Lumeart Privacy Policy
How Lumeart collects, uses, stores, shares, and protects account, project, creative-asset, and AI-task information.
On this page
Welcome to Lumeart. This Privacy Policy explains how we collect, use, store, share, and protect your personal information, and how you may exercise related rights, when you access or use the Lumeart website, web application, creation workspace, organization and project collaboration, AI image, video, comic, and short-form drama creation tools, public-work displays, sharing pages, subscriptions and credits, APIs (where applicable), and related services (collectively, the “Services”).
Read this Policy carefully before using the Services. Where the law requires separate consent, express consent, or another special notice for a processing activity, we will provide additional information on the relevant feature page. If you do not agree with this Policy, do not continue to access or use the Services.
This Policy should be read together with the Lumeart User Agreement, content rules, subscription and credit descriptions, developer documentation, and other applicable rules.
1. Scope
1.1 This Policy applies to personal information that we process through the Services, including information relating to accounts, organizations, projects, creative assets, AI tasks, public works, sharing links, subscription payments, API calls, devices, and usage logs.
1.2 This Policy does not apply to products or services independently provided by third parties that determine their own processing purposes and means. When you use third-party sign-in, payment, AI model, or external-link services, you should also review the applicable third party’s privacy policy.
1.3 If a feature includes a contextual notice, specific privacy notice, or separate authorization page, that information applies together with this Policy. If there is an inconsistency, the specific notice for that feature will control.
2. Information we collect and process
2.1 Account and sign-in information
When you register, sign in, or maintain an account, we may process your email address, user identifier, display name, profile image, language preference, account status, and other information you choose to provide. If you use third-party sign-in, we may receive account identifiers, email, display name, profile image, or authentication information necessary to complete sign-in, depending on your authorization and the information the provider actually returns.
2.2 Organization, seat, and team-collaboration information
When you create, join, or manage organizations and projects, we may process organization names, member information, invitations, seats, roles, permission settings, project ownership, administrator actions, member join or departure records, collaboration records, usage, and billing associations. Organization owners, administrators, and other authorized members may view relevant member information, project content, task records, and usage according to their permissions.
2.3 Creative content and project materials
To provide creation, storage, collaboration, public-display, and sharing features, we may process content you upload, submit, enter, edit, generate, save, publish, or share, including:
(1) Prompts, story settings, scripts, storyboards, chapters, pages, panels, text, and feedback;
(2) Images, video, audio, characters, scenes, props, style references, canvases, and other uploaded assets;
(3) Model names, model parameters, generation configurations, task records, generation-process information, and AI-generated results;
(4) Titles, descriptions, covers, author display names, profile images, and views or other public information actually shown for public works; and
(5) Sharing links, sharing permissions, link status, and records of views, copies, downloads, or imports through sharing pages, where the relevant feature is available.
We do not ask you to provide sensitive personal information such as identity documents, facial-feature templates, precise location, health information, or complete payment credentials for registration or general use. Images, video, or audio that you voluntarily upload may nevertheless contain an identifiable person’s likeness, voice, or other personal information. Upload only content necessary for creation that you have the right to process.
2.4 AI task and API information
When you submit an AI task or use an API, we may process prompts, selected models, parameters, assets, task types, task status, result locations, credit consumption, errors, request IDs, API Key identifiers, call times, call frequency, response status, and necessary security logs. You must safeguard API Keys and other API credentials and must not disclose them to unauthorized persons.
2.5 Subscription, credit, and transaction information
When you purchase subscriptions, credits, feature packages, seats, or other paid benefits, we may process products, order numbers, prices, currencies, taxes, subscription periods, renewal status, credit changes, refund status, invoice information, and transaction results returned by payment processors. Payments are generally processed by Stripe or other payment processors that we may support from time to time. We generally do not directly collect or store complete card numbers, security codes, or other sensitive payment credentials held by the payment processor.
2.6 Customer-support, complaint, and rights-request information
When you contact us or submit product feedback, a refund request, an appeal, an infringement complaint, or a privacy-rights request, we may process contact details, issue descriptions, relevant account or order information, content locations, supporting materials, communications, and outcomes. To verify a request, we may ask for identity or authorization evidence proportionate to its scope.
