← Back to Luminiea

Privacy Policy

Last updated: September 30, 2026
Effective date: September 30, 2026

Adults only (18+). Our products and services are intended solely for adults who are at least 18 years old (or the age of majority in your jurisdiction, if higher). We do not knowingly collect personal data from minors.

This Privacy Policy explains how Luminiea (“we,” “us,” or “our”), operated by Beijing Lingxi Dance Technology Co., Ltd., collects, uses, discloses, and protects personal information when you use our websites (including www.luminiea.com), the Lumini mobile application, connected intelligent devices, APIs, and related cloud services (collectively, the “Services”).

We designed this Policy to align with the EU/EEA General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable privacy laws. Where local law provides stronger rights, we will honor those rights.

1. Who we are (data controller)

For personal data processed in connection with the Services, the controller is:

If we appoint an EU or UK representative under Article 27 GDPR / UK GDPR, we will update this Policy with their contact details.

2. Personal data we collect

Depending on how you interact with us, we may process the following categories:

CategoryExamples
Account & identityEmail address, display name, password hashes, account IDs
Contact & supportMessages you send us, partnership inquiries
Device & pairingDevice serial / hardware identifiers, pairing status and timestamps, firmware version
Usage & interactionFeature usage, session duration, preference settings, crash/diagnostic logs, in-app feedback
Voice / multimodal inputsAudio or text you submit for AI features (processed to provide the feature you request)
Permissions-relatedMicrophone (voice chat), Bluetooth (device connect), approximate location permission where required solely to scan BLE devices — we do not use GPS for tracking
Technical / websiteIP address, browser type, device type, referrer, cookie identifiers (see Cookie Policy)
Payment (if applicable)Processed by third-party payment providers; we typically receive limited billing metadata, not full card numbers

We do not require sensitive special-category data to use core Services. If you voluntarily share intimate or health-related content in chats, we process it only to deliver the feature you requested, under applicable legal bases and safeguards.

3. Purposes and legal bases (GDPR / UK GDPR)

You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

4. How we use personal data

5. Device permissions

6. Sharing and disclosures

We do not sell personal information as “sale” is commonly understood (exchange for money). We also do not knowingly “share” personal information for cross-context behavioral advertising under the CCPA/CPRA. If that ever changes, we will provide a “Do Not Sell or Share My Personal Information” mechanism.

We may disclose personal data to:

7. International transfers

We may process and store personal data in China and other countries where we or our processors operate. Where we transfer personal data from the EEA/UK/Switzerland to a country not deemed adequate, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) (and UK addendum / Swiss adaptations as applicable), plus supplementary measures where needed. Contact us for a copy of relevant transfer safeguards (subject to redactions).

8. Retention

We retain personal data only as long as necessary for the purposes described above, including:

9. Security

We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS), access controls on a least-privilege basis, and monitoring for abuse. No method of transmission or storage is 100% secure; please use strong unique passwords and keep your devices updated.

10. Your rights

EEA / UK / similar jurisdictions (GDPR)

Subject to applicable law, you may have the right to: access; rectification; erasure; restriction; data portability; object to processing based on legitimate interests; and withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.

California (CCPA/CPRA)

California residents may have the right to: know/access; delete; correct; opt out of sale/sharing (we do not currently sell or share as defined); limit use of sensitive personal information where applicable; and non-discrimination for exercising rights. You may designate an authorized agent subject to verification.

How to exercise

Email [email protected] with the subject “Privacy Request.” We will verify your identity and respond within the timeframe required by law (generally within 30 days under GDPR, or within CCPA statutory timelines). You may also delete your account and stop collection by uninstalling the app and requesting account deletion.

11. Children’s privacy

The Services are for adults only (18+ / age of majority). We do not knowingly collect personal data from children. If you believe a minor has provided personal data, contact us and we will take reasonable steps to delete it and restrict access.

12. Automated decision-making & AI

Our Services use AI models to generate conversational and control responses. These outputs are not intended as legal, medical, financial, or other professional advice. We do not use solely automated decision-making that produces legal or similarly significant effects about you without appropriate human involvement where required by law.

13. Cookies and similar technologies

See our Cookie Policy for details on essential and optional cookies and how to manage preferences.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted on this page with an updated “Last updated” date, and where required we will provide additional notice (e.g., email or in-app). Continued use after the effective date constitutes acceptance where permitted by law.

15. Contact us