Skip to content

Privacy Policy

Effective Date: March 18, 2026 · Last Updated: August 27, 2026

Lumitone ("we," "us," or "our"), a Deruvish Labs LLC service operated at lumitone.io, is built around a single principle: your taste data is yours. This Privacy Policy explains what limited data we process, why, and your rights under the GDPR, CCPA, and KVKK.

1. Minimum Data, Written Down Exactly

We keep as little as we can, and this policy states precisely what that is. For a free analysis we store nothing, with one exception you control: the optional rating buttons and, if you unlock the rating bonus, the inputs of that run, stored de-identified unless you choose "Don't store" at the button (section 2.1):

  • We do not store your analysis history as a guest. Without an account there is nothing to attach a history to. If you sign in, the lists you save or buy are kept, and the inputs of each run you make while signed in are kept for model improvement unless you switch that off (sections 2.2 and 3).
  • Each recommendation is computed in real-time and the inputs are gone when the request ends.
  • We do not cache your queries. Every request is computed fresh; your raw inputs are never written to a database or cache.
  • Analysis inputs and results exist only in volatile memory (RAM) for the duration of the computation.

Operational logs, stated plainly. We keep server logs for security and debugging, and we want to be exact about what is in them, because “we only ever log a hash” would not be true:

  • Our application log never writes a username. When we fetch a public profile you asked for, the log line carries a short one-way hash so we can trace one request, and nothing else.
  • Our web server access log records the URL that was requested, which is what every web server does by default. A results page URL contains the public username you typed, so that username appears in this log in readable form. It is a handle that is already public on the platform it belongs to, we never link it to an identity, and these logs are rotated and deleted after 14 days.

One narrow exception, gifts: when you buy a gift, we store the generated recommendation package together with the input it was generated from (the Letterboxd username or the songs/artists you picked for your friend), plus the buyer and recipient email addresses needed to deliver it. This is the only case in which recommendation results persist. In short: for gift delivery we retain only the data strictly necessary to deliver the gift, and we delete it on request. Gift links themselves remain permanent so your recipient can return anytime; the underlying data is removed whenever you ask us by email.

A second narrow exception, uploaded film history exports: if you upload your Letterboxd data export (ZIP) or your IMDb ratings export (CSV), the file is parsed in memory and the raw ZIP and CSV files are not retained after processing: they are never written to our database or to any persistent application or object storage, and our error records carry no file content. What we keep server-side is a derived summary of your film history (catalogue identifiers with rating, liked and watch information, plus counts), because without it a purchase made from that upload could not be delivered or re-shown. It is kept for 24 hours if you do nothing, 7 days once a checkout has been started, and 1 year with a completed purchase, after which it is deleted automatically; you can ask us to delete it sooner at any time. The free result you see stays in your own browser tab only.

2. Data We Process

2.1 Data You Provide

DataWhenRetention
User-provided public profile data (a public username you enter)Requesting an analysisNot stored for free analyses, processed in real-time and deleted after the session. For a purchase, the username is kept with the purchase record (see below).
Songs and artists you pick by handRequesting a film analysisNot stored for free analyses, processed in real-time and deleted after the session. For a purchase, your picks are kept with the payment provider's transaction record so we can deliver and re-show what you bought.
Uploaded Letterboxd or IMDb export (derived viewing history only; the raw ZIP/CSV is not retained after processing and never written to our database or persistent storage)Uploading your data export for a fuller analysis24 hours without a purchase; 7 days once a checkout is started; 1 year with a completed purchase. Deleted sooner on request.
Email address & the inputs you purchased forPurchase (all purchases are guest purchases)Kept with the purchase record for up to 1 year
Improvement inputs: the picks and usernames behind a purchase, a saved list, or any run made while signed in (catalog ids of matched films, picked songs and artists, including any imported from Spotify (CSV upload), Apple Music or Last.fm), linked to your email or accountImproving our recommendations and models. On by default; turn it off any time on your account page or by emailing us, which also deletes these inputs. Guest analyses are never kept for thisUntil you ask us to delete it (email [email protected])
Ratings you choose to give on recommendations (the rated song or film and your like, neutral or dislike). For guests these are de-identified: once your bonus list is delivered, the run identifier is removed and what remains is linked to nothing, no name, email, IP or runPressing the optional rating buttons, where shownSigned in: until you delete the account or switch model improvement off, which deletes them. Guest, de-identified: up to 12 months
The inputs of a run whose rating bonus you unlock as a guest (the catalogue identifiers of the films or the songs and artists that produced the list; no dates, no review or rewatch flags, no star ratings). Stored de-identified with the same batch as your ratings: no name, email, IP, username, account or run identifierPressing the bonus unlock button with storing on. A "Don't store" control sits under the button; choosing it skips this entirely and you still get the bonusUp to 12 months

