Privacy Policy

Effective date: July 24, 2026

Lumis is a local-first AI face analysis and glow-up coach app for iPhone. This policy explains what stays on your device, what is sent for AI analysis and purchases, and how to control or delete your data. Lumis scores and insights are AI-generated estimates for entertainment and self-improvement only, and are not medical, dermatological, or psychological advice.

1. Overview

This Privacy Policy applies to the Lumis mobile app for iOS (iPhone), its AI analysis service, Pro purchase features, and public support pages. Lumis requires iOS 16 or later.

Lumis lets you take a selfie and receive AI scores from 0 to 10 across five categories — jawline, skin, symmetry, eyes, and harmony — plus an overall score and a "potential" score. It then builds a personalized rolling 28-day Glow-Up Plan of skincare, body, habit, and face-exercise tasks with daily check-offs and streaks, a progress timeline with score charts and scan comparisons, and an optional local daily reminder.

Lumis does not create user accounts and does not operate a cloud history database for your scans. The app stores your scans, photos, plan, progress, quiz answers, and settings locally on your device. When you start a scan, your selfie and a small amount of request information are sent transiently to Lumis backend services and Google Gemini so the analysis can be generated.

Lumis scores and insights are AI-generated estimates for entertainment and self-improvement purposes only. Lumis is not a diagnostic tool and does not provide medical, dermatological, or psychological advice. Consult a dermatologist or doctor for skin or health concerns. AI results can be inaccurate or vary between scans.

2. Short Summary

Accounts Lumis does not require account creation, login, or an email address.
Ads and tracking Lumis shows no third-party ads and includes no analytics or tracking SDKs. It does not track you across apps or websites.
Local app data Scans, captured photos, scores, your 28-day plan, progress history, streaks, quiz answers, and settings are stored only on your device.
AI provider Lumis uses the Google Gemini API through a stateless Cloudflare Worker to generate scores and plans from your selfie.
Payments Apple processes App Store payments. RevenueCat manages the Lumis Pro entitlement and receives purchase and entitlement information, not your identity.
Deletion Settings → "Delete All My Data" permanently wipes everything on-device and rotates the install ID. Deleting the app also removes local data.

3. Information Stored Locally on Your Device

Lumis is local-first, so the app can work without an account. Your data is stored on-device: captured photos in the app's Documents area, and structured data as JSON in Application Support. Local data can include:

  • Onboarding status and your quiz answers, such as gender, age range, goal, and skincare level.
  • Your selfie photos, including the optional side-profile photo, kept on-device.
  • Scan results, including category scores, overall and potential scores, and generated insights.
  • Your rolling 28-day Glow-Up Plan, daily task check-offs, and streaks.
  • Progress history, score charts, and scan comparisons over time.
  • App settings, including your daily reminder preference.
  • A random install identifier (UUID) used only for rate limiting, which is rotated when you delete all data.

If you uninstall Lumis, iOS normally removes the app's local data. Device backups controlled by Apple or your device settings may include local app data.

4. Camera and Photo Library Access

Lumis may ask for camera access so you can take a selfie with the front camera, and for photo library access if you prefer to pick an existing photo. The app uses camera and photo access only for scans you start.

  • Your selfie is sent for AI analysis only when you capture or choose an image and start a scan.
  • Lumis does not continuously monitor your camera or photo library.
  • Images are downscaled on your device before upload.
  • You can change camera and photo permissions in iOS Settings at any time.
  • Face photos are sensitive. Only scan photos you are comfortable sending for automated analysis.

5. Information Sent for AI Analysis

When you start a scan, Lumis sends only what is needed for that scan to the Lumis backend over HTTPS. This can include:

  • Your selfie image, and the optional side-profile image, downscaled on-device before upload.
  • Your quiz answers — gender, age range, goal, and skincare level — used only to personalize your results and plan.
  • Your device locale identifier, used to localize results where appropriate.
  • A random install identifier (UUID) used only for rate limiting, not linked to your identity.
  • Technical request data needed to transmit, route, secure, and rate-limit the request.

Lumis asks the AI provider to return structured results, including category scores, an overall score, a potential score, insights, and the content used to build your Glow-Up Plan.

6. How AI Requests Travel

  1. You take a selfie with the front camera or choose a photo, optionally adding a side profile.
  2. The app downscales the image on your device and sends it, with your quiz answers, locale, and the random install ID, to the Lumis Cloudflare Worker over HTTPS.
  3. The Worker validates the request and applies rate limiting keyed to the random install ID.
  4. The Worker forwards the image and prompt to the Google Gemini API for analysis.
  5. Google Gemini returns generated results to the Worker.
  6. The Worker validates and normalizes the response, then returns it to the app.
  7. The app stores your scan, scores, plan, and progress locally on your device.

The Worker is stateless. Neither the Worker nor Lumis stores your photos or request bodies. The only data the Worker keeps is a rate-limit counter keyed to the random install ID in Cloudflare KV, with a one-hour time-to-live.

7. Backend Processing and Logs

The Lumis backend is hosted on Cloudflare Workers. It receives scan requests, validates inputs, applies rate limiting, builds the Gemini prompt, forwards the image and prompt to Google Gemini, and returns the generated result.

Lumis does not store your selfies, scan results, or request bodies in a Lumis database. Cloudflare may process technical and network information needed to operate the backend, such as IP address, routing information, request timing, status code, endpoint, security events, and operational logs. The only persistent value the Worker writes is a temporary rate-limit counter tied to the random install ID.

