이 문서는 현재 영어로 제공됩니다.
Privacy Policy
Last Updated: August 28, 2026
Children's Privacy Protection
Lumisia is an app for children and parents to use together, operated by EISOL LLC ("Company"). We design the service to align with the principles of COPPA (Children's Online Privacy Protection Act) and GDPR-K, and we do not knowingly collect personal information from children under 13 without parental notice and consent.
Parental Consent Process
Where required by law or for a particular feature involving a child under 13, we notify the parent and request an express confirmation from that parent or legal guardian. A child's use of the Service alone does not constitute parental consent:
- Notice: We describe the data involved, the purpose of processing, and whether it is shared externally in a parent-facing screen or through the parent's contact channel.
- Express confirmation: Through a checkbox or another express action on the parent account, the adult confirms that they are the child's parent or legal guardian and have the required legal authority. For a paid transaction, we also record the version of the terms or notice confirmed, confirmation time, account, and transaction reference.
Until a required confirmation is completed, we do not enable the feature or begin collecting optional data that requires that confirmation.
Parents can review, export, or delete their child's data at any time from the parent dashboard, or by contacting us at privacy@lumisia.world.
1. Information We Collect
We collect only the minimum information necessary to operate the service:
- Account Info: Parent's email address, display name
- Child Profile: Nickname, age range (strictly for age-appropriate content generation)
- User Content: Stories created, prompts entered, drawings
- Usage Data: Favorites, reading history, app preferences
- Technical and Security Data: IP address, user agent, request timestamp, path and referrer, error data, abuse and security signals, and rate-limit decision data
- Payment Info: Records of subscriptions and printed-goods payments made by the parent (payment credentials such as credit card numbers are handled by Stripe or the applicable app store and are not stored by us)
- Consent and Confirmation Evidence: The version of the terms, policy, or notice confirmed; the items confirmed; confirmation time; confirming account; and related transaction reference
- Goods Order Data: Originals, finished and print-ready images, order details, name, shipping address, phone number, and shipment status when the parent orders printed goods
- My First Shop Request Data: The role category selected by an invited family member, the relevant shop and creation, request status, and creation/update timestamps. We do not collect the invited family member's real name, email address, postal address, payment information, or payout details
Invited family members only send an “I want this” request to the parent; they do not place an order with or pay the Company. We do not collect details about money exchanged directly within a family and do not intermediate payment, hold proceeds, maintain balances, or make payouts.
For distributed rate limiting, we create an irreversible, purpose-namespaced digest from the identifier used to detect abuse and store it only with the time to live (TTL) required for the rate-limit window. The original identifier is not stored in the rate-limit store, and the digest expires when its TTL ends.
2. AI Data Usage Policy
🚫 NO AI Training on User Data
We value your trust. We do NOT use your stories, prompts, or your child's profile data to train our AI models.
Creative content is processed to provide the generation, storage, and other features you request. Child artwork uploaded to My First Shop is processed only as needed for invite-only display, product mockups, the parent's checkout display, manufacturing, shipping, and support. Unless the parent or legal guardian gives separate express consent, we do not use that artwork for AI-model training or advertising. Display in an invite-only shop is not public release or advertising.
