Privacy Policy
Version unversioned. This is the same version recorded when you gave consent. If it ever changes materially, you'll be asked to review and re-consent before Lumina talks to your child again.
The short version
Lumina is built for one family at a time. Your child's data lives on infrastructure Parker runs and controls — not a shared cloud database — and nothing about your child is ever sold, used to train a model, or shown to anyone outside your family without your say-so. A handful of specialist companies process pieces of the data to make the product work (listed below, in full). You can see everything Lumina has, and permanently delete it, at any time from the Parent Panel.
Who sees your child's input, and why
When your child talks with Lumina, a few third-party processors necessarily see pieces of that conversation to make it work. Each is listed below with exactly what it sees and why. None of them are permitted to use your child's data for their own purposes (advertising, model training, etc.) beyond providing the service to Lumina.
- OpenRouter — routes your child's text chat messages to the language model that plays Lumina, and separately routes session transcripts to a cheap review model after each session ends (the automated reviewer that flags anything concerning for you and suggests small memory updates). OpenRouter sees the text of the conversation to generate a response; it does not receive your child's name, birth year, or account information.
- Your chosen voice provider — OpenAI, xAI (Grok), or Gemini Live, whichever you connect with your own API key (BYOK) in the Voice tab of the Parent Panel. If you turn on voice mode, your child's spoken audio is sent to that provider to be turned into text and a spoken reply, in real time. Voice only ever goes to the ONE provider you pick and pay for directly — Lumina does not resell or mark up their usage, and raw audio is never stored by Lumina itself (see Retention, below).
- Stripe — processes payments when you add funds to your family's wallet. Stripe handles your card details on its own secure, PCI-compliant systems — your card number never touches Lumina's servers. Lumina only ever sees the resulting balance and transaction history (amount, date, a Stripe reference id), never card data.
- Google — used only for parent sign-in (Google OAuth). Google confirms your identity (email address); it never sees your child's conversations, memory, or any other in-app data.
What we store, and where
Your family's data — child profiles, chat transcripts, the Context Vault (memory facts), safety flags, session analytics, and the wallet ledger — is stored in a self-hosted Postgres database that Parker operates directly. It is not shared with, or accessible to, other families or any analytics/advertising platform.
Retention
- Chat transcripts are kept for 30 days so you can review them in the Parent Panel, then automatically and permanently deleted by a nightly purge job.
- Voice audio is never stored. It is converted to text in real time and discarded immediately by the voice provider — Lumina's own servers never write raw audio to disk.
- The wallet ledger is financial record-keeping (deposits, session charges, refunds) and is append-only — entries are never edited or deleted individually — for as long as your account is active, so the balance always reconciles. It is fully and permanently erased if you close your account (see Deletion, below).
- Vault facts (your child's interests, preferences, and memories) and safety flags are kept indefinitely while your account is active, since they're what makes Lumina remember your child between sessions and what lets you review anything concerning. You can edit, unshare, or delete any individual memory from the Memory tab at any time.
Your rights as a parent
Under COPPA, and built into Lumina from day one, you can at any time, from the Parent Panel:
- Review everything Lumina has recorded about your child — every transcript, memory, and safety flag — in the Transcripts, Memory, and Flags tabs.
- Export a complete, machine-readable copy of your family's data (every child's profile, vault facts, transcripts, session analytics, and the wallet ledger) as a JSON file, from the Data tab.
- Delete your family's data permanently — every child profile, chat, memory, and the wallet — also from the Data tab. This is irreversible: once confirmed, it cannot be recovered by you or by Parker.
Consent
No profile is created for your child, and no data is collected about them, until you — a verified parent, signed in with Google — read and accept this policy on the Consent page. If this policy changes materially (for example, when voice mode adds a new processor), you'll be asked to review and re-consent before your child's next session.
Questions
Reach out to the parent who set up your family's Lumina account with any questions about this policy or your data.