Privacy Policy
Last updated: 11 June 2026
Privacy Policy
1. Who We Are
LumiCat is operated by FIBREWISE LTD, the data controller responsible for your personal information under UK and EU data protection law.
- Company number 11376004 (registered in England and Wales)
- Registered office: 86-90 Paul Street, London, EC2A 4NE, United Kingdom
How to contact us about privacy is set out in §17.
This Privacy Policy explains what we collect, how we use it, who we share it with, how long we keep it, and the rights you have.
2. Information We Collect
LumiCat is available as an iPhone app and a web platform. The iPhone app pairs a private, on-device journal (Collections) with the AI Studio; the website is a supporting service that provides the AI Studio in your browser on the same account. Your journal — photos, videos, and the notes you record alongside them in Collections — lives on your device by default, and is synced through your own iCloud account where enabled. That content does not pass through our servers as part of ordinary journal use. The AI Studio, available on both the iPhone app and the web, is handled as described in §4 and §5.
When you use LumiCat, we may collect the following information:
- Account information (email or sign-in identifier) when you create an account
- Inputs you send to the AI Studio — the prompt you type and any photos or videos you attach to a generation — handled as described in §4 and §5
- Studio creations you generate, and metadata about them (the model used, parameters, timestamps, and credit cost)
- Purchase and credit records (transactions, balances, and ledger entries)
- Device information and basic usage analytics
- Preferences and settings
3. How We Use Your Information
We use your information to:
- Provide AI-powered generation of images, video, audio, and other media
- Maintain your Studio library and history across the web and your devices
- Process purchases, credits, and refunds
- Operate content moderation and prevent abuse
- Improve our app functionality and user experience
- Send you service and account messages (see Communications below)
Communications
We use your email address to send you service and account messages — for example, notices that your credits or account are about to expire, security and policy updates, and replies to your support requests. These messages are necessary to provide the service, so we send them on the basis of our contract with you or our legitimate interests, and they are not marketing.
We do not send marketing or promotional emails without your consent. If you have any questions about the messages we send, you can reach us through the contact options in §17.
4. AI Processing and Third-Party Services
Our service uses third-party AI providers to process the inputs you send to the AI Studio and to generate new media. Important information about AI processing:
- We do not use your prompts or the photos or videos you upload to the AI Studio to train AI models
- Your inputs may be processed by third-party AI services in accordance with their privacy policies
- AI processing occurs on secure servers with encryption in transit
- We operate content moderation to prevent processing of prohibited content
- AI processing is subject to the terms and privacy policies of our third-party providers
- We may use anonymized, aggregated data to improve our service
5. Media Processing and Storage
It is important to distinguish between the inputs you attach to a request and the creations you generate, because they are handled differently.
Inputs you attach. When you use the AI Studio, the prompt you type and any photos or videos you attach to a generation are sent to the AI provider that runs the selected model. To make that handoff work, we hold those attached inputs on our servers only briefly while the request is in flight, then remove them shortly after the generation completes (typically within about a day). Attached inputs are not kept as a permanent library.
Creations you generate. The media you create in the Studio, and the metadata about it, are stored in your cloud library (using our hosting and object-storage providers) so your history is available on the web and across your devices. Your creations remain until you delete them, until your account is deleted, or until the retention window in §6 elapses.
- Inputs and creations are encrypted in transit
- We do not share your inputs or creations with unauthorized third parties
- Your journal content (photos, videos, and notes outside the AI Studio) stays on your device and your own iCloud, and is not stored on our servers
Facial features and biometrics
A photo you attach to a generation may contain a face, which a model processes to fulfill your request. That is not biometric identification. We do not perform biometric identification, we do not create or store face templates or biometric identifiers, and we do not match faces against any identity database.
