Lumi Quest — Privacy Policy
Effective Date: May 25, 2026 Last Updated: May 25, 2026 Applies to: Lumi Quest iOS application, all versions, all regions
Effective Date: May 25, 2026 Last Updated: May 25, 2026 Applies to: Lumi Quest iOS application, all versions, all regions
Lumi Quest ("the App", "we", "us", "our") is an iOS application developed by an independent developer ("the Developer") and distributed through the Apple App Store. We do not operate any backend servers, user accounts, login systems, or data warehouses. The App runs entirely on your device.
Contact: bang77bang88@gmail.com
If you are in the European Union or United Kingdom, the Developer is the "data controller" only to the extent that processing occurs at all — which, as described below, is essentially limited to your relayed AI-inference requests. For all on-device storage, you are the sole controller.
Before the legal-style sections below, here is a plain summary of how Lumi Quest treats your data:
No accounts. We never ask you to sign up, sign in, or hand over an email.
No tracking SDKs. No Firebase, no Google Analytics, no Facebook SDK, no ad networks, no crash-reporting telemetry, no attribution providers.
No advertising. We don't show ads and we don't sell or share data with advertisers. Period.
No servers we own. All your conversations, saved itineraries, and translations are stored only on your iPhone, in Apple's SwiftData database. We cannot access them.
AI inference is the only network call. When you ask Lumi to plan a trip, translate a phrase, or analyze a photo, your input text and selected images travel directly from your device to Replicate (replicate.com), a third-party AI hosting service, which runs Google's Gemini 2.5 Flash model and returns the answer. No copy of your input is kept by us; what Replicate retains is governed by their own privacy policy at https://replicate.com/privacy.
One-tap delete. Settings → Clear All Data wipes everything stored on your device. Removing the App also removes everything.
If anything in the legal sections below contradicts this summary, the summary controls in your favor.
For clarity, here is an explicit list of categories of personal data we do not collect, do not transmit to ourselves, and do not store on any server we control:
Names, email addresses, phone numbers, mailing addresses
Apple ID, Game Center ID, Sign in with Apple identifiers
Advertising identifiers (IDFA, IDFV)
Device fingerprints (we do not record device model, OS version, screen size, timezone, locale, carrier, IP address, or any combination thereof)
Precise or coarse location (no CoreLocation usage; the App does not request location permission)
Health, fitness, or medical data
Financial information, credit cards, banking data
Contacts, calendar entries, reminders
Browsing history outside the App, search history, web cookies
Photos library inventory (we read only a photo you explicitly pick; we do not enumerate or scan your photo library)
Microphone audio outside an explicit translation session
Anything from HealthKit, HomeKit, Wallet, or other Apple frameworks
If, during the course of a single AI-inference request, you voluntarily type or speak any of the above into the App's input field, that text is treated under §5 ("Data You Send to Replicate"), not as data we collect.
The following are stored exclusively on your iPhone, in storage spaces managed by iOS:
Onboarding selections (language, role, interests). Stored in UserDefaults. Used to personalize AI prompts. Delete via Settings → Reset Onboarding.
Conversation history (your prompts + AI replies). Stored in SwiftData (Conversation, Message entities). Used to resume past chats. Delete via Settings → Clear All Data.
Saved itineraries. Stored in SwiftData (Itinerary entity). Used for the Trips tab. Delete via Settings → Clear All Data, or swipe-to-delete a single trip.
Translation history & favorites. Stored in SwiftData (TranslationEntry). Used for the Recent and Favorites tabs. Delete via Settings → Clear All Data.
Custom Replicate API key (if user provides one). Stored in iOS Keychain. Overrides the bundled fallback key. Delete via Settings → Clear All Data.
Last-used UI theme + tab. Stored in UserDefaults. Used for UX continuity. Removed when the App is uninstalled.
We never read these stores from any process outside your device. iOS sandboxing prevents us from doing so even if we wanted to. You can inspect everything we store at: Settings (iOS) → General → iPhone Storage → Lumi Quest.
Uninstalling the App through iOS removes 100 % of these stores, including any Keychain items the App created. iCloud Backup may retain a snapshot of the SwiftData store; to erase that, follow Apple's documented steps for managing iCloud backups.
The App's core features (city itinerary planning, multi-language translation, photo analysis) require AI inference. We do not run the AI ourselves. Instead:
The App sends an HTTPS request directly from your device to https://api.replicate.com/v1/... carrying:
The text of your message (e.g., "Plan a 3-day Tokyo trip focused on AI labs")
For photo analysis: the bytes of the photo you explicitly selected
For translation with voice input: the transcribed text only (the audio is transcribed locally by Apple's Speech framework before transmission when possible)
A short, hardcoded "system prompt" describing Lumi's persona, plus your role/interest selections from §4 (so the AI tailors responses)
Replicate, Inc. routes the request to Google's Gemini 2.5 Flash model hosted on their infrastructure.
The streaming response comes back over the same connection.
What Replicate does with your data is governed by Replicate's privacy policy at https://replicate.com/privacy and Replicate's terms at https://replicate.com/terms. As of the Effective Date, Replicate's public statements indicate they retain prediction inputs and outputs for abuse detection and a limited operational period; they do not train their own models on user inputs.
Because there is no account binding, the only identifier accompanying your request is the API token. By default this is a shared token bundled with the App, so Replicate cannot identify which user sent which request — only that the request originated from a Lumi Quest installation.
If you supply your own Replicate API key in Settings, requests are billed to your Replicate account and Replicate links them to your Replicate identity rather than ours. In that case, Replicate's policy applies to you directly as their customer.
The App declares the following iOS permissions in Info.plist. Each is requested only when the corresponding feature is used, never on launch:
Camera (NSCameraUsageDescription). Asked the first time you tap the photo capture button inside Translate or Plan. Used to take a photo for AI analysis. If denied, the capture button is disabled; you can still pick from Photos.
Photo Library (NSPhotoLibraryUsageDescription). Asked the first time you pick a photo from your library. Used to read the chosen photo's bytes for AI analysis. If denied, the library picker will not open; camera capture still works.
Microphone (NSMicrophoneUsageDescription). Asked the first time you tap the mic button in Translate. Used to capture speech for transcription. If denied, voice input is disabled; you can still type.
Speech Recognition (NSSpeechRecognitionUsageDescription). Asked the first time you use voice input. Used to convert your speech to text via Apple's on-device speech engine. If denied, voice input is disabled.
Local Network. Not requested.
Background Refresh. Not requested.
Push Notifications. Asked only when you tap "Set Reminder" on a saved trip. Used to send local reminders before your departure date. If denied, the reminder feature is disabled.
We never request location, contacts, calendar, health, motion, Bluetooth, HomeKit, or Apple Music permissions.
Notifications are scheduled locally with UNUserNotificationCenter and do not involve any push server. We do not collect a device push token.
Lumi Quest is rated 4+ in the App Store but is not directed at children under 13 (or under 16 in jurisdictions that apply that threshold under the General Data Protection Regulation).
We do not knowingly collect personal information from children, because we do not knowingly collect personal information from anyone. If a parent or guardian becomes aware that a child has used the App and has sent content to Replicate that should be erased, the parent should:
Use Settings → Clear All Data to wipe the device-side store.
Contact us at bang77bang88@gmail.com to confirm deletion of any incidental record we may hold (we do not maintain user-level records, so there is typically nothing for us to delete on our side).
Optionally contact Replicate at privacy@replicate.com to request deletion of any logs they retain.
We do not, and will not:
Sell your data, encrypted or otherwise.
Share your data with data brokers, ad networks, attribution providers, or analytics companies.
License your inputs or AI outputs to model trainers.
Use your inputs to train any model under our control.
Disclose your data in response to non-binding informal government requests; we will respond only to lawful, specific subpoenas, and where legally permitted, we will notify the user first. Note that we hold essentially nothing to disclose.
Because the App holds your data locally rather than in any server we control, the security perimeter is your iPhone's:
iOS sandboxing isolates Lumi Quest's storage from other apps.
SwiftData uses Apple's Data Protection class FileProtection.complete by default (encrypted while device is locked).
The Keychain, where we store any user-supplied API key, is encrypted with the device's hardware Secure Enclave.
All network connections from the App use TLS 1.2 or higher (NSAllowsArbitraryLoads = false in Info.plist).
The shared Replicate API token bundled with the App can be discovered by sufficiently determined parties through binary inspection. We acknowledge this risk and plan to migrate to a server-side proxy in a future version. The token's permissions are limited to running predictions on the specific Gemini model and cannot read user-level account data.
We do not run a bug bounty program at this time, but security researchers may report vulnerabilities to bang77bang88@gmail.com. We will not pursue civil or criminal action against good-faith research that does not exfiltrate other users' data, does not disrupt the service, and gives us reasonable disclosure time.
On-device storage (SwiftData, UserDefaults, Keychain). Retained until you delete it or uninstall the App.
Inference requests we forward to Replicate. We retain none — the App does not log requests.
Replicate's logs. Per Replicate's policy at https://replicate.com/privacy.
Crash reports. We do not collect crash reports. Apple's optional system-level crash sharing (Settings → Privacy & Security → Analytics & Improvements) is independent of us.
We may update this Privacy Policy from time to time. When we do:
The Last Updated date at the top of this document is incremented.
For material changes (e.g., we begin collecting new categories of data, or we add a new third-party recipient), we will surface an in-app banner on first launch after the update, requiring you to acknowledge it before continuing.
Continued use of the App after a non-material change constitutes acceptance of the updated terms. For material changes, you may decline by uninstalling the App.
For privacy questions or security issues:
Email: bang77bang88@gmail.com
We aim to respond within 30 days. For urgent issues (active security vulnerability, suspected data leak), please put URGENT in the subject line; we monitor that channel daily.
Lumi Quest is a personal travel and learning companion. Travel recommendations, museum information, university details, and translations generated by the AI are for informational purposes only and should not be relied on for visa, legal, medical, or financial decisions. Verify critical facts (opening hours, addresses, transit schedules, currency conversions) with official sources before acting.