LuminalPRIVACY POLICY
DASHBOARD →

Luminal API — Privacy Policy

Effective October 7, 2026

1. Who we are

This policy explains what Luminal AI, Inc. (“Luminal”, “we”, “us”) collects when you use the Luminal Text API at flash.luminal.cloud, the Luminal Images API at images.luminal.cloud, and the dashboard at dash.luminal.com (the “Service”), and what we do with it. It is part of our Terms of Service, at dash.luminal.com/terms. Questions and requests go to founders@luminal.com.

2. What we collect

Account data. You sign in through our identity provider, Clerk, which holds your name, email address and sign-in credentials under its own privacy policy. We store an account identifier, your API keys (hashed), key names and the first characters of each key, your balance, limits and account status. We read your verified email address once, when you create your first key, to apply any eligibility rules such as institutional credits, and keep only the domain.

Payment data. Payments are handled by Stripe. We never see or store card numbers. We keep the identifier of each payment session and the amount credited.

Request records. For every API request we record token or image counts, the quality tier, timestamps, the model, which server or provider answered, latency, status and error codes, and your account and key identifiers. These records do not contain the content of your text requests or the model’s outputs. We keep them as billing records for as long as we need them for accounting.

Operational logs. Our servers keep logs of request handling for up to ninety days. They do not contain request content or outputs, but when a model provider returns an error, the log may include a short excerpt of the provider’s error message. When a request carries an invalid or revoked key, we log the requesting IP address.

Dashboard usage. The dashboard uses only the cookies our sign-in provider needs to keep you signed in. We do not run analytics or advertising trackers.

3. Your requests and the model’s outputs

Luminal does not use your requests, source images, or the model’s outputs to train models; a provider that answers a request may, as section 4 describes. We do not log text requests or outputs in the normal course of serving your request, except in the safety and error-handling cases described below and in section 2.

To keep the Service safe and to check compliance with section 5 of the Terms, we sample text requests, including their full content and the model’s output, and run them through automated safety tools that we operate on our own servers. Samples are deleted after seven days. Conversations the tools flag are kept for up to ninety days for review, and the tool’s short finding is kept with your account record for the life of your account. We also keep, for seven days, the content of text requests that failed on our servers, so that we can diagnose the failure.

For image requests we keep, for thirty days, a record of the request: its settings and identifiers, the first two kilobytes of the prompt, and, where the provider refused the request, the reason it gave. We keep a copy of each delivered image for seven days, so that we can answer support questions and verify what you were billed for. Requests the provider’s safety or copyright detection flags may be reviewed by our staff.

4. Providers

Text requests are answered from servers we operate on third-party cloud infrastructure. When those servers are full, failing, or being updated, we send the request to a backup provider so that it is still answered. We choose when. The backup providers we use today are:

  • DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd., China). DeepSeek’s published privacy policy permits it to use inputs to train and improve its models and states that it stores data in the People’s Republic of China. We have no agreement with DeepSeek that changes this.
  • Fireworks AI (Fireworks.ai, Inc., United States). Fireworks states that it does not log or store prompts or outputs for the models we use, and does not use them for training.
  • Z.AI (Jingsheng Hengxing Technology Pte. Ltd., Singapore). Z.AI states that it does not store the content customers provide or generate through its API.

Image requests are answered by Ideogram (Ideogram AI, Inc., United States). Ideogram’s API terms state that it does not use API inputs or outputs to train its models unless they are flagged as violating its usage policies. Generated images are served from Ideogram’s own URLs.

Each provider processes the requests it answers under its own terms and privacy policy. This list is current as of the effective date above.

Our other service providers are Clerk (sign-in), Stripe (payments) and our cloud hosting providers. They process data to provide their service to us, under their own privacy policies.

5. Sharing

We do not sell your data. We share it only with the providers and service providers in section 4, when the law requires it, to protect the Service or others from abuse, or as part of a merger or sale of the business, in which case this policy continues to apply to it.

6. Security and retention

We protect your data with reasonable technical and organizational measures, including encryption in transit and at rest for stored samples. No service is perfectly secure. Retention periods are stated in sections 2 and 3; we keep data no longer than those periods or than the law requires.

7. Your choices

You can view your usage and revoke keys on the dashboard at any time. To close your account and have your account record deleted, write to founders@luminal.com. Three things survive: billing records we must keep for accounting, flagged conversations for up to ninety days, and anything we are legally required to keep. Your Clerk and Stripe data is subject to their deletion processes.

8. Children

The Service is for adults and businesses. We do not knowingly collect data from anyone under 18.

9. Changes

We may update this policy as the Service changes. The effective date at the top tells you when it last changed.

10. Contact

Luminal AI, Inc. · founders@luminal.com

© 2026 Luminal · dash.luminal.com/terms