Privacy Policy
Effective date: July 14, 2026
1. Introduction
This Privacy Policy explains how SGL Technology Limited ("we", "us", "our") collects, uses, and protects your personal data when you use Lume.
It covers every way you can use Lume:
- the lume.pics website and web app;
- the Lume apps for iOS and Android;
- the Lume app for Canva;
- the Lume app for Shopify, where made available.
We are the data controller for this data. We comply with the UK Data Protection Act 2018 and the UK GDPR. Where you are in the EEA, we apply equivalent standards under the EU GDPR.
2. Information We Collect
2.1 Account and identity data
What we hold depends on how you signed up:
- Web and mobile: your email address, an authentication identifier, and, if your provider supplies it, your display name. Sign-in is handled by Firebase Authentication using email and password, Google, Apple, or Facebook, depending on the Platform. If you use Sign in with Apple with Hide My Email, we receive Apple's private relay address rather than your real one.
- Canva: Canva gives us only your Canva user ID and your Canva team (brand) ID. Canva never gives us your email address or your name. We create a Lume account keyed to that Canva user ID so you can start working immediately. You can optionally add an email address later.
- Shopify: your store domain and the store owner's email address, obtained from Shopify when you install the app.
- All platforms: which Platform you signed up on, your timezone, your marketing preferences, and your account status.
2.2 Content you provide
The product photos you upload, the images we generate for you, and the products, projects and template choices you create. On mobile, photos come from your camera or your photo library, at your choice.
2.3 Payment and purchase data
- Web and Canva purchases are processed by Stripe. We receive your subscription and payment status, the amount, and your billing country. We never see or store your full card details.
- In-app purchases on iOS and Android are processed by Apple and Google. We do not receive your payment details. Through our subscription provider RevenueCat, we receive purchase and renewal events, the product purchased, the transaction identifier, and your subscription status, so that we can grant you the plan and credits you paid for.
- Shopify purchases are billed by Shopify; we receive your plan and charge status.
2.4 Usage and analytics data
We use PostHog to understand how the product is used, on the web and in the mobile apps. We record events such as signing in, viewing or selecting a template, uploading a photo, starting a generation, downloading an image, and viewing the pricing screen, along with the screen you are on. Your Lume user identifier, your email address, and your plan tier are attached to your analytics profile so that we can support you and understand behaviour across the Platforms you use.
On the website we also use Google Analytics for traffic measurement, Meta for conversion tracking, and PostHog session recordings, in which form inputs and other sensitive fields are automatically masked. These are set only in line with your cookie choices, described in our Cookie Policy.
In the mobile apps we do not use session recording, and we do not use Google Analytics or Meta tracking.
2.5 Device and technical data
Device or browser type, operating system version, app version, language and locale, an app-generated device identifier used by our analytics, and server logs including IP address. In the mobile apps, this also includes lifecycle events such as the app being installed, opened, or sent to the background.
2.6 Device permissions on mobile
The mobile apps ask for permission to use:
- Your camera, only when you choose to photograph a product. We do not access the camera in the background.
- Your photo library, only to let you pick the product photo you want to use. We access only the photos you select, and we do not scan or index your library.
- Saving to your photo library, only when you tap to save an image Lume generated for you.
You can change or revoke these permissions at any time in your device settings. The app will still work, but the features that need them will not.
2.7 What we do not collect
To be explicit about the mobile apps, we do not collect your location, your contacts, your calendar, or audio from your microphone. We do not use the advertising identifier on your device, we do not track you across other companies' apps or websites, and we do not sell your personal data. We do not read, export, or scan the contents of your Canva designs.
3. How We Use Your Information
We use your information to:
- provide and operate the Service, including generating your images;
- maintain your account, credits and subscription across Platforms;
- process payments and honour purchases made on any Platform;
- improve, debug and secure the Service, and prevent fraud and abuse;
- respond to support requests;
- send you service messages, and marketing where you have not opted out;
- comply with our legal obligations.
Legal bases (UK GDPR)
- Performance of a contract: operating your account, processing your images, taking payment, delivering credits.
- Legitimate interests: product analytics, security, fraud and abuse prevention, and improving the Service. We balance these against your rights, and you can object at any time by contacting us.
- Consent: non-essential cookies and similar technologies on the website, and marketing emails where consent is required. You can withdraw consent at any time.
- Legal obligation: tax, accounting, and responding to lawful requests.
4. One Account Across Platforms: Linking and Merging
Lume is built around a single account that works everywhere. This means that if you sign in on more than one Platform, we associate those sign-in methods with the same Lume account, and your credits, images and subscription follow you between them.
