← Back to Home

Privacy Notice

Last updated: July 2026

1. Who we are

Lumi's Little AI Lab is operated by Ramona Anghel ("we", "us", "the seller"). We are the data controller for the personal data described in this notice. You can reach us at privacy@lumilittleailab.com.

2. Designed for children — no child data collected

Lumi's Little AI Lab is designed for kids ages 6–10. We do not ask children for names, emails, photos, voice recordings, or any other personal information. There is no child sign-up, login, or chat. Mission progress is stored only in the child's browser (localStorage) and never leaves the device.

3. Personal data we collect from adults

  • Feedback form data (optional): first name, email address, role, testimonial text, and consent choices — collected only when an adult chooses to submit feedback from the For Grown-Ups area.
  • Purchase and billing data: name, email, billing address, and payment details — collected and processed by our payment provider Paddle (see section 6). We receive an order confirmation with the buyer's email and a transaction reference.
  • Restore-access requests: the email address submitted to restore an Explorer Pack purchase, plus a short-lived, hashed restore token.
  • Basic technical data: standard server logs (approximate IP, timestamp, user-agent) generated by our hosting provider for security and abuse prevention.

4. How we use personal data and the legal basis

  • Providing the service (delivering the Explorer Pack, restoring access on a new device) — legal basis: performance of a contract.
  • Improving the app using submitted feedback — legal basis: legitimate interests.
  • Publishing a short testimonial — legal basis: explicit, separate consent given on the feedback form. Adults can withdraw consent at any time.
  • Security, fraud prevention, and abuse detection — legal basis: legitimate interests.
  • Complying with legal, tax, and accounting obligations — legal basis: legal obligation.

5. Cookies and analytics

The app uses only strictly-necessary browser storage (localStorage) to remember settings and mission progress. We do not use advertising cookies or third-party cross-site tracking.

6. Who we share data with

We share personal data only with the following categories of recipients:

  • Paddle.com Market Ltd. — Merchant of Record. Paddle handles the sale, payment processing, billing, tax compliance, invoicing, refunds, and customer service inquiries for all purchases. See Paddle's Privacy Notice.
  • Hosting and infrastructure providers that run the website and database on our behalf, under contractual confidentiality and security terms.
  • Transactional email provider used to send restore-access emails.
  • Professional advisers (legal, accounting) where strictly needed.
  • Authorities where required by law.

We do not sell personal data.

7. Data retention

  • Feedback submissions: kept for up to 24 months, then deleted or anonymised.
  • Purchase records: kept for as long as required by tax and accounting law (typically 6–10 years, depending on jurisdiction).
  • Restore-access tokens: expire within 30 minutes and are deleted shortly after use.
  • Server logs: kept for a short period for security purposes and then rotated.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data; to data portability; to withdraw consent at any time; and to lodge a complaint with your local supervisory authority. To exercise any of these rights — including deletion of feedback you submitted — email privacy@lumilittleailab.com. We aim to respond within one month.

For requests related to your purchase or billing data, you can also contact Paddle directly via paddle.net.

9. International transfers

Some of our service providers may process data outside the UK or EEA. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent mechanisms.

10. Security

We apply appropriate technical and organisational measures to protect personal data, including HTTPS in transit, access controls, row-level security on the database, hashed restore tokens, and least-privilege server credentials. No system is 100% secure, but we work to keep risks low.

11. Our promises about feedback

We never offer rewards in exchange for positive reviews, never include child information in published testimonials, and never change the meaning of an adult's feedback.

12. Changes to this notice

We may update this notice from time to time. The "Last updated" date at the top will reflect the most recent change.