Privacy Policy

How Lumi collects, uses, stores, shares and protects your personal information, and how you can view, export, correct and delete it.

Version
1.1
Effective
Last updated

Lumi is provided by Zhixike Technology (Guangzhou) Co., Ltd. (“XicoAI”, “we”, “us”). What you bring to Lumi is your journal, your plans, your spending, your health and your goals in life, which is about as personal as information gets. We treat protecting it as the foundation of the product, not a clause at the end. This policy explains what personal information we collect, why, where it is stored, how long we keep it, who we share it with, how we protect it, and the rights you have.

Together with the Personal Information Collection List, the Third-Party Sharing & SDK List, Children’s Privacy and the Cookies & Local Storage Notice, this policy makes up our full privacy notice. The rules for using Lumi are in the Terms of Service, and the rules for its AI features are in the AI Service Terms. We put the parts about sensitive personal information, international transfers and your key rights in bold. Please read them carefully.

At a glance

  • We don’t sell your data and we don’t show ads. Lumi has no advertising and does not track you across apps or websites.
  • Your content is used only for you. Your journals, documents, AI conversations and other content are stored on our servers in Tokyo, Japan. They have no additional application-layer or end-to-end encryption; strict access controls protect them instead, and our admin console has no screen that shows them. Neither we nor our AI providers use your data to train AI models. Original mail, inbox metadata and mailbox credentials are encrypted with your unique key; see section 11.
  • AI works only with your permission. Cloud AI stays off until you agree. You decide, module by module, what Lumi can read, and you can hide any single journal entry or document from Lumi.
  • Optional basic diagnostics, no location in your photo files. The web and Apple apps have no third-party analytics SDKs. Basic stability diagnostics are off by default and you choose whether to enable them in Settings. Lumi never gets your location in the background and saves only places you add yourself; location data is removed from photo and video files before they are stored.
  • We tell you plainly where your data lives. Lumi’s servers are currently in Tokyo, Japan. If you use Lumi in mainland China, your information leaves China, so we ask for your separate consent before anything you create is uploaded. AI requests from users in mainland China are handled only by DeepSeek, a domestically filed model, and pass through a keyword content filter. Once our China region launches, mainland users’ data will be stored in China.
  • You stay in control. You can export all of your data for free, correct or delete anything, or delete your account at any time.

1. Who we are

Lumi is operated by Zhixike Technology (Guangzhou) Co., Ltd., registered at Rm 215A, Rm 410, 4/F, Bldg 1, No. 19 Guangsheng Rd, Nansha, Guangzhou, Guangdong, China. We are the personal information handler responsible for your information and, for users in the European Economic Area, the United Kingdom and Switzerland, the “controller” under data protection law.

We have appointed a person responsible for personal information protection. You can reach us at support@xicoai.com. For privacy requests, please put “Personal Information Protection” in the subject line so that your email goes directly to that person.

2. Scope

This policy covers the following products and services we provide under the Lumi brand (together, “Lumi”):

  • the Lumi website at lumi.xicoai.com (the “website”);
  • the Lumi web app at /app/, currently in early access;
  • the Lumi apps for iPhone, iPad and Mac (in development and coming soon to the App Store);
  • related services such as verification and notification emails and customer support.

This policy does not cover third-party services you connect to or are redirected to through Lumi, such as Apple, Google, Microsoft, WeChat and QQ accounts and services, or payment providers. They handle your information under their own privacy policies, which we encourage you to read. Future platforms such as Windows and Android will also be covered by this policy; if they handle information differently, we will update this policy before they launch.

3. Information we collect

We collect only what we need to make Lumi work. The categories are described below; the full list by feature is in the Personal Information Collection List.

3.1 Account information

You can sign in with Apple, Google, WeChat or QQ, with a one-time code sent to your email or phone (currently +86 numbers only), or with a password. Depending on the method you choose, we collect:

  • your email address, phone number, display name and, if you add one, your profile photo;
  • third-party account identifiers, such as your Apple user ID, Google account ID, and WeChat or QQ unionid / openid, plus a masked label (such as a masked email address) so you can tell your sign-in methods apart in Settings;
  • if you set a password, only a salted scrypt hash of it, from which no one, including us, can recover your password;
  • your data region (see section 9).

When you use a third-party sign-in, we receive only what is needed to sign you in, for example the name, email address and profile photo of your Google account. If you choose Hide My Email with Sign in with Apple, we receive only the relay address Apple provides. When you use Sign in with Apple, we also keep the authorization token Apple issues (encrypted with a key unique to you, see section 11). We use it only to revoke Lumi’s authorization at Apple when you delete your account or remove this sign-in method.

3.2 Content you create in Lumi

This is the heart of Lumi: everything you write, record or upload, including:

  • Tasks and calendar: tasks, lists, subtasks, reminders, events, attendees and meeting links;
  • Journal: entries, moods, tags, photos and other attachments, and any place you add to an entry yourself (a place name or location coordinates; location data inside photo files is removed before they are stored; see section 5.3);
  • Docs: page content and attachments such as images and files;
  • Money: accounts, transactions, budgets, categories, merchants, notes and receipt photos you add;
  • Habits: habit settings, check-ins, and the notes and photos you add to them;
  • Life and growth: your birthday, life expectancy setting, life goals, life blueprint, growth plans, reviews, countdowns and time capsules (coming later);
  • Conversations with Lumi: your questions, Lumi’s answers, and the briefings, plans and insights Lumi creates for you.

We process this content to store it, sync it across your devices and provide the features you use. Your content may include information about other people (for example, a friend you mention in your journal). Please be respectful of them when you do.

