Third-Party Sharing & SDK List

Every third-party provider and SDK Lumi uses, with what each one does, what it receives, why, where it processes data, and which are not in use yet.

Version
1.1
Effective
Last updated

This list is part of our Privacy Policy. It names the third-party providers that process your personal information so we can run Lumi, and the third-party SDKs built into Lumi’s Apple apps. For what Lumi collects, see the Personal Information Collection List.

1. Our commitments

  • We don’t sell your personal information or share it with advertisers. Lumi has no ads.
  • Only what’s necessary: each provider receives only what it needs to do its job. Before anything is sent to an AI model, phone numbers, email addresses, ID numbers and card numbers are masked.
  • Bound by contract: every provider that processes personal information on our behalf has signed an agreement with us requiring it to follow our instructions, use the information only for the agreed purpose, protect it with appropriate security, and delete or return it when the engagement ends. AI providers may not train on your data and must keep it for the shortest possible time.
  • Changes are reviewed: adding or replacing a provider requires a privacy review first, and this list is updated at the same time. For material changes, we notify you as described in the Privacy Policy.

In the tables, “in preparation” means a service for the China region, which has not launched yet. “Not in use yet” means we don’t use the service today and none of your information is sent to it; we will update this list before we start using it.

2. Cloud hosting and infrastructure

Provider Service Information shared Purpose Where processed Region / when used Privacy policy
Amazon Web Services (AWS Lightsail) Servers, database, file storage; local production-server backups (Amazon S3 off-site backups are not enabled) All of your Lumi data Run the Lumi service, disaster recovery Tokyo, Japan Global region (currently the only production environment) aws.amazon.com/privacy
Alibaba Cloud Computing Co., Ltd. (Alibaba Cloud) Servers, database, object storage All Lumi data of China-region users Run the China-region service Mainland China China region (in preparation) See the provider’s website
Cloudflare Content delivery network and attack protection IP address, request information Faster access, defense against attacks Cloudflare’s global network Not in use yet cloudflare.com/privacypolicy

3. AI model providers

Lumi sends data to these providers only after you agree to AI processing. Which one handles a request depends on your data region, where you are, the model you choose and the type of task. AI requests from users in mainland China are handled only by DeepSeek. See section 6 of the Privacy Policy.

Provider Service Information shared Purpose Where processed Region / when used Privacy policy
Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd. (DeepSeek) Large language models The question and context needed for the task (masked) Answers, briefings, plans and insights Mainland China Primary model in the China region; in the global region, the only model for users in mainland China, Hong Kong and Macau See the provider’s website
Alibaba Cloud Computing Co., Ltd. (Alibaba Cloud Bailian, Qwen) Large language models (backup), text embeddings Question and context (masked); allowed content to be embedded Backup model, semantic search Mainland China China region (in preparation) See the provider’s website
OpenAI Large language models Question and context (masked) Answers Mainly the United States Global region (not for users in mainland China, Hong Kong or Macau) openai.com/policies/privacy-policy
Anthropic (Claude) Large language models Question and context (masked) Answers, plans and insights Mainly the United States Global region, once we confirm we meet its eligibility requirements (not for users in mainland China, Hong Kong or Macau) anthropic.com/legal/privacy
Apple (on-device models and Private Cloud Compute) Light AI tasks The content the task needs Light tasks such as quick-capture parsing and journal tagging, with no tokens used Your device or Apple’s servers Not in use yet apple.com/legal/privacy
Alibaba Cloud Computing Co., Ltd. (content security service) AI content safety review AI inputs and outputs Meet legal content-safety obligations for generative AI Mainland China China region (in preparation) See the provider’s website

Lumi has no voice transcription or web search today, so no recordings or search queries are sent to any provider. We will list the services involved here before those features launch. In the global region, text embeddings are generated on our own servers and are not sent to any third party.

Mail text and image attachments are sent only as needed to the actually enabled model providers above, and only while cloud AI consent and separate email permission are both active. Connecting a mailbox does not grant AI access.

