Skip to content
lumapair✦Open LumaPair
AboutTermsPrivacySafetyCommunityContact

CONNECTION STARTS WITH TRUST

Your information. Clear choices.

This Privacy Policy explains how Cullinan Global Innovations handles personal information when you visit LumaPair or use a member account. It describes the current web service.

Updated September 10, 2026 · Cullinan Global Innovations

Share at your own pace. Publishing a profile makes the details you choose visible to eligible signed-in members. Chat is not end-to-end encrypted. A report can include recent messages if the reporting member chooses to share them.

We do not sell personal information or use private messages for advertising or monetization analytics.

On this page

  1. 1. Who handles your information
  2. 2. Information we handle
  3. 3. Why we use information
  4. 4. Sensitive details and member visibility
  5. 5. Messages, calls, and reports
  6. 6. Verification information
  7. 7. Service providers and other disclosures
  8. 8. Cookies and browser storage
  9. 9. Retention and deletion
  10. 10. Your choices and privacy requests
  11. 11. Adults only and security
  12. 12. Policy updates

1. Who handles your information

Cullinan Global Innovations operates LumaPair and is responsible for the personal information described here. Use Contact & requests to ask about your information or exercise privacy rights. Service providers process information needed to support the functions described below.

2. Information we handle

  • Account and sign-in: account identifiers, email address, sign-in provider information, account status, and authentication/session information. If you choose Google or Apple, we receive the information supplied by that provider for sign-in, such as your name and email. We do not receive your Google or Apple password.
  • Profile and preferences: name, date of birth, gender, city, biography, relationship intentions, interests, optional marital status, philosophies and lifestyle details, social handles, and discovery preferences such as age range, distance, or interests.
  • Location: your chosen city and location you choose to provide for nearby discovery. With permission, the browser supplies location coordinates, which the service uses in an approximate form for discovery. Member profiles show approximate location or distance, not your exact coordinates.
  • Photos: images you upload and their account/storage references. The app resizes and crops images and removes image metadata during processing. Still photos are supported; profile video uploads are not.
  • Connections: likes, matches, message text, reactions, shared prompt answers, date plans, blocking choices, and reports. Call setup uses connection information and call status/timing records.
  • Safety and support: report descriptions, message context a reporter elects to include, moderation reasons, administrator access/action records, restriction records, and information you provide when asking for help.
  • Technical information: IP address and request/network information handled by our hosting and sign-in services, device/browser information used for service delivery, session identifiers, and security or rate-limit records.

3. Why we use information

We use information to create and secure accounts, provide profiles and discovery, support mutual matching and conversations, deliver calls and shared activities, manage member choices, respond to requests, investigate abuse, enforce rules, and comply with legal obligations.

Discovery uses your preferences and profile information to filter or suggest members. It is not a background investigation, and does not establish relationship compatibility. Operational analysis uses aggregate counts, such as members, matches, or reports; private message content is excluded from monetization analytics.

Where laws require a legal basis, ordinary account and communication processing is used to provide the service you request; proportionate security and abuse prevention serve our legitimate interests; legal compliance rests on applicable obligations; and optional uses requiring consent depend on that consent. You may object to processing based on legitimate interests or withdraw consent as applicable. Withdrawing consent does not invalidate earlier lawful processing.

4. Sensitive details and member visibility

Philosophical or religious beliefs, relationship preferences, and details revealing sexual orientation can be sensitive personal information. Optional fields can be left blank or removed. Do not include details you are uncomfortable sharing with other members. Where explicit consent is legally required for sensitive processing, it must be obtained separately; simply reading this policy is not that consent.

A saved profile is not made discoverable until you choose to publish it. A discoverable profile shares the selected profile details and photos with eligible signed-in members. Other members see your age rather than your full date of birth. Your account email and verification number are not shown in profile badges. Social handles are shared only when you enable their sharing.

Messages and shared activities are visible to the participants. Members can copy, screenshot, or disclose information outside the service; we cannot guarantee they will keep it confidential. Pausing discovery limits future discovery exposure, but is not account deletion and does not erase existing conversations or copies.

5. Messages, calls, and reports

Messages are stored to provide your conversation history and are not end-to-end encrypted. Authorized operational access may be necessary to maintain or secure the service, meet legal obligations, or address a support or safety issue.

The administrator interface shows message excerpts submitted with reports, rather than providing unrestricted inbox browsing. When filing a conversation report, the reporter can choose whether to include up to 20 recent messages. Such a report may contain messages from either participant. Access to reported context is recorded in an audit log.

Audio/video calls use WebRTC and may use Cloudflare relay infrastructure. You control browser microphone and camera permissions. LumaPair has no built-in call-recording feature. Connection metadata, such as IP/network information and call timing or status, is processed to establish and support a call. Direct peer connections can disclose a participant’s IP address to the other endpoint. Participants could record using tools outside LumaPair; obtain consent before recording.