We apply strict rules to this, because incorrectly joining two people's accounts would be a serious data breach:
- Same sign-in, same account. Our web and mobile apps share one authentication system, so signing in with the same credentials gives you the same account automatically.
- We never merge two accounts silently. Where we detect that a verified email address matches another Lume account, we only offer you the option to merge. Nothing is combined unless you explicitly confirm it.
- We only act on proven email addresses. Before an email address can be used to link or merge, you must prove control of it, by entering a one-time code we send to it, or by signing in with that provider. Unverified addresses are never used to match accounts.
- Apple private relay addresses are never used to match accounts, because they are unique per app and cannot reliably identify a person.
- What a merge does. The account you merge in has its sign-in methods, credit packs, uploaded and generated images, products, projects and credit history moved to the account you keep. The merged account is then closed. This is irreversible.
- Paid accounts are not merged automatically. If the account being merged in has an active paid subscription, we refuse the merge and ask you to contact support, so that your billing is not disrupted.
We process this data to give you one coherent account across Platforms, on the basis of our contract with you and your explicit confirmation of the merge. You do not have to link or merge anything; you can keep separate accounts if you prefer.
5. AI Image Generation
To generate your images, we send the product photo you upload, together with the template instructions, to Google's Gemini API, which acts as our processor. The generated image is returned to us, stored in our storage, and made available to you.
We do not use your photos or generated images to train our own AI models. We use the paid Gemini API, under which Google states that it does not use content submitted through it to train its models.
We may review images where necessary to investigate a suspected breach of our Terms of Service, to respond to a legal request, or to fix a technical fault you report to us.
6. Who We Share Data With
We share data with the following categories of service provider, who act on our instructions:
| Provider | Purpose | Data shared |
|---|---|---|
| Google (Gemini API) | AI image generation | Uploaded photo, template prompt |
| Google (Firebase) | Authentication | Email, auth identifier |
| Amazon Web Services | Image storage and delivery | Uploaded and generated images |
| Stripe | Payments (web and Canva) | Email, payment and billing data |
| Apple, Google Play, RevenueCat | In-app purchases and subscription status | Account identifier, purchase events |
| PostHog | Product analytics | Account identifier, email, plan, usage events |
| Brevo | Transactional and marketing email | Email, name, plan, account status |
| Sentry | Error monitoring (server side) | Error reports, account identifier |
| Intercom (website and web app) | Customer support chat | Email, name, support messages |
| Google Analytics, Meta (website only) | Traffic and conversion measurement | Cookie identifiers, conversion events |
| FirstPromoter | Affiliate attribution | See below |
Affiliate attribution: FirstPromoter is used to attribute affiliate clicks and conversions for our referral program. When you arrive via an affiliate link, FirstPromoter sets a cookie identifying the click; on conversion (purchase), we share with FirstPromoter your visitor IP, device fingerprint, email address, and the subscription amount and currency required to award the referrer their commission. Data retention follows FirstPromoter’s policy.
We may also disclose data to legal authorities where required by law, and to a buyer or successor in the event of a merger or acquisition, in which case we will notify you.
We do not sell or rent your personal data, and we do not share it for cross-context behavioural advertising.
7. Referrer Visibility
When you arrive via a referral link from an existing Lume customer, the person who referred you is never shown your email address, name, or any other personal identifier. Referrers see only aggregate counts (number of signups, conversions, credits earned) and anonymized event dates. Your identity is not disclosed to third-party referrers under any circumstances.
8. Try-Before-Signup Demo
Our landing pages let you generate a sample image without creating an account. When you use this demo, we process the product photo you upload and the generated result to provide the demo itself. These images are stored for up to 1 year and then permanently deleted from storage.
Email capture: you can optionally leave your email address to save your generated image and receive free credits. We use this address to attach the image and credits to your account when you sign in, and to send you occasional product tips and offers. You can unsubscribe at any time using the link in every email or by contacting us, and you can request deletion of your address at any time. Marketing emails are sent via Brevo, our email service provider.
Abuse prevention: to keep the free demo available, we store a hashed (non-reversible) form of your IP address and your browser type for rate limiting. We process this under legitimate interest; the raw IP address is never stored.
9. Content Restrictions and Automated Decisions
You may not upload hateful, abusive, discriminatory, or sexually explicit material, or images of a person without their consent. We may suspend or delete accounts that violate this policy or our Terms of Service.