3.3 Integrations and imports

Lumi accesses the following services only when you connect them:

  • Google Calendar: with your Google authorization, Lumi reads and writes your calendar list and events (see section 14);
  • Microsoft Outlook Calendar and Microsoft To Do: with your Microsoft authorization, Lumi reads and writes your events, task lists and tasks;
  • Apple Calendar and Reminders: with your permission on iPhone, iPad and Mac, Lumi reads and writes them directly on the device and syncs the events and reminders to your Lumi account so you can see them on the web and your other devices. Server-side iCloud Calendar sync using an app-specific password is coming later;
  • Apple Health: see section 5.1;
  • Journaling Suggestions: through Apple’s system picker, Lumi receives only the suggestion you choose and needs no photo library or other permission;
  • Bill and data imports: bill files you export from Alipay or WeChat, or CSV and Excel files exported from other money or task apps. Bill files are read on your device and the original file is never uploaded; only the records you review and confirm are saved to Money.

The following disconnect rules apply to calendar and task integrations; mailbox disconnect rules are in section 14. Authorization credentials (refresh tokens) for Google and Microsoft, and iCloud app-specific passwords, are stored on our servers encrypted with a key unique to you (see section 11), and can be used only by the server to sync. You can disconnect an integration at any time in Settings, or revoke access in your Google or Microsoft account settings. When you disconnect, we revoke the Google token or delete the Microsoft token, and delete the synced data for that integration; you can choose to keep content you have already imported into Lumi.

Connected mailboxes and mail you choose to forward to Lumi share the same inbox and confirmation flow. Available connections are shown in Settings and are authorized separately from sign-in. Section 14 describes Gmail access, optional AI processing, retention and deletion; the same mail handling rules apply to other mailboxes and forwarded mail.

3.4 Information used by AI features

When you use Lumi’s AI features, we process your questions and instructions, the content needed for the task (only from modules you have allowed), the AI’s output, the memories Lumi keeps about you, the Lumi Activity log, and usage records for each call such as the model used, the number of tokens and the feature. Feedback you give on answers (such as “helpful” or “not helpful”) is also recorded so we can improve answer quality. See section 6.

3.5 Purchase and subscription information

When you buy a membership or a token pack, we process the product, price, currency, purchase channel, order or transaction ID, purchase time, subscription and trial status, renewal and expiry dates, refund records, and your token wallet balance and history.

Payments are handled by Apple (In-App Purchase) or Stripe. WeChat Pay and Alipay on the web are not available yet; once they are, they will handle those payments. We never receive or store your full card number, payment password or other payment credentials. For App Store purchases, we receive transaction information from Apple but not the payment details of your Apple Account.

3.6 Device and log information

To run Lumi reliably and securely on your devices, we collect:

  • Device information: platform and device model, operating system version, Lumi version, time zone, language, and a push token for sending notifications. Lumi creates an identifier for each device you sign in on, used for sync and device management;
  • Security records: sign-ins, sign-ins from a new device, password changes, linking or unlinking sign-in methods, data exports and account deletion requests. In these records, your IP address and your browser and device type (user agent) are stored only as salted hashes. You can see the last 90 days of records in Settings → Account & Security; security records are deleted after about 13 months;
  • Server access logs: request time, a truncated IP address (the first 24 bits of an IPv4 address, the first 48 bits of an IPv6 address), requested path and response status, used for security and troubleshooting. Access logs never record your full IP address, your browser type (user agent) or the query string of a URL, and they are deleted after 14 days. Server error logs may contain the full IP address of a failed request and are also deleted after 14 days;
  • Application logs: the operating logs of our server software, used for troubleshooting. They never contain your content.

3.7 Usage and diagnostic information

Neither the web app nor the Apple apps include third-party product-analytics or crash-reporting SDKs. Our own server records the following content-free usage information. Optional basic stability diagnostics are off by default:

  • Activity records: if your account uses Lumi on a given day, the server records that it was active that day (at most one record per account per day, by UTC date), so we can count daily active users and retention. It does not record what you did;

  • AI usage metering: for each AI call, the feature, model, token counts, latency and result status, used to charge tokens, show you your usage and account for costs. It does not record your questions or the AI’s answers.

  • Basic stability diagnostics (optional): after you enable “Share diagnostics” on the web or “Help Improve Stability” in the Apple app, signed-in clients send only the app version, platform, module and error category to Lumi to help identify failures. The Apple app uses system MetricKit to detect the presence of crashes, hangs or resource exceptions, without uploading raw reports. Diagnostics exclude journals, tasks, chats, amounts, error messages, stacks and URLs. Nothing is uploaded while signed out, and you can disable the setting anytime. Diagnostics enter our application logs; the associated authenticated access log may still contain an account identifier.

Before adding a third-party analytics or crash-reporting service, we will update this policy and the Third-Party Sharing & SDK List, announce the change and obtain any required authorization.

3.8 When you contact us

When you email us or send feedback in the app, we process your contact details, your description of the issue, and any screenshots and diagnostic information you choose to attach. Feedback is the only way our staff can see your content: we see only what you choose to put in it.

3.9 The website

When you browse the website, we use no cookies, no analytics tools and no third-party scripts, and we host our fonts ourselves. The website stores only the currency you choose for prices in your browser, and it is never sent to us. Like any website, the web server produces the access logs described in section 3.6. See the Cookies & Local Storage Notice.

3.10 What we don’t do

  • We don’t use advertising identifiers (such as the IDFA), track you across apps or websites, or include any advertising SDK;
  • we never get your location in the background, and we save a place only when you add it yourself (see section 5.3);
  • we don’t scan your photo library on our servers; we process only photos you choose, and remove the location data inside the photo files before they are stored;
  • we don’t include any product-analytics, crash-reporting or other third-party statistics SDK;
  • we don’t use your personal information for unfair differential pricing.

