Luminary

Luminary Privacy Policy

Last Updated: September 1, 2026

LuminaryAITech, Inc. (together with our affiliates, "Luminary," "we," "our," or "us") develops AI-powered products and services that help people ask questions, understand information, work with documents and images, and explore ideas in more interactive ways.

We are committed to respecting your privacy and protecting the personal information we obtain from you or about you. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you use our website, web application, mobile applications, and other products, services, and features that link to this Privacy Policy (collectively, the "Services"). It also explains the choices available to you and your rights regarding your personal information.

Please read this Privacy Policy carefully. By using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, you should not use the Services.

If you have questions about this Privacy Policy or would like to exercise your privacy rights, you can contact us at support@useluminary.ai. For legal notices, you can contact us at admin@useluminary.ai.

1. Personal Information We Collect

We collect personal information in three main ways: information you provide to us, information we receive from your use of the Services, and information we receive from third-party services that help us operate Luminary. We minimize our collection of personal information to what is reasonably necessary to provide, secure, maintain, improve, and develop the Services, support the features you request, comply with law, and protect Luminary and our users.

Some information is required to provide the Services. For example, if you create an account, we need account and authentication information. If you send a chat message, upload a document, analyze an image, or use voice input, we need to process that content to provide the requested feature. Some information is optional. For example, location permission is optional and used for local or regional news; camera, microphone, photo library, and media permissions are used only when you choose features that require them; and push notifications are optional and used to notify you when an answer, analysis, or requested result is ready. Some information is collected automatically when you use the Services, such as logs, device information, usage information, and security-related information.

When you create an account or sign in, we may collect account information such as your username, email address, Clerk ID or other authentication identifier, account type, verification status, authentication tokens, session information, document usage information, push notification tokens, deletion request timestamp, account creation and usage timestamps, and related account records. If you sign in using Google Sign-In or Sign in with Apple, we may receive information made available by that authentication provider, such as your email address and authentication identifier, depending on the provider and your settings. For users authenticated through Luminary-controlled password systems, passwords are hashed using bcrypt, and we do not store plaintext passwords. For users created through Clerk or another authentication provider, authentication may be handled by that provider.

Luminary may allow you to use certain features as a guest. For guest users, we may create or use a device-based guest identity. This may include a stable per-install device identifier, a backend-issued guest user record, guest access tokens, guest session identifiers, timestamps, and usage information associated with the guest account. Guest users do not provide an email address, name, phone number, or other account identifier unless they later sign up or sign in. Guest or temporary sessions may be cache-only and may expire after a limited period, such as 24 hours. Guest accounts may not have all account-management, recovery, or deletion options available in the app.

We collect the content you provide to Luminary, including prompts, questions, chat messages, uploaded files, selected or highlighted text, documents, PDFs, Word files, presentations, screenshots, images, photos, diagrams, charts, graphs, slides, forms, handwritten notes, audio recordings, links, webpages, YouTube or video links, notes, generated content, and any other material you choose to submit, upload, attach, analyze, or interact with through the Services (“User Content”). We also collect or generate information related to your use of the Services, such as AI-generated responses, analysis outputs, explanations, quizzes, citations, sources, videos, images, maps, overviews, related ideas, session titles, session summaries, memory outputs, insight outputs, and other content generated or displayed in connection with your use of Luminary.

When you use Luminary, we collect information about your activity and interactions with the Services. This may include the features you use, messages you send, answers you receive, concepts you click, text you highlight, Quick Analysis and Deep Analysis activity, videos opened, sources opened, documents opened, images uploaded, maps and overviews opened, quizzes generated or answered, Play activity, search queries, news queries, selected interest topics, server-side session search queries, public share activity, link interactions, session duration, navigation patterns, timestamps, and other usage events. Luminary is designed around interactive exploration, so we may collect information about how you move through information, including exploration order, concepts explored, depth of exploration, frequency and recency of interactions, highlights, analysis usage, document activity, image activity, video activity, source activity, quiz activity, Play activity, and similar signals.

We collect log data and technical information when you access the Services. This may include IP address, request URL, HTTP method, response status, user ID, session ID, message ID, document ID, share ID, device ID, error messages, stack traces, AI request metadata, AI response metadata, truncated question or search-query text where configured, timestamps, and performance information. Server logs may be stored in systems such as AWS CloudWatch, Rollbar, load balancer logs, or other operational systems.