6. Data Retention
We keep personal information only for as long as we need it:
- Account information is kept while your account is active. When you request deletion, your account enters a short pending-deletion period (around 30 days) before it is permanently purged from our systems
- Attached inputs are removed from our servers shortly after the generation completes (typically within about a day)
- Studio creations are kept while your credits are active and for a further 30 days after your credits expire. Buying any credit pack within that window extends your credits by another 90 days and keeps your creations; otherwise your cloud creations are deleted after the 30-day grace period. Creations you delete yourself are removed from our systems after a short tombstone period
- Credits expire 90 days after your most recent credit purchase or addition; any new purchase extends the expiry of your whole balance by a further 90 days. Refunds for failed generations do not extend expiry — only purchases and grants do
- Billing and credit ledger records are retained for as long as required for accounting, tax, and legal purposes
Copies of creations you have already downloaded or saved to your device are local to that device and are not affected by deletion from our servers.
7. Multiple Devices and the Web Studio
You can use LumiCat on your iPhone and in a browser on the same account. Your credits and Studio creations are tied to your account, not a single device, so they are available wherever you sign in. Your journal stays on your phone and your own iCloud. How account deletion behaves across the app and the website is described in our Terms of Service (§15).
8. Data Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal information to third parties for their own marketing. We share information only with the service providers (sub-processors) who help us operate LumiCat, and only as needed to provide the service. These fall into the following categories:
- AI model providers that process your inputs and return generations
- Database, hosting, and storage providers that run our backend and store your Studio creations
- Authentication providers that manage sign-in
- Payment providers that handle purchases and refunds
- Analytics and error-monitoring providers that help us understand aggregate usage and diagnose problems
We do not display advertising, we do not sell your personal information, and we do not share it with third parties for advertising or ad measurement (cross-context behavioural advertising).
We may also disclose information when required by law or legal process, or to protect our rights, property, or safety. All service providers handle your data under confidentiality and security obligations.
9. Lawful Bases for Processing
Where UK or EU data protection law applies, we rely on the following lawful bases:
- Performance of a contract — to provide the Service you have signed up for, including processing generations and purchases
- Legitimate interests — to keep the Service secure, prevent abuse, and improve it, balanced against your rights
- Consent — for optional analytics or usage-data sharing, where applicable; you can withdraw consent at any time
- Legal obligation — to keep accounting and tax records
10. Automated Moderation
We use automated systems — ours and those of our AI providers — to moderate content and prevent prohibited or abusive use. These systems may block a generation request. They are not used to make decisions that produce legal or similarly significant effects about you. If you believe a decision was wrong, you can appeal through our support channels.
11. Data Security
We implement appropriate security measures to protect your information:
- Encryption in transit for media uploads
- Secure servers with regular security updates
- Access controls and authentication measures
- Regular security monitoring
- Compliance with third-party AI provider security standards
12. Your Rights
Depending on where you live, you have rights over your personal information. Under UK and EU GDPR you have the right to:
- Access your personal information
- Correct or update inaccurate information
- Delete your account and associated data (erasure)
- Restrict or object to certain processing
- Data portability
- Withdraw consent where processing is based on consent
To exercise any of these rights, use the account and deletion controls in the app and on the website, or contact us through the options in §17. We aim to respond within one month. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
If you are in California or another US state with applicable privacy laws, you have rights to know about, access, and delete your personal information, and we do not sell or share your personal information.
13. Cookies and Analytics
We may use cookies and similar technologies to improve your experience and analyze app and website usage. Where any are used, you can control them through your browser or device settings. We do not use them to display advertising or to sell or share your personal information for advertising.
14. Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13. We also do not knowingly process media of minors without proper parental consent. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
15. International Users
LumiCat is operated from the United Kingdom, and we rely on a distributed set of service providers. Your information may be processed and stored in the United Kingdom, the European Economic Area, and the United States, as well as other countries where our service providers operate. Where required by law (e.g. UK GDPR or EU GDPR), we rely on appropriate safeguards for international transfers, such as UK adequacy regulations, Standard Contractual Clauses, or the EU-US Data Privacy Framework.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including changes required by our AI service providers or applicable law. We will notify you of any changes by posting the new Privacy Policy on this page and updating the published date shown at the top.
17. Contact Us
LumiCat is operated by FIBREWISE LTD, 86-90 Paul Street, London, EC2A 4NE, United Kingdom (company number 11376004).
If you have any questions about this Privacy Policy or our data practices, you can reach us:
- Using our contact form on the website
- Through the in-app support form under Profile → Support, or
- By email at privacy@lumicat.app
