Customer policy
Privacy for families
How Lumi Stories handles child photos, illustrations, orders, support evidence, and website measurement, which service providers help, and how long things are kept.
Effective October 2, 2026 · Version privacy-2026-10-02-v6
Seller, privacy officer, and contact
Lumi Stories is a sole proprietorship owned and operated by Elif Bozokluoglu.
Privacy Officer: Elif Bozokluoglu.
Customer service, privacy questions, access or correction requests, and complaints: lumi@lumistories.ca.
The original child photo
The photo is used only to create your child’s illustrated character. Lumi stores it privately. An AI service reads it to describe visible features, such as hair, eye colour, and skin tone, so the illustration can match your child, and an AI image service creates the character from it. A member of the Lumi team may look at the photo while it is stored if a character needs help.
The original photo is deleted immediately after you approve the character. Checkout and full-book generation remain blocked until the deletion record exists. Later artwork uses the approved character sheet, not the original photo.
If you do not approve a character, Lumi’s daily clean-up deletes the photo within about two days of upload.
These deletions cover Lumi’s own copy. AI service providers that processed the photo may keep their own temporary copies for a limited time, as explained under “How we use AI service providers”.
Recorded permission
Before upload, the uploader separately confirms they are 18 or older and have the parent or legal guardian’s permission to submit the child’s photo for the personalized book. Lumi records the permission version, account, project, upload reference, and server timestamp without retaining the photo in the consent record.
How we use AI service providers
Lumi uses outside AI services to create your child’s illustrated character and the pages of the book. Each one receives what it needs for its task. The requests that create the illustrations do not include your child’s name, exact age, or the opening-page message.
- fal.ai creates the illustrated character from your child’s photo and draws the pages of the book, which it may also enlarge for print. The image models it runs for Lumi include OpenAI’s GPT Image models. For the character it receives the photo; for the pages it receives the approved character and the story artwork, not the photo.
- OpenAI reads the photo to describe visible features such as hair, eye colour, and skin tone. It is also a backup for creating the illustrations, and when used for the character it receives the photo. Lumi may also use it to check text you enter, such as the child’s first name and the opening-page message, before it is printed.
- Kie.ai creates illustrations as a backup for the character and for some of the book’s pages. When it is used for the character, it receives the photo.
What AI service providers keep
AI service providers handle what they receive under their own terms and privacy policies. They may keep their own temporary copies of the photo and of each request for a limited time—often up to about 30 days, and sometimes longer for logs or where they must keep content for safety or legal reasons. Illustrations they create may stay in their storage for longer. Lumi does not control these copies and cannot delete them for you.
Lumi does not use your child’s photo or illustrations to train AI models.
To ask about these providers, or to ask Lumi to delete your information, email lumi@lumistories.ca from your account email.
What is retained
- Inactive unpaid or unapproved project photo/assets: deleted after 30 days of inactivity.
- Minimum approved character-sheet and preview evidence: retained for 180 days, extended only for an active claim or legal hold.
- Print-ready book files: deleted 90 days after delivery, unless a documented active claim or legal hold requires the minimum affected evidence.
- Minimum non-image order, consent, payment, and financial records: retained for six years.
Payments, printing, and support
Stripe handles payment and collects the delivery address. Lumi receives the address and Stripe’s payment references, never your full card details. After the order passes Lumi’s cancellation period and quality checks, Lumi’s print partner, Gelato, receives the print file, the recipient’s name and delivery address, and the account email for delivery updates.
Support may use the order, approved character sheet, approved preview, shipment evidence, customer messages, and claim-specific photos. The original child photo is never retained or used as dispute evidence.
Other service providers
- Vercel hosts the Lumi website and stores photos and book files privately for Lumi. If you choose Allow measurement, Vercel also measures page visits and page speed on public marketing pages.
- Neon hosts Lumi’s database in the United States.
- Clerk runs account sign-in, including any Google or Facebook sign-in you choose, and holds your account email and name.
- Resend sends Lumi’s emails, such as order updates.
Where your information is processed
Lumi’s service providers are based in, or process information in, the United States and other countries. Your information, including your child’s photo, may therefore be stored and processed outside Canada, where it is subject to the laws of those countries, including laws that may allow authorities to access it.
Website and advertising measurement
Lumi records privacy-minimal aggregate arrival counts on public marketing pages unless you turn measurement off using Privacy choices. These records contain only the page category, public story identifier, sanitized campaign labels, and server time. They do not contain an account, project, order, child, IP address, browser fingerprint, full URL, or raw advertising-click identifier.
After you choose Allow measurement, Lumi may use a random first-party session to connect product-funnel steps such as character generation, preview, cart, checkout, and confirmation. The browser cookie expires after four hours. Only a one-way session hash is stored with the event records for up to 90 days, and it is not linked to an account, project, order, child, photo, generated artwork, or gift message.
Lumi also uses optional Meta advertising measurement on public marketing pages. Meta may set the cookies _fbp and _fbc in your browser. Server-side Purchase measurement runs only after you choose Allow measurement. It may include pseudonymous SHA-256 hashes of the account email and account identifier, together with order value, selected public stories, IP address, and browser type. Hashing reduces exposure but does not make those identifiers anonymous.
Lumi also uses Google Analytics on public marketing pages, under the same choice: it runs unless you turn measurement off. Google receives the pages you visit and shopping steps such as viewing a story or starting checkout, and may set analytics cookies in your browser.
Lumi never sends Meta or Google a child’s photo, child’s name, generated artwork, gift message, or other personalization details. Lumi honours a Global Privacy Control signal by keeping website, Meta, and Google measurement off. Turning measurement off does not change the site or personalization experience, and you can change your choice here at any time.
No unrelated reuse
Apart from the advertising measurement described above, Lumi does not use child photos, generated artwork, project data, or order data for model training, marketing, portfolios, creator content, or unrelated reuse without separate explicit permission.
Questions and deletion requests
Email lumi@lumistories.ca using the parent account email and book project details. Do not email child photos. Account deletion is reviewed so active orders and required non-image business records are handled correctly.