This policy explains what data the Luma app collects, why it is collected, who it is shared with, and how you can delete it. It applies to the Android app with the package name com.lvsmsmch.aichat and to the backend that serves it.
Operator and controller
Lvsmsmch — Andrii Maltsev
Feichtner Str. 23
83349 Palling, Germany iamajavagod@gmail.com
1. What we collect
Account. When you first open the app, a guest account is created and tied to a random identifier generated on your device. It is not a hardware identifier and it does not identify you personally.
Google sign-in (optional). If you sign in with Google, we receive and store your Google account identifier, email address, name and profile picture URL from the sign-in token.
Profile. Username, bio and avatar, if you add them.
Content you create. Messages you exchange with AI characters, characters you create, comments, reviews, likes, follows, blocks and reports.
Images. Pictures you upload as avatars or character art, and images generated for you inside a chat.
Technical data. A session token, the IP address a session was created from, the device identifier described above, a push notification token, and usage counters such as the number of messages and chats.
Diagnostics. Crash reports and basic performance and usage data collected by Google Firebase.
2. Why we use it
To run the app: your account, your chats, your characters and your library.
To generate replies and images: the text of your messages and the character's description are sent to AI providers, which return the reply.
To apply usage limits and prevent abuse, including keeping limit counters against a device identifier so that deleting and recreating an account does not reset them.
To send push notifications, if you allow them.
To handle reports and blocks, and to keep the service safe.
To fix crashes and understand which parts of the app are used.
3. Who we share it with
We do not sell your data. We use the following providers, who process data on our behalf:
AI providers — Google (Gemini), Groq, OpenAI, xAI and Fal. The content of your chat messages and the character prompt are sent to them to generate replies and images.
Google Firebase — crash reporting, analytics and push notification delivery.
Google Play services — sign-in with Google, and advertising through Google AdMob where ads are shown in the app.
DigitalOcean — hosting. Our server and database are located in Frankfurt, Germany.
Some of these providers are established outside the European Economic Area. Where data is transferred outside the EEA, it is done under the safeguards those providers offer, such as the European Commission's Standard Contractual Clauses.
4. Legal bases (GDPR)
Performance of a contract — creating your account, storing your chats and characters, generating replies.
Legitimate interests — keeping the service secure, enforcing usage limits, preventing abuse, fixing crashes.
Consent — push notifications and, where applicable, personalised advertising. You can withdraw consent at any time in your device settings.
5. Retention and deletion
You can delete your account from inside the app at any time, or ask us to do it by email. Both routes, and the exact list of what is removed and what is not, are described on Delete your account. Otherwise, data is kept while your account exists.
6. Security
All traffic between the app and our server is encrypted with TLS. Access to the server is restricted, and account passwords, where used, are stored only as hashes and never in plain text.
7. Children
The app is intended for adults and is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will remove it.
8. Your rights
Under the GDPR you have the right to access your data, to correct it, to have it deleted, to restrict or object to its processing, and to receive a copy in a portable format. To exercise any of these, write to iamajavagod@gmail.com. You also have the right to lodge a complaint with your local data protection authority.
9. Changes
If this policy changes, the new version is published on this page with a new date at the top. Significant changes will also be announced in the app.