2.7 Device, network, and usage information
When you access or use the Services, we may automatically collect device type, operating system, browser type and version, language, IP address, access times, page views and interactions, feature usage, sign-in status, session information, crash and error information, performance data, and necessary device or security identifiers.
We retain access, activity, diagnostic, audit, and security logs to troubleshoot issues, prevent fraud and abuse, and maintain service stability. Under current product arrangements, general access and activity logs are usually retained for approximately 30 days. Records associated with security incidents, dispute resolution, legal requirements, or specific audits may be retained longer.
2.8 Cookies and similar technologies
We use necessary cookies, local storage, and similar technologies to maintain sign-in, remember language and interface preferences, identify sessions, protect accounts, and provide basic page functionality. We may also use analytics technologies to understand service performance and feature usage. You may clear or restrict these technologies in your browser, but some sign-in, preference, project-collaboration, or security features may then stop working correctly.
3. How we use information
We may use information on the basis of performing our contract with you, complying with legal obligations, protecting legitimate interests, obtaining your consent, or another basis permitted by applicable law for the following purposes:
(1) Creating and maintaining accounts and completing registration, sign-in, authentication, risk verification, and account-security management;
(2) Providing organizations, seats, projects, permissions, asset management, scripts and storyboards, generation tasks, canvases, public displays, sharing links, and team collaboration;
(3) Routing prompts, parameters, and assets necessary to perform tasks to the relevant AI model or infrastructure and returning generated results;
(4) Saving projects, prompts, model parameters, task records, and generated results so that you can continue creating, trace tasks, manage projects, and troubleshoot issues;
(5) Processing subscriptions, credits, orders, renewals, refunds, invoices, and billing records;
(6) Providing customer support, service notifications, troubleshooting, infringement-complaint handling, content appeals, and privacy-rights responses;
(7) Detecting and preventing fraud, payment fraud, attacks, bulk registration, non-compliant content, abuse, and other security risks and enforcing content safety and access controls;
(8) Analyzing service performance, feature usage, and failure trends to improve product reliability, interfaces, and operational efficiency;
(9) Meeting accounting, tax, regulatory, sanctions and export-control, dispute-resolution, law-enforcement assistance, and other legal obligations; and
(10) Processing information with your consent or according to your express instructions.
3.1 Model training and algorithm optimization
Unless we separately give you clear notice and obtain any consent required by law, we will not use your prompts, uploaded assets, or AI outputs to train or optimize generative AI models. To protect the Services, troubleshoot failures, and evaluate system performance, we may analyze task status, error information, content-safety results, and de-identified or aggregated data to the extent necessary, but this does not give us ownership of your User Content.
3.2 Content-safety review
To identify unlawful, harmful, infringing, or rule-violating content, we may use automated tools and human review to inspect inputs, outputs, public works, shared content, and content that is reported or reasonably considered risky. Review results may be used to reject tasks, restrict sharing, reduce visibility, remove content, restrict features, or take action on accounts.
4.1 Service providers
To provide the Services, we may provide necessary information to providers supporting third-party sign-in, payment, cloud computing and storage, communications, security, and AI model processing. Services currently or potentially used by the business include Stripe payment services, Alibaba Cloud services, and third-party AI models or APIs from OpenAI, ByteDance AI Lab, Alibaba, Google, MiniMax, and others. Specific providers, models, and data flows may change with features, regions, and supply arrangements.
We limit sharing according to the service purpose and use contracts, security measures, or other reasonable means to require providers to protect information. Where a third party independently determines the purposes and means of processing, its processing is also governed by its own privacy policy.
4.2 Organization and project collaboration
Organization owners, administrators, and authorized project members may access relevant member information, scripts, storyboards, assets, generated results, collaboration records, task records, and usage according to organization or project permissions. After a member leaves or is removed, the organization may continue to retain content and necessary activity records submitted to organization projects. Before joining an organization or project, understand its internal permission, confidentiality, and data-management arrangements.
4.3 Public publication and sharing links
If you publish a work to a public-work display page, community, or other public page, the work, author display name, profile image, title, description, and interaction or statistical information shown on the page may be visible to the public and may be searched, browsed, copied, or forwarded.
If you create or enable a sharing link, anyone holding the link may view, copy, download, or import relevant content using the capabilities provided on the page. Revoking a link generally prevents only future access through the original link and does not automatically delete copies saved before revocation. Share only with trusted recipients and configure permissions carefully.