When you use the Luminary mobile apps, we may collect or process device and app information, including device ID or per-install identifier, push notification token, platform, device model, brand, manufacturer, whether the device is physical, operating system, operating system version, app version, build number, Expo SDK version, environment, effective app language, device locale, and IP address visible to our backend when requests are made. Firebase Messaging may generate a Firebase Installation ID and FCM token as part of push notification functionality.

The Luminary app may request permissions depending on the features you use. On iOS, Luminary may request location when in use for local or regional news, camera access to take a photo to attach to a chat or document-analysis flow, microphone access for voice input, photo library read access to pick existing images, photo library add access to save images from the in-app image viewer, and push notification permission for notifications such as “your answer is ready” or “analysis is ready.” On Android, Luminary may request permissions such as internet access, push notifications, coarse or fine foreground location for local news, audio recording for voice input, audio settings permissions for recording or playback, media read permissions for image, video, or audio picking, selected-photo permissions on newer Android versions, legacy external storage permissions for older Android versions, foreground service permissions for audio playback, vibration for haptic feedback, and related media or file permissions depending on the device and operating system version.

Location access is optional and foreground-only. If you grant location permission for local or regional news, your coordinates may be reverse-geocoded to an address string, and that address string may be sent as the “location” parameter of a news request. Raw coordinates are not sent as part of the news request. If you do not grant location permission, Luminary may fall back to your device locale country or another non-precise location signal where available. We do not request or use background location.

If you use voice input, audio recordings may be uploaded to our backend for speech-to-text processing and may be routed to speech-to-text or AI providers depending on the feature. If you use camera, image, screenshot, photo, document, or file features, those materials may be uploaded to our backend and processed to provide analysis, OCR, explanations, concept extraction, summaries, quizzes, maps, overviews, citations, memory, insights, or other AI-powered functionality.

Push notifications may be used to notify you when an answer, analysis, or other requested result is ready. If you decline push notification permission, no push token is registered for notification delivery. Signing out unregisters the device token from the backend. Notifications may be suppressed while the app is in the foreground. Luminary does not currently offer in-app notification controls. You can manage or disable push notifications through your device operating system settings.

Luminary may perform limited background-related activity, including push notification handling, remote-notification background mode on iOS, FCM background handling, notification tap handling and deep-link routing into chat sessions, saved analyses, shared content, or news content, Android audio playback foreground service, video picture-in-picture where video continues playing while the app is not in front, and push-token retry when a token is not obtainable at launch and the app later returns to the foreground. Luminary does not use background fetch, background sync, background upload continuation, background download continuation, background location, silent data pushes, scheduled background tasks, expo-task-manager, expo-background-fetch, or WorkManager jobs for ordinary background processing. Uploads and downloads run only while the app is open.

We do not collect advertising identifiers such as IDFA or AAID. We do not request App Tracking Transparency permission because we do not use IDFA or cross-app advertising tracking. We do not collect contacts, SMS, call logs, calendar information, health information, Bluetooth information, MAC address, IMEI, carrier information, screen recordings, or keystrokes. We do not use advertising SDKs, ad networks, or cross-site targeted advertising tracking in the mobile app.

Luminary may store information locally on your device to operate the Services, maintain sessions, remember preferences, improve performance, and support app functionality. This may include authentication session material, guest access tokens, guest user records, access tokens, refresh tokens if used by a third-party authentication system or local client flow, device ID, latest or guest session IDs, theme preference, language preference, onboarding and tutorial flags, cached session lists including titles or summaries, link-preview cache, handled push notification IDs, chat mode, queued Rollbar reports, temporary analysis IDs, attachments, downloaded files, copied content when you choose to copy an answer, and other local app data. On Android, downloaded files may be saved to public Downloads through a native module or platform storage mechanisms. On iOS, files or images may be saved through the share sheet or photo library when you choose to do so.

Luminary uses third-party providers and infrastructure services to operate the Services. Depending on the feature, your prompts, conversation history, uploaded documents, uploaded images, uploaded audio, URLs, extracted file text, extracted webpage text, selected text, analysis requests, and other relevant context may be sent from our backend to AI providers, AI gateway providers, OCR providers, transcription providers, search providers, scraping providers, or other service providers so they can process the request and return results. Our AI routing may include providers or services such as OpenAI, Anthropic, xAI, Mistral OCR, Groq, LLM Gateway or similar routing providers, LangSmith, and other AI or infrastructure providers. The provider used may vary based on feature, query type, model availability, performance, cost, reliability, user plan, enterprise configuration, safety, or product settings. The specific AI provider or model used may vary based on query type, model availability, performance, reliability, cost, user plan, enterprise configuration, safety, and system settings. We route requests to help provide accurate, reliable, and efficient AI-powered features.

