Personal Information Collection List
Every piece of personal information Lumi collects, by feature, with its purpose and how it is collected, plus every device permission Lumi asks for.
This list is part of our Privacy Policy. It sets out, feature by feature, the personal information Lumi collects and the device permissions Lumi asks for. For what we share with third parties, see the Third-Party Sharing & SDK List.
How to read it:
- Required? “Required” means the feature cannot work without the information. “Optional” means you can leave it out, and only that feature is affected.
- Platforms: the web app (/app/) is available now in early access. The iPhone, iPad and Mac apps are in development and coming soon to the App Store; this list also describes how they will handle information when they launch. Features marked “coming later” are not available yet.
- Your content: journal entries, documents, AI conversations, AI memories and other content are stored on our servers in Tokyo, Japan, with no additional application-layer or end-to-end encryption. They never appear in logs, and our admin console has no screen that shows them. Original mail, inbox metadata and mailbox credentials are encrypted with your unique key; see section 11.
- No third-party analytics SDKs: our server records daily activity and AI usage. Optional basic stability diagnostics are off by default and you choose whether to enable them (see sections 4 and 7).
- Sensitive personal information is marked “sensitive”. We ask for your separate consent before processing it.
1. Account and sign-in
| Feature | Personal information | Purpose | How and when it is collected | Required? |
|---|---|---|---|---|
| Sign in with Apple | Apple user ID; the name and email (or relay address) you choose to share | Create your account, verify your identity, sign you in | Provided by Apple when you choose Sign in with Apple | Required for this method |
| Sign in with Google | Google account ID; name; email; profile photo | Create your account, verify your identity, sign you in | Provided by Google when you choose Google sign-in | Required for this method |
| Sign in with WeChat or QQ | unionid / openid; nickname (used as the label for this sign-in method) | Create your account, verify your identity, sign you in | Provided by Tencent when you authorize WeChat or QQ sign-in | Required for this method |
| Email code sign-in | Email address; one-time code | Verify your identity, sign you in, recover your account | We email you a code after you enter your address | Required for this method |
| Phone code sign-in (+86) | Phone number (sensitive); one-time code | Verify your identity, sign you in, recover your account | We text you a code after you enter your number | Required for this method |
| Password sign-in | Email or phone number; password (only a salted scrypt hash is stored) | Verify your identity, sign you in | When you set or enter a password | Required for this method |
| Profile | Display name; profile photo | Address you by name and show your photo in Lumi | You enter them during onboarding or in Settings | Optional |
| Linking and unlinking sign-in methods | Identifier and masked label of the linked method | Keep several sign-in methods on one account | When you use Settings → Account & Security | Optional |
| Devices and sessions | Platform, device model, OS version, Lumi version, device identifier; sign-in sessions | Keep you signed in, sync, sign out devices remotely from your device list | Automatically when you sign in | Required |
| Security records | Event type, time and device; IP address and user agent (salted hashes only) | Protect your account, detect suspicious sign-ins, show you the last 90 days of records; deleted after about 13 months | Automatically on sign-in, password changes, linking, exports and deletion requests | Required |
| New-device sign-in alerts | Email address; device type; sign-in time | Let you spot unfamiliar sign-ins | Sent automatically when a new device signs in | Required |
| Data region | Data region; App Store or system region | Decide where your data is stored | Detected at sign-up; you can switch it on the sign-in screen | Required |
| Separate consent to transfer outside mainland China (users in mainland China) | Your choice and when you made it | Record your separate consent to the cross-border transfer before anything you create is uploaded | On the transfer consent screen, the first time a user in mainland China signs in | Required to sync with an account; without it you can still use Lumi on your device |
2. Core features
| Feature | Personal information | Purpose | How and when it is collected | Required? |
|---|---|---|---|---|
| Tasks | Task titles, notes, lists, subtasks, due dates, reminders, priority, images | Track and manage tasks, remind you on time | When you create or edit tasks | Required to use the feature |
| Calendar | Event titles, times, time zones, locations, notes, attendees, meeting links | Show and manage events, remind you | When you create or edit events | Required to use the feature |