6. Verification information

At this policy’s publication, optional SMS verification has been prepared but is not activated. Government-ID and live-selfie checks are not connected. Do not send identity documents, verification codes, or sensitive identifiers by email or chat.

If phone verification is made available, its screen will explain the active method before you choose it. The number is sent to the verification provider to deliver and check a code. LumaPair’s phone-verification design stores a protected number fingerprint, last four digits, verification status, and limited challenge/abuse-prevention records rather than displaying your full number to members. A materially different verification service or biometric/ID process requires updated notice before collection.

Member badges show only which checks have actually completed. They do not show the underlying document or phone number and do not indicate a criminal background screening.

7. Service providers and other disclosures

We use Clerk for authentication and account management, and Cloudflare for hosting, database and photo storage, live connections, security, and call relay infrastructure. Providers receive information needed for those functions. A Google or Apple account is involved if you choose that sign-in method. An external social website receives information when you choose to follow a link to it.

We may disclose relevant information when legally required, to respond to valid legal process, or where law permits and it is necessary to address fraud, abuse, or threats to safety. If the business is reorganized or transferred, relevant information may transfer with the service, subject to applicable safeguards and notice requirements.

Providers may process information in countries other than your own. Where required, international transfers must use an applicable legal safeguard, such as approved contractual terms. Contact us for information about arrangements relevant to your request. We do not claim that all information stays in your home country or that a particular international-transfer certification applies to us.

Payment collection is not currently enabled; we do not collect bank-account or payment-card details through the app. We do not sell personal information or share it for cross-context behavioral advertising.

8. Cookies and browser storage

Sign-in and security services use cookies or similar storage to maintain sessions and prevent abuse. LumaPair also stores a device-level preference to avoid repeatedly showing a dismissed verification reminder. This preference is separate from your account’s verification status.

The current app does not include advertising pixels or a third-party behavioral analytics integration. If optional tracking is introduced, we will provide the relevant notice and obtain consent where required before enabling it.

You can clear cookies and site storage through your browser, which may sign you out or reset local preferences. Browser settings also control location, camera, and microphone permissions. Blocking necessary sign-in storage can prevent account features from working.

9. Retention and deletion

We retain account, profile, photo, and conversation information while needed to provide your account and requested features. We retain reports, support correspondence, security records, and audit information for as long as reasonably needed for their purpose, applicable legal obligations, fraud prevention, or resolving a dispute. We assess the type of information, the reason for keeping it, and legal requirements rather than promising one deletion period for every record.

Contact-form requests are stored for administrative handling and are scheduled for removal 180 days after being marked resolved. A request kept under review for an ongoing matter is retained while needed. Minimal access/action audit records are separate from the request’s text and reply email.

Account deletion removes the account, associated profile/photo records, and associated conversations from active service storage through our deletion process. Safety-report copies, audit records, or limited restriction records may remain where retention is necessary and lawful. Provider recovery copies or backups may persist for their applicable lifecycle; deletion is not a promise of instantaneous removal from every backup. Copies independently retained by another member remain outside our control.

Expired call-setup signals and verification challenges are cleaned up periodically. Call-status records are scheduled for removal after their expiry and a 30-day cleanup window. Deletion failures are queued for retry rather than being treated as a completed deletion.

10. Your choices and privacy requests

You can edit profile details, remove photos, pause discovery, adjust optional sharing and permissions, block or report a member, and use Export my data in your signed-in workspace.

Depending on your location and which laws apply, you may have rights to access, correct, delete, or receive a copy of personal information; withdraw consent; object to or restrict processing; limit certain uses of sensitive information; or appeal a decision about a request. Where applicable, you may use an authorized agent and complain to your privacy regulator. We will not unlawfully discriminate against you for exercising these rights.

Use Contact & requests to request help or account deletion. We may need proportionate information to verify account ownership, protect others’ information, or establish an agent’s authority. We respond within the periods required by applicable law and explain any lawful reason a request cannot be fully fulfilled. Do not send an ID document or password as an initial request.

Because we do not currently sell personal information or share it for cross-context behavioral advertising, there is no such sale or sharing to opt out of. If that practice changes, we must first provide legally required notices and choices, including handling applicable opt-out preference signals.

11. Adults only and security

LumaPair is for adults 18 and older. We do not knowingly permit minors to hold accounts. Report a suspected underage account through the member’s reporting controls or contact us so it can be reviewed and appropriate removal taken.

We use access controls, private media storage, session security, and administrative safeguards to protect information. No service can promise absolute security. Protect your account and devices and tell us about suspected unauthorized access.

12. Policy updates

We will update the date on this page when practices change. Material changes will receive additional notice and fresh consent where required before new processing begins. Contact Cullinan Global Innovations with questions about this policy.

© 2026 LumaPair · Cullinan Global Innovations

AboutTermsPrivacySafetyCommunityContact

For adults 18+. Respect, consent, and care come first.

Privacy Policy | LumaPair