4. How we use personal information and our legal bases

Purpose Information involved Legal basis
Sign-up, sign-in and account security Account information, device information, security records Necessary to perform our contract with you; legal obligations such as cybersecurity law; our legitimate interest in keeping accounts secure
Storing and syncing your content and providing features Your content, device information Necessary to perform our contract
Providing cloud AI features Your questions, relevant content from allowed modules, memories Your consent; your separate consent where sensitive information is involved
Syncing calendar and task services you connect Integration data, authorization credentials Necessary to perform our contract (once you connect); your consent
Saving places you add to journal entries Place names or location coordinates (see section 5.3) Your consent: you add them yourself, and your browser asks for your permission before your current location is read
Processing health data (arriving with the iPhone and iPad apps) See section 5.1 Your separate consent
Purchases, subscriptions, token wallet and refunds Purchase and subscription information Necessary to perform our contract; tax, accounting and consumer protection obligations
Reminders, briefings and service notices, including notices before auto-renewal charges Push tokens, email address, phone number Necessary to perform our contract; legal obligations
Customer support and feedback Contact details, feedback you provide Necessary to perform our contract; your consent
Billing, counting active users and retention, accounting for AI costs Daily activity records and AI usage metering (neither contains your content) Necessary to perform our contract; our legitimate interest in running and improving the service
Security, fraud and abuse prevention, troubleshooting Device information, logs, security records, usage records Legal obligations; our legitimate interest in keeping the service and users safe
Labeling AI-generated content AI-generated content in export files Legal obligations
Crisis support messages The conversation that triggered crisis detection Necessary to protect your life and health in an emergency

In mainland China, we process personal information on the grounds set out in Article 13 of the Personal Information Protection Law. “Legitimate interest” in the table applies only under laws that recognize it, such as the GDPR; elsewhere we rely on your consent or another basis provided by law.

We also commit that:

  • We won’t use your information for purposes not described in this policy. If we need to use it for a new purpose, we will tell you and ask for your consent first.
  • We don’t make decisions that significantly affect you based solely on automated processing. Lumi offers suggestions, plans and reminders based on your data, but any change to your data follows the confirmation rules in section 6.7. You can set Lumi’s proactive reminders to zero or turn off AI access to any module in Settings.
  • We don’t send marketing messages unless you separately agree. Service notices, such as renewal reminders and security alerts, are not marketing.

Under applicable law, we may process your personal information without your consent where it is necessary to enter into or perform a contract to which you are a party; to fulfil statutory duties or obligations; to respond to a public health emergency or to protect someone’s life, health or property in an emergency; for news reporting or public-interest supervision within a reasonable scope; to process, within a reasonable scope, information you have made public or that has otherwise been lawfully made public; or in other circumstances provided by law.

5. Sensitive personal information

If sensitive personal information is leaked or misused, it can easily harm your dignity or your personal or financial safety. The sensitive personal information Lumi may process includes financial accounts and transactions, your phone number, location coordinates you add to journal entries yourself, and, once the Apple Health features arrive, the health data you allow Lumi to read. What you write in journals, documents and conversations may also include sensitive information such as health or religious beliefs.

Before we read or upload health data, or send health data to AI, we explain why it is needed and how it may affect you, and we ask for your separate consent. Location coordinates are saved only when you add them yourself (see section 5.3). If you say no, only that feature is unavailable; everything else keeps working.

5.1 Health data (Apple Health)

The Apple Health features will arrive with the iPhone and iPad apps; Lumi does not read any health data today. Once they arrive, we handle health data as follows:

  • Where it is read: only on iPhone and iPad, after you grant permission in the system. You can allow only some data types. Mac cannot read health data; on Mac and the web, Lumi shows only the health summaries that have been synced.
  • Data types: steps, walking and running distance, active energy, exercise minutes, stand hours, sleep, resting heart rate, heart rate variability, weight, mindful minutes, workouts and State of Mind. When you log a mood in Lumi, you can choose to save it to the Health app as well.
  • Use: only for health-related features, such as automatic habit check-ins, goal progress, reviews and, if you turn them on, AI health insights.
  • Upload and sync: only with your separate consent do we upload daily summaries and workout summaries (without routes) to our servers. Health data is never stored in iCloud, never used for advertising, marketing or data mining, and never sold.
  • AI: health data is sent to AI providers only with your additional, separate consent, and we send daily summaries rather than detailed records whenever possible.
  • Withdrawing: you can turn off Lumi’s access in iOS Settings → Privacy & Security → Health, or turn off health uploads or AI access in Lumi and choose to delete the health summaries already uploaded.

5.2 Financial information

  • Accounts, transactions and budgets in Money are entered by you or imported from bill files you export. Lumi does not connect to your bank accounts and never receives sign-in credentials for your bank or payment accounts.
  • When you import Alipay, WeChat or similar bills, the file is read on your device and the original is never uploaded. Before anything is imported, Lumi lists the records for you to review and confirm.
  • Amounts never appear in logs. Card numbers, ID numbers and similar identifiers are masked before anything is sent to AI.
  • You can turn on Privacy Mode in Money to hide all amounts in public.

5.3 Location

Lumi never gets your location in the background. It saves a place for a journal entry only when you add one yourself, in one of three ways:

  • Type a place name, such as “Shanghai” or “Home”;
  • Use current location (web app): tap “Use current location” in the entry’s Place field, and Lumi asks your browser once for your current coordinates (latitude and longitude). The first time, your browser asks for your permission; if you say no, you can still type a place name;
  • Keep photo locations (web app): this setting is off by default. If you turn it on in the entry’s photo menu, Lumi reads the coordinates of the place where a photo was taken when you add it, and saves them as a separate field of that photo; if the entry has no place yet, they also become the entry’s place.

