Privacy & Security
Trust is
Lumi’s foundation.
You trust Lumi with the most private parts of a life. A single breach could end that trust — so protection is built into the product from the first line of code.
Five principles
- 1
Private by default, minimal by design
We collect only what a feature needs: no analytics or crash-reporting SDKs, photo files lose their location data before they’re stored, and a place is saved only when you add it yourself. Nothing is public, shared or used for training by default.
- 2
Your data is yours
View, export, correct or delete it any time; withdrawing consent takes effect immediately.
- 3
No ads, ever
We don’t sell personal information or track you across apps and websites.
- 4
Defense in depth
Transport, storage, application, access and operations each have their own safeguards.
- 5
Compliance up front
Filings, registrations and assessments run alongside development, not at the last minute.
How we protect your data
-
Encrypted in transit
HTTPS everywhere (TLS 1.2 / 1.3) with HSTS.
-
Storage and backups
Your content lives in the database and file storage on our servers in Tokyo (AWS). It has no additional application-layer or end-to-end encryption; strict access controls protect it. The database, attachments and feedback screenshots are periodically backed up on the production server in Tokyo, protected by access controls and retained on a rolling schedule. Amazon S3 off-site backups are not enabled. A copy on the same server does not cover loss of that server.
-
Credentials encrypted separately
Calendar authorization tokens, iCloud app-specific passwords and Sign in with Apple tokens are encrypted with AES-256-GCM under a key unique to you, and the master key protecting those keys is kept outside the database. Deleting your account destroys your key. Passwords are stored only as salted scrypt hashes.
-
Our tools can’t show your content
The admin console has no screen that shows journals, docs, tasks, transactions or AI chats — only account details, subscriptions, usage counts and feedback you choose to send. Signing in requires two-factor authentication, and every action is audit-logged. Direct server and database access is limited to a few authorized engineers using key-based login.
-
Logs without content
Web server access logs keep only a truncated IP address (IPv4 /24, IPv6 /48), with no user agent or query strings, and are deleted after 14 days. Security records such as sign-ins store IP and user agent only as salted hashes. Application logs never contain your content.
-
Sessions and devices
Short-lived access tokens and device-bound refresh tokens. Sign out any device remotely, and get notified about new sign-ins.
Protection by sensitivity
| Level | Data | Protection |
|---|---|---|
| Most sensitive content | Journals, docs, AI chats and memories, life blueprint, growth plans | No admin screen shows it; AI access by module permission; never in logs |
| Sensitive personal information | Financial accounts and transactions, phone number, sign-in credentials and third-party authorizations | Passwords kept only as salted hashes; third-party authorizations encrypted with your own key; masked before reaching AI |
| Personal information | Nickname, email, birthday, time zone, device info | Encrypted in transit; admin access audit-logged |
| General data | Settings, preferences, daily activity records | Standard protection |
Where your data lives
Lumi’s servers, database and file storage currently run in Tokyo, Japan (Amazon Web Services), and current backups are kept locally on the production server on a rolling schedule. Amazon S3 off-site backups are not enabled. A mainland-China data region is being prepared; once it launches, mainland users’ data will be stored in China. Until then, if you use Lumi in mainland China your data is stored in Japan: we ask for your separate consent before anything you create is uploaded, and AI requests are handled only by DeepSeek, a domestically filed model, with a keyword content filter.
AI and your data
- Explained and consented to before cloud AI is first used
- Permission by module; exclude any single entry
- Phone numbers, emails, ID and card numbers masked before reaching a model
- Providers are contractually barred from training, with minimal retention
- AI memory you can view, edit and delete
You’re in control
-
Export your data
JSON, Markdown and CSV in one download — free plan included.
-
Recently Deleted
Restore anything deleted in the last 30 days.
-
Delete your account
After a 7-day cooling-off, all data and files are deleted and calendar and Sign in with Apple authorizations are revoked; data in local backups is deleted when the corresponding backups expire on the rolling retention schedule.
Incidents and vulnerability reports
If an incident happens, we contain it, investigate, and notify authorities and affected users as the law requires. We commission third-party penetration tests before launch and every year after. Found a security issue? Email support@xicoai.com with “Security” in the subject — we take every report seriously.
Start today.
Make every week count.
Lumi for the web is open in early access. The iPhone, iPad and Mac apps are being polished and are coming soon to the App Store.