photos, and any images you upload are stored in Cloudflare storage located in eastern North America.
- The app and its requests — served through Cloudflare's global edge network, so both the app and the requests it makes are handled at whichever location is nearest to you.
- The sub-processors listed in § 04 — each operates from its own jurisdiction, which is not always the same as ours or yours. Their locations and safeguards are described in their own privacy policies, linked above.
Each of these providers publishes the safeguards it applies to international transfers, such as the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework. We rely on those safeguards rather than maintaining separate ones of our own.
If you would rather your data were not processed in these locations, please do not create an account. If you already have one, you can delete it at any time from Profile → Data management, which removes your personal data as described in § 07.
Why we are allowed to process your data
If you are in the EEA or the UK, data protection law requires us to have a lawful basis for each thing we do with your data. Ours are:
- To provide the service you asked for (performance of a contract) — creating and running your account, signing you in, storing your recipes, gear, journal, and vault, and running the AI features when you invoke them. Without this we cannot give you the product.
- To take payment (performance of a contract, and legal obligation) — processing subscriptions through Polar, and keeping the billing records that tax and accounting law requires us to keep even after you leave.
- To keep the service safe and working (legitimate interests) — automated moderation of images posted to the community, rate limiting, abuse prevention, and error reporting; and recording the product milestones described in § 04, so we can see where people get stuck between signing up and subscribing (you can switch these off in Settings). Our interest is in protecting users, keeping Luma running and improving it; we have weighed that against your privacy and limited what is sent to what each check needs.
- With your consent — push notifications, and the “find spots near me” search, which is the only feature that uses your location. You choose whether to turn these on, and you can withdraw consent at any time in Settings or in your browser, without affecting anything you did before you withdrew it.
Where we rely on legitimate interests, you have the right to object — see § 08.
Data retention
We retain your account data for as long as your account is active. If you delete your account, all personal data is permanently removed within 30 days, except where retention is required by law (e.g. billing records).
Transient AI processing data (e.g. EXIF analysis inputs) is discarded within 24 hours.
Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Object to or restrict certain processing.
- Data portability (receive your data in a structured format).
To exercise any of these rights, email us at info@craftedpxl.com. You can also delete your account directly from the app under Settings → Data → Delete account.
Cookies and local storage
Luma uses browser localStorage and session tokens only to keep you signed in and remember your preferences. We do not use advertising cookies or cross-site tracking.
Children
Luma is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe we have collected data from a child, please contact us and we will delete it promptly.
Changes to this policy
We may update this policy from time to time. We'll notify you of material changes via in-app notice or email. Continued use of Luma after the effective date constitutes acceptance of the updated policy.
Contact
Questions? Requests? Something feels off? Email us at info@craftedpxl.com — we read every message.