Web-search, image-search, video-search, source, news, and webpage features may use providers such as Serper, Firecrawl, or Linkup where enabled, Google favicon service, DuckDuckGo icons, YouTube, or similar services. Search providers may receive the query or URL needed to perform the search, scrape, or retrieval. We do not intend to send user identifiers to search providers where they are not needed. Luminary may surface videos, images, sources, webpages, citations, links, and other third-party content. Video playback may load third-party embed pages or services such as YouTube, and Google or other third parties may receive requests and may set cookies or collect information according to their own terms and privacy policies. Luminary is not responsible for the privacy practices of third-party websites, videos, embeds, services, or content that we do not own or control.

Luminary may offer free plans, paid plans, subscriptions, usage-based pricing, trials, promotions, enterprise plans, organization plans, or other paid features. If you purchase a paid plan or subscription, payment information may be processed by third-party payment providers such as LemonSqueezy or other payment processors. We do not store full payment card numbers on our own servers. Payment providers may collect and process payment method details, billing information, tax information, transaction information, subscription status, and related records according to their own terms and privacy policies. We may collect or receive payment-related metadata such as plan type, billing status, subscription ID, customer ID, renewal status, cancellation status, usage limits, invoices, receipts, and transaction history.

If you use Luminary through a company, school, organization, workspace, group, team, enterprise account, classroom, or other managed environment, we may collect and process information related to that organization or group. This may include organization name, workspace name, team membership, role, permissions, access level, administrator settings, shared documents, shared sessions, shared Play experiences, group activity, invitations, collaboration activity, aggregate usage, cohort-level insights, knowledge gaps, organizational exploration patterns, and other information needed to provide the Services. Depending on the applicable plan, settings, agreement, and feature configuration, administrators or authorized organization representatives may be able to access, manage, export, delete, configure, or view certain information associated with their workspace or account. If you use Luminary through an organization, your use may also be subject to that organization’s policies.

Luminary may offer memory, personalization, Message Insights, Session Insights, Thinking Profiles, Personal Knowledge Graphs, exploration graphs, understanding graphs, discovery edges, blind-spot detection, serendipity recommendations, cohort insights, organization insights, and related features. These features may process information from your interactions with Luminary, including chat messages, responses, concepts explored, highlighted text, Quick Analysis and Deep Analysis activity, videos opened, sources opened, documents uploaded or analyzed, images uploaded or analyzed, questions asked, quizzes generated or answered, Play activity, session order, navigation paths, time spent, recency, frequency, depth of exploration, saved chats, memory candidates, session summaries, thinking signals, exploration signals, personalization preferences, evidence used to support insights, and confidence indicators. Memory and insight features are intended to help Luminary maintain useful context across sessions, personalize responses, connect your interactions over time, surface useful patterns, and provide deeper understanding. Message Insights may reveal meaningful observations, patterns, opportunities, connections, and recommendations from a recent interaction. Session Insights may show what emerged across a full conversation. Thinking Profiles may connect patterns across sessions to help Luminary understand how you think, learn, explore, and make decisions over time.

2. App Privacy and Data Safety Summary

This section summarizes the main categories of data Luminary may collect for App Store and Google Play privacy disclosures. The full details are described throughout this Privacy Policy.

Luminary may collect identifiers, including email address, username, user ID, Clerk ID, guest device ID, device ID, push token, session ID, message ID, document ID, share ID, and similar identifiers. Account identifiers are required for registered accounts. Guest device identifiers are required for guest access. Push tokens are optional and collected only if push notifications are enabled. Some identifiers may be linked to your account, device, or activity.

Luminary may collect contact information, such as your email address, when you create an account, sign in, contact support, receive account-related communications, or use paid features. Luminary does not request access to your device contacts.

Luminary may collect User Content, including prompts, chats, uploaded documents, images, screenshots, photos, audio recordings, selected text, generated outputs, shared content, quiz activity, Play activity, and other content you provide or create. This information is required when you use the relevant feature. For example, document content is collected only when you upload or analyze a document; image content is collected only when you upload, capture, or analyze an image; and audio content is collected only when you use voice input.

Luminary may collect usage data, including feature interactions, concepts clicked, highlights, Quick Analysis and Deep Analysis activity, videos opened, sources opened, maps and overviews opened, session duration, search queries, news queries, document activity, sharing activity, Play activity, and similar product interactions. Usage data is used to provide, maintain, analyze, secure, personalize, and improve the Services.

