1. Who we are
Lumino is an AI creative platform for children ages 5 to 16, operated from Amsterdam, the Netherlands. When we say “Lumino,” “we,” or “us,” we mean the team behind Lumino. We are the data controller for the personal data described in this policy.
2. Children's privacy comes first
Lumino is built for children, and we treat children's data with extra care. We comply with the EU General Data Protection Regulation (GDPR), including its provisions for children's data, and we follow the spirit of COPPA (the US Children's Online Privacy Protection Act) as a matter of good practice.
Key commitments:
- Children under 13 can only use Lumino through a parent-managed account
- We never collect real names from children — only usernames chosen by them or their parent
- We do not collect location data, school information, or contact details from children
- We do not serve advertising or share children's data with advertisers
- Parents can review, download, or delete their child's data at any time
3. What data we collect
Information you provide
- Parents: email address, password (hashed), and payment information (processed by Stripe — see section 7)
- Teens (13+): email address and password (hashed)
- Children (under 13): username and birth year only, provided by a parent
Information created through use
- Creations: stories, games, art, tools, and other projects made on the platform
- Conversations with Lumi: the messages exchanged during creative sessions
- Usage data: which features are used, session length, and interactions per day (for usage limits and product improvement)
- Onboarding quiz answers: responses to the creative style quiz used to set the age-appropriate path
What we do NOT collect
- Real names of children
- Physical addresses or location data
- School or class information
- Phone numbers
- Photos or videos of children
- Social media profiles
4. How we use your data
We use the data we collect to:
- Operate the platform and provide the creative experience
- Set the right age path and adjust Lumi's tone and complexity
- Enforce usage limits (e.g., 10 interactions/day on the free tier)
- Process payments and manage subscriptions
- Improve the platform, fix bugs, and develop new features
- Ensure safety and enforce our content guidelines
- Communicate with parents about their account (never directly with children under 13)
Our legal basis for processing under GDPR is: contract performance (providing the service), legitimate interest (safety, improvement), and consent (where specifically required, such as for marketing emails).
5. How AI interactions work
When a child talks to Lumi, their messages are sent to the Anthropic API (Claude) to generate responses. Here is what you should know:
- Anthropic does not use Lumino user data to train its AI models
- Conversations are sent via encrypted connection and are not stored long-term by Anthropic
- Lumino stores conversation history in our database so children can continue projects and parents can review interactions
- Conversations are processed with safety instructions that keep Lumi's responses age-appropriate
For more on how Anthropic handles data, see Anthropic's privacy policy.
6. Where data is stored
Your data is stored using Supabase, with databases hosted in the EU (Frankfurt region). This means your data stays within the European Economic Area.
Our application is hosted on Vercel. Static assets and serverless functions may be served from edge locations globally, but personal data is stored in the EU.
7. Payment data
All payment processing is handled by Stripe. When you subscribe to Lumino+, your card details are sent directly to Stripe and are never stored on our servers. We only receive confirmation of payment status, subscription details, and a Stripe customer ID.
See Stripe's privacy policy for how they handle payment data.
8. Parental controls and access
Parents and guardians can:
- View all of their child's projects and conversations with Lumi
- Manage their child's account settings and age path
- Download their child's data
- Delete their child's account and all associated data
- Cancel subscriptions at any time
These controls are available through the parent dashboard. If you need help accessing these features, contact us at hello@lumino.academy.
9. Data retention and deletion
We keep your data for as long as your account is active. When you delete an account:
- Personal data (email, username, birth year) is deleted within 30 days
- Creations and conversation history are permanently deleted
- Anonymised usage statistics may be retained for product improvement
- Payment records are retained as required by law (typically 7 years for tax purposes)
You can request deletion at any time by emailing hello@lumino.academy or through your account settings.
10. Cookies
Lumino uses minimal cookies:
- Authentication cookies: required to keep you logged in. These are essential and cannot be disabled.
- Preference cookies: to remember settings like your selected age path.
We do not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not track children across other websites.
11. Third-party services
We use the following third-party services to operate Lumino:
Each of these services has their own privacy policy. We have chosen them carefully, prioritising EU data residency and strong privacy practices.
12. Your rights under GDPR
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you or your child
- Correct inaccurate data
- Delete your data (“right to be forgotten”)
- Port your data to another service
- Object to processing based on legitimate interest
- Restrict processing in certain circumstances
- Withdraw consent where processing is based on consent
To exercise any of these rights, email us at hello@lumino.academy. We will respond within 30 days.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.
13. Changes to this policy
We may update this policy from time to time. If we make material changes — especially anything affecting how we handle children's data — we will notify parents by email at least 14 days before the changes take effect.
14. Contact us
For any questions about this privacy policy, your data, or your child's data:
Lumino · Amsterdam, the Netherlands