| Journal | Entries, moods, tags; photos and other attachments (with location data removed from the files before storage); places you add: a place name or location coordinates (sensitive) | Record and look back on your life | When you write; a place is saved only when you add it yourself: by typing a place name, tapping “Use current location” in the web app, or turning on “Keep photo locations” (off by default) | Entry text required; attachments and places optional |
| Docs | Page content; attachments such as images and files | Write and organize | When you create or upload | Required to use the feature |
| Money | Accounts, transaction amounts and currencies, categories, merchants, notes, budgets (sensitive); receipt photos | Track spending, budgets and statistics | When you log, edit or import transactions | Transaction details required; photos optional |
| Habits | Habit settings, check-ins, values, notes, photos | Check in, track streaks and completion rates | When you check in; automatic check-ins need Health permission | Required to use the feature |
| Life and growth | Birthday, life expectancy, life goals, life blueprint, growth plans, reviews, countdowns, time capsules (coming later) | Life grid, goals and plans, reviews | You enter them during onboarding or on the related pages | Birthday optional; used for the life grid and age-based goal suggestions |
| Today and daily summary | Today’s data from each module | Build the Today page and the non-AI daily summary | Compiled automatically from your data | Required to use the feature |
| Quick capture | Text you enter | Turn it into a task, event, transaction, journal entry and so on | When you use the capture bar; parsed on your device first, AI parsing only if you have agreed to AI | Required to use the feature |
| Search | Search terms | Find things in your data | When you search, performed locally | Required to use the feature |
| Notifications and reminders | Push token; notification settings; quiet hours; devices that receive notifications | Send reminders for tasks, events, habits and briefings, and avoid duplicates across devices | After you allow notifications | Optional |
| Sync | All of your content; device identifier; sync progress | Sync across your devices | Automatically | Required |
| Recently Deleted | Items you delete | Let you restore them within 30 days | When you delete something | Required |
| Share cards | The content you choose to include | Create an image for you to share | When you tap Share | Optional |
| Data export | Your data (except attachment files); labels on AI-generated content in the archive | Create an export file for you to download; the file is kept for 24 hours | When you request an export in Settings | Optional |
3. Integrations and imports
| Feature | Personal information | Purpose | How and when it is collected | Required? |
|---|---|---|---|---|
| Google Calendar | Calendar list and events; authorization token (encrypted with a key unique to you) | Two-way sync with Google Calendar | When you connect and authorize in Settings | Optional |
| Microsoft Outlook Calendar | Events; authorization token (encrypted with a key unique to you) | Two-way sync with Outlook Calendar | When you connect and authorize in Settings | Optional |
| Microsoft To Do | Lists, tasks and steps; authorization token (encrypted with a key unique to you) | Two-way sync with Microsoft To Do | When you connect and authorize in Settings | Optional |
| Apple Calendar and Reminders (Apple apps) | Calendars, events, reminder lists and reminders | Two-way sync on your device, synced to your account so you can see them on the web | After you grant system permission | Optional |
| iCloud Calendar server sync (coming later) | Apple Account email; app-specific password (encrypted with a key unique to you); events | Sync iCloud Calendar directly on the web | When you connect it by following the guide | Optional |
| Apple Health (iPhone, iPad) | Steps, distance, active energy, exercise, stand hours, sleep, resting heart rate, heart rate variability, weight, mindful minutes, workouts, State of Mind (sensitive) | Automatic habit check-ins, goal progress, reviews, AI health insights | After you grant system permission and give separate consent; only daily summaries are uploaded | Optional |
| Journaling Suggestions (iPhone, iPad) | The photos, places, workouts, music, contacts and so on in the one suggestion you pick | Pre-fill a journal entry | When you pick a suggestion in the system picker; no permission needed | Optional |
| Bill import | Transactions in Alipay or WeChat bill files (sensitive) | Import into Money | After you pick a file, it is read on your device and the original is never uploaded; only the records you review and confirm are imported | Optional |
| Imports from other apps | Tasks or transactions in CSV, Excel or JSON files exported from other task or money apps | Move your data into Lumi | When you upload a file | Optional |