A place is saved as a separate field of the entry, and you can change or delete it at any time. Whether or not you use these settings, photo and video files themselves never keep location data: the web app first re-encodes each photo in your browser, removing all of its metadata, and our server additionally strips location metadata from every uploaded image and video, including GPS data in the EXIF and XMP of JPEG, HEIC / HEIF, AVIF, PNG and WebP images and the location information in MP4 and MOV videos (the GIF format carries no location metadata).

The iPhone, iPad and Mac apps don’t request location access today; a place in a journal entry there is a place name you type. You can withdraw the web app’s location permission at any time in your browser settings.

5.4 Phone number

Your phone number is used for sign-in, account recovery and security verification. We protect it as sensitive information: it never appears in plain text in logs and is masked before anything is sent to AI.

5.5 Private things you write

Your journal, documents and conversations may contain very private information about your health, feelings, religious beliefs or relationships. Our admin console has no screen that shows this content, and it never appears in logs (see section 11). Lumi’s memory does not automatically remember sensitive categories such as health conditions, religion, political views, sexual orientation or financial account numbers unless you explicitly ask it to.

6. How AI features handle your information

6.1 Explained first, enabled second

Before you first use cloud AI, Lumi shows a dedicated consent screen explaining what data Lumi will read, which AI providers will receive it, why, and that the providers do not train on it. Cloud AI stays off until you explicitly agree. You can withdraw your cloud AI consent at any time in Lumi’s settings, and Lumi immediately stops sending your data to AI providers.

AI features are available only to users aged 18 or older (or the higher age required by local law).

6.2 Control by module

Once you agree, Lumi can by default read seven modules: journal, docs, tasks, calendar, money, habits, and goals & plans. You can turn off any of them in Settings → Lumi. Health data needs separate permission under section 5.1. AI access to email must be enabled separately; connecting a mailbox does not enable AI. In addition:

  • you can mark any journal entry or document “Don’t let Lumi read this”;
  • modules you have not allowed and items you have excluded are filtered out at retrieval, so they never reach a model.

6.3 What is sent to a model

For each request, Lumi sends only the minimum the task needs. That usually includes your question, relevant content from the current page, relevant passages retrieved from allowed modules, relevant memories, and a “life snapshot” summary generated from the data you have allowed (such as the name you go by, your goals, and recent mood and habit trends). Phone numbers, email addresses, ID numbers and card numbers are masked before sending. Numbers about your data (such as “how much did I spend on dining in October”) are calculated by deterministic code; the model only explains them.

To support semantic search, Lumi converts the content you have allowed into vectors (a mathematical representation). In the global region, vectors are generated on our own servers; in the China region, Alibaba Cloud Bailian’s embedding service may be used.

Voice input and web search are not available yet. Before they launch, we will explain in this policy which services will process your recordings and search queries.

6.4 AI providers and where they process data

Lumi calls the following providers through our own model gateway. Which one handles a request depends on your data region, where you are, the model you choose and the type of task. The consent screen lists the providers you may use.

Applies to Providers Where data is processed
China region (in preparation) DeepSeek (Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd.) as primary; Alibaba Cloud Bailian (Qwen) as backup, possibly also for embeddings Mainland China
Global region, most countries and regions OpenAI; DeepSeek; Anthropic (Claude, enabled once we confirm we meet its eligibility requirements) OpenAI and Anthropic mainly in the United States; DeepSeek in mainland China
Global region, Hong Kong and Macau DeepSeek and other providers that support these regions (not OpenAI or Anthropic) Depends on the provider; DeepSeek in mainland China

Please note: even if you are a global-region user, requests handled by DeepSeek are processed in mainland China. Members can choose a preferred model in a conversation. AI requests from users in mainland China are handled only by DeepSeek; see section 6.9.

If no AI provider is available, the affected AI features are paused or hidden. Lumi never passes off simulated or canned content as an AI answer.

6.5 No training, shortest retention

We never use your data to train any model. Our data processing terms with AI providers prohibit them from training on your data and require the shortest possible retention. Under their terms, providers may keep request records briefly to prevent abuse.

For each AI call, we record only usage information such as the feature, model, token counts, latency and result status, for billing and for investigating quality and cost issues. We don’t record the content of your questions or the answers there. Your conversations with Lumi are kept as your content in your account, where you can view and delete them.

6.6 Memory

To really get to know you, Lumi builds “memories” from your conversations, journal and planning interviews, such as your job, preferences and goals.

  • Every memory shows its source. You can view, edit and delete memories in Lumi’s Memory, or say “forget this” in a conversation to delete one; the related vectors are deleted too;
  • memories Lumi is unsure about go to a “to confirm” list and take effect only after you confirm them;
  • sensitive categories such as health conditions, religion, political views, sexual orientation and financial account numbers are never remembered automatically unless you explicitly ask;
  • the Lumi Activity log shows everything Lumi read, did and created.

6.7 You decide what Lumi does

Lumi can create or change your data, but it proposes first. Only if you turn on “Auto-run low-risk actions” will a reversible single action (such as adding one task) run directly, with Undo. Batch or structural changes, anything that affects other people or outside systems (such as sending updates to event attendees), and irreversible actions such as deletion always need your confirmation. Deleted items go to Recently Deleted for 30 days.

6.8 Safety and labeling

  • Labels on AI-generated content: in Lumi, AI answers carry the Lumi orb, and answers in conversations are labeled “AI-generated” by default. When you export your data, the AI-generated content in the archive — Lumi’s answers in conversations, briefings, insights, AI summaries of journal entries and reviews, growth-plan analyses and generated plan text, and the memories Lumi created — carries an explicit “AI-generated” label in the Markdown files and an ai_generated label in the JSON files, and the archive includes metadata naming the service provider. We apply these labels under China’s Measures for Labeling AI-Generated Synthetic Content.
  • If Lumi detects signs of a crisis such as self-harm, it responds with a fixed, caring message and local help lines. We record only that crisis support was triggered, not what was said.
  • Lumi does not give medical diagnoses, specific investment advice or legal advice. AI-generated text can be wrong, so please verify anything important before you act on it.

