Privacy Policy
Luma keeps your data on your devices by default. An account is required only for optional Luma Cloud services.
Last updated: July 24, 2026
The Luma app
Luma does not include advertising, tracking, or product-usage telemetry. Your hosts, settings, snippets, credentials, keys, and session data are stored locally on your device by default. You can use the app without creating a Luma account or sending this data to us.
Optional sync
If you enable sync, Luma creates an end-to-end encrypted copy of the data selected for sync. Depending on your settings, that may include hosts, usernames, snippets, terminal profiles, port forwards, settings, credentials, and private keys. Your sync passphrase stays on your devices and is not sent with the encrypted copy.
With Luma Cloud, we store the current encrypted sync copy and up to 20 prior encrypted revisions. We also store an account identifier, a random storage identifier, storage usage and quota, and account creation, update, and deletion timestamps. We cannot read the contents of the encrypted copies without your sync passphrase.
If you instead configure a local folder, WebDAV, or GitHub Gist, the selected provider stores the encrypted copy and processes related account and request information under its own privacy policy.
Accounts and collaboration
When you create or use a Luma Cloud account, our identity service processes the account and authentication information needed to sign you in. Luma stores authentication tokens in your device's protected credential storage. Signing out removes the local cloud session but does not delete the cloud account or its stored data.
If you use collaborative terminal features, the service stores account identifiers, device identifiers and public encryption keys, room identifiers, room membership and roles, encrypted room-key envelopes, and related creation, revocation, and deletion timestamps. It also stores encrypted room snapshots and temporarily processes encrypted terminal events, presence, and control state to operate the live session. Other room members receive the encrypted session information their role permits them to access.
Service operation and logs
When you use Luma Cloud, collaboration, the website, app updates, or connect to a remote host, the service you contact necessarily receives network and request information such as your IP address, request time, route, response status, and user agent or device information. We and our infrastructure providers process operational logs to deliver, secure, troubleshoot, and prevent abuse of the services. Luma's cloud infrastructure uses service providers, including Cloudflare, for application, database, object-storage, and network services.
Website analytics
This website uses a self-hosted Umami analytics service to understand aggregate traffic. It does not use advertising cookies or build cross-site profiles. The analytics service may process limited technical data such as the page visited, referrer, browser, device type, country derived from an IP address, and a truncated or hashed network identifier. We use this information only to maintain and improve the website.
When you contact us
If you email support or submit a GitHub issue, we receive the information you choose to provide, along with the metadata handled by your email provider or GitHub. We use it only to respond, troubleshoot, maintain security, and improve Luma. Please do not send passwords, private keys, or other secrets.
Data sharing and retention
We do not sell personal information. We disclose information only to provide a feature you request, to service providers acting on our behalf, to protect Luma and its users, or when required by law. Cloud data remains until you delete it or request account deletion, except for short-lived operational data, backups, records we must retain for legal or security reasons, and data retained by another provider you selected. Operational logs and support correspondence are kept only as long as reasonably necessary for their purposes.
Your choices and deletion
You can use Luma without an account, cloud sync, or collaboration. You can disable sync or sign out at any time. To delete a Luma Cloud account and its encrypted sync copies, or to request deletion of support correspondence, contact us at the address below. Deleting a cloud account does not delete copies already downloaded to your devices, shared with collaborators, or stored with a third-party sync provider. You can avoid website analytics by using browser tracking protection or a content blocker.
Changes to this policy
We may update this policy as Luma changes. The date above shows the latest revision.
Contact
Questions or privacy requests can be sent to [email protected].