| Connected and forwarded mail | Mailbox address; senders, subjects, message text and attachments; raw messages and metadata; OAuth tokens or IMAP authorization codes / app passwords (credentials, originals and inbox metadata are encrypted with a unique key) | Show mail and propose tasks, events and money records for your confirmation | When you connect an available mailbox service or deliberately forward mail; AI also requires cloud AI consent and separate email permission | Optional |
4. Lumi, your AI companion
| Feature | Personal information | Purpose | How and when it is collected | Required? |
|---|---|---|---|---|
| AI consent | Consent record (time, version, scope); per-module access switches | Record your consent and choices | When you agree on the consent screen or change settings | Required to use AI |
| Conversations | Your questions; current page content; passages retrieved from allowed modules; life snapshot; relevant memories; Lumi’s answers | Generate answers | When you talk with Lumi | Required to use AI |
| Briefings, plans and insights | Relevant data from allowed modules | Create morning briefings, Plan my day, growth plans and review insights | At the times you set or when you ask | Optional |
| Health insights | Daily health summaries (sensitive) | Give health-related suggestions | After your additional, separate consent | Optional |
| Memory | Memories drawn from conversations, journal entries and planning interviews, with their sources | Help Lumi get to know you | Built automatically in the background; you can view, edit and delete them | Processed when you use AI; can be deleted at any time |
| Semantic search | Vectors generated from allowed content | Find related content by meaning | Generated automatically in the background | Processed when you use AI |
| Voice input (coming later) | Audio recordings; transcripts | Turn speech into text | We will update this list before it launches | Optional |
| Web search (coming later) | Search queries generated from your request | Find outside information and cite sources | We will update this list before it launches | Optional |
| Lumi actions | Proposed actions; your confirmations or undos | Create or change data as you decide | When you accept or decline an action card | Optional |
| Activity log | Records of what Lumi read, did and created | Let you review and undo | Recorded automatically | Required to use AI |
| Token metering | Feature, provider, model, token counts, latency, cost, result status and time (never the content of questions or answers) | Billing, showing usage, cost accounting, investigating AI quality issues | Recorded automatically for every call | Required to use AI |
| Answer feedback | Your rating of an answer; the conversation, if you agree to include it | Improve answer quality, investigate problems | When you send feedback | Optional |
| Labels on AI-generated content | The “AI-generated” label, the ai_generated label and metadata naming the service provider, added to AI-generated content in export files |
Meet legal obligations on labeling AI-generated content | Added automatically when you export your data | Required for exports |
| Region check for AI features | The country or region and time zone your device reports to Lumi | Determine whether you are in mainland China, so that only domestically filed models are used and AI inputs and outputs are filtered | Automatically; no GPS and no IP address are used | Required |
5. Membership and payments
| Feature | Personal information | Purpose | How and when it is collected | Required? |
|---|---|---|---|---|
| In-App Purchase (Apple apps) | Product, transaction ID, purchase and expiry dates, renewal and refund status, App Store region | Grant your benefits, handle renewals and refunds | Provided by Apple after you buy | Required to purchase |
| Web payments (global region) | Order ID, product, amount, currency, payment status, Stripe customer and subscription IDs, email address | Grant your benefits, send receipts, manage your subscription | Provided by Stripe after you pay | Required to purchase |
| Web payments (mainland China, not available yet) | Order ID, product, amount, payment status, your user identifier at the payment provider | Grant your benefits, reconcile payments | Once available, provided by WeChat Pay or Alipay after you pay | Required to purchase |
| Token wallet | Balance; history (source, amount, time) | Billing, showing your balance and history | Recorded automatically | Required |
| Renewal and trial reminders | Email address, phone number or push token; subscription details | Notify you before every renewal charge and before a trial ends | Sent automatically | Required when you subscribe |
| Redemption codes | Code; redemption time | Redeem membership or tokens | When you enter a code | Optional |
We never receive or store your full card number, payment password or other payment credentials.