Why ratings exist. Rating is always optional. Ratings do two things: they build the bonus recommendations unlocked by completing a rated list, and they improve our recommendation models. Ratings are feedback you choose to give about our own output, one button press at a time. A guest rating carries no name, email or IP, and after the bonus is delivered it is de-identified as described above.

Why unlock storing exists. A rating only teaches the model something when it is paired with the taste that produced the list, so at the moment you unlock the bonus we keep the two together: the run's inputs and your ratings, under one random batch identifier that links to nothing else. This is the one way a guest run contributes to model improvement, it is stated right at the button, and the "Don't store" control there switches it off without costing you the bonus. Be aware that a long film history is distinctive in itself; that is why we store bare catalogue identifiers only and never your username alongside them.

2.2 Accounts (Optional), and One Optional Connection

An account is optional. Every analysis, free or paid, works without one. If you sign in (with a one-time link sent to your email, or with Google), we keep: your email address, the lists you save or buy, the inputs those lists were made from (a Letterboxd username, your picks, or imported listening), your saved taste (the films and the songs or artists you picked, so you never re-enter them), your choice about model improvement (section 3), and the sign-in timestamps our authentication provider records. Signing in with Google gives us only your email address and basic profile name; we never post to or read anything else from your Google account. There are no passwords. A purchase made with an email address appears automatically in the account that uses the same address. From the account page you can download everything we hold, switch model improvement on or off, and delete the account with all of its data, yourself and at any time.

We never connect to, read from, or write to your Spotify, Letterboxd, or any other account. Everything the Service knows comes from what you type, pick by hand, or upload yourself, with a few optional imports you control:

Apple Music import (optional). On the music input page you can click Import from Apple Music. This runs entirely in your browser: Apple's MusicKit software loads only after you click, you approve access in Apple's own window, and your recently played songs, frequently played songs, and library are read once. The sign-in token Apple issues stays in your browser and never reaches our servers. What our server receives is only the derived song list (standard recording codes, titles, artist names) to match against our catalog; it is processed in real-time and not stored, with one exception you control: if you later buy a package or save a list, the matched songs from your import are kept with those inputs, linked to your email, and used to improve our recommendation models exactly like hand-picked songs (see section 2.1), unless you turn model improvement off on your account page or by emailing us, which also deletes them. Requires an active Apple Music subscription; how Apple handles the connection on its side is governed by Apple's own privacy policy.

Spotify import (optional). There is no Spotify sign-in and we never connect to your Spotify account. On the music input page you can upload a CSV of your own library that you export yourself (for example with the Exportify tool, under your own login). The file is read in your browser and is never uploaded to us; only song and artist names are sent to our server to match against our catalog, and the file itself is kept nowhere. The matched songs then behave exactly like hand-picked songs: nothing is stored for a guest, and if you are signed in, buy a package or save a list, they are kept with those inputs and used to improve our recommendation models (see section 2.1), unless you turn model improvement off on your account page or by emailing us, which also deletes them.

Last.fm import (optional, where available). If a Last.fm import option is shown, you type your own public Last.fm username and our server reads your public top and recent tracks from the Last.fm API once, matches them against our catalog, and keeps none of it. There is no Last.fm sign-in and we never see your Last.fm password or private data. Last.fm's handling of its side of the request is governed by Last.fm's own policies.

2.3 Purchase Records

Payment processing is handled entirely by our payment provider; we never see or store card numbers. We retain transaction identifiers, tier information, and timestamps as required for accounting and fraud prevention.

2.4 Automatically Collected Data

  • Cookies: we set one of our own, and only after you sign in: a strictly necessary session cookie that keeps you signed in. It carries no tracking and is removed when you sign out. Without an account we set no cookies at all. A results page contacts Spotify only if you activate a player for a track; until then nothing is loaded from Spotify. Once you do, Spotify can set cookies on its own domains, and closing the player does not delete them. Likewise, the music input page contacts Apple only if you start an Apple Music import; during that flow Apple can set cookies on its own domains. Our Cookie Policy explains both and how to avoid them.
  • In-browser records (sessionStorage, not cookies): your picks, the free result computed from an uploaded export, and a small purchase-attempt record live only in your browser tab and are destroyed when it closes. They are listed one by one in the Cookie Policy; none of them is an identifier we can read across visits.
  • Anonymous usage counts: we record which steps of the site get used, so we can see where people get stuck. This is first-party: the data goes to our own database and no third party is involved. We set no cookies for it, we do not record your IP address, and we create no identifier that outlives your browser tab. A random session id is held in your browser's sessionStorage and is destroyed the moment the tab closes, so we cannot connect two visits to the same person. What we store is the name of the step (for example “a result was shown”) plus small non-personal details such as how many items were listed and whether the device is a phone or a desktop. The only free text we keep is a search term that returned no results, so we can find gaps in our catalogue. Kept for up to 180 days, and this is enforced rather than promised: a scheduled job runs every day and deletes anything older.
  • Server security logs: we keep standard web server and application logs, exclusively for security, abuse prevention, DDoS protection, and debugging. They contain the IP address, user agent, timestamps, the requested URL, and our own hashed request identifiers. Web server access logs are deleted after 14 days. Application logs are capped by size rather than by date: we keep the most recent 30 MB per service and older lines are discarded as new ones arrive. As explained in section 1, a public username you type appears in the access log because it is part of the URL; it is never written to the application log. These logs are never used for profiling, analytics, or marketing.

3. How We Use Data

PurposeLegal Basis (GDPR)
Generate AI recommendations in real-time from data you provideContractual necessity
Process payments and deliver purchased content (including gifts)Contractual necessity
Send transactional emails containing your requested resultsContractual necessity
Security, fraud and abuse preventionLegitimate interest
Improve our recommendation models from the inputs behind purchases, saved lists and signed-in runs, from de-identified rating feedback including guest ratings, and from the de-identified inputs of guest runs whose rating bonus was unlocked with storing onLegitimate interest (signed in: opt-out on your account page or by email; guests: a "Don't store" control at the unlock button, and identifiers are never kept)

4. What We Do NOT Do

  • We do not store your analysis history or query results (except gift deliveries and the derived history behind an uploaded-export purchase, both described above).
  • We do not sell your personal data to any third party.
  • We do not share your data for advertising or marketing purposes.
  • We use guest analyses for model improvement through exactly one path, and it is in your hands: if you unlock the rating bonus with storing on, that run's inputs and your ratings are kept de-identified (section 2.1); the "Don't store" control under the unlock button switches it off and the bonus arrives anyway. A guest run you do not rate, or one you rate but unlock without storing, is never used. Purchases, saved lists and signed-in runs are used as before, and you can turn that off at any time on your account page or by email, which also deletes those inputs.
  • We do not track you across other websites, and we use no third-party analytics, advertising pixels, or social media scripts. The anonymous usage counts described in 2.4 are our own, stay on our own infrastructure, and are never shared.

We are not affiliated with, endorsed by, or sponsored by any third-party media or music platforms.

5. Service Providers

We share data only with the following processors, strictly as necessary to operate the Service, and only at the moment of the relevant transaction:

ProviderPurposeData Processed
StripePayment processingEmail, payment details (handled by Stripe), and order parameters including the username or song/artist picks you supplied
ResendTransactional email deliveryRecipient email and message content at the moment of sending; Resend retains standard delivery logs under its own policy
Supabase (EU)Purchase & gift delivery databasePurchase records, gift packages, and the derived viewing history behind uploaded-export purchases, as described above
Hetzner (Finland, EU)Server infrastructureEncrypted data at rest on our servers

6. Data Retention Summary

Data TypeRetention Period
Account (email, consent choice, sign-in timestamps)Until you delete the account (self-service on the account page)
Lists saved to or bought with an account, and their inputsUntil you delete the list or the account
Analysis inputs & results, free analysisNot stored, real-time processing only
Analysis inputs, purchased analysis (the username or the picks you bought for)Kept with the purchase record, 1 year after purchase
Uploaded Letterboxd or IMDb export, derived viewing history (raw ZIP/CSV not retained after processing)24 hours without a purchase; 7 days once a checkout is started; 1 year with a purchase
Fulfilment problem records (payment reference and a short error label, no content)Until the affected order is resolved
Gift recommendation packages (input and generated result)Until the gift is deleted on request
Purchase records1 year after purchase
Anonymous usage counts180 days
Ratings on recommendations (section 2.1)Signed in: until account deletion or improvement opt-out; guest: de-identified at bonus delivery, then up to 12 months
Guest run inputs stored at bonus unlock (section 2.1)Up to 12 months
Web server access logs14 days
Application logsMost recent 30 MB per service, older lines discarded

7. Data Security

  • All traffic encrypted in transit (HTTPS/TLS).
  • Sign-in uses one-time email links or Google, so we store no passwords. Session cookies are scoped to lumitone.io and end when you sign out.
  • Payment card data handled exclusively by our payment provider.
  • Purchase and gift records are accessible only to our backend service role, never from the browser.
  • Servers located in the EU (Helsinki, Finland), accessible only through a reverse proxy.

8. International Data Transfers

Our servers are located in the EU/EEA. Some processors (payments, email) may process data in the United States under the EU-US Data Privacy Framework, Standard Contractual Clauses, or equivalent safeguards.

9. Your Rights

Under the GDPR (EU/EEA), CCPA (California), and KVKK (Turkey) you may request: access to your data, correction, deletion ("right to be forgotten"), restriction of processing, portability, and objection to processing based on legitimate interest. Because free analysis data is never stored, most deletion requests are already satisfied by design; purchase and gift data, and the derived history behind an uploaded-export purchase, will be deleted on request within 30 days. De-identified guest ratings, and the de-identified run inputs stored at a bonus unlock, are linked to nothing we could look you up by, so in practice we cannot tell which rows are yours; the moment to decide about them is the "Don't store" control at the unlock button. If you can nevertheless provide information that identifies your rows (Article 11 GDPR), we will act on your request. You may also lodge a complaint with your local data protection authority (any EU DPA, the California AG, or the Turkish KVKK authority).

With an account, three of these are self-service: on your account page you can download everything we hold about you as one file (access and portability), switch model improvement off (objection, which also deletes the inputs kept for it), and delete the account together with its lists and inputs (erasure). Purchase records then keep their order facts without your email.

For anything else, contact [email protected]. We may ask you to verify your identity first.

10. AI and Automated Decision-Making

Recommendations are generated by machine learning models for entertainment and discovery purposes only. No decisions with legal or similarly significant effects are made about you. Apart from the improvement inputs described in sections 2.1 and 3 (which