Data you provide
Luminary stores the account name, email, date of birth, Terms acceptance time and version, and optional avatar URL you provide; your password in hashed form; saved provider keys in encrypted form; provider model catalog details; character settings and revisions; rooms; conversations, messages, summaries, and memory entries; imported package content; generated-image prompts, results, and settings; and the profile or privacy choices you save. Date of birth is used to enforce the adults-only registration requirement.
Session and recovery records
The application uses session records to keep you signed in. Depending on the active server configuration, those records can include a session identifier, account identifier, IP address, browser user-agent string, session cookie identifiers, and recent activity time. Password-reset requests create a time-limited reset record and send a reset link to the account email.
Cookies and browser storage
Luminary uses authentication and session cookies to operate signed-in features. If you choose Keep me logged in, a secure remember cookie can keep the account signed in for up to 30 days. The documented Analytics QA preference is stored in that browser, and Google Analytics may use its own browser-side identifiers or storage as part of that service.
How the app uses data
Account data supports authentication and account controls. Character, room, conversation, summary, and memory data provide the context needed for the chat and export features you choose to use. Operational records support security and troubleshooting.
Provider keys
Saved Venice and OpenRouter keys are encrypted at rest using the application's encryption key, excluded from normal account serialization, and not displayed back after saving. Luminary uses a key when you validate provider access or request a response from a model available through that provider. You can replace or remove either key in Settings.
AI providers
The context required for a text response, or the prompt and settings required for image generation, is sent to Venice or OpenRouter according to the model and feature you select. OpenRouter may route a request to another model provider. Those services receive data under their own privacy, retention, training, and billing rules. Review the provider and model before sending sensitive information.
Generated images
Generated image files are saved under a public web address with a randomized filename, while their prompts and related settings are saved with the chat message. Anyone who receives or discovers an image URL may be able to open it without signing in. The current service does not automatically remove the separate image file when its message, chat, or account is deleted; contact us to request removal of a generated file.
Memory and summaries
Conversation history and summaries stay with their chat. When cross-chat memory is enabled, Luminary can use saved facts, preferences, plans, or story continuity in later conversations for that character. You can turn memory features off, edit memory, or clear chat history and memory in the app.
Diagnostics
Chat-turn records can include status codes and error details. When anonymous diagnostics are enabled, text and image generation records may also include the request context sent to a provider and the provider response. When diagnostics are disabled, new chat-turn diagnostics omit those request and response payloads.
Analytics
Google Analytics records page paths and basic engagement data on the site. Luminary does not intentionally send provider keys, password-reset tokens, arbitrary query strings, chat messages, or saved memories to Analytics. The documented QA mode disables the Luminary GA4 property in that browser until it is turned off.
Contact and product feedback
The contact form sends the name, email, subject, and message you enter to the project email and the shared Logan Pendragon Forge contact intake. The shared Feedback control accepts anonymous reports, an optional reply email, and separately consented contributor credit. It records the product, release stage, page origin and path, and feedback details; query strings and application state are not intentionally included.
Exports and deletion
Settings provides a JSON export of selected account details, chats, character snapshots attached to those chats, messages, summaries, and memory entries. It does not include passwords, provider keys, sessions, reset records, chat-turn diagnostics, generated-image files or their message metadata, contact submissions, or Feedback records. You can delete messages, conversations, and memory, clear chat history and memory, or permanently delete the account in-app. Account deletion removes the account and associated character, chat, and memory records through the current database relationships and invalidates the current browser session.
Retention
The current service does not publish a fixed retention period for active account data, generated-image files, server logs, session or reset records, backups, contact messages, or feedback submissions. Separate generated-image files, contact submissions, and feedback records are not removed automatically when an account is deleted. Use the in-app controls for active account data and contact us about records not exposed through those controls.
Security limits
Luminary uses application safeguards such as hashed passwords, encrypted provider keys, authenticated account boundaries, and restricted private routes. No online service can promise absolute security. Use a unique password, protect your provider accounts, and rotate a provider key if you believe it has been exposed.
Privacy requests
For privacy questions, account cleanup, accessibility help with these controls, or a deletion request, use the contact form or email loganpendragonmultiverse@gmail.com.