6. Support and feedback
| Feature | Personal information | Purpose | How and when it is collected | Required? |
|---|---|---|---|---|
| Email support | Email address; your description of the issue and attachments | Answer questions, handle requests | When you email support@xicoai.com | Optional |
| In-app feedback | Your feedback; screenshots you attach; technical diagnostics (browser or device, system and app versions, language, time zone and the like, never your content; you can leave them out) | Answer questions, fix problems; deleted with your account | When you send feedback | Optional |
| Privacy requests | Information needed to verify your identity | Verify your identity and handle your request | When you make a request | Required to exercise your rights |
7. Security, operations and improvement
| Feature | Personal information | Purpose | How and when it is collected | Required? |
|---|---|---|---|---|
| Server access logs | Truncated IP address (first 24 bits of IPv4, first 48 bits of IPv6); request time; requested path (without query string); response status. No browser type (user agent) | Security and troubleshooting; deleted after 14 days | Automatically when you visit the website or use Lumi | Required |
| Server error logs | The IP address (possibly in full) and request details of a failed request | Troubleshooting; deleted after 14 days | Automatically when a request fails | Required |
| Daily activity records | Account identifier; date (at most one record per account per day, and nothing about what you did) | Count daily active users and retention | Automatically when you use Lumi on a given day | Required |
| Basic stability diagnostics | App version, platform, module and error category; no content, error text, stacks or URLs. The associated authenticated access log may include an account identifier | Identify failures and improve stability | Off by default; sent only after you enable it and while signed in; can be disabled anytime | Optional |
8. The website
| Feature | Personal information | Purpose | How and when it is collected | Required? |
|---|---|---|---|---|
| Price currency | The currency you choose, stored only in your browser and never sent to us | Show prices in that currency | When you switch currency | Optional |
| Access logs | As for “Server access logs” in section 7 | Security and troubleshooting | Automatically when you visit the website | Required |
The website uses no cookies, analytics tools or third-party scripts.
9. Device permissions
Lumi asks for a permission only when you use a feature that needs it, and explains why first. You can change your choices at any time in your system or browser settings, and saying no affects only the related feature. The web app asks the browser for only two permissions: notifications and location.
| Permission | Platforms | Purpose | When we ask | If you decline |
|---|---|---|---|---|
| Notifications | iPhone, iPad, Mac; web app (browser notifications) | Reminders for tasks, events, habits and countdowns; briefings; messages from Lumi | During onboarding or when you first set a reminder | No push notifications; reminders still appear in the app |
| Calendars | iPhone, iPad, Mac | Read and write events in Apple Calendar and sync them | When you choose to connect Apple Calendar | Apple Calendar won’t sync; Lumi’s own calendar and other integrations still work |
| Reminders | iPhone, iPad, Mac | Read and write Apple Reminders and sync them | When you choose to connect Reminders | Apple Reminders won’t sync |
| Health | iPhone, iPad | Read health data for automatic check-ins, goals and reviews; save your moods as State of Mind | When you turn on a health-related feature | Health-related features are unavailable; everything else works |
| Microphone (coming later) | iPhone, iPad, Mac | Voice input and voice journal entries | The first time you use voice | No voice input; you can type instead |
| Speech recognition (coming later) | iPhone, iPad, Mac | Turn speech into text on your device | The first time you use voice | Speech can’t be transcribed on your device |
| Photos | iPhone, iPad, Mac | Add photos to journal entries, transactions, habits and docs | No permission is needed to add photos through the system photo picker, and Lumi sees only the photos you pick; Photo Moments (coming later) will ask for access and analyze photos only on your device | The picker still works; declining affects only Photo Moments |
| Camera (coming later) | iPhone, iPad | Photograph receipts and turn them into transactions | The first time you scan a receipt | No camera; you can pick a photo instead |
| Location | Web app | Get your current coordinates once, as the place of a journal entry | When you tap “Use current location” in an entry’s Place field | No location is read; you can still type a place name |
| Face ID / Touch ID | iPhone, iPad, Mac | Open a journal you have locked | When you lock a journal and then open it | You can use your device passcode instead. Biometrics are verified only on your device; Lumi never receives them and they never leave your device |
Journaling Suggestions uses Apple’s system picker and needs no permission. The iPhone, iPad and Mac apps don’t request location access today. Lumi never gets your location in the background, and never asks for access to your contacts or for permission to track you for advertising.