Luminary may collect diagnostics, including crash reports, error messages, stack traces, environment, device information, app version, session ID, document ID, URL, and related technical metadata. Diagnostics are used to identify, debug, secure, and improve the Services.

Luminary may collect location information only when you grant location permission or when general location is inferred from technical information such as IP address. Precise or approximate foreground location is optional and used for local or regional news. Luminary does not collect or use background location.

Luminary may collect photos, videos, documents, files, audio, and other media only when you choose to upload, capture, attach, analyze, save, or interact with those materials. Luminary does not access these materials without the relevant permission or user action.

Luminary may collect payment and subscription information if paid features are offered and you purchase a plan. Payment method details are processed by payment providers, and Luminary does not store full card numbers on its own servers.

Luminary does not collect health information, fitness information, contacts, SMS, call logs, calendar data, advertising identifiers, or browsing history from other apps. Luminary does not sell personal information, does not share personal information for cross-context behavioral advertising, does not use advertising SDKs, and does not track you across other companies’ apps or websites for targeted advertising.

3. How We Use Personal Information

We use personal information to provide, operate, maintain, secure, analyze, improve, and develop the Services. This includes using information to create and manage accounts, authenticate users, provide guest access, process prompts, generate responses, analyze documents, analyze images, transcribe audio, provide AI explanations, generate quizzes, surface videos and sources, create maps and overviews, process highlights, support Play experiences, save and retrieve chats, manage documents, deliver push notifications, enable sharing, process payments, provide support, troubleshoot issues, prevent abuse, and comply with legal obligations.

We use User Content and related context to provide the features you request. For example, if you upload a document, we may extract text, create chunks, generate vectors, store document metadata, route content to AI or OCR providers, retrieve relevant passages, generate explanations, answer questions, provide citations, produce summaries, or support document-based chat. If you upload an image, we may process that image to explain what it contains, identify relevant concepts, generate analysis, or support follow-up exploration. If you use voice input, we may process the audio to generate a transcript and use that transcript to respond to your request.

We use usage, interaction, and technical information to understand how the Services are used, improve the product experience, measure performance, identify bugs, improve onboarding, improve tutorial flows, understand feature adoption, evaluate retention, detect abuse, protect accounts, monitor infrastructure, debug errors, and develop new features. This may include analyzing activation funnels, feature usage, session duration, concept clicks, highlight activity, Quick Analysis and Deep Analysis usage, video and source usage, document activity, search behavior, and similar product signals.

We use information to personalize and customize the Services. This may include using your recent activity, saved chats, memory, prior sessions, explored concepts, documents, highlights, interaction patterns, language preference, and other context to provide more relevant responses, explanations, recommendations, sources, quizzes, maps, insights, or product experiences. When memory and insight features are available, they may use prior interactions to make Luminary more useful over time.

We use information to communicate with you. This may include responding to support requests, sending service messages, sending account-related notices, delivering security alerts, notifying you about answers or analyses being ready, providing product updates, sending administrative messages, and communicating about changes to our Services, Terms, Privacy Policy, or features. If we send marketing communications, you may be able to opt out using the instructions in those communications.

We use information to protect the Services and our users. This includes preventing fraud, spam, abuse, misuse, security incidents, unauthorized access, violations of our terms or policies, illegal activity, and harm to Luminary, users, or third parties. We may use logs, account information, technical information, content metadata, and other available signals for safety, security, integrity, and enforcement purposes.

We may use information to comply with legal obligations, enforce agreements, respond to lawful requests, resolve disputes, maintain business records, process payments, perform accounting and tax obligations, and protect the rights, privacy, safety, or property of Luminary, users, or others.

We may aggregate or de-identify personal information so that it no longer identifies you. We may use aggregated or de-identified information to analyze usage, improve the Services, develop new features, conduct research, produce business insights, measure performance, and for other lawful purposes. Where we maintain information in de-identified form, we will not attempt to re-identify it unless permitted or required by law.

4. AI Processing and Model Training

Luminary uses AI systems and third-party AI providers to provide responses, explanations, summaries, analyses, quizzes, maps, overviews, OCR, transcription, memory, insights, recommendations, and related features. To provide these features, we may send relevant User Content and context to AI providers, AI gateway providers, OCR providers, transcription providers, or related service providers.

We do not use your User Content to train Luminary-owned AI models by default. We do not sell your chats, documents, images, audio, or other User Content. We do not use your User Content for cross-context behavioral advertising. If we introduce an optional setting that allows users to contribute content for model improvement or training, we will describe that setting and any available controls in the Services or in an updated policy.