4. Sign-in

Provider Service Information shared Purpose Where processed Region / when used Privacy policy
Apple Sign in with Apple Sign-in request; Apple returns your user ID, an authorization token and the name and email you choose to share. When you delete your account or remove this sign-in method, we send Apple a request to revoke Lumi’s authorization Verify your identity, sign you in, revoke authorization Apple’s servers When you choose Sign in with Apple apple.com/legal/privacy
Google Sign in with Google Sign-in request; Google returns your account ID, name, email and profile photo Verify your identity, sign you in Google’s servers When you choose Google sign-in (global region) policies.google.com/privacy
Shenzhen Tencent Computer Systems Co., Ltd. (WeChat, QQ) WeChat and QQ sign-in Sign-in request; Tencent returns your unionid / openid and nickname Verify your identity, sign you in Mainland China When you choose WeChat or QQ sign-in See the provider’s website

5. Calendar, task and mailbox integrations

Provider Service Information shared Purpose Where processed Region / when used Privacy policy
Google Google Calendar Events you create or change in Lumi; authorization token Two-way sync with Google Calendar Google’s servers When you connect Google Calendar (global region) policies.google.com/privacy
Google Read-only Gmail connection Authorization requests and tokens; Google returns the mailbox address and INBOX messages (senders, subjects, text and attachments) to Lumi Show mail and propose records for confirmation; no sending or modifying Gmail messages Google’s servers; see the Privacy Policy for Lumi storage When you separately connect Gmail, subject to actual availability policies.google.com/privacy
Microsoft Outlook Calendar and Microsoft To Do (Microsoft Graph) Events and tasks you create or change in Lumi; authorization token Two-way sync with Microsoft services Microsoft’s servers When you connect a Microsoft account privacy.microsoft.com/privacystatement
Apple iCloud Calendar server sync (CalDAV, coming later) Apple Account email and app-specific password; events you create or change Sync iCloud Calendar directly on the web Apple’s servers When you connect it by following the guide apple.com/legal/privacy

On Apple devices, Apple Calendar, Reminders and Health data will be read and written on your device through system interfaces, and Lumi will send nothing extra to Apple for this.

6. Payments

Provider Service Information shared Purpose Where processed Region / when used Privacy policy
Apple In-App Purchase Product and transaction information; you give your payment details directly to Apple Complete purchases, renewals and refunds Apple’s servers Purchases in the Apple apps apple.com/legal/privacy
Stripe Web payments (cards, Apple Pay, Google Pay) and subscription management Order details, product, amount, currency, email; you give your payment details directly to Stripe Take payment, manage subscriptions, send receipts The United States and other locations Web purchases in the global region stripe.com/privacy
Tenpay Payment Technology Co., Ltd. (WeChat Pay) Web payments Order details, product, amount Take payment Mainland China Not in use yet See the provider’s website
Alipay (China) Internet Technology Co., Ltd. Web payments Order details, product, amount Take payment Mainland China Not in use yet See the provider’s website

We never receive or store your full card number, payment password or other payment credentials.

7. Text messages, email and push notifications

Provider Service Information shared Purpose Where processed Region / when used Privacy policy
Alibaba Cloud Computing Co., Ltd. (SMS service) Text messages Phone number, verification code Send sign-in and security codes Mainland China When you sign in or verify with a +86 number See the provider’s website
Tencent Exmail or Amazon SES Email delivery (one of the two is enabled) Email address; email content such as codes, security alerts and renewal notices Send service emails Tencent Exmail: mainland China; Amazon SES: AWS servers When we send service emails Tencent: see the provider’s website; AWS: aws.amazon.com/privacy
Apple Push Notification service (APNs) Push notifications Push token, notification content Deliver notifications to your Apple devices Apple’s servers Not in use yet apple.com/legal/privacy
Browser push services (such as Google, Apple, Mozilla and Microsoft) Web push Push subscription endpoint, encrypted notification content Deliver notifications to your browser Depends on your browser Not in use yet See your browser vendor’s privacy policy

Today, habit reminders in the web app are shown locally by your browser while Lumi is open, and habit reminders in the Apple apps are scheduled locally on your device; neither goes through a push service.

8. Maps and weather

Provider Service Information shared Purpose Where processed Region / when used Privacy policy
Apple (MapKit, WeatherKit) Maps, place search, weather Location coordinates, place search terms Show places and local weather Apple’s servers Not in use yet apple.com/legal/privacy

Lumi does not use any third-party map or weather service today. “Use current location” in the web app relies on your browser’s built-in location feature and reads your location only once, when you tap it.