To provide public display, content discovery, content safety, technical adaptation, and in-Service promotion, we may store, copy, reformat, transmit, and display works that you choose to make public to the extent necessary.
4.4 Legal, security, and rights protection
Where reasonably necessary, we may disclose information to courts, regulators, law-enforcement authorities, professional advisers, or other relevant parties to comply with applicable law, legal process, or government requests; investigate fraud, security incidents, or unlawful conduct; protect the lawful rights of users, third parties, and the platform; or handle claims, complaints, and disputes.
4.5 Business transactions
In a merger, financing, reorganization, bankruptcy, asset sale, or business transfer, information may be transferred as part of the transaction. We will require the recipient to continue providing appropriate protection under this Policy and applicable law and will give notice where required by law.
4.6 At your direction
We may share information with a third party you designate according to your express instructions, authorization, or consent, such as when you invite organization members, create a sharing link, connect a third-party service, or ask us to transmit content to another service.
5. AI model processing
5.1 To complete image, video, text, comic, short-form drama, or other generation tasks, prompts, parameters, reference assets, and task information that you submit may be sent to the third-party AI model or related infrastructure you select or that the system assigns. Different models may be provided by different providers in different countries or regions and may use different content-review, caching, and task-processing mechanisms.
5.2 We process such information only to the extent necessary to complete tasks, return results, maintain safety, record usage and credit consumption, and troubleshoot failures. Do not include identity documents, financial accounts, health information, precise locations, non-public communications, or other sensitive personal information that is unnecessary for the task in prompts or assets.
5.3 If a model service requires additional authorization, or a third party applies materially different processing arrangements to inputs or outputs, we will provide a supplemental notice on the relevant page.
6. Storage locations and international processing
6.1 Under current business arrangements, your information may be stored or processed by cloud, AI model, or other service providers located in the United States or other countries and regions. The location may differ based on the data category, feature, model, and infrastructure arrangement. Because users, organization members, sign-in, payment, cloud infrastructure, and AI model services may be distributed across different countries or regions, your information may be transferred to, stored in, or processed outside your country or region.
6.2 We use reasonable international-transfer safeguards as required by applicable law, such as entering into data-protection terms with recipients, restricting access, using encryption or transmission safeguards, and, where applicable, using standard contractual clauses or other recognized mechanisms. Data-protection rules in other countries or regions may differ from those where you live.
6.3 If applicable law requires separate consent, an assessment, or additional information for a particular international transfer, we will take the required measures.
7. Retention and deletion
7.1 We retain information only for as long as necessary to fulfill the purposes described in this Policy, maintain account and organization relationships, provide project collaboration, protect security, resolve disputes, and meet legal obligations. Specific periods vary based on data type, account and project status, organization permissions, subscription and order records, backup cycles, security risk, and applicable law.
7.2 Account information is generally retained while the account exists. Project assets, prompts, model parameters, generation records, and generated results are generally retained while the account or organization remains in use, the project has not been deleted, and storage and traceability features are still being provided. The absence of a preset automatic deletion period in business systems does not mean that we will retain information indefinitely in all circumstances.
7.3 After you delete content or a project through product features, withdraw a public display, dissolve an organization, or submit a deletion request, information may first be removed from online services and then deleted or de-identified after a reasonable backup cycle, security-audit period, or legally required retention period. Organization-project content may not be deleted immediately or completely because of another member’s lawful use, organization-management permissions, dispute resolution, or legal obligations.
7.4 General access and activity logs are usually retained for approximately 30 days. Payment, refund, invoice, tax, and accounting records may be retained longer as required by law. Records involving fraud, security incidents, complaints, litigation, or regulatory investigations may be retained until the matter is resolved and any necessary period expires.
7.5 When you close your account, we will stop providing the corresponding Services and process information according to the account, organization, project, subscription, dispute, and legal-obligation context. Back up content you wish to retain before closing your account.
8. Data security
8.1 We use administrative, technical, and organizational measures appropriate to the nature and risk of the data, including access controls, permission isolation, authentication, transmission safeguards, audit logging, security monitoring, vulnerability management, and employee-confidentiality controls, to reduce the risk of unauthorized access, disclosure, alteration, loss, or misuse.