Automated decisions about your account
To prevent fraud and abuse of our free credits, we run automated checks on sign-ups, including checking the email address against lists of known disposable and throwaway email providers. If an address matches, the account can be restricted or deactivated and its credits removed automatically, without a person reviewing it first. We also apply automated rate limits to the free demo.
You have the right to a human review of any such decision. If your account has been restricted or deactivated and you believe it is a mistake, email [email protected] and a person will look at it, explain the decision, and reinstate your account and credits if the decision was wrong. We do not use automated profiling for any purpose beyond fraud and abuse prevention, and we do not make automated decisions using special category data.
10. Data Retention
- Account data, uploads and generated images: kept while your account is open, and deleted within 30 days of you closing it, apart from data we must keep longer by law.
- Canva accounts: if you uninstall the Lume app in Canva, we keep your account and credits so they are still there if you reinstall. Ask us to delete them and we will.
- Demo images: deleted from storage after 1 year. Email addresses captured through the demo are kept for marketing until you unsubscribe or ask us to delete them.
- Billing and tax records: kept for 6 years, as UK law requires.
- Security and abuse logs: kept for up to 12 months.
- Analytics data: kept for up to 24 months, after which it is deleted or aggregated so that it no longer identifies you.
11. Deleting Your Account and Data
You can delete your account:
- In the mobile apps: Account, then Delete Account.
- On the web, in Canva, or in Shopify: email [email protected] with the subject line "Account Deletion Request".
Full instructions, including what is deleted and what we must keep, are on our Delete Your Account page. You do not need to install an app to delete your account.
Deletion applies to your whole Lume account, across every Platform, not just the one you asked from. We stop your billing straight away, close your account, and permanently erase your personal data, uploaded photos and generated images 30 days later, apart from records we are legally required to keep, such as invoices. Any remaining credits are forfeited.
You can change your mind during those 30 days. Sign in and choose to restore your account, and everything comes back. We email you when deletion is scheduled, so that if a request was ever made without your knowledge, you have time to stop it. After 30 days the erasure is permanent and cannot be undone.
Deleting your Lume account does not cancel a subscription billed by Apple or Google. Cancel that separately in your Apple or Google account settings, or you will continue to be charged.
12. Security
We use reasonable technical and organisational measures to protect your data, including encryption in transit, encrypted storage, access controls, and time-limited signed links for your images so they cannot be guessed or enumerated. However, no system is 100% secure.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and we will tell you directly without undue delay where the risk to you is high.
If you believe you have found a security vulnerability in Lume, please report it to [email protected] or [email protected] rather than disclosing it publicly. We will not pursue legal action against researchers who report in good faith and do not access other people's data.
13. International Transfers
We are based in the UK, and some of our providers process data outside the UK, including in the United States and the EU. Where data leaves the UK, we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with additional safeguards where needed. You can ask us for details of the safeguards that apply.
14. Your Rights
Under UK GDPR you have the right to access your data, correct inaccurate data, request deletion, object to processing, restrict processing, and receive your data in a portable form. Where we rely on consent, you may withdraw it at any time.
To exercise your rights, email [email protected]. We respond within 30 days. You will not be charged, and we will not treat you differently for exercising a right.
If you are in the United States: we do not sell or share your personal information as those terms are defined under US state privacy laws, and we do not use it for cross-context behavioural advertising. The rights above are available to you on the same basis.
15. Third-Party Login and Facebook Data Deletion
We offer sign-in via third-party providers including Google, Apple and, on the website, Facebook. When you sign in using Facebook Login, we receive your name and email address from Meta. We do not access your Facebook friends list, posts, or other profile data.
You can revoke Lume's access to your Facebook data at any time via your Facebook Settings, then Apps and Websites.
To request deletion of all data associated with your Facebook account, remove Lume from your Facebook Apps and Websites settings, and email [email protected] with the subject line "Facebook Data Deletion Request". We will delete your account and all associated data within 30 days.
16. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
17. Changes to This Policy
We may update this Privacy Policy. Updates will be posted on this page with a revised effective date, and we will tell you about material changes by email or in the product.
18. Contact and Data Protection
Data Controller
SGL Technology Limited
17 Green Lanes, Newington Green
London, England, N16 9BS
Company Number: 11120804
Privacy Enquiries
For questions about this Privacy Policy or our data practices:
Email: [email protected]
(For general support, contact: [email protected])
Data Subject Requests
To exercise your rights (access, deletion, portability, rectification):
Email: [email protected]
Subject line: "Data Subject Request"
We will respond within 30 days as required by GDPR.
Supervisory Authority
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113
(For UK GDPR complaints and data protection concerns)