6.9 Users in mainland China

Lumi’s AI features are available to users in mainland China. For users in mainland China, AI requests are handled only by DeepSeek, a domestically filed large language model (processed in mainland China), and are never sent to OpenAI or Anthropic. AI inputs and outputs pass through a keyword content filter, and requests or answers found to violate the rules are blocked or stopped; the filter records only that an event happened, never the content or the matched word.

Lumi determines whether you are in mainland China from the country or region and the time zone your device reports to Lumi. It does not use GPS or your IP address for this.

We are completing the generative AI service registration and related filings. Once they are complete, we will publish the names of the models used and their registration and filing details, and update this policy.

7. Cookies and local storage

The website uses no cookies; it only stores your chosen price currency in your browser. The web app uses browser storage (IndexedDB and localStorage) to keep you signed in and to hold an offline copy of your data, and may use strictly necessary cookies during sign-in. When you choose to sign in with a provider such as Google or Apple, that provider sets its own cookies on its own domain. We use no advertising cookies and do no cross-site tracking. See the Cookies & Local Storage Notice.

8. How we share, transfer and disclose personal information

8.1 We don’t sell personal information

We don’t sell or rent your personal information, share it with advertisers, or share it with other companies for their marketing.

8.2 Service providers

To run Lumi, we engage service providers in these categories to process personal information on our behalf: cloud hosting (currently AWS in Tokyo, Japan), AI models, SMS and email delivery, and payments. We don’t use a third-party crash-reporting or analytics service; Lumi receives optional basic diagnostics itself. Our contracts require them to process personal information only on our instructions and for the purposes in this policy, to protect it with appropriate security measures, and to delete or return it when the engagement ends. The full list, what each receives and where it processes data are in the Third-Party Sharing & SDK List.

8.3 Third parties you choose to connect or use

When you sign in with Apple, Google, WeChat or QQ, connect Google or Microsoft calendars and tasks, or pay through Apple, Stripe, WeChat Pay or Alipay, we exchange with those services the information needed for that function. They act as independent handlers of your information under their own privacy policies.

When you save changes to an event that has attendees, the attendees receive the update through the relevant calendar service. Lumi always asks you to confirm before sending such updates.

8.4 Content you share

Share cards and export files created by Lumi leave Lumi only when you choose to share or save them, and you choose the recipients. Share cards can hide sensitive numbers such as amounts and weight.

8.5 Disclosure required by law

We disclose personal information only when required by law, when needed to resolve litigation or disputes, or when a government or judicial authority makes a lawful request. We check the legal basis of each request, provide only what is necessary, and tell you when the law allows.

8.6 Mergers, acquisitions and transfers

If personal information must be transferred because of a merger, division, dissolution or bankruptcy, we will tell you the recipient’s name and contact details and require the recipient to keep the commitments in this policy. If the recipient changes the original purpose or method of processing, it must ask for your consent again.

8.7 Public disclosure

We do not make your personal information public unless you give separate consent or the law requires it.

9. Where your data is stored and international transfers

9.1 Where your data is stored today

Lumi currently has a single production environment. Its servers run in Amazon Web Services (AWS Lightsail) data centers in Tokyo, Japan. Your content — journals, documents, tasks, calendar, money, habits, goals, AI conversations and memories, and attachments — is stored in the database and file storage on these servers. The database, attachment files and feedback screenshots are periodically backed up on the production server in Tokyo, protected by access controls and retained on a rolling schedule. Amazon S3 off-site backups are not enabled. A copy on the same server does not cover loss of that server. This environment is Lumi’s “global region”.

9.2 Data regions

When you sign up, Lumi picks a data region based on your App Store region or system region, and you can switch it on the sign-in screen. After sign-up, your data region does not change automatically. A China region (data stored with Alibaba Cloud in mainland China, using only models filed in China) is in preparation. Until it launches, every account belongs to the global region.

9.3 Users in mainland China: transfer outside China

If you use Lumi in mainland China before our China region launches, your account information and everything you create and sync in Lumi are stored on servers in Tokyo, Japan. This is a transfer of personal information outside the People’s Republic of China. We ask for your separate consent to it before anything you create is uploaded.

Lumi determines whether you are in mainland China the same way as in section 6.9: from the country or region and the time zone your device reports to Lumi. For users in mainland China:

  • The first time you sign in, Lumi shows a separate consent screen that explains the items in the table below. Accounts created before this screen was introduced see it the next time they open Lumi.
  • Until you agree, nothing you create in Lumi is uploaded. Our servers hold only the account information needed to sign you in.
  • If you don’t agree, you can keep using Lumi on this device without an account (your data stays on the device), or sign out.
  • After agreeing, you can withdraw at any time by deleting your account in Settings (see section 12.5) or by emailing support@xicoai.com. We then stop syncing and delete your data from our servers through the account deletion process (see section 10 and Delete Your Account).
Item Details
Overseas recipient Amazon Web Services (AWS), as the hosting provider that operates our servers in Tokyo, Japan for us. The data is controlled by Zhixike Technology (Guangzhou) Co., Ltd.; AWS provides hosting only on our instructions
Contact support@xicoai.com (subject: “Personal Information Protection”)
Purpose Storing and syncing your data and providing the Lumi service
Method Transferred over HTTPS; stored in the database and file storage on our servers in Tokyo; backed up locally on the production server in Tokyo, protected by access controls and retained on a rolling schedule; Amazon S3 off-site backups are not enabled; used as described in this policy
Categories Account information (such as your email address, phone number, display name, profile photo and third-party account identifiers); everything you create and sync (tasks, calendar, journal including places you add, documents, money, habits, goals and plans, AI conversations and memories, attachments); device information and security records; purchase and subscription information. Financial information in Money, your phone number and location coordinates you add are sensitive personal information
Retention See section 10
How to exercise your rights View, export, correct and delete in the app, or email support@xicoai.com (subject: “Personal Information Protection”). See section 12

