Lume

Privacy Policy

Effective date: 3/6/2026

1. Introduction

This Privacy Policy explains how SGL Technology Limited ("we", "us", "our") collects, uses, and protects your personal data when you use the Lume.Pics Service.

We comply with the UK Data Protection Act 2018 and the UK GDPR.

2. Information We Collect

Account Information: email address, login credentials (via Firebase/Google/Facebook).

Payment Information: handled by Stripe; we do not store card details.

Usage Data: interactions with the Service, logs, device/browser type. We use PostHog for product analytics, which may include session recordings with personal data (like form inputs) automatically masked.

Uploaded Content: images or data you provide for processing.

3. How We Use Your Information

We use your information to:

Provide and operate the Service.

Process payments and subscriptions.

Improve and secure the Service.

Respond to support requests.

Comply with legal obligations.

Legal Basis: For logged-in users, we process certain analytics data (such as image generation events and feature usage) under legitimate interest to improve our service. This server-side tracking does not use cookies. You can object to this processing by contacting us.

4. Sharing of Data

We may share your data with:

Service providers (e.g. hosting, Firebase authentication, Stripe, Google Gemini for AI image generation, Meta/Facebook for authentication).

Analytics providers (PostHog for product analytics, Google Analytics for traffic measurement, Meta for conversion tracking).

Legal authorities where required by law.

We do not sell or rent your data to third parties.

5. Content Restrictions

You may not upload hateful, abusive, discriminatory, or sexually explicit material.

We are not responsible for user-generated content.

We may suspend or delete accounts that violate this policy.

6. Data Retention

We retain personal data only as long as necessary to provide the Service, comply with law, or resolve disputes.

7. Security

We use reasonable security measures to protect your data. However, no system is 100% secure.

8. International Transfers

Some data may be processed outside the UK by our cloud and AI providers. We ensure adequate safeguards are in place.

9. Your Rights

Under UK GDPR, you have rights to:

Access your data

Correct inaccurate data

Request deletion

Object to processing

Data portability

To exercise your rights, contact us at [email protected]

10. Third-Party Login & Data Deletion

We offer sign-in via third-party providers including Google and Facebook. When you sign in using Facebook Login, we receive your name and email address from Meta. We do not access your Facebook friends list, posts, or other profile data.

You can revoke Lume's access to your Facebook data at any time via your Facebook Settings > Apps and Websites.

To request deletion of all data associated with your Facebook account, you can:

Remove Lume from your Facebook Apps and Websites settings.

Email [email protected] with the subject line "Facebook Data Deletion Request".

Upon receiving a deletion request, we will delete your account and all associated data (uploaded images, generated images, profile information) within 30 days.

11. Children's Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Privacy Policy. Updates will be posted on this page with a revised effective date.

13. Contact & Data Protection

Data Controller

SGL Technology Limited
17 Green Lanes, Newington Green
London, England, N16 9BS
Company Number: 11120804

Privacy Enquiries

For questions about this Privacy Policy or our data practices:
Email: [email protected]
(For general support, contact: [email protected])

Data Subject Requests

To exercise your GDPR rights (access, deletion, portability, rectification):
Email: [email protected]
Subject line: "Data Subject Request"
We will respond within 30 days as required by GDPR.

Supervisory Authority

You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113
(For UK GDPR complaints and data protection concerns)