Privacy Policy
Last updated: 22 September 2026
The data controller is named, with a postal address and a contact address, in section 8.
The short version
LUMA analyses the colours of your face to place you among the twelve seasonal colour harmonies. The analysis runs entirely on your device. There is no server, and nothing is ever uploaded.
Your photograph itself is never saved: it exists in memory for the length of one analysis and is discarded when it ends. One image is kept, in the app's own private storage on your phone — your face cut out: head and hair, cropped at the neck, with the room and everything else in the frame already discarded before the file exists. It is kept so the app can show you colours against your own face after you close it, instead of asking you to photograph yourself again every time.
It never leaves the device. It is not written to your photo library, other apps cannot see it, and it is not backed up to iCloud Photos. Settings → Delete my analysis deletes the file itself, and deleting the app removes it with everything else.
We do not ask for an account. We do not ask for your name, email, phone number or date of birth. We have no advertising and no analytics SDK.
The only personal data that leaves your device is what the app stores (Apple, Google) and our purchase processor need in order to sell you something and to restore what you bought.
1. What we process, and why
1.1 Photographs and the colours derived from them
| What | Camera frames you capture, or an image you choose from your library. |
| Why | To measure the colour of your skin, hair and irises. |
| Where | On your device only. |
| Retention | In memory, for the duration of one analysis. The full photograph is never written to disk. |
| Shared with | Nobody. |
1.2 The cut-out
| What | Your face, segmented out of the photograph: head and hair, cropped at the neck. The background, your clothes and everything else in the frame are discarded before the file is created. |
| Why | So the drape and the shareable card can show colours against your own face on a later launch, without a fresh photograph each time. |
| Where | The app's private container on your device (not the photo library, not iCloud Photos, not visible to other apps). |
| Retention | Until you delete your analysis, replace it with a new scan, or delete the app. One file: a new scan overwrites it. |
| Shared with | Nobody. It is never transmitted. |
If the segmentation does not succeed, nothing is kept — the app falls back to showing no face rather than storing a photograph it could not crop.
The measured results — a season, three axis values, the hex codes of your skin, hair and eyes, a confidence figure — are stored locally on your device so the app can show them again when you reopen it. You can delete them at any time from Settings → Delete my analysis, which erases them permanently from the device. There is no copy anywhere else, so there is nothing else to delete.
We never derive, infer or store any health, medical, biometric-identification, racial or ethnic information. The measurement is a colorimetric reading of a surface, in the same sense that a paint app reads a wall. It is not used to identify or authenticate anyone, and it is not a facial-recognition template.
1.3 Purchases
| What | A randomly generated app user ID, your purchase and restore history, country, and basic device/OS information. |
| Why | To sell you a one-off purchase, to restore it on a new device, and to prevent fraud. |
| Processor | RevenueCat, Inc. (United States), acting as our processor. |
| Also involved | Apple (App Store) or Google (Google Play), as independent controllers of the payment itself. |
| Retention | For as long as needed to honour restores and to meet accounting obligations. |
We never see or receive your card number. Payment is handled entirely by the app store.
1.4 Crash and performance data
We do not integrate a crash-reporting SDK. Apple and Google may provide us with aggregated, anonymised crash and performance statistics if you have opted into sharing them with them; we cannot link those to you.
2. Legal bases (GDPR, where it applies)
- Performing the analysis — Article 6(1)(b), performance of a contract you
asked for. Processing happens on your device; we are not a recipient.
- Purchases and restores — Article 6(1)(b), performance of a contract.
- Fraud prevention and accounting — Article 6(1)(c) and 6(1)(f).
We do not rely on consent for any processing, because we do not carry out any processing that would require it: no advertising, no profiling with legal effects, no sale of data.
3. Who we share data with
| Recipient | What they get | Why |
|---|---|---|
| RevenueCat, Inc. | Anonymous app user ID, purchase events, country, device/OS | Purchase and restore infrastructure |
| Apple / Google | Whatever the payment itself requires | Processing your payment |
That is the complete list. We do not sell personal data, we do not share it for advertising or cross-context behavioural advertising, and we have no data brokers. For the purposes of the CCPA/CPRA we have not sold or shared personal information in the preceding twelve months.
LUMA is sold worldwide, so data may be processed in a country other than the one you live in. Transfers of purchase records to the United States (RevenueCat) are made under the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for transfers subject to the UK GDPR and the Swiss addendum for transfers subject to the Swiss FADP. Where you live somewhere with its own transfer rules, we rely on the mechanism that law provides; and there is nothing here but a random identifier and a record of what you bought.
4. Your rights
Where the GDPR or UK GDPR applies you may request access, rectification, erasure, restriction, portability, and you may object to processing. Where the CCPA/CPRA applies you may request to know, to delete, to correct, and to opt out of sale or sharing (there is none to opt out of).
In practice:
- Your analysis and your cut-out are on your device. Delete them yourself
in Settings → Delete my analysis — which deletes the cut-out file itself, not merely the entry pointing at it — or by deleting the app. We hold no copy and cannot retrieve one.
- Purchase records — write to the contact address above and we will ask
RevenueCat to delete the records associated with your app user ID. Note that doing so also destroys our ability to restore your purchase.
Wherever you live
The rights above are written in the vocabulary of the GDPR because it is the most demanding of them, not because it is the only one that applies. We apply the same standard everywhere LUMA is sold: you may ask what we hold, ask for it to be corrected, and ask for it to be deleted, whatever your country calls those rights — the GDPR and UK GDPR in the EEA and the United Kingdom, the CCPA/CPRA in California, the LGPD in Brazil, PIPEDA in Canada, the Privacy Act in Australia, the APPI in Japan, and their equivalents elsewhere. Where a local law gives you more, that law wins.
California. We do not sell or share personal information, and have not in the preceding twelve months. We do not process sensitive personal information for the purpose of inferring characteristics. There is therefore no "Do Not Sell or Share My Personal Information" link to provide, and no financial incentive programme. We do not knowingly process the personal information of anyone under 16.
You may complain to the data protection authority of the country where you live. Our lead supervisory authority, because that is where we are established: Garante per la protezione dei dati personali.
5. Children
LUMA is not directed to children. We do not knowingly process the data of anyone under 13 (or under the age of digital consent in your country, where that is higher). The app is rated accordingly on both stores. Because we collect no identifying data, we cannot proactively detect a child's use; if you believe a child has used the app, simply delete the app and its data.
6. Security
Results are stored in your device's own app-private storage and protected by the operating system's sandbox and, where enabled, device encryption. Because photographs never leave the device and there is no account, the most common categories of breach do not apply to this app.
7. Changes
If we change this policy we will update the date above and, where the change is material, show a notice in the app before it takes effect.
8. Data controller and contact
Riccardo Sasso, Via dei Brusati 21, 00163 Roma, Italy. Contact: hello@lumacolors.com