Privacy policy
Effective 2026-08-26. This version is published ahead of a legal review; if that review changes anything material, we will say so here.
Effective date: 2026-08-26
1. Who we are and what this covers
lumento is a product of Peyer Media LLC, a Minnesota company. This policy covers the lumento iOS app, lumento.app and its dashboard, photographer portfolio pages, and the delivery links subjects receive.
Privacy contact: privacy@lumento.app
Mail: Peyer Media LLC, PO Box 1053, Chanhassen, MN 55317, USA
2. Who you might be
lumento sits between two people: a photographer and the person they photographed. This policy speaks to four situations, and one login can hold more than one of them at once.
- A photographer. You have an account, upload photos, and deliver them.
- A person who was photographed. We call you a subject. You may have no account at all. Your photos reach you through a delivery link.
- An account holder saving photos. A subject who created a free account to keep their sessions. The same login can also be a photographer account.
- A visitor. You browsed lumento.app or a portfolio page.
3. Information we collect
From photographers
- Account details: sign-in is handled by our authentication provider (Clerk), with Apple and Google sign-in as options. We also store your email address ourselves so we can send you service messages.
- Profile details you add: display name, handle, bio, location label, links, and a profile photo. If you change your handle, we keep the old one so links to it forward to your new page.
- Content: the photos you upload, the back-of-camera preview that becomes a session's cover, portfolio images, and the private notes and location hint you can attach to a session. Notes and location hints never appear on a delivery page. A note can appear in a reminder notification sent to your own device, and staff can see uploaded photos during a review (section 5).
- Housekeeping: how many bytes your uploads use, counted against your plan's storage limit.
About subjects
- A delivery contact, so we can tell you when your photos are ready. Today that is an email address. You can also skip contact entirely and keep the link. The address is encrypted the moment our servers receive it, and once it is stored, no photographer-facing screen ever shows it again; the photographer's app and dashboard only show that a contact exists, and when the delivery was opened and last viewed, never who you are.
- Sometimes the photographer types your email in for you, at your request, in their app. This happens on the street, including offline. When it does, we record that the photographer entered it and the time you agreed, and we write to you directly (section 5). Until the photographer's phone is back online, that address waits in encrypted storage on their device, for up to 30 days, before it syncs to us.
- If you ask a collection page to email you when new photos post: that email address, handled the same way as a delivery contact. It is encrypted on arrival, the photographer only ever sees a count, and every email we send you carries a link that deletes it.
- If you create a free account: your email and the sessions you save.
- If you send a booking inquiry: your message, what you are interested in, and the contact you give. That contact goes to the one photographer you wrote to. This is the one contact a photographer does see, because replying is the point.
- If you report content and leave an email so we can follow up, we store that address encrypted and use it only for the report.
If you join the updates list
- The email you give us, stored encrypted, plus a one-way fingerprint of it so the same address is not added twice. For account holders, the date you turned update emails on is your consent record. Update emails are off unless you turn them on.
Automatically, from everyone
- Basic device and app information, and a push token if you turn on notifications.
- Country-level location only. Our own records never hold your IP address: abuse counters use a keyed, self-expiring fingerprint of it, and the address itself is only processed in the moment, including a pass to Cloudflare's bot check on our public forms. Our hosting provider keeps short-lived technical request logs on our account.
- Usage events: things like "a delivery page was opened" or "a photo was downloaded," recorded with the session, the photographer, and the country, and never with the viewer's name, email, or account identifier. We use these to run and improve lumento. They are deleted after 12 months.
- Diagnostics: if the app or site hits an error, a crash report goes to our error-monitoring provider (Sentry) with technical context such as device, OS, app version, and the request involved. We configure these reports to exclude user identifiers and to mask delivery links.
4. How we use information
- To deliver photos and to notify subjects when photos are ready, on the way, or removed. We send those messages on the photographer's behalf.
- To email people who asked a collection page for updates when a new gallery is posted there.