3. How We Use Information
- To provide the interactive storytelling experience
- To ensure content safety and age-appropriateness
- To maintain and improve service reliability
- To investigate errors, protect the Service, detect attacks or unauthorized access, and apply rate limits
- To communicate important updates to parents
- To retain evidence of a parent's consent or confirmation and handle inquiries, cancellations, refunds, or disputes
- To display invite-only shops and let parents review and decide family “I want this” requests
- To manufacture, ship, cancel, return, refund, and support printed-goods orders placed by parents
- To perform anonymized statistical analysis of service usage
4. Cookies & Tracking Technologies
We use the following cookies and tracking technologies:
| Technology | Purpose | Provider |
|---|---|---|
| Google Analytics 4 | Service usage analysis & improvement | Google LLC (USA) |
| Meta Conversion API | Advertising effectiveness measurement (server-side conversion tracking) | Meta Platforms, Inc. (USA) |
| Google Ads Data Manager | Advertising effectiveness measurement (server-side Purchase conversion tracking) | Google LLC (USA) |
| Firebase Authentication | User authentication | Google LLC (USA) |
| Sentry | Application error monitoring (technical and error-context data is processed; we configure filtering and masking to minimize direct identifiers) | Functional Software, Inc. (USA) |
| Cookie Consent | Storing consent preferences | Local (no external transmission) |
| Withdrawal capability for measuring a parent's My First Shop print order | Stops an unsent or retry-pending Purchase measurement after the parent starts print-order checkout (cannot read an order or grant consent; retained for up to 365 days) | Browser storage (sent only to our server when withdrawing) |
Analytics and advertising tracking is automatically disabled for child accounts. An invited family member's “I want this” request is not a purchase and is not sent as a Purchase conversion. Purchase measurement for a My First Shop print order runs only when the signed-in parent explicitly consents to analytics at checkout start and has not enabled DNT or GPC. The parent's email is SHA-256 hashed before transmission; purchase value, currency, the Stripe Checkout Session ID (for deduplication), consented Google advertising click IDs, and—only when a dedicated Meta destination is configured—Meta browser/click identifiers (_fbp/_fbc) may also be sent. We do not send a child's name or drawing, or the invited family member's role category. If consent is withdrawn after checkout starts before our server begins an external transmission, or while a Purchase measurement is awaiting retry, the browser uses an order-scoped withdrawal capability to stop that pending measurement and delete advertising identifiers stored on the order. A failed request is retried when the same browser next opens the Service. Withdrawal is not retroactive to a transmission our server began before withdrawal or to an event a provider already accepted, but stops later processing. If the browser control is unavailable, contact privacy@lumisia.world.
For users accessing from GDPR-regulated regions, analytics cookies require explicit opt-in consent before activation.
5. Third-Party Service Providers
We use the following third-party services to deliver the Service. The information actually transmitted depends on the feature used, configuration, and consent choices:
- Google Firebase: Authentication and data storage, including My First Shop images
- Google Cloud AI / Azure OpenAI: Content generation APIs (we do not provide user data for model-training purposes and use the available API settings and service terms to limit retention)
- Azure Speech Service: Text-to-speech narration generation
- Stripe: Payment processing for web subscriptions and printed-goods orders placed by parents (we do not store credit card numbers; for My First Shop, we share the dedicated URL of the finished image so it can be displayed in the parent's checkout)
- Apple App Store and Google Play: Billing and subscription management when a parent subscribes in an app (payment credentials are handled by the applicable store)
- Meta Platforms: Advertising effectiveness measurement for parents who explicitly consent to analytics at checkout start (Conversion API; hashed parent email, purchase data, and _fbp/_fbc may be sent only to the dedicated destination; disabled for child accounts and invited-family requests)
- Google Ads Data Manager: Purchase effectiveness measurement for parents who explicitly consent to analytics at checkout start and have not enabled DNT or GPC (the parent's email is hashed before transmission; invited-family requests are not sent)
- Printful, Printio (operated by 株式会社OpenFactory), and other print partners: Manufacturing and shipping physical goods (order details, print-ready images, name, shipping address, and phone number are shared only as needed to fulfill the order)
- Sharp Marketing Japan Corporation (Network Print Service): Temporary registration of print-ready images and issuance of a user number and QR code when a user selects convenience-store printing (we do not share names, addresses, or payment data)
- Sentry: Application error monitoring (technical and error-context data is processed; we configure filtering and masking to minimize direct identifiers, although relevant information may be included depending on the failure)
- Resend: Email notifications (parental notices, service-related emails)
- Google Workspace (Google Chat): Internal operations alerts needed to handle physical-goods production, refunds, and disputes (order and payment reference numbers, product, amount, and status only; we do not include the drawing image, name, address, phone number, or email address)
- ipapi.co: IP-based country detection (used to determine GDPR applicability; results are cached locally in the browser)
My First Shop invite links and dedicated image URLs: Invite links and dedicated URLs for originals, finished images, and print-ready images contain hard-to-guess tokens, but there is no separate password or identity check. The URL itself acts as the key, so anyone who knows it may view the shop or creation. We do not publish or list these URLs for the general public, and image responses include cache-control settings intended to prevent browser and intermediary storage. Parents should share links individually only with intended, trusted family members, avoid social-media posting or forwarding, and close the shop if unintended sharing is suspected.
We share a dedicated URL or the image itself with Stripe as needed to display the product in the parent's print-order checkout, and with manufacturing partners such as Printful or Printio as needed to manufacture and ship the order. Invited family members receive access only to display the creation through the invite link. Deleting the image from our storage after its deadline invalidates the dedicated URL, but it cannot automatically recall copies a service provider obtained earlier for its work. Each provider's terms and privacy policy also apply to its handling of those copies.
