Lumee Privacy Policy

Companionship for love, marriage & the relationships that matter
Version: v1.2 (overseas storage · full disclosure)
Effective: June 16, 2026 | Last updated: July 9, 2026
Operator / Data controller: Capstone IQ Group Limited (Hong Kong)
Privacy contact: hi@mylumee.cn

"Lumee" (the "App", "we", "us") is operated by Capstone IQ Group Limited (Hong Kong). This Policy applies to your entire use of our services through the App's web version and mobile clients. This is the English edition; where a translated term differs from the Chinese original at pp.html, the Chinese version governs for users in mainland China and this English version governs for users elsewhere.

1. Introduction

Lumee is a companionship app that walks with you through love, marriage and the important relationships in your life. Here you may write down very private thoughts, record the details of a relationship, or even upload a voice you want to keep. Precisely because this content is so private and so important, we want to tell you plainly and completely how we handle your information.

Please read this Policy in full before using the App — especially the bold parts and any clauses involving "sensitive personal information." If you do not agree, please do not use the relevant features; by continuing to use the App you confirm that you have read and agree to this Policy.

In one line: your information is yours. We collect only what is necessary to provide a feature; the most sensitive content (voice, face, private thoughts) is asked about and consented to separately before we process it; you can view, correct and delete it at any time, and you can close your account and export your own personal data (your profile, text records and the like) or erase it. Note: this personal-data export covers your own data; it does not include downloadable audio files of a cloned voice — synthesized voice audio (including a deceased or living person's cloned voice) cannot be exported or downloaded, to prevent misuse, deepfakes and voice-rights infringement. Please also note: our servers are currently located in Hong Kong (outside your country for most users), so your information is transferred across borders — see Sections 7 and 11.

2. What we collect and how

We follow the principle of "minimum necessary" and collect information only within the scope needed to provide a specific feature to you.

2.1 When you register and sign in

2.2 When you fill in or record content

2.3 When you use AI companionship features

2.4 When you use sensitive features (this is sensitive personal information — see Section 6)

2.5 When you use community, consultation and paid features

2.6 Information generated automatically

We do not collect information unrelated to a feature (such as your contacts, SMS, precise location, or your entire photo library). Some content (e.g. journal photos) may be stored only locally on your device and not uploaded to the cloud.

3. How we use your information

If we need to use your personal information for a purpose not stated in this Policy, we will seek your consent again.

4. Cookies and similar technologies

To keep you signed in and provide a basic experience, we use cookies and local storage on your device to: maintain the login session (e.g. a login token, 30-day sliding validity), remember your preferences, and protect security. We do not use cookies for precise advertising tracking or cross-context behavioral advertising. You can clear local storage via your browser or system settings, though this may require you to sign in again or disable some features.

5. How we share, transfer or disclose

5.1 Processors and sharing list

To deliver specific features we entrust the minimum necessary information to the service providers listed below, bound by contract to process it only as we direct and not for other purposes.

ProviderInformation sharedPurpose
AI conversation provideryour conversation / venting / analysis textgenerate AI responses, chat-log analysis, legal Q&A
AI voice & image provideruploaded audio, facial photos, text to synthesizevoice-clone modeling, text-to-speech, AI image generation
Cloud storage providerimages and audio you uploadobject storage and delivery
SMS provideryour phone numbersend sign-in / registration verification codes
Email provideryour email addresssend overseas email sign-in / registration codes
Payment providersorder number, amount, currency, payment statusprocess payments and reconciliation
Sign-in providersWeChat / Apple / Google identity tokens, user identifiersthird-party sign-in
Real-time voice/video providercall channel identifier, connection inforeal-time voice calls with human counselors
Except for the providers listed above, we do not share your personal information with other third parties. We do not sell your personal information.

5.2 Transfer

We do not proactively transfer your personal information. If a transfer is needed due to merger, acquisition or restructuring, we will require the recipient to remain bound by this Policy or seek your consent again.

5.3 Disclosure

We do not publicly disclose your personal information except with your separate consent or where required by law or a competent judicial/administrative authority.

6. Sensitive personal information (please read carefully)

The App involves the following sensitive personal information, processed with separate notice and separate consent and stricter safeguards:

6.1 What is involved

6.2 Our processing rules

6.3 AI-synthesis / generated-content labeling

6.4 Prohibited uses

You agree not to use the App or a cloned voice for any unlawful, infringing or harmful purpose, including impersonation, fraud, extortion, harassment, defamation, deepfakes made to deceive, cloning a voice without the person's consent, or removing the AI-synthesis label. We may immediately suspend accounts and delete content, and reserve the right to pursue liability.

