Privacy
Privacy Policy
What we collect, why, who else sees it, and how to get it back or deleted. Regional annexes cover India's DPDP Act, the GDPR and UK GDPR, and US state privacy laws.
Who we are#
StreamLumo is operated by Talluri AI Labs LLP, registered in Karnataka, India ("StreamLumo", "we", "us", "our"). We are the data controller for the personal data described in this policy, except where §6 says otherwise.
Privacy contact: legal@streamlumo.com
This policy covers all StreamLumo surfaces: the website, desktop application, web studio, mobile application, overlay packs, and our cloud services.
What this policy does not cover#
- Payments. Purchases are made from Paddle.com Market Limited as merchant of record. Paddle collects and processes your payment details under its own privacy policy. We never see your full card number.
- Third-party platforms. When you broadcast to YouTube, Twitch, Kick, TikTok, Facebook or Instagram, that platform's privacy policy governs what it does with your stream and your viewers' data.
- Other sites. Links from our site to elsewhere are not covered.
The short version, in a table#
| We collect | Why | Legal basis (EEA/UK) |
|---|---|---|
| Account details | To create and run your account | Performance of a contract |
| Sign-in and security records | To keep your account secure, prevent abuse | Legitimate interests |
| Subscription and billing records | To give you the plan you paid for | Contract; legal obligation (records) |
| Content you save to the cloud | To store and return your recordings | Contract |
| Live session data | To composite and deliver your broadcast | Contract |
| Diagnostics and crash reports | To find and fix faults | Legitimate interests; consent where required |
| How you found us | To understand which channels work | Legitimate interests |
Information you give us#
Creating an account. Email address, display name, and a password (stored only as an Argon2id hash — we cannot read it). If you sign in with Google, we receive your Google account identifier, email address and profile details instead of a password.
Phone number. We currently ask for a phone number at registration. It is stored on your account and used only to contact you about your account where necessary. We do not verify it, we do not use it for marketing, and we do not send it to anyone else.
Your consent record. When you accept the Terms of Service and this policy, we record the date and time of that acceptance. This is how we demonstrate that consent was given.
Profile and workspace content. Display picture, brand assets, scene and layout configurations, and stream destination settings you choose to save.
Support correspondence. What you send us when you contact support, and our replies.
Information we collect automatically#
Sign-in records. Each sign-in creates a record containing your IP address, browser or device user agent, which surface you used, and the sign-in method. We use these to detect suspicious access and to help you recover an account. See §11 for how long we keep them.
Device and diagnostic data. If the application crashes or hits an error, we may receive a crash report containing the error, a stack trace, the application version, and the operating system. We use Sentry and our own self-hosted error-reporting service for this. You can turn diagnostic sharing off in the desktop application's settings.
Bot protection. We may use a bot-protection check at account registration, which examines browser signals to confirm you are not an automated script. Where this is active it is provided by Cloudflare and is necessary to protect the service from automated abuse.
How you found us. If you arrive from a campaign or referral, we record the campaign parameters in the link (such as utm_source) and any advertising click identifier the link carries, along with the referring site and the page you landed on. This tells us which channels bring people to StreamLumo. It is not used to build an advertising profile, and we do not share it with advertising networks.
Live sessions, and people who are not our users#
This section matters, and it is the part most privacy policies get wrong.
Your own broadcast. When you produce a stream on the desktop application, the video and audio are processed on your own machine and sent directly to the platforms you have chosen. It does not pass through us.
Web studio sessions with guests. When you host a session with remote guests, it is different: each participant's camera and microphone are sent to our servers, which decode them, combine them into a single programme, re-encode it, and deliver it to your chosen destinations. Guest audio and video genuinely pass through and are processed by our infrastructure. We hold them only for as long as needed to produce the broadcast, and we do not retain guest media after the session unless the host has chosen to record.
We also keep a session log for each guest — display name, role, and join and leave times — so hosts can see who attended and so we can investigate abuse.
Who is responsible. When you host a session, you are the controller for your guests' personal data and we act on your instructions as processor. Before capturing anyone you must tell them they are being captured, that the session may be recorded, and that their media is processed by our servers — and obtain any consent their local law requires. If you need a data processing agreement, contact legal@streamlumo.com.
If you are a guest and want to know how your data was handled, contact the host first — they decided the session. You can also contact us at legal@streamlumo.com and we will help.
Chat from streaming platforms. If you connect a platform chat, we receive and briefly store the display names and messages of people writing in your chat, so the application can show and moderate them. Those people are not our users. We keep this data only as long as needed for the feature, we never use it for any other purpose, and we do not sell or share it. Platform chat is also subject to that platform's own terms.
What we deliberately do not do#
These are commitments, not marketing:
- We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
- We do not run advertising trackers, ad pixels or third-party analytics on our website or in our applications.
- We do not use your video, audio, recordings or content to train machine-learning models, ours or anyone else's.
- Camera and audio intelligence runs on your device, not ours. Automatic captions, background blur, and camera effects are processed on your own computer, and that media never reaches us. No face template or biometric identifier is created, stored or transmitted to us. Turning on background blur downloads the segmentation model from a public software distribution network (jsDelivr), which sees your IP address but never any video or audio. The one exception is the web studio described in §6, where media is processed on our servers to build the broadcast — but not to analyse or identify anyone.
- We do not make your recordings public. Cloud recordings are private to your account and are only accessible through short-lived links generated for you.
Where your data is stored#
We are based in India and our infrastructure runs in ap-south-1 (Mumbai, India). Some of our service providers operate globally, so your personal data may be transferred to and processed in countries other than your own, including outside the EEA and the UK.
Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — and we take account of the protections in the destination country. You can request a copy of the safeguards we use at legal@streamlumo.com.
How we protect it#
- Passwords are stored only as Argon2id hashes and are never recoverable, by us or anyone else.
- Cloud recordings are stored with server-side encryption using managed keys, are private by default, and are reachable only through short-lived signed links.
- Stream keys and destination credentials are encrypted before storage.
- Access to production systems is restricted and audited.
- Traffic is encrypted in transit.
No system is perfectly secure. If a breach affects your personal data and the law requires it, we will notify you and the relevant regulator within the required time.
Security issues can be reported to security@streamlumo.com — see our security.txt.
How long we keep it#
We keep personal data for as long as we need it for the purpose we collected it, and then delete it. Because how long that is depends on the data, we describe the criteria rather than a single fixed period:
| Data | How long we keep it |
|---|---|
| Account details | While your account is open |
| Cloud recordings and content | Until you delete them, or until your account closes |
| Sign-in and security records | While they remain useful for securing your account and investigating abuse |
| Guest session logs | While they remain useful to the host and for investigating abuse |
| Platform chat messages | Only while the session needs them |
| Crash and diagnostic reports | While the fault is being investigated, and no longer than our error-reporting provider's retention setting |
| Support correspondence | While needed to handle your query and any follow-up |
| Billing records | As long as tax and accounting law requires |
When you close your account, we delete your account and your stored content. Some records are removed immediately and others are removed as part of routine clean-up, so allow a short period for this to complete. We keep only what we must for a legal obligation — most commonly billing records — or what has been irreversibly anonymised.
You can ask us at any time what we still hold about you, and ask us to delete it — see §12.
Your rights#
Wherever you live, you can:
- get a copy of the personal data we hold about you;
- correct anything inaccurate;
- delete your account and your data;
- export your data in a portable format;
- object to or restrict certain processing; and
- turn off diagnostic and crash reporting.
To exercise any of these, email legal@streamlumo.com or use the account settings in the application. We will respond within 30 days. We do not charge for this, and we will not treat you differently for asking.
If you are unhappy with our response, you can complain to your local data protection authority. In India, that is the Data Protection Board; in the EEA and UK, your national supervisory authority.
Children#
StreamLumo is not intended for children under 13, or under 16 in the EEA and UK. We do not knowingly collect personal data from them. If you believe a child has given us personal data, contact legal@streamlumo.com and we will delete the account and its data.
Cookies and similar technologies#
Our website and web application use a small number of cookies and similar storage. Some are strictly necessary — keeping you signed in, and remembering your privacy choices. Where we use anything beyond that, we ask for your consent first if the law where you are requires it.
Campaign attribution on the marketing website. When you first arrive at our marketing website we record how you got here, in your own browser's local storage under the key sl_attr. It holds the campaign parameters in the link you followed (utm_source, utm_medium, utm_campaign, utm_term, utm_content), an advertising click identifier if the link carried one (for example gclid or fbclid), the website that referred you, and the first page you landed on.
Three things about it are worth stating plainly:
- It is first-touch only — written once, on your first visit, and not overwritten afterwards.
- It is first-party. It stays in your browser, we set no identifier of our own in it, and we do not read it from any other site or share it with an advertising network.
- It is sent to us only if you submit a form, so that we can tell which campaign an enquiry came from. If you never submit anything, it never leaves your browser.
You can clear it at any time through your browser's site-data controls, and doing so does not affect your use of the site.
Changes to this policy#
We may update this policy. For changes that materially affect your rights, we will give at least 30 days' notice by email and in the application before they take effect. Other changes take effect when posted. The current version and its effective date are always at /privacy.
Contact#
| Purpose | Address |
|---|---|
| Privacy, data rights, this policy | legal@streamlumo.com |
| Security reports | security@streamlumo.com |
| Everything else | support@streamlumo.com |
Talluri AI Labs LLP, Karnataka, India.
Annexes — regional information
Annex A — India (Digital Personal Data Protection Act, 2023)#
We process your personal data on the basis of your consent, or for legitimate uses permitted by the Act. You may withdraw consent at any time by contacting legal@streamlumo.com or closing your account; withdrawal does not affect processing already carried out.
You have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to grievance redressal.
Grievances: legal@streamlumo.com. We will acknowledge within 24 hours and resolve within the period the Act requires. If you are not satisfied, you may complain to the Data Protection Board of India.
Annex B — European Economic Area and United Kingdom (GDPR / UK GDPR)#
Controller: Talluri AI Labs LLP, Karnataka, India. Contact: legal@streamlumo.com.
Legal bases. Contract — running your account, delivering the service, billing. Legitimate interests — security, abuse prevention, diagnostics, understanding how people find us; we have balanced these against your rights and you may object at any time. Legal obligation — tax and accounting records. Consent — non-essential cookies and any marketing, withdrawable at any time.
Your rights are those in §12, plus the right to lodge a complaint with your supervisory authority.
Transfers out of the EEA/UK rely on Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum.
Automated decision-making. We do not make decisions producing legal or similarly significant effects about you by automated means alone.
Annex C — United States#
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not knowingly process the personal information of anyone under 16 for those purposes.
Depending on your state, you may have the right to know, delete, correct, and obtain a portable copy of your personal information, and to appeal a refusal. Exercise any of these at legal@streamlumo.com. We will not discriminate against you for doing so.
Because we do not sell personal information or share it for cross-context behavioural advertising, and we run no advertising trackers, there is no opt-out for those activities to exercise.