- To run accounts, profiles, portfolios, and the dashboard.
- To pass a booking inquiry to the photographer so they can reply directly. lumento does not sit in the middle of that conversation.
- To show photographers activity on their own sessions: view and download counts, and when a delivery was opened and last viewed.
- To enforce our rules and handle reports. Staff may review uploaded photos, including photos in private deliveries, and authorized staff can access account records and reports to handle support, abuse, and legal requests.
- To send one orientation email when you set up a photographer profile, and one when you first save photos to an account. These are service emails, separate from the updates list.
- To send product updates and tips, only to people who asked. Every one has a one-click unsubscribe that works without signing in.
- To keep lumento secure, prevent abuse, fix problems, and improve it.
- To meet legal obligations.
We do not sell personal information and we do not use photos to train machine-learning models.
5. If a photographer took your photo
This section is for subjects, whether or not you ever touch lumento yourself.
The photographer decided to take and share the photos. lumento is the delivery tool. For anything about the photos themselves, including not wanting them taken or kept, the photographer is the right person to ask. We can help you reach them through the delivery page, and we act ourselves on anything about the contact details we hold.
Your delivery link is the key. Anyone holding the link can see the session, so treat it like a ticket. The photos shown on the page, the previews, and the standard download are stripped of metadata, including GPS location. If your photographer turns on original-file downloads, you can also download the file exactly as captured, and that one may still contain camera and location data the photographer chose to leave in. Our metadata policy lists what each version contains.
Your first email carries a way out. Every delivery email includes a one-click link that deletes your address from that session. No login, no reply needed. If the photographer entered your email for you, that first message also explains who we are and why you are hearing from us.
If the photos come down. When a photographer deletes a session's photos, we notify you, and your contact details are deleted from that session once that notice clears our send queue. If the photographer deletes their whole account, their sessions and the contact details tied to them are erased. A contact on a session that never receives photos stays stored until you remove it with your erase link or ask us.
If something is wrong. Active delivery pages have a report link. A report opens a request that our staff review and act on; you can report content or ask for your contact details to be removed, without an account. You can also email privacy@lumento.app with your delivery link.
Saving photos. If you create a free account and save a session, it stays in your account unless the photographer removes the session, its saves, or you delete your account. We email you if a saved session's photos arrive later.
6. How we share information
We do not sell personal information. We share it only to run lumento:
- With the photographer: booking-inquiry contacts only, as described above. Stored delivery contacts are never shown to the photographer.
- With service providers under contracts that limit them to running the service for us: Clerk (sign-in), Cloudflare (hosting, storage, image processing, email delivery, and the bot check on public forms), Expo together with Apple and Google (push notifications and app distribution), and Sentry (error monitoring, as described in section 3). If we turn on text-message delivery, Twilio will deliver those texts, and we will update this policy first. When payments launch they will run through Stripe, and lumento will never hold your card details.
- For legal reasons, if required by law or to protect rights, safety, or the integrity of the service.
- In a business transfer, subject to this policy.
Our servers run on Cloudflare's global network, so data may be processed outside your country (section 10).
7. How long we keep things
lumento does not automatically delete or expire photos, sessions, or accounts today. Photographers keep their content until they delete it. Plans carry an access window that the dashboard shows but that we do not yet enforce with deletion; if we begin enforcing it, we will give notice first.
- Deleted photos and sessions: removed from the service right away and held in a recovery area for 30 days in case a deletion went wrong, then gone permanently. We also ask our CDN to drop cached copies when something is removed, and retry if either step fails.
- Subject delivery contacts: encrypted while a delivery needs them. Deleted when the photographer deletes the session's photos (once the removal notice clears our send queue), when you use the one-click erase link or the report flow, or when we act on an emailed request.
- Booking inquiries: kept in the photographer's inbox until their account is deleted. No automatic window today.
- Usage events: deleted after 12 months. Enforced in code.
- Records of messages we sent (never your contact details, which live separately): kept until the related account or session is deleted.