6. Security Measures
We implement the following measures to protect your data:
- Technical: TLS/SSL encryption for all communications, database access controls, PII redaction in application logs
- Organizational: Limited access to personal data, employee training on data protection
- Infrastructure: Use of Google Cloud Platform infrastructure with physical security features
7. Cross-Border Data Transfer
Your personal data may be transferred to and stored on servers located in the following countries:
- United States: Google Cloud Platform (Firebase, AI APIs), Stripe, Resend
Where a transfer to a foreign service provider is a regulated cross-border transfer, we review the service, destination, and configuration and provide information, use contractual measures, or obtain consent as required by applicable law. Each provider's terms and privacy policy also apply to its processing.
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion |
| Generated content (stories, images) | Until account deletion |
| Usage logs | Up to 12 months from collection |
| Operational logs, including IP address, user agent, request, error, and security data | Up to 12 months from collection. Irreversible, namespaced digests used for distributed rate limiting are retained only for the TTL needed for the rate-limit window |
| Parent subscription payment records and printed-goods order/shipping records | As required by law after the transaction (up to 7 years). Transaction records such as amount, product, shipping, and refunds remain after images are deleted |
| Evidence of parent consent or confirmation | With the related transaction records for the legally required period after the transaction (up to 7 years). Evidence not tied to a transaction is retained until the related account or feature ends |
| My First Shop originals, finished images, and print-ready images | Due for deletion 30 days after upload if the parent has not created or paid for a print order, 30 days after cancellation or full refund, or 180 days after shipment. An unshipped partial refund is retained until the remaining charge is resolved; images also remain while manufacturing, delivery, or a dispute is active. We recheck for at least 24 hours before deletion |
| Invite-only shops and family “I want this” request records | Until the parent account is deleted. Shops and requests become unavailable in the interface after their publication deadline and, while retained, are used only for parent management, fraud prevention, and support |
| Convenience-store print images, user numbers, and temporary authentication data | Normally within 24 hours after the print deadline, or earlier when the user deletes the registration |
| Cookie consent preferences | Until changed or browser data is cleared |
When you delete your account, account data such as created stories, shops, and family requests is deleted. Payment, order, and consent-confirmation records required by law, or information needed to complete manufacturing, shipping, refunds, or dispute handling, is retained only for the periods described above.
9. Your Data Rights
Parents have full control over their family's data. You can:
- Review personal information collected from your child
- Request correction of inaccurate data
- Request deletion of your child's data
- Refuse further data collection
You can start account deletion from the App Settings > Account > Delete Account menu. The account is made unavailable as deletion begins; the retention exceptions and deletion periods stated above still apply. You may also make requests by emailing us at privacy@lumisia.world.
10. Additional Rights for EU/EEA/UK Residents (GDPR)
Note: The Service currently restricts access from EU/EEA/UK/Switzerland while we complete the appointment of an EU representative under GDPR Art. 27. We will update this policy when service becomes available in these regions. The rights below will apply once the Service is accessible from those regions.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following additional rights under the General Data Protection Regulation (GDPR):
- Right to Access (Art. 15): Request a copy of the personal data we hold about you
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data
- Right to Erasure (Art. 17): Request deletion of your personal data
- Right to Restrict Processing (Art. 18): Request limitation of how we process your data
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent. Withdrawal applies to subsequent processing and does not affect the lawfulness of processing completed before withdrawal
Legal Basis for Processing: We process your data based on: (a) Contractual Necessity — to provide the Service; (b) Consent — for analytics cookies and marketing communications; (c) Legitimate Interest — for service improvement and security.
Right to Lodge a Complaint: You have the right to file a complaint with your local supervisory authority if you believe your data protection rights have been violated. A list of EU Data Protection Authorities can be found at edpb.europa.eu.
11. Additional Rights for California Residents (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you
- Right to Delete: You may request deletion of your personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
We do not sell personal information. We do not sell, rent, or share personal information for cross-context behavioral advertising purposes.
12. Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will:
- Notify affected users via email within 72 hours of becoming aware of the breach
- Report to relevant authorities as required by applicable law (e.g., supervisory authorities under GDPR)
- Provide details about the nature of the breach, the data affected, and the measures taken to address and mitigate it
- Take immediate action to contain the breach and prevent further unauthorized access
We maintain an incident response plan and regularly test our security measures to minimize the risk of data breaches.
13. Contact Us
If you have any questions about our privacy practices, please contact us: