Security Policy
Last updated: September 15, 2026
Lumily AI is committed to protecting the security and privacy of our users. This Security Policy describes the measures we take to safeguard your data.
1. On-Device Processing
Lumily's core AI processing is performed entirely on your device. Your photos are loaded into device memory, processed by on-device machine learning models, and the memory is released immediately after processing. No images are ever transmitted to or stored on external servers.
2. Network Security
- All network communications use HTTPS encryption
- Plain HTTP (cleartext) traffic is explicitly forbidden
- Only trusted system certificates are accepted
- No sensitive user data is transmitted over the network
3. Local Data Encryption
When the app stores data locally that requires protection, we use industry-standard encryption methods including:
- AES-256 encryption for stored values
- Hardware-backed key protection where available
4. Machine Learning Models
The AI models used for photo processing are bundled within the app and loaded from local storage. These models are:
- Never uploaded or downloaded during runtime
- Processed entirely in device memory
- Protected by the app's sandbox environment
5. Camera Access
Lumily does not directly access your camera hardware. Instead, we use Android's system camera intent to launch the default camera app. The camera app handles all hardware interactions, and we only receive the resulting photo. This approach minimizes our app's access to sensitive hardware.
6. File Storage
The app stores files in the following locations:
- Photo gallery — Processed images are saved to your device's standard photo gallery, in a dedicated folder
- Temporary storage — Temporary files for camera captures and image sharing, automatically cleaned by the system
No sensitive data is stored in publicly accessible locations.
7. Third-Party Services
We use the following third-party services, each with their own security practices:
- Google Firebase — Analytics and crash reporting (data encrypted in transit and at rest)
- Google AdMob — Advertising delivery (subject to Google's security standards)
- Google Play Billing — Subscription management (PCI-compliant payment processing)
8. Data Breach Response
While the risk of data breach is minimal due to our on-device processing approach, in the event of a security incident, we will:
- Investigate and contain the incident promptly
- Notify affected users within 72 hours if personal data is involved
- Provide clear information about what data was affected and steps you can take
- Take corrective measures to prevent future incidents
9. Reporting Security Issues
If you discover a security vulnerability in Lumily, please report it responsibly through the feedback feature in the app or via email at support.lumilyapp@gmail.com. We will respond to your report within 48 hours.
10. Changes to This Policy
We may update this Security Policy periodically. Any changes will be reflected on this page with an updated "Last updated" date.