8. Face Photos, Biometrics, and AI Training

Face photos are sensitive, and Lumis is designed to handle them carefully:

  • Selfie images used for analysis may be considered biometric information or special-category personal data under laws such as the EU General Data Protection Regulation (GDPR) and the Illinois Biometric Information Privacy Act (BIPA). Lumis processes these images only to generate your scores, based on your consent when you start a scan, does not store them on a server, and does not use them to identify you.
  • Lumis does not perform biometric identification and does not use your photos to identify who you are.
  • Lumis does not build or store face templates, faceprints, or other biometric identifiers.
  • Lumis does not use your photos to train AI models.
  • Lumis does not sell or share your personal information.
  • The random install UUID is used solely for rate limiting and is not linked to your identity.

9. Google Gemini Processing

Lumis uses the Google Gemini API to analyze your selfie and generate your scores and plan content. The information sent to Gemini can include the image, prompt, quiz answers, and locale, along with the generated output. Google processes images under its Gemini API terms and may process technical usage information necessary to operate, secure, and support the Gemini API service for the Lumis developer account.

AI provider retention, safety review, abuse monitoring, and legal disclosure practices may depend on the Gemini API terms, account configuration, region, and policies in effect at the time of processing.

10. Purchases, Apple, and RevenueCat

Lumis offers Lumis Pro through Apple App Store in-app purchase. Apple processes the payment transaction. Lumis does not receive your full payment card number.

RevenueCat helps validate purchases, restore purchases, and determine whether Lumis Pro is active. RevenueCat may process an app-specific anonymous identifier, product identifiers, entitlement status, subscription and renewal status, expiration information, transaction identifiers, and device or app technical information. RevenueCat receives purchase and entitlement information, not your personal identity.

11. Service Providers

Lumis uses a small set of service providers to operate app features:

  • Apple, for App Store distribution, iOS permissions, in-app purchase, and Apple ID subscription management.
  • Cloudflare, for stateless Worker hosting, routing, security, rate limiting, and operational logs.
  • Google, for the Google Gemini API used to generate your scores and plan.
  • RevenueCat, for purchase validation, entitlement management, and restore purchases.

12. Sensitive Data and Not Medical Advice

Lumis scores and insights are AI-generated estimates for entertainment and self-improvement purposes only. Lumis is not a diagnostic tool and does not provide medical, dermatological, or psychological advice. Consult a dermatologist or doctor for any skin or health concerns. AI results can be inaccurate or vary between scans.

Only submit photos you are comfortable having processed by Lumis, Cloudflare, and Google Gemini for automated analysis.

13. Your Choices and Data Deletion

  • You can decline camera or photo permissions, though scan features need image access to work.
  • You can change camera, photo, and notification permissions in iOS Settings.
  • You can turn the optional daily reminder on or off in the app.
  • You can use Settings → "Delete All My Data" to permanently wipe every scan, photo, plan, progress record, quiz answer, and setting on your device and rotate the install ID.
  • You can remove any remaining local app data by deleting Lumis from your device.
  • You can manage or cancel Lumis Pro through your Apple ID subscription settings.
  • You can contact support with privacy questions at [email protected].

14. Security

Lumis uses HTTPS for AI requests and relies on platform security controls provided by iOS, Cloudflare, Google, RevenueCat, and Apple. No method of transmission, processing, or storage is perfectly secure, and AI processing requires transmitting your selfie to service providers.

15. International Processing

Lumis and its providers may process information in countries other than your own. Data protection laws may differ from those in your country or region.

16. Your Privacy Rights (GDPR, UK GDPR, and EEA)

If you are in the European Economic Area, the United Kingdom, or another region with similar laws, you have rights over your personal data. Because Lumis is local-first, most of your data stays on your device and is not held by Soldra, so many of these rights are exercised directly on your device by viewing, editing, exporting, or deleting your data in the app or by deleting the app.

Subject to applicable law, you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Correct inaccurate or incomplete personal data.
  • Delete your personal data ("right to erasure").
  • Restrict or object to certain processing of your personal data.
  • Receive your data in a portable format where technically feasible.
  • Withdraw consent at any time, without affecting processing already carried out.
  • Lodge a complaint with your local data protection supervisory authority.

Where Soldra processes limited personal data (for example, support emails or subscription status), our legal bases are: your consent (such as allowing notifications); performance of a contract (providing the app and any subscription you buy); our legitimate interests (operating, securing, and supporting the app); and compliance with legal obligations. To make a request, email [email protected]. We may need to verify your request before acting on it.

17. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act as amended by the CPRA. Lumis does not sell or share your personal information, and has not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes that would require an opt-out.

Subject to applicable law, you have the right to:

  • Know what personal information is collected and how it is used.
  • Request access to or deletion of your personal information.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information (we do not sell or share).
  • Not be discriminated against for exercising your privacy rights.

Because Lumis keeps your records on your device, you can exercise most of these rights directly in the app. For other requests, contact [email protected].

18. Data Retention

  • Records you create in Lumis stay on your device until you delete them in the app or delete the app; device backups you control may retain copies.
  • Support emails and their attachments are kept only as long as needed to handle your request and for a reasonable period afterward for our records.
  • Subscription status handled by Apple and RevenueCat is retained under their policies for as long as needed to manage your entitlement.
  • Images or text you submit for AI analysis are sent only to generate your result and are not used by Soldra to advertise to you or build a marketing profile; any retention by our backend or the third-party AI provider is governed by their terms.

19. Children

Lumis is intended for users who are at least 13 years old. Onboarding includes an age gate that blocks users under 13, and the AI also rejects images that appear to be of minors as well as non-face images. Lumis does not knowingly collect personal information from children under 13.

20. Changes to This Policy

This policy may be updated when the app, providers, legal requirements, purchase setup, or data practices change. The effective date above shows when this version took effect.

21. Contact

For privacy questions, support requests, or deletion questions, contact [email protected].