GDPR · Privacy policy

Your creations, your data

Lumineer complies with the EU General Data Protection Regulation (GDPR). This page explains, in plain terms, where your generations live, who can access them, and what happens when you delete them.

Where your creations are stored

Every generation is saved in our encrypted database (Lovable Cloud / Supabase, EU region). The media files (images, videos, audio) produced by your generations are downloaded and copied to our private storage following this layout:

uploads/
└── {your_user_id}/
    ├── refs/              ← your uploaded references
    │   └── {uuid}.{ext}
    └── generations/
        └── {generation_id}/
            ├── 00.png
            ├── 01.mp4
            └── …

Only your account can access its own files, via time-limited signed URLs. Row-Level Security policies prevent any other user from reading this folder.

Right to erasure (GDPR Article 17)

When you delete a creation from your library:

  • the corresponding row is permanently removed from our database;
  • all associated media files (images, videos, audio) are immediately erased from storage;
  • no cache, no user backup copy is kept after the operation;
  • already-consumed credits are not refunded (except on model-side failures, where an automatic refund is applied).

Deletion is irreversible. Download your creations before deleting them if you want to keep them.

Account deletion

You can request full account deletion at any time from your profile, or by writing to privacy@lumineer.ai. This entails:

  • removal of your profile and authentication history;
  • removal of all your generations from the database;
  • removal of every file stored under your folderuploads/{your_id}/;
  • cancellation of any active subscriptions.

What we keep (and why)

For accounting and legal reasons, we retain billing records (Stripe) for the duration required by applicable law (up to 10 years in France). These records contain no media from your library — only transaction information.

To exercise your GDPR rights (access, rectification, portability, objection, erasure), write to privacy@lumineer.ai. We reply within 30 days. You may also lodge a complaint with your local data protection authority (in France, the CNIL).