We carry out a personal information protection impact assessment as required by law, protect transferred data with measures such as encryption in transit and access control, and transfer data only under the conditions set by law. Once the China region launches, personal information of users in mainland China will be stored in China. For accounts created earlier in the global region, we will announce the migration arrangements in advance and ask for your consent where the law requires.

9.4 Users in other countries and regions

Global-region data is stored in Japan. Your information is also processed in other countries or regions when AI requests are handled by OpenAI or Anthropic (mainly in the United States) or by DeepSeek (in mainland China), when payments go through Stripe, and by the other providers in the Third-Party Sharing & SDK List.

For personal data from the European Economic Area, the United Kingdom and Switzerland: Japan is covered by an adequacy decision of the European Commission. For transfers to other countries without an adequacy decision, we use the European Commission’s Standard Contractual Clauses (SCCs) or another lawful transfer mechanism where the law requires.

10. How long we keep information

We keep personal information only for the shortest time needed for the purposes in this policy, unless the law requires otherwise.

Information Retention
Account information and your content For as long as your account exists; items you delete stay in Recently Deleted for 30 days and are then permanently deleted
Data after account deletion 7-day cooling-off period after you request deletion; then every database record about your account (including content, vectors, AI memories, devices and sessions, activity records and AI usage metering), attachment files, data export archives and feedback screenshots are deleted, your calendar integrations’ authorizations are revoked, and Lumi’s Sign in with Apple authorization is revoked at Apple
Backups Local backups expire on the rolling retention schedule; deleted data can remain until the corresponding backup expires
Bill files Read on your device and never uploaded to our servers
Calendar and task integration sync data Deleted when you disconnect; you can keep content already imported
Data export archives Kept for 24 hours after they are created, then deleted
Server access and error logs Deleted after 14 days
Security records You can see the last 90 days; deleted after about 13 months
Purchase and transaction records Kept while your account exists and deleted with your account; payment providers such as Apple and Stripe keep their own records under their policies
Support conversations Deleted once the issue is resolved and no follow-up is needed, and in any case when your account is deleted
Connected and forwarded mail Default cleanup: raw messages after 7 days (waiting or ongoing processing can last longer); inbox history after 90 days once raw mail is removed. Confirmation cards, attachment copies and saved records follow normal content retention. Disconnecting does not automatically delete them. Both periods are measured from receipt by Lumi.

When a retention period ends, we delete or anonymize the information. Where immediate deletion is technically impractical (for example, in backups that have not yet expired), we stop all processing other than storage and necessary security measures.

If Lumi ever shuts down, we will stop collecting personal information, tell you individually or by public notice, give you time to export your data, and then delete or anonymize your personal information.

11. How we protect your information

  • Encryption in transit: all connections use HTTPS (TLS 1.2 / 1.3) with HSTS.
  • How your content is stored: your content (journals, documents, tasks, calendar, money, habits, goals, AI conversations and memories, and attachments) is stored in the database and file storage on our servers in Tokyo, Japan (AWS). It has no additional application-layer encryption and no end-to-end encryption; the access controls described below protect it.
  • Mail storage: Original messages (including embedded attachments) and inbox metadata are encrypted with a key unique to each user, as are mailbox OAuth tokens and IMAP authorization codes or app passwords. The server decrypts them to provide the feature; this is not end-to-end encryption. Confirmation cards, saved records and separately stored attachment copies use the normal content storage described above.
  • Backups: the database, attachment files and feedback screenshots are periodically backed up locally on the production server in Tokyo, protected by access controls and retained on a rolling schedule. Amazon S3 off-site backups are not enabled. A copy on the same server does not cover loss of that server.
  • Encrypted credentials: third-party authorizations — Google and Microsoft calendar tokens, iCloud app-specific passwords and Sign in with Apple tokens — are envelope-encrypted with AES-256-GCM under a key unique to you, and the master key that protects those keys is kept outside the database. Deleting your account destroys your key. Passwords are stored only as salted scrypt hashes, and administrators’ two-factor secrets are encrypted too.
  • Staff access: the admin console has no screen that shows users’ content (journals, documents, tasks, transactions, AI conversations) and no “sign in as user” feature. Staff see only account details, subscription and billing information, usage counts, and feedback you choose to send us. The console requires two-factor authentication, and every staff action is audit-logged. Direct access to our servers and database is limited to a small number of authorized engineers using key-based login.
  • Account protection: rate limits on codes and sign-ins, protection against suspicious sign-ins, and alerts for sign-ins from new devices. You can sign out any device remotely from your device list.
  • On-device protection: in the Apple apps you can lock a journal so that opening it requires Face ID, Touch ID or your device passcode. In the web app, signing out deletes the local data stored in that browser.
  • Minimal logging: server access logs keep only a truncated IP address, never the user agent or query strings, and are deleted after 14 days; security records store IP addresses and user agents only as salted hashes. Application logs never contain your content or plain-text email addresses, phone numbers, codes or tokens.
  • Ongoing testing: independent penetration tests before launch and every year after; personal information protection impact assessments for AI processing and sensitive personal information.