9. Monitoring and analytics

Provider Service Information shared Purpose Where processed Region / when used Privacy policy
Sentry (Functional Software, Inc.) Crash and error reports Stack traces, device model, system and app versions, a de-identified user identifier; no content Find and fix problems Sentry’s cloud or our own self-hosted servers Not in use yet sentry.io/privacy
PostHog, Inc. Product analytics Feature usage events, a de-identified user identifier, device and version; no content Understand how features are used and improve Lumi PostHog’s cloud or our own self-hosted servers Not in use yet posthog.com/privacy
Langfuse (self-hosted) AI call tracing Would run on our own servers and send nothing to the Langfuse company Investigate AI quality and cost issues Our servers Not in use yet Not applicable

Lumi does not use a third-party monitoring, crash-reporting or product-analytics service today. Our own servers record daily activity, AI usage and basic stability diagnostics that users choose to enable, without their content. The Apple app uses system MetricKit and sends only exception categories to Lumi, without uploading raw reports; see section 3.7 of the Privacy Policy. Before we start using any of the services above, we will update this list and the Privacy Policy, announce the change, and give you a switch in Settings to turn it off.

10. Third-party SDKs

Today, Lumi’s iPhone, iPad and Mac apps include exactly one third-party library: GRDB, an open-source local database that runs only on your device and neither collects nor sends any information. The web app includes no third-party SDKs. The table below lists SDKs we plan to add but have not integrated:

SDK Provider Purpose Information collected When it is active Privacy policy
WeChat OpenSDK Shenzhen Tencent Computer Systems Co., Ltd. WeChat sign-in Sends the authorization request to WeChat and receives the authorization code; any information the SDK itself collects is described in Tencent’s published personal information rules Not integrated yet; once integrated, called only when you tap WeChat sign-in See the provider’s website
Sentry SDK Functional Software, Inc. (Sentry) Crash and error reports Stack traces, device model, system and app versions and app state at the time of a crash; no content Not integrated yet; we will update this list first sentry.io/privacy
PostHog SDK PostHog, Inc. Product analytics Feature usage events, a de-identified user identifier, device model, system and app versions; no content Not integrated yet; we will update this list first and give you a switch to turn it off posthog.com/privacy

In the Apple apps, Google sign-in runs in the system’s web authentication session, with no Google SDK embedded, and WeChat and QQ sign-in currently use web authorization, with no Tencent SDK embedded. Before adding any new SDK, we will complete a privacy review and update this list.

For transparency, the table below lists the Apple system frameworks Lumi’s Apple apps use or plan to use. They are part of the operating system, not third-party SDKs, and any that need permission ask for your consent first.

System framework Used for
AuthenticationServices Sign in with Apple; web-based sign-in (Google, WeChat, QQ)
StoreKit In-App Purchase and subscription management
JournalingSuggestions The system Journaling Suggestions picker
PhotosUI The system photo picker
UserNotifications Habit reminders scheduled locally on your device
LocalAuthentication Journal lock (Face ID, Touch ID or device passcode, verified only on your device)
EventKit (not in use yet) Reading and writing Apple Calendar and Reminders
HealthKit (not in use yet) Reading health data and saving State of Mind
Speech (not in use yet) On-device speech-to-text
Foundation Models (not in use yet) Apple on-device models and Private Cloud Compute
Core Location, MapKit, WeatherKit (not in use yet) Location, maps and weather

11. Third-party services you choose to connect

When you sign in with Apple, Google, WeChat or QQ, connect Google or Microsoft calendars and tasks, or pay through Apple or Stripe, those services are also independent handlers of your information and process what you hold with them under their own privacy policies. You can unlink a sign-in method in Lumi under Settings → Account & Security, disconnect an integration in Settings, or revoke Lumi’s access in that service’s account settings.

12. Updates to this list

We review this list before every major release. Adding, replacing or retiring a provider always goes through privacy review and updates this page. For material changes to who receives your information, what they receive or where it is processed, we will notify you in advance as described in the Privacy Policy and ask for your consent again where needed. Questions about this list are welcome at support@xicoai.com with “Personal Information Protection” in the subject line.