6.5 Security and deletion

Sensitive personal information is stored encrypted with strictly limited access. You may delete your voice samples, cloned voices, uploaded photos and related data at any time in-app or by contacting us.

7. Storage of your information

7.1 Location

The main servers and database that run the App (account info, conversations, journals, relationship records, orders, etc.) and the cloud storage for uploaded images are currently located in Hong Kong. When you use the App, your personal information is transferred abroad for storage and processing — see Section 11. AI text and voice/image processing is entrusted to third-party AI providers whose node locations depend on those providers. We do not claim end-to-end encryption; we apply encryption in transit and access controls.

7.2 Retention

We keep your personal information for the shortest period necessary to fulfill the purposes in this Policy; afterward we delete or anonymize it (unless the law requires otherwise). After you close your account we delete or anonymize your personal information; a limited set of records required for legal compliance (e.g. synthesis-authorization records, transaction and risk-control records) is kept in de-identified form for the statutory minimum period and then destroyed. Voiceprint/face samples are deleted promptly once modeling/generation is complete, or immediately when you delete them.

Deceased-voice "keepsake buyout": where you purchase a deceased-voice keepsake as a one-time buyout, the associated cloned-voice model is retained to provide an in-app listening service for a 3-year keepsake service term from the date of purchase (this is a fixed-term service, not lifetime or permanent storage); after the term ends the keepsake service ends and the model may be deleted unless you have renewed. Throughout, the synthesized audio itself cannot be exported or downloaded — the buyout is an in-app listening service right, not ownership of an audio file — to prevent misuse, deepfakes and voice-rights infringement. You may delete the voice and content at any time.

7.3 Local storage

Some content (local drafts, un-uploaded journal images) is stored only on your device and does not move automatically when you change devices.

8. Security measures

9. Your rights (GDPR / general)

You have the following rights over your personal information, exercisable in-app or via the contact in Section 13:

We respond within the time required by law (generally within one month under the GDPR; up to 15 working days under Chinese law).

10. Protection of minors

The App is designed and operated for adults (18 and over) and is not offered to minors. It involves emotional, breakup, domestic-abuse, voice-cloning and paid content unsuitable for minors. We do not knowingly collect personal information from minors; if we learn we have done so without proper guardian consent, we will delete it promptly. Guardians can contact us via Section 13.

11. Cross-border transfer

Because our servers, database and image storage are in Hong Kong (see 7.1), your personal information is provided abroad for storage and processing.

12. AI nature, disclaimers and crisis support

13. Updates and how to contact us

We may update this Policy from time to time. For material changes (sensitive-information processing, sharing recipients, your rights) we notify you conspicuously and, where needed, seek your consent again.

14. U.S. users (CCPA/CPRA + BIPA)

This section applies to users located in the United States and supplements the above; where it conflicts, this section controls for U.S. users.

14.1 Who we are

The business and controller responsible for U.S. users' personal information is Capstone IQ Group Limited (111 Argyle Street, Mong Kok, Kowloon, Hong Kong). Privacy contact: hi@mylumee.cn.

14.2 Biometric Data Retention & Destruction Policy (BIPA)

Lumee creates a voiceprint — a biometric identifier derived from the voice recordings you provide — solely to create and operate a cloned voice for companionship and remembrance. We obtain your separate written consent before collecting it. We do not sell, lease, trade or otherwise profit from your biometric data, and we do not share it except with the cloud processor that performs the cloning on our behalf.

Retention & destruction: raw recordings are deleted immediately after the voiceprint is created. The voiceprint / cloned-voice model is retained only while your account is active and you keep that voice, and is permanently destroyed when you delete the voice or your account. You may withdraw consent at any time by deleting the voice or your account.

14.3 Your California privacy rights (CCPA/CPRA)

To exercise these rights, contact hi@mylumee.cn; we respond within the time required by law (up to 45 days under the CCPA).

14.4 Deletion

You can delete your account in-app (Me → Settings → Delete account), which permanently and irreversibly deletes your personal data, including cloud-stored voice models. A limited set of records required by law is kept in de-identified form and then destroyed; we do not represent that we erase all data with no exceptions.

14.5 Cross-border storage

Your information is transmitted to and stored outside your country. Our servers and database are located in Hong Kong, and AI text/voice/image processing and object storage are performed by third-party AI and cloud service providers. We protect information in transit with encryption and apply access controls.

14.6 Crisis support

Lumee offers emotional companionship, not professional grief counseling, therapy or medical advice. If you are in crisis or thinking about harming yourself, call or text 988 (Suicide & Crisis Lifeline, U.S.), available 24/7, or find a helpline for your country at findahelpline.org.