If a security incident such as a personal data breach occurs, we will act immediately to contain and investigate it, report it to the authorities as the law requires (under the GDPR, to the supervisory authority within 72 hours), and notify you if you are affected, by in-app notice, email or text message, explaining what happened, the likely impact, what we have done, and what you can do to protect yourself.

No system is perfectly secure. Please keep your sign-in methods safe, never share verification codes, and contact us right away if you notice anything unusual in your account. See our Security page for more.

12. Your rights

12.1 Access and copy

You can see all of your content in Lumi at any time. In the web app under Settings → Privacy & Data → Export all data, or in the Apple apps under Settings → Account & Security → Export my data, you can export your data for free: structured data as JSON, journal entries and documents as Markdown and money transactions as CSV, packaged in one zip file that you can download for 24 hours after it is created. Attachment files such as photos are not included in the archive for now; the Markdown files link to them. AI-generated content in the archive is labeled (see section 6.8).

12.2 Correction

You can edit all of your content and account details directly in Lumi, and you can edit or delete Lumi’s memories.

12.3 Deletion

You can delete any content at any time. You can also ask us to delete your personal information if the purpose of processing has been achieved, cannot be achieved or is no longer needed; if we stop providing the service or the retention period has expired; if you withdraw consent; or if we process it in violation of the law or our agreement with you.

12.4 Withdrawing consent

You can withdraw consent at any time. The related processing stops immediately, although processing already carried out based on your consent is not affected:

  • cloud AI: withdraw your cloud AI consent in Lumi’s settings; by module: Settings → Lumi;
  • health data (arriving with the iPhone and iPad apps): iOS Settings → Privacy & Security → Health, or turn off uploads and AI access in Lumi and optionally delete data already uploaded;
  • location, notifications, calendars, reminders and other permissions: in your system or browser settings; “Keep photo locations”: turn it off in the journal’s photo menu;
  • integrations: disconnect them in Settings;
  • transfer of personal information outside mainland China: see section 9.3.

12.5 Deleting your account

You can delete your account in the Apple apps under Settings → Account & Security → Delete Account, or in the web app (/app/) under Settings → Privacy & Data → Delete account. There is a 7-day cooling-off period; sign in again during that time to cancel the deletion and restore your account. After 7 days, we delete every database record about your account, your attachment files, data export archives and feedback screenshots, and they cannot be recovered. We also revoke the authorizations of your calendar integrations (Google’s at Google; Microsoft tokens are deleted) and revoke Lumi’s Sign in with Apple authorization at Apple. Data in local backups is deleted when the corresponding backups expire on the rolling retention schedule. Any remaining membership time and purchased tokens are forfeited unless the law says otherwise. Deleting your account does not cancel an App Store subscription; please cancel it in Apple’s subscription settings. See Delete Your Account.

12.6 Portability

Exports use common formats so you can take your data elsewhere. Where the conditions set by China’s cyberspace authority are met, you can ask us to transfer your personal information to another handler you designate.

12.7 Explanation

You have the right to ask us to explain the processing rules in this policy.

12.8 Deceased users

After a user dies, their close relatives may, for their own lawful and legitimate interests, exercise the rights in this section, such as access, copying, correction and deletion, over the deceased’s personal information, unless the deceased arranged otherwise.

12.9 How to make a request

You can exercise most rights directly in the app. You can also email support@xicoai.com (subject: “Personal Information Protection”). To protect your account, we first verify your identity, for example by asking you to write from the email address linked to your account or to confirm while signed in. We reply within 15 working days after verifying your identity; for requests under the GDPR, within 30 days. For complex requests we may extend this as the law allows and will tell you why.

We normally handle requests free of charge. We may refuse requests that are unreasonably repetitive, clearly abusive, would harm the lawful rights of others, or relate directly to national security, public safety or criminal investigations, as the law permits. If we refuse, we will explain why and tell you how you can seek a remedy.

13. Children’s personal information

Lumi is not directed to children. In mainland China you must be at least 14 to create an account; elsewhere you must be at least 13, or older where local law requires (for example 16 in some EU countries). Users under 18 should use Lumi with a parent’s or guardian’s consent and guidance, and AI features are only for users aged 18 or older. If we learn that we have collected a child’s personal information without verifiable parental consent, we will delete it promptly. See Children’s Privacy.

14. Google user data

Lumi’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can read the Google API Services User Data Policy on Google’s website.

The Google data we access. When you sign in with Google, we receive your Google account ID, name, email address and profile photo. When you connect Google Calendar, we read your calendar list, and read, create, update and delete events.

How we use it. Connected Google Calendar data is used only to provide the calendar features you turn on: showing your Google Calendar events in Lumi, creating or changing events at your request, and keeping both sides in sync. If you have allowed AI access to the calendar module, relevant events may be sent to the AI providers listed in section 6.4 when you use an AI feature (such as “Plan my day”), solely to produce the result you asked for; providers may not use them to train models.

Our commitments. These commitments also cover data derived from Google user data:

  • not used for advertising, including personalized, retargeted or interest-based advertising;
  • not sold;
  • not used to develop, improve or train any AI or machine-learning model, generalized or otherwise;
  • not read by any human unless you have given explicit permission, it is necessary for security purposes (such as investigating abuse), or it is required by law.

You can also remove Lumi’s access on your Google Account permissions page.

Gmail

Google’s read-only Gmail permission can view messages and settings. Lumi limits its actual access to INBOX messages and the mailbox address, without modifying Gmail. Lumi reads your email address and INBOX senders, subjects, message text and attachments to show mail and propose tasks, calendar entries and money records. The first import covers the last 7 days; later syncs catch up on missed mail. Lumi does not send, mark as read, change or delete Gmail messages.