- Updates-list emails: kept until you unsubscribe or delete your account. Either way we keep a do-not-email fingerprint, without the address itself, so it is not added again by mistake. Joining the list again is fresh consent. For account holders, the in-settings switch simply turns update emails off.
- Reports and moderation records: kept while we may need them to enforce our rules and defend our decisions, including after the account or content they concern is deleted.
- Legal holds: if we remove content for child-safety or other legal reasons, we may preserve a copy as evidence for as long as the law requires, even if the account or session is deleted. Together with the bullet above, this is the exception to the erasure promises in this policy.
8. Your rights and choices
- Your data, downloadable. Photographers and account holders can download the data our export tool covers from Settings, as one file, both roles included. Links to original photos inside it work for 7 days. Very large accounts are exported up to set limits, and the file says so; email privacy@lumento.app for the rest. Some records are left out on purpose and the file says that too: subject contact details (sealed from photographers), who saved a session (counts only), security tokens, and moderation records while their legal treatment is under review.
- Erasure, photographers: delete any session's photos yourself at any time; the subjects are notified and their contacts on that session are deleted right after. Deleting your account, in the app under Settings or on the web, erases your photos, sessions, portfolio, the contact details tied to them, and your updates-list address, with the exceptions in section 7.
- Erasure, subjects: no account needed. Use the report link on your delivery page, the one-click erase link in your delivery email, or write to privacy@lumento.app with your delivery link.
- If you cannot sign in for any reason, email privacy@lumento.app and we will handle your request manually after verifying it is you.
- Push notifications: turn them off in your device settings any time.
- Update emails: one-click unsubscribe in every email, plus a switch in Settings. Delivery notifications you asked for are not affected.
We respond within the time the law requires and never penalize you for asking. GDPR and UK GDPR rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent) and US state rights are covered in the next two sections.
9. US state privacy rights
We do not sell or share personal information for advertising, and we do not use it for targeted advertising or profiling. Residents of California and other states with privacy laws can exercise the rights in section 8 through privacy@lumento.app.
10. GDPR and users outside the US
Legal bases: performing our contract with photographers; legitimate interests in running and securing the service and delivering photos a photographer asked us to deliver; consent, for push notifications, update emails, and a subject's delivery contact; and legal obligations.
Where data leaves the EU, UK, or your country, we rely on an appropriate transfer mechanism such as the EU Standard Contractual Clauses.
11. Cookies and on-device storage
lumento uses no advertising or third-party analytics cookies. What we do use:
- Sign-in cookies from our authentication provider, on the pages where you sign in. Strictly necessary.
- Your own browser can remember the email you typed on a delivery page, so a booking form can offer it back to you. It stays in your browser's local storage on your device; we can read it back only on our own pages, and you can clear it by clearing site data.
- In the photographer's app, an offline-captured subject contact waits in the device's encrypted storage until it syncs, at most 30 days. A server-side erasure cannot reach a copy that has not synced yet.
12. Children
You must be at least 16 to have a lumento account, and at least 18 to sell photos or receive payments once payments exist. We do not ask your age at sign-up; the floor is a term of use. We do not knowingly collect account data from anyone under 16, and we delete it if we learn of it.
Photographers work in public, so a photographed subject could be a minor of any age. A parent or guardian can reach us about a minor's photos or contact details at privacy@lumento.app, and the erasure routes in section 8 work without an account.
13. Security
Personal information is encrypted in transit and at rest, with access controls on top. A subject's delivery contact is encrypted with a key held only by our servers, is never shown to the photographer once stored, and is decrypted only at the moment we send a notification. Our own records never hold raw IP addresses. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires.
14. Changes to this policy
We may update this policy. For material changes we give reasonable notice in the app or by email. The effective date at the top shows when it last changed.
15. Contact
privacy@lumento.app
Peyer Media LLC, PO Box 1053, Chanhassen, MN 55317, USA