8.2 Internet transmission and electronic storage cannot be guaranteed absolutely secure. You should protect your email, password, third-party sign-in accounts, and API Keys; configure organization-member permissions and sharing links appropriately; and promptly contact us if you discover an unusual sign-in or security incident.
8.3 If a personal-information security incident legally requires notification, we will take remedial measures and notify affected users and relevant regulators as required by applicable law.
9. Your choices and rights
9.1 Depending on applicable law where you live, you may have the right to:
(1) Ask or confirm whether we process your personal information;
(2) Access, copy, or obtain a copy of your personal information;
(3) Correct inaccurate or incomplete information;
(4) Delete personal information or request account closure;
(5) Restrict or object to particular processing;
(6) Withdraw consent-based processing, without affecting the lawfulness of processing before withdrawal;
(7) Request data portability where applicable;
(8) Object to direct marketing, or opt out of the sale or sharing of personal information, where provided by applicable law;
(9) Lodge a complaint with a competent data-protection or consumer-protection authority; and
(10) Not receive discriminatory treatment for lawfully exercising privacy rights.
9.2 Where supported by the product, you may manage account details, organization members and permissions, project assets, public works, sharing links, subscriptions, and cookie settings. Submit other requests through the contact channel identified in this Policy.
9.3 To protect your and your organization’s data, we may verify your identity, control of the account, organization role, and request scope. If we cannot reasonably verify identity, or if a request involves another person’s rights, an organization project, a legal retention obligation, a security risk, or is manifestly repetitive or excessive, we may lawfully restrict or deny it and explain why.
9.4 If you submit a request on behalf of another person or organization, you must provide valid authorization. You may also designate an authorized agent where permitted by applicable law.
10. Supplemental notices for particular regions
10.1 European Economic Area, United Kingdom, and Switzerland
Where the relevant data-protection laws apply, our legal bases for processing may include performing a contract, complying with legal obligations, protecting our or a third party’s legitimate interests, and obtaining consent in particular circumstances. You may have the right to complain to your local regulator and may exercise the access, correction, deletion, restriction, objection, and portability rights described in Section 9.
10.2 Certain U.S. states
If applicable U.S. state privacy law grants you rights to access, correct, delete, obtain a copy, opt out of sale, sharing, or targeted advertising, or limit use of sensitive personal information, you may submit a request through the channel identified in this Policy. Based on current business information, we do not sell your personal information for monetary consideration. If our practices change, we will update our disclosures and provide applicable choices as required by law.
10.3 Other regions
If the laws where you live provide additional or different privacy rights, we will process your request in accordance with applicable law. Nothing in this Policy limits rights that the law grants you and does not permit us to exclude by agreement.
11. Children’s privacy
11.1 The Services are intended only for users who have reached the legal age of majority where they live and have the relevant legal capacity. Minors may not register for or use the Services.
11.2 We do not knowingly collect personal information from minors. If you believe a minor has submitted personal information to us, contact us through the channel identified in this Policy. After verification, we will take measures such as restricting the account or deleting information as required by applicable law.
12. Third-party websites and services
12.1 The Services may include third-party websites, plug-ins, models, payments, or other external resources. A third party may independently collect and process your information, and its activities are outside our control. Review its privacy policy and terms before use.
12.2 We use reasonable care in selecting and managing service providers that process data on our behalf, but we make no warranties regarding processing activities for which third parties independently determine the purposes and means. Use of third-party services does not reduce our responsibility under applicable law for our own processing activities.
13. Changes to this Policy
13.1 We may update this Policy due to changes in features, models or providers, legal requirements, security practices, or operations and will display the most recent update date on the page.
13.2 If a change materially affects your rights or the processing of personal information, we will provide notice through a page notice, in-product message, email, or another reasonable method and will obtain renewed consent where required by applicable law.
14. Language versions
14.1 We may provide this Policy in multiple languages. Each version is intended to have equal effect; if versions conflict, the language expressly designated as controlling on the product page will govern, subject to any mandatory law regarding the effect of language versions.
15. Contact us
15.1 To exercise privacy rights or ask about the collection, use, sharing, storage, or security of personal information or this Policy, contact us as follows:
15.2 To protect your account and data, do not include passwords, verification codes, complete card information, or unrelated sensitive materials in your initial message. We may verify your identity, control of the account, or organization permissions before processing a request.