Credentials, original messages and inbox metadata are encrypted with a key unique to you on Lumi’s servers in Tokyo, Japan. The server decrypts them to provide this feature; this is not end-to-end encryption. Raw mail is normally removed 7 days after Lumi receives it (pending processing can last longer); inbox history is removed after 90 days from receipt when raw mail is already removed. Confirmation cards, attachment copies and saved records use Lumi’s normal content storage and retention.

Connecting Gmail does not enable AI or trust senders. Optional AI recognition runs only when your cloud AI consent and separate email permission are already active. Necessary mail text and image attachments may then be sent to the model providers listed in the Privacy Policy. We and these providers do not use this data or derived data to train models. Records need your confirmation.

Disconnect in Settings to stop new reads and remove saved credentials. Imported mail and saved records remain. Delete mail in Lumi’s inbox; delete confirmed records in their module. These actions do not delete the original Gmail message.

15. Apple platforms

  • Sign in with Apple: we receive your Apple user ID and the name and email address you choose to share (or Apple’s relay address). When you delete your Lumi account, or remove Sign in with Apple as a sign-in method in Settings → Account & Security, we revoke Lumi’s authorization at Apple.
  • Health data: handled under the rules in section 5.1 and never shared with any third party, except with AI providers when you have given separate consent.
  • Journaling Suggestions: the system picker gives Lumi only the suggestion you choose; Lumi cannot browse your photo library or location history.
  • In-App Purchase: Apple handles payments and refunds; we receive only transaction information.
  • Widgets and Spotlight: widgets show the content you choose on your Home Screen or Lock Screen. Spotlight indexes only the titles of tasks, documents and journal entries, on your device, never their content, and you can turn it off in iOS Settings.
  • No tracking: Lumi does not “track” you as the App Store defines it, so it never asks for tracking permission. Our App Store privacy labels match what Lumi actually does and are reviewed with every release.

16. California residents

This section provides the additional disclosures required by the California Consumer Privacy Act, as amended by the CPRA, to the extent it applies.

Categories of personal information we collect. In the past 12 months and going forward, we collect the following categories from you, your devices and the services you connect, for the purposes described in section 4:

  • identifiers: name, email address, phone number, account IDs, device identifiers and IP address;
  • customer records and commercial information: purchase and subscription records;
  • internet or other electronic network activity: daily activity records, AI usage metering and logs;
  • geolocation data: location coordinates you add to journal entries yourself;
  • inferences: memories and the life snapshot Lumi builds, used only to provide the service to you;
  • sensitive personal information: account log-in credentials, financial account information, precise geolocation you add yourself, and the journal entries, documents and conversations you store in Lumi; once the Apple Health features arrive, also the health information you allow Lumi to read.

We don’t sell or “share” personal information. We do not sell your personal information or share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16. We use sensitive personal information only for purposes the law permits, such as providing the services you request and keeping them secure, so there is no need for a “Limit the Use of My Sensitive Personal Information” option. We treat Global Privacy Control (GPC) signals as a valid opt-out request.

Your rights. You have the right to know and access the personal information we collect, to request deletion, to request correction, to receive your data in a portable format, and not to be discriminated against for exercising these rights. You can make a request as described in section 12.9 or through an authorized agent; we will verify your identity and the agent’s authority. We do not disclose personal information to third parties for their direct marketing purposes.

17. Users in the EEA, the UK and Switzerland

  • Controller: Zhixike Technology (Guangzhou) Co., Ltd.; contact details in section 20.
  • Legal bases: performance of a contract, your consent, our legitimate interests (security, abuse prevention, and counting activity to run and improve the service), legal obligations, and protecting your vital interests. See section 4.
  • Your rights: access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interests (including daily activity statistics), and withdrawing consent at any time. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. You also have the right to lodge a complaint with the data protection authority where you live or work, or where you believe an infringement took place.
  • International transfers: see section 9.4.
  • Representative: where the law requires, we will appoint representatives in the EU and the UK and publish their contact details in this policy.
  • Age: the age of digital consent varies between 13 and 16 across member states; see section 13.

18. Other countries and regions

If the law where you live gives you additional rights over your personal information, we will honor them as that law requires. You can contact us as described in section 12.9.

19. Changes to this policy

We may update this policy when our services change or the law requires. For material changes, we will tell you before they take effect through a prominent in-app notice, pop-up or email, and where the law requires, we will ask for your consent again. We will not reduce your rights under this policy without your explicit consent.

Material changes include, for example: a significant change in how our service works (such as the purposes, types or methods of processing personal information); significant changes in our ownership or organization; a change in the main recipients of shared, transferred or publicly disclosed personal information; significant changes in your rights or how to exercise them; changes in our privacy contact or complaint channels; and a personal information protection impact assessment that identifies a high risk.

The top of this page shows the current version, effective date and last-updated date. You can request earlier versions of this policy from support@xicoai.com.

20. Contact us

  • Email: support@xicoai.com. For privacy requests, please put “Personal Information Protection” in the subject line so your email goes to the person responsible for personal information protection.
  • Operator: Zhixike Technology (Guangzhou) Co., Ltd.
  • Registered address: Rm 215A, Rm 410, 4/F, Bldg 1, No. 19 Guangsheng Rd, Nansha, Guangzhou, Guangdong, China

We reply within 15 working days after verifying your identity (within 30 days for requests under the GDPR). If you are not satisfied with our reply, or believe our processing has harmed your rights, you can complain to the competent authorities (in mainland China, for example, the cyberspace, telecommunications, public security or market regulation authorities; in the EEA, the UK and Switzerland, your data protection authority). You can also bring a claim before the competent people's court at the defendant's domicile. This policy is governed by the laws of the People's Republic of China (for the purposes of these terms, excluding Hong Kong, Macao and Taiwan), without affecting any rights you have under the mandatory laws of the place where you live.