Third-party AI providers may process User Content and related data according to their own service terms, data processing terms, enterprise settings, API settings, retention settings, and privacy practices. We seek to use API, enterprise, or provider settings that limit provider-side training on submitted content when those settings are available and appropriate for the Services. Provider retention, abuse monitoring, safety review, and logging practices may vary by provider and configuration. For data processed by third-party AI providers, responsibility and liability are governed by our agreements with those providers and applicable law.

AI outputs may be inaccurate, incomplete, outdated, inappropriate, or not suitable for your particular circumstances. You should not rely on Luminary as a substitute for professional advice, including medical, legal, financial, tax, accounting, psychological, safety, engineering, or other professional advice. You should avoid submitting sensitive personal information unless it is necessary for your use of the Services and you are comfortable with that information being processed as described in this Privacy Policy.

5. Automated Processing, Memory, and Insights

Certain Luminary features may use automated processing to generate responses, recommendations, insights, personalization, memory, Message Insights, Session Insights, Thinking Profiles, Personal Knowledge Graphs, discovery edges, blind-spot suggestions, cohort insights, organization insights, or similar outputs. These features are intended to help users and organizations explore and understand information more effectively.

Message Insights may generate observations, patterns, opportunities, connections, and recommendations based on a recent interaction. Session Insights may synthesize what emerged across a conversation, including what was explored, what the user went deeper on, and what patterns appeared. Thinking Profiles may connect patterns across sessions to help Luminary understand how a user thinks, learns, explores, and makes decisions over time. These outputs are generated using available evidence and may be probabilistic. They are not definitive judgments about you, your identity, your personality, your abilities, your health, your legal status, your finances, or your future outcomes.

Luminary’s automated processing and insight features should not be used as the sole basis for high-stakes decisions, including decisions about employment, education, credit, housing, insurance, healthcare, legal status, access to essential services, or other significant matters. Enterprise or organizational users should ensure that any use of analytics, profiles, cohort insights, or automated recommendations complies with applicable law, workplace rules, and human review requirements.

6. How We Disclose Personal Information

We disclose personal information in the circumstances described below.

We disclose personal information to vendors and service providers that help us operate, host, secure, analyze, support, and improve the Services. These may include cloud hosting providers, database providers, storage providers, authentication providers, AI model providers, AI gateway providers, OCR providers, transcription providers, search providers, scraping providers, vector database providers, queue and processing providers, cache providers, logging providers, crash and error reporting providers, analytics providers, email providers, push notification providers, payment processors, customer support providers, infrastructure providers, and other technology providers. These providers may access, process, or store personal information only as needed to perform services for us, subject to their applicable terms, contracts, and privacy obligations.

Current or possible service providers and infrastructure may include AWS, ECS Fargate, Lambda, SQS, Secrets Manager, CloudWatch, S3, DynamoDB, MongoDB Atlas, Redis Cloud, Pinecone, Clerk, Firebase Cloud Messaging, APNs, Rollbar, OpenAI, Anthropic, xAI, Mistral OCR, Groq, LLM Gateway or similar routing providers, LangSmith, Serper, Firecrawl, Linkup where enabled, Google services, DuckDuckGo icons, Hostinger, LemonSqueezy, and other providers used to operate the Services. The exact providers may change over time as we improve Luminary.

We may disclose information to AI, search, OCR, transcription, or other processing providers when necessary to provide the Services. For example, prompts, conversation history, uploaded documents, uploaded images, uploaded audio, URLs, extracted file text, extracted webpage text, selected text, or other relevant context may be sent to providers so they can generate responses, analyze content, transcribe audio, perform OCR, retrieve sources, or complete requested actions. We do not send user ID, email, name, IP address, or device/browser metadata to AI providers unless necessary for a specific feature, security, support, enterprise configuration, or legal requirement.

We may disclose information to other users or third parties when you choose to share it. For example, if you create or open a public share link, recipients may access the shared chat, analysis, document-derived output, or other shared content without logging in, depending on the sharing feature. When you share a chat, a recipient may receive access to that shared content or may create their own independent copy. If you delete your original chat, your deletion may revoke access to your original shared link, but it does not delete independent copies, forks, screenshots, exports, downloads, or other copies already created by recipients. Recipients are responsible for deleting their own copies separately. Luminary may not currently offer a separate unshare endpoint for all shared links.

