Privacy & Security

Trust is
Lumi’s foundation.

You trust Lumi with the most private parts of a life. A single breach could end that trust — so protection is built into the product from the first line of code.

Five principles

  1. 1

    Private by default, minimal by design

    We collect only what a feature needs: no analytics or crash-reporting SDKs, photo files lose their location data before they’re stored, and a place is saved only when you add it yourself. Nothing is public, shared or used for training by default.

  2. 2

    Your data is yours

    View, export, correct or delete it any time; withdrawing consent takes effect immediately.

  3. 3

    No ads, ever

    We don’t sell personal information or track you across apps and websites.

  4. 4

    Defense in depth

    Transport, storage, application, access and operations each have their own safeguards.

  5. 5

    Compliance up front

    Filings, registrations and assessments run alongside development, not at the last minute.

How we protect your data

  • Encrypted in transit

    HTTPS everywhere (TLS 1.2 / 1.3) with HSTS.

  • Storage and backups

    Your content lives in the database and file storage on our servers in Tokyo (AWS). It has no additional application-layer or end-to-end encryption; strict access controls protect it. The database, attachments and feedback screenshots are periodically backed up on the production server in Tokyo, protected by access controls and retained on a rolling schedule. Amazon S3 off-site backups are not enabled. A copy on the same server does not cover loss of that server.

  • Credentials encrypted separately

    Calendar authorization tokens, iCloud app-specific passwords and Sign in with Apple tokens are encrypted with AES-256-GCM under a key unique to you, and the master key protecting those keys is kept outside the database. Deleting your account destroys your key. Passwords are stored only as salted scrypt hashes.

  • Our tools can’t show your content

    The admin console has no screen that shows journals, docs, tasks, transactions or AI chats — only account details, subscriptions, usage counts and feedback you choose to send. Signing in requires two-factor authentication, and every action is audit-logged. Direct server and database access is limited to a few authorized engineers using key-based login.

  • Logs without content

    Web server access logs keep only a truncated IP address (IPv4 /24, IPv6 /48), with no user agent or query strings, and are deleted after 14 days. Security records such as sign-ins store IP and user agent only as salted hashes. Application logs never contain your content.

  • Sessions and devices

    Short-lived access tokens and device-bound refresh tokens. Sign out any device remotely, and get notified about new sign-ins.

Protection by sensitivity

LevelDataProtection
Most sensitive content Journals, docs, AI chats and memories, life blueprint, growth plans No admin screen shows it; AI access by module permission; never in logs
Sensitive personal information Financial accounts and transactions, phone number, sign-in credentials and third-party authorizations Passwords kept only as salted hashes; third-party authorizations encrypted with your own key; masked before reaching AI
Personal information Nickname, email, birthday, time zone, device info Encrypted in transit; admin access audit-logged
General data Settings, preferences, daily activity records Standard protection

Where your data lives

Lumi’s servers, database and file storage currently run in Tokyo, Japan (Amazon Web Services), and current backups are kept locally on the production server on a rolling schedule. Amazon S3 off-site backups are not enabled. A mainland-China data region is being prepared; once it launches, mainland users’ data will be stored in China. Until then, if you use Lumi in mainland China your data is stored in Japan: we ask for your separate consent before anything you create is uploaded, and AI requests are handled only by DeepSeek, a domestically filed model, with a keyword content filter.

AI and your data

  • Explained and consented to before cloud AI is first used
  • Permission by module; exclude any single entry
  • Phone numbers, emails, ID and card numbers masked before reaching a model
  • Providers are contractually barred from training, with minimal retention
  • AI memory you can view, edit and delete
About Lumi AI

You’re in control

  • Export your data

    JSON, Markdown and CSV in one download — free plan included.

  • Recently Deleted

    Restore anything deleted in the last 30 days.

  • Delete your account

    After a 7-day cooling-off, all data and files are deleted and calendar and Sign in with Apple authorizations are revoked; data in local backups is deleted when the corresponding backups expire on the rolling retention schedule.

Incidents and vulnerability reports

If an incident happens, we contain it, investigate, and notify authorities and affected users as the law requires. We commission third-party penetration tests before launch and every year after. Found a security issue? Email support@xicoai.com with “Security” in the subject — we take every report seriously.

Start today.
Make every week count.

Lumi for the web is open in early access. The iPhone, iPad and Mac apps are being polished and are coming soon to the App Store.