Fair AI portraits that look like you — and privacy you can actually verify. This page explains, in plain English, what we collect, where your photo goes, and the rights you have over your data.
Effective date: January 1, 2026
1. Who we are
LumTale is a web application that turns your photo into a stylized Lumling portrait — a warm, illustrated look we designed ourselves. Our core promise is simple: fair AI portraits that look like you. We built LumTale specifically because most mainstream avatar apps quietly reshape non-white faces to be paler and more "standard." We refuse to do that. We also refuse to hide where your photo goes.
This Privacy Policy applies to the LumTale website and services available at lumtale.com, including our early-access waitlist and our two portrait creation paths, "Door 1" and "Door 2."
LumTale is operated by a small independent team. For any privacy question, you can reach us at hello@lumtale.com. This policy is effective as of January 1, 2026 and governs all personal information we process from that date onward.
2. Door 1 vs. Door 2: where your photo goes
We give you a real choice about privacy, and we make it transparent. The single most important thing to understand is that the two doors handle your photo completely differently:
Door 1 — 100% on your device
Processed locally, never uploaded
Door 1 runs entirely inside your web browser using on-device machine learning (WebGPU and ONNX inference). When you use Door 1, your photo is read by your own device, transformed in your browser's memory, and the result is shown to you or downloaded by you. Your photo is never transmitted to our servers or to any third party. It does not travel across the network at any point.
Because the image never leaves your device, we have no technical ability to store it, review it, or use it for anything. This is the strongest privacy guarantee we can offer, and it is the default for anyone who wants a truly local AI avatar.
Door 2 — Cloud render
Uploaded to a vetted GPU partner
Door 2 produces a higher-quality, illustration-grade Lumling portrait. To do that, the photo you choose to upload is sent from your browser to a vetted, third-party GPU processing partner who renders the portrait on our behalf. This is a genuine upload: the image leaves your device. We disclose it clearly before you upload, link you to the partner's own data-use policy, and we never train on or keep the image afterward.
You decide which door to use. If you do not want your photo to leave your device, use Door 1. If you want the premium cloud render, Door 2 is available with honest, upfront disclosure.
The short version: Door 1 = your photo stays on your device, full stop. Door 2 = your photo is uploaded to a vetted GPU partner for rendering only. Either way, we never train on your image, never sell it, and never whiten or warp your features.
3. Categories of data we collect
We collect only what we need to run LumTale. Here are the categories, in plain terms:
Waitlist email address. If you join our early-access list, we collect the email address you submit through the signup form. That is the only piece of personal information our waitlist requires.
Uploaded photos (Door 2 only). If you use Door 2, the photo you explicitly choose to upload is sent to our GPU partner for rendering. We do not collect photos through Door 1 — they are processed locally and never uploaded.
Basic technical and analytics data. Like most websites, we collect anonymous, aggregated usage data such as pages viewed, broadly approximate region (derived from your IP address), device type, and referral source. This is used only to understand and improve the site, not to identify you personally.
Communications you send us. If you email hello@lumtale.com, we receive and store the content of your message and your email address so we can reply.
We do not collect government identifiers, payment card numbers directly (any future payment is handled by a separate payment processor), biometric templates, or any "special category" data beyond the photos you choose to upload. We do not build facial-recognition profiles of you.
4. How we use your data
We use the limited data we collect for the following purposes only:
To send waitlist updates. Your email is used to notify you when Lumling Studio launches new styles or early-access pricing becomes available. Nothing else.
To render your portrait (Door 2). The uploaded photo is used solely to generate the Lumling portrait you requested, then deleted per Section 11.
To operate and improve the site. Anonymous analytics help us fix bugs, measure performance, and decide what to build next.
To respond to you. If you contact us, we use your message and email address to reply and, where relevant, to resolve a privacy request.
To comply with the law. If we are legally required to disclose information (for example, a valid court order), we will do so only to the extent required.
We do not use your data to advertise to you on other platforms, and we do not share it with data brokers.
5. We never train on, sell, or warp your photos
This is the heart of LumTale's promise, so we want to be explicit:
We do not train on your photos. Images processed through Door 1 never reach us at all. Images uploaded through Door 2 are used only to render your requested portrait and are then removed. We do not add your photos to any training dataset, and we do not use them to improve our models.
We do not sell your data. We do not sell, rent, or trade your email address or your photos to anyone. We are not in the data-resale business, and we never will be.
We do not whiten or warp your features. Our generation is identity-preserving by design. We refuse the industry norm of subtly reshaping non-white faces into something paler or more "standard." Your face stays your face.
Our standing commitment: No whitening, no warping, no training on your photo, no selling your data. These are product guarantees, not marketing fluff — they are reflected in how Door 1 and Door 2 are engineered.
6. Door 2 cloud partner disclosure
Door 2 relies on a vetted third-party GPU processing partner to render higher-quality Lumling portraits. When you upload a photo through Door 2, that photo is transmitted to the partner's infrastructure, processed to create your portrait, and then deleted by the partner according to the retention terms below and in their own policy.
We selected this partner on the basis of their security posture and data-handling commitments. To be fully transparent, we encourage you to read their data-use policy before uploading. Their privacy practices apply to the uploaded image while it is in their hands:
We don't ask you to take our word for it. We reviewed the partner's published data policy (last updated April 1, 2026) and verified the following before routing Door 2 through them:
Processor, not a seller. The partner states that it acts as a "processor" or "service provider" when handling customer data, and that it does not sell or share personal information as defined by U.S. state privacy law.
"Training data" has a specific meaning — and we never trigger it. In their policy, "training data" means images a customer uploads to train a model. We only call their rendering (inference) API — never their training API — so your photo is submitted solely to generate your portrait, never to train or fine-tune anything.
Retention is tied to providing the service. Their policy retains customer data only as long as necessary to provide the service. Our render completes in seconds, and the image is discarded when processing finishes.
Straight talk: we can only promise what we control — we never store your photo on our servers, we never sell it, and we never submit it for training. While the image is with our partner, their published policy applies. If you want your photo to never leave your device, use Door 1 instead.
FAQ: "Will my photo be used to train an AI model?"
Short answer: No — not by us, and not through the Door 2 flow as we operate it.
We never train on your photo, and the partner's "training data" definition only covers images uploaded to their training API — which we never call. Your Door 2 upload is sent to their rendering API once, used to create your portrait, and discarded when processing finishes.
We can't speak for what any third party might do with data outside our control, which is exactly why we keep our own footprint as close to zero as possible: no storage on our servers, no training, no selling, and a fully local alternative (Door 1) that never uploads anything at all.
LumTale remains responsible for choosing and overseeing this partner, and for ensuring your upload is used only to generate your portrait. If you would prefer that your photo never leave your device, use Door 1 instead — no account or upload required.
7. Children's privacy (COPPA)
LumTale is intended for adults and is not directed to children under the age of 13. We do not knowingly collect personal information from anyone under 13. Our waitlist, Door 1, and Door 2 are all designed for users who can lawfully consent to these activities in their jurisdiction.
If you are a parent or guardian and believe a child under 13 has provided us with personal information, please contact us at hello@lumtale.com. We will delete that information as quickly as we reasonably can. Where a user is between 13 and the age of legal majority in their region, we handle their data only as permitted under applicable law (including, in the United States, the Children's Online Privacy Protection Act and, in the EU/UK, the GDPR's rules on minors' consent).
8. California residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you specific rights regarding your personal information.
Right to know. You can request details about the categories and specific pieces of personal information we have collected about you, where it came from, why we use it, and who we share it with.
Right to delete. You can ask us to delete the personal information we hold about you, subject to legal exceptions (for example, information we must keep for security or to comply with law).
Right to correct. You can ask us to fix inaccurate personal information we maintain about you.
Right to opt out of "sale" or "sharing." We do not sell your personal information and we do not share it for cross-context behavioral advertising. Because we do not sell or share your data, no opt-out mechanism is required — but you can always confirm this by emailing us.
Right to non-discrimination. We will not deny you service, charge you different prices, or provide a different level of quality because you exercise your CCPA/CPRA rights.
To exercise any California right, email hello@lumtale.com with "California privacy request" in the subject line. We will verify your identity (typically by confirming control of the email address in question) before acting, and we will respond within the timeframe required by law, generally within 45 days.
9. EU & UK visitors (GDPR)
If you access LumTale from the European Union, the United Kingdom, or the European Economic Area, the General Data Protection Regulation (GDPR) and the UK GDPR apply to the personal data we process about you.
Legal basis for processing
Consent: We rely on your consent for sending waitlist emails and for uploading your photo to our Door 2 partner. You can withdraw consent at any time (for emails, via the unsubscribe link; for uploads, simply by not using Door 2).
Legitimate interests: We rely on our legitimate interest in operating, securing, and improving LumTale for anonymous, aggregated analytics. We balance this against your rights and keep the data non-identifying.
Contract: Where you request a portrait, processing your upload is necessary to provide that service to you.
Your GDPR rights
Right of access — obtain a copy of the personal data we hold about you.
Right to rectification — correct inaccurate or incomplete data.
Right to erasure ("right to be forgotten") — request deletion of your data where there is no overriding reason to keep it.
Right to restrict or object to processing — including objection to processing based on legitimate interests.
Right to data portability — receive your data in a structured, commonly used format.
Right to lodge a complaint with your local supervisory authority (for example, your national Data Protection Authority, or the UK ICO).
To exercise any GDPR right, email hello@lumtale.com. We will respond within one month as required by the GDPR. Note that because Door 1 photos never leave your device, there is simply no data about those images for us to access, correct, or erase — the strongest form of data minimization.
10. Cookies & analytics
LumTale uses a minimal set of cookies and similar technologies:
Strictly necessary cookies. These keep the site functioning — for example, remembering your preference to dismiss a notice. They are essential and cannot be switched off.
Anonymous analytics. We use privacy-respecting, aggregated analytics to understand which pages are useful and where the site is slow. This is not used to build a profile of you, and we do not combine it with other identifiable data.
We do not use third-party advertising cookies, and we do not use tracking pixels that follow you across other websites. You can control or delete cookies through your browser settings at any time; doing so will not break the core experience of LumTale.
11. Data retention
We keep personal data only as long as necessary for the purposes described in this policy:
Waitlist emails: retained until you unsubscribe or ask us to delete them, or until the waitlist is no longer needed (whichever comes first).
Door 2 uploaded photos: transmitted to our GPU partner solely to render your portrait, then deleted by the partner after rendering is complete — typically within hours, and in any case no later than the retention window stated in the partner's policy linked in Section 6. We do not retain copies on our own systems.
Door 1 photos: never stored by us at all, because they never leave your device.
Analytics data: kept in anonymized, aggregated form for a limited period to track site performance.
Support emails: retained only as long as needed to resolve your request and for a short follow-up window, then deleted.
12. Your rights & how to exercise them
Across all regions, you have practical control over your data:
We answer every privacy request we receive and act on it within the legal timeframes described above (45 days under CCPA/CPRA; one month under GDPR). Verification is lightweight and proportionate — usually confirming control of the relevant email address.
13. Security
We take the protection of your data seriously and apply security measures appropriate to the limited data we hold:
Encryption in transit. All connections to LumTale use HTTPS/TLS, so any data exchanged with our servers is encrypted.
Local-first by design. The most sensitive data — your Door 1 photos — never touches our infrastructure, which is the safest possible outcome.
Minimal data surface. We collect as little as possible (often just an email address) and delete uploads promptly, so there is little to expose.
Vetted partners. Our Door 2 GPU partner is selected and monitored for security; uploads are limited to what is needed to render your portrait.
Access controls. The small LumTale team limits access to any stored personal data to what is strictly required to operate the service and respond to you.
No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. We do commit to handling your information responsibly and to notifying you promptly if a security incident affecting your data occurs, as required by applicable law.
14. Changes to this policy
We may update this Privacy Policy as LumTale evolves (for example, if we add a new portrait style or processing partner). When we make changes, we will update the "Effective date" at the top of this page and, for material changes, we will note them here or by email to waitlist members where appropriate. We encourage you to review this page periodically. The version that applies to you is the one in effect at the time we process your data.
15. Contact us
Questions, requests, or concerns about your privacy? We're a small team and we read every message.
For privacy requests, please tell us which right you'd like to exercise (access, correction, deletion, or opt-out of communications) and the email address associated with your request so we can verify and respond quickly.