If you use group, Play, multiplayer, classroom, organization, workspace, enterprise, or collaboration features, information may be visible to other participants, teammates, group members, instructors, administrators, or organization representatives according to the feature, settings, permissions, and applicable agreement. Shared activity may include names or identifiers, responses, scores, rankings, accuracy, response times, difficult questions, useful insights, documents, chats, analyses, comments, collaboration activity, and other group-related information.

If you use Luminary through an enterprise, school, company, institution, or managed workspace, we may disclose certain account, usage, content, analytics, insights, or administrative information to authorized administrators or organization representatives, depending on the product configuration and applicable agreement. Organization administrators may be able to manage access, view usage, configure settings, review shared content, export data, delete data, or receive aggregate insights.

We may disclose personal information as part of a corporate transaction, such as a merger, acquisition, financing, investment, reorganization, sale of assets, bankruptcy, receivership, transition of service to another provider, or similar transaction. Personal information may be disclosed during diligence and transferred as part of the transaction, subject to applicable law.

We may disclose personal information to government authorities, law enforcement, regulators, courts, legal advisors, or other third parties when we believe disclosure is required or appropriate to comply with law, legal process, or lawful requests; protect our rights, privacy, safety, property, users, employees, or the public; enforce our Terms or policies; detect, prevent, or address fraud, security, or technical issues; prevent abuse or misuse of the Services; or protect against legal liability.

We may disclose aggregated or de-identified information that does not reasonably identify you for analytics, research, product development, business reporting, marketing, enterprise insights, or other lawful purposes.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not process personal information for targeted advertising. We do not use advertising SDKs, targeted advertising SDKs, or third-party ad networks in the mobile app.

7. Storage and Security

Luminary uses technical, administrative, and organizational measures designed to protect personal information from unauthorized access, disclosure, alteration, loss, misuse, or destruction. These measures may include access controls, authentication, encryption, private storage, limited-duration signed URLs, logging and monitoring, secure infrastructure providers, secrets management, and operational safeguards. However, no internet, mobile, cloud, email, or electronic system is fully secure, and we cannot guarantee absolute security.

Our backend infrastructure may be hosted on AWS, including ECS Fargate for backend services, Lambda for document-processing pipelines, SQS for queues, Secrets Manager for secrets, CloudWatch for logs, S3 for file storage, and DynamoDB for document chunk text. We may use MongoDB Atlas as a primary database, Redis Cloud as a cache, Pinecone for document vectors, and other infrastructure providers. Production infrastructure may be located in the United States, including AWS us-east-1. Personal information may be processed and stored in the United States and other jurisdictions where we, our affiliates, or our service providers operate.

Uploaded files and generated files may be stored in private AWS S3 storage. Server-side encryption may be enabled for stored files. Files may be accessed through authenticated routes or limited-duration signed URLs. Signed URLs may be generated for client access or for AI-provider processing where needed, and they expire after a limited period. Document-processing systems may access files through backend-controlled infrastructure permissions.

We use commercially reasonable measures designed to protect information in transit and at rest. We also rely on reputable third-party infrastructure, authentication, cloud, storage, AI, analytics, and security providers. You are responsible for maintaining the confidentiality of your account credentials and for using secure devices, browsers, and networks when accessing Luminary.

8. Retention and Deletion

We retain personal information for as long as reasonably necessary to provide, maintain, secure, improve, and develop the Services, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, maintain business records, and carry out the purposes described in this Privacy Policy. Retention periods depend on the type of information, account type, feature used, user settings, deletion requests, legal requirements, and technical configuration.

Registered-user chats and related records are generally retained until you delete them or delete your account, unless a different retention setting applies. Guest or temporary sessions may be cache-only and may expire after a limited period, such as 24 hours. Redis cache copies may expire after a limited period, such as 24 hours. Search result metadata, image metadata, video metadata, citations, and related records may be retained to support the Services unless deleted or purged as part of account deletion or other retention processes. Extracted webpage text may not be persisted and may be cached briefly, depending on the feature. Webpages themselves may not be stored.

Uploaded documents, S3 files, Pinecone vectors, DynamoDB chunks, document metadata, and related records may be retained while your account remains active or as otherwise needed to provide the Services. When you delete a chat, the chat is removed from active display or marked as deleted according to the product flow. Associated records, files, vectors, chunks, logs, caches, shared copies, forked copies, or backups may remain until account deletion, system cleanup, legal retention periods, or other retention processes are completed. Shared or forked copies created by other users have their own independent lifecycle and are not deleted when you delete your original chat or account.

When you delete your account, Luminary locks the account and begins the account deletion process. As part of that process, Luminary deletes or purges associated account data, which may include document chunks, vector namespaces, S3 files, database records, cache keys, and the authentication user record where applicable. If the deletion process takes longer to complete, it may continue through an asynchronous background process. We retain one audit record of the deletion request to verify deletion, maintain compliance records, prevent abuse, resolve disputes, or comply with law. Unless a shorter period is later configured or required by law, this audit record may be retained indefinitely.

Some information may be retained longer where required or permitted by law, including where necessary for security, fraud prevention, abuse prevention, legal compliance, dispute resolution, enforcement of our Terms, financial records, tax obligations, accounting, audit, backup, or other legitimate business purposes. If information has been aggregated or de-identified so that it no longer reasonably identifies you, we may retain and use it without further notice, unless required otherwise by law.

Logs may be retained according to the settings of the relevant system. CloudWatch logs, Rollbar logs, load balancer logs, database backups, cache persistence, and point-in-time recovery systems may have different retention periods depending on configuration. Backup and logging systems may retain information for a limited period after deletion before it is overwritten, deleted, or expires according to the relevant system’s retention process.

9. Your Choices and Data Controls

Depending on the Services and features available to you, you may have choices and controls over certain personal information. You may be able to create an account, sign in, sign out, delete individual chats, delete your account, manage device permissions, decline push notifications, control app or browser permissions, manage local files, clear local device data, unsubscribe from marketing communications, or contact us to exercise privacy rights.

Signed-in users may delete their account in the app through Profile, the top-right three-dot menu, and Delete Account. Users may also delete their account through the Luminary web app by logging in through a desktop or mobile browser, opening Settings, and selecting Delete Account. Account deletion invalidates the token and begins server-side deletion or purge processes. Some audit records may be retained as described in the Retention and Deletion section.

You can manage mobile permissions such as location, camera, microphone, photo library, media access, and notifications through your operating system settings. If you disable a permission, some features may not work. If you decline push notifications, no push token is registered for notification delivery. You can disable notifications through your device operating system settings. Luminary does not currently offer in-app notification controls. Signing out unregisters the device token from the backend.

You may delete chats or sessions in Luminary. Deleting a chat may soft-delete the chat and may soft-revoke public share links associated with it, but certain related records, files, vectors, chunks, logs, caches, forked copies, audit records, or backups may remain for some period or until account purge, depending on the feature and technical configuration.

Luminary does not currently provide a self-service data export tool. You may contact support@useluminary.ai to request access to or a copy of personal information associated with your account, subject to verification, technical feasibility, and applicable law.

Luminary may provide memory, personalization, Message Insights, Session Insights, Thinking Profiles, Personal Knowledge Graphs, or related features. When these features are active, Luminary may provide controls for supported memory or personalization features. Luminary will describe available controls in the Services or in an updated policy when those controls are available.

If you receive marketing communications from us, you may opt out by using the unsubscribe link or instructions in those messages. Even if you opt out of marketing communications, we may still send non-marketing messages, such as account, security, legal, payment, support, or service-related notices.

10. Your Privacy Rights

Depending on where you live, you may have certain rights in relation to your personal information. These may include the right to request access to personal information we hold about you, request correction of inaccurate personal information, request deletion of personal information, request restriction or objection to certain processing, request portability of personal information, withdraw consent where processing is based on consent, appeal a decision we make regarding a privacy request, and lodge a complaint with a data protection authority.

To exercise privacy rights, you may contact us at support@useluminary.ai. We may need to verify your identity before fulfilling a request. If you have an account, we may ask you to verify your request through your account or provide information sufficient to confirm that you are the account owner. If you do not have an account, or if we suspect fraudulent, abusive, or malicious activity, we may ask for additional information to verify your identity. If we cannot verify your identity, we may not be able to fulfill the request.

Authorized agents may submit requests where permitted by law, but we may require proof of authorization and independent verification of the user. Some rights may be limited by applicable law, technical feasibility, security requirements, legal obligations, business records, abuse prevention, backup systems, de-identified information, or the rights and freedoms of others. We will respond to requests as required by applicable law.

AI-generated outputs may sometimes be inaccurate. Luminary may generate responses, insights, summaries, explanations, quizzes, recommendations, or other outputs based on probabilities, retrieved context, User Content, and model behavior. If an AI-generated output contains inaccurate personal information about you, you may contact us to request correction or deletion where applicable and technically feasible. We will consider such requests according to applicable law and the technical capabilities of the Services.

11. U.S. State Privacy Disclosures

Certain U.S. state privacy laws require additional disclosures about categories of personal information collected, used, and disclosed. Depending on how you use the Services, we may collect identifiers such as email address, username, user ID, Clerk ID, device ID, IP address, push token, session ID, document ID, and similar identifiers; account information such as verification status, account type, usage limits, billing status, and deletion request timestamp; commercial information such as payment status, subscription information, transaction history, invoices, and plan information; internet or network activity such as usage data, feature interactions, logs, requests, responses, search activity, video activity, document activity, concept activity, and session activity; geolocation information such as IP-based general location or optional foreground location used for local or regional news; device information such as operating system, app version, device model, platform, and build information; audio, visual, and electronic information such as uploaded audio recordings, transcripts, images, screenshots, photos, documents, and files; User Content such as prompts, chats, uploaded materials, highlighted text, AI responses, generated outputs, shared content, and interactions; inference or insight information such as memory outputs, thinking signals, exploration signals, Message Insights, Session Insights, Thinking Profiles, Personal Knowledge Graphs, recommendations, and related personalization outputs; and communication information such as support messages and feedback.

We use these categories of information to provide, operate, maintain, secure, personalize, analyze, improve, and develop the Services; process AI requests; store and retrieve chats and documents; provide search, video, source, quiz, map, overview, Play, memory, and insight features; communicate with you; process payments; prevent fraud and abuse; comply with law; enforce our Terms; and carry out the other purposes described in this Privacy Policy.

We may disclose these categories of information to vendors and service providers, AI providers, infrastructure providers, authentication providers, payment processors, analytics providers, crash and error reporting providers, push notification providers, search and scraping providers, other users or third parties you choose to interact with or share information with, enterprise or organization administrators where applicable, government authorities or other third parties for legal and safety reasons, and parties involved in corporate transactions.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not process personal information for targeted advertising. We do not knowingly sell or share personal information of children under 16. We do not use advertising SDKs or ad networks in the mobile app.

Depending on your state of residence, you may have rights to know, access, correct, delete, or obtain a copy of your personal information, opt out of certain processing, limit certain uses of sensitive personal information where applicable, appeal privacy decisions, and be free from discrimination for exercising privacy rights. You may exercise these rights by contacting support@useluminary.ai.

12. Children and Teens

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are under 13, you may not use the Services. Luminary complies with the Children’s Online Privacy Protection Act by not knowingly collecting personal information from children under 13. If we learn that we have collected personal information from a child under 13 without appropriate consent, we will take steps to delete that information as required by law.

If you are between 13 and 18, you may use the Services only with permission from your parent or legal guardian. Luminary does not currently offer automated parental controls, parent-linking, or parental-consent verification. Parents and guardians should review this Privacy Policy and our Terms of Service with their child and ensure appropriate supervision. Parents or guardians who believe that a child or teen has provided personal information to Luminary or is using the Services without appropriate permission may contact us at support@useluminary.ai.

14. Cookies and Similar Technologies

Luminary may use cookies, local storage, tokens, browser storage, device storage, and similar technologies to operate the Services, authenticate users, maintain sessions, remember preferences, improve performance, support security, provide customer support, analyze usage, and improve the product experience. The exact technologies used may vary between the website, web app, mobile app, and third-party embedded content.

Third-party services, such as authentication providers, analytics providers, video embeds, payment processors, and other integrations, may also use cookies or similar technologies according to their own policies. You can manage cookies and similar technologies through your browser or device settings. Disabling certain technologies may affect the functionality of the Services.

Luminary does not use advertising SDKs or cross-site targeted advertising tracking in the mobile app.

15. International Processing

Personal information may be processed and stored in the United States and other jurisdictions where we, our affiliates, vendors, or service providers operate. Data protection laws may vary by jurisdiction. Where required by law, we use appropriate safeguards for international transfers of personal information.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes, we will post the updated Privacy Policy and update the “Last Updated” date above, unless a different type of notice is required by law. Your continued use of the Services after the updated Privacy Policy becomes effective means you acknowledge the updated Privacy Policy.

17. Data Controller

LuminaryAITech, Inc. is responsible for the processing of personal information described in this Privacy Policy, unless another entity is identified in a separate agreement or product-specific notice.

If you use the Services through an enterprise, school, organization, workspace, or other managed account, that organization may also act as a controller, business, or similar responsible party for certain personal information, and Luminary may process information on behalf of that organization under a separate agreement.

18. How to Contact Us

If you have questions, requests, or concerns about this Privacy Policy or our privacy practices, you can contact us at:

LuminaryAITech, Inc.

Privacy Contact
support@useluminary.ai
General Support
support@useluminary.ai