LumaEcho



Privacy Policy (GDPR)

1. Privacy at a Glance

The following information provides a simple overview of what happens to your personal data when you visit this website.

2. General Information

The responsible party for data processing on this website is:

LumaEcho
Ürziger Str. 7
50969 Cologne
Germany
Email: info@lumaecho.com

3. Data Collection on This Website

Who is responsible for data collection on this website?
Data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.

How do we collect your data?
Your data is collected, on the one hand, by you providing it to us. This could, for example, be data that you enter into a contact form.

4. Audio Recordings and Public Content

Important Privacy Notice:
When you create audio content (posts, echoes, or replies) on LumaEcho, you have the option to set the visibility of your content. Please be aware:

  • Public Content: If you set a post, echo, or reply to "PUBLIC", your voice recording will be accessible and audible to everyone, including visitors who are not logged in to the platform.
  • Followers Only: Content set to "FOLLOWERS_ONLY" will only be accessible to users who follow you.
  • Private Content: Content set to "PRIVATE" will only be visible and audible to you.

Attached Information: For every publicly accessible post, echo, or reply, your username, your profile picture, and the automatically generated transcription of your voice recording (the "comment") are also displayed.

Private Profile: If you set your profile to "private" in your account settings, the "PUBLIC" setting on your posts and echoes no longer applies without restriction: this content — including your username, profile picture, and transcription — is then only visible to yourself and to users you have approved as followers. Content set to "FOLLOWERS_ONLY" or "PRIVATE" is unaffected, since the narrower visibility already applies to it.

By uploading and publishing audio recordings, you consent to the storage and accessibility of your voice data according to the privacy settings you have chosen. Public content will be accessible to anyone, including non-registered visitors. You can delete your audio content at any time.

5. Third-Party Data Processors

To provide our services, we use trusted third-party service providers who process your personal data on our behalf. These processors are contractually bound to comply with GDPR requirements and process data only according to our instructions.

OpenAI (Transcription Service)
We use OpenAI's Whisper API to automatically transcribe your audio recordings into text. When you upload audio content:

  • Your audio file is transmitted to OpenAI's servers for processing
  • OpenAI transcribes the audio into text format
  • The transcription is returned to us and stored in our database
  • OpenAI does not retain your audio data after processing (per their API usage policy)
  • Data transfer occurs to the United States (OpenAI is a US-based company)

Purpose: Transcriptions enable search functionality, accessibility features, and content moderation.
Legal basis: Legitimate interest (Art. 6 Para. 1 lit. f GDPR) and your consent when uploading content.
OpenAI Privacy Policy: https://openai.com/privacy

OpenAI (LumaBot – Automated Community Replies on Daily Prompts)
We use OpenAI's GPT-4o-mini API to let "LumaBot", our automated community companion, respond on the daily writing/speaking prompt ("Daily Prompt"). Unlike the AI text correction and dictation features (see below), you do not need to trigger this processing yourself — it happens automatically:

  • When a new Daily Prompt post is published, its text is transmitted to OpenAI so LumaBot can write a welcoming icebreaker reply
  • The first time you reply to a Daily Prompt post with an echo, the text of your echo (or, for voice recordings, the automatically generated transcription) along with the prompt's text is transmitted to OpenAI so LumaBot can react personally to your reply
  • Every reply generated by LumaBot is additionally screened through OpenAI's Moderation API before publication, to detect and withhold inappropriate content
  • Data transfer occurs to the United States (OpenAI is a US-based company)

Purpose: Automated, personal reactions to encourage community engagement with the Daily Prompt feature.
Legal basis: Legitimate interest (Art. 6 Para. 1 lit. f GDPR) in a lively community feature, as well as your consent through your use of the Daily Prompt feature.
OpenAI Privacy Policy: https://openai.com/privacy

OpenAI (AI Text Correction)
We use OpenAI's GPT-4o-mini API to power the optional AI text correction feature. When you actively tap the sparkle (✦) button to check your draft text:

  • The draft text you have written is transmitted to OpenAI's servers for grammar and style analysis
  • The corrected suggestion is returned to you — you decide whether to apply it or discard it
  • This transmission only occurs when you deliberately trigger the feature — your text is never sent automatically
  • Data transfer occurs to the United States (OpenAI is a US-based company)

Purpose: Improving the quality and clarity of user-generated text content.
Legal basis: Your explicit consent (Art. 6 Para. 1 lit. a GDPR) — the feature is entirely optional and only triggered by you.
OpenAI Privacy Policy: https://openai.com/privacy

OpenAI (Voice Dictation Feature)
We also use OpenAI's Whisper API for the optional dictation feature in the post, echo, and reply text editors. When you tap the microphone icon to enter text by speaking:

  • Your short voice recording is transmitted to OpenAI's servers for transcription
  • The transcribed text is returned to you and inserted at the cursor position in your text field
  • Unlike voice posts (posts, echoes, replies), this recording is not stored permanently — it is used solely for transcription and deleted from our servers immediately afterward
  • This transmission only occurs when you deliberately trigger the feature — no voice post is published
  • Data transfer occurs to the United States (OpenAI is a US-based company)

Purpose: Dictating text as an alternative to typing in post, echo, and reply editors.
Legal basis: Your explicit consent (Art. 6 Para. 1 lit. a GDPR) — the feature is entirely optional and only triggered by you.
OpenAI Privacy Policy: https://openai.com/privacy

Cloudflare (Security and Bot Protection)
We use Cloudflare to provide:

  • Bot detection and protection during login/registration
  • DDoS protection and security services
  • SSL/TLS encryption for data transmission
  • Web application firewall

Cloudflare may process metadata such as IP addresses, request headers, and access logs during authentication processes.
Data transfer: Cloudflare operates globally with servers in the EU and other regions.
Legal basis: Legitimate interest (Art. 6 Para. 1 lit. f GDPR) for security and fraud prevention.
Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy

DeepL (Translation Service)
We use the DeepL API to translate transcriptions of audio content (posts and echoes) into other languages. When you request a translation:

  • The text transcription of the audio content is transmitted to DeepL SE servers for translation
  • DeepL translates the text into your preferred language
  • The translated text is returned to us and displayed to you
  • DeepL does not store your data after processing (per their API terms)
  • DeepL SE is a German company with servers in the EU

Purpose: Translations enable users to understand content in other languages.
Legal basis: Legitimate interest (Art. 6 Para. 1 lit. f GDPR) and your consent when requesting a translation.
DeepL Privacy Policy: https://www.deepl.com/privacy

Data Transfer Safeguards
For transfers to third countries (e.g., USA), we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the EU Commission
  • Data Processing Agreements (DPAs) with all processors
  • Regular security and compliance audits
6. Analytics (Plausible Analytics)

We use the privacy-friendly web analytics service Plausible Analytics to collect anonymized usage statistics (e.g. number of page views, referral source, device type). The service is self-hosted and runs on our own server in Germany — no data is shared with third parties.

Plausible Analytics:

  • does not use cookies or any other persistent browser storage
  • does not collect personal data and does not create cross-device profiles of individual visitors
  • processes IP addresses only briefly to calculate unique visitor counts and does not store them afterwards (hashed with a daily-rotating salt)
  • is fully GDPR, ePrivacy, and CCPA compliant

Since no cookies are set and no personal data is stored, no consent is required under the ePrivacy Directive and Art. 6 Para. 1 lit. f GDPR. The legal basis is our legitimate interest in understanding and improving our website.
More information: https://plausible.io/data-policy

7. Rights of the Data Subject

You have the right at any time to:

  • Request information about your stored data
  • Request correction of incorrect data
  • Request deletion of your data
  • Request restriction of data processing
  • Request data portability
  • Object to data processing
8. Cookies

This website uses cookies. Cookies are small text files stored on your device. We distinguish the following types:

Strictly necessary cookies (no opt-in required):

  • Authentication cookies (JWT access and refresh tokens, HttpOnly)
  • Cookie consent cookie (lumaecho-cookie-consent, 365 days)
9. Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us.

10. Guest Comments

LumaEcho lets visitors who are not logged in ("guests") leave a short text comment under a post. To keep this feature safe from abuse while collecting as little personal data as possible, the following processing takes place:

  • IP address (hashed): Your IP address is never stored in plain text. It is hashed (SHA-256 with a dedicated, server-side secret) and used only to enforce a rate limit and to detect abuse. The hash cannot be reversed back into your IP address.
  • Cloudflare Turnstile: Submitting a guest comment requires passing a Cloudflare Turnstile challenge to block automated abuse — see the Cloudflare entry in Section 5 above for details on this processor.
  • Content moderation: Before publication, the text of your comment is automatically screened through OpenAI's Moderation API to detect and block hateful, harassing, self-harm-related, sexual, or violent content — see the OpenAI entries in Section 5 above for details on this processor.
  • Identity: Your comment is shown publicly under a fixed, server-assigned label ("Guest 1", "Guest 2", …) counted per post. No name, email address, or other identifying information is requested, stored, or displayed.
  • Delete token (local storage): After you submit a comment, a one-time, random delete token is stored locally in your browser (localStorage, key lumaecho.guestCommentTokens) and is never linked to an identity on our servers. As long as it remains there, your own comment shows a ⋮ menu with a delete option. If you clear your browser data or switch devices, this ability is lost permanently — we cannot restore it for you.

Legal basis: Legitimate interest (Art. 6 Para. 1 lit. f GDPR) in preventing abuse of a publicly accessible, unauthenticated feature. Storing the delete token requires no consent under the ePrivacy Directive, since it is strictly necessary to provide a feature you actively requested — the ability to remove your own comment later.

11. Contact

If you have any questions about data protection, please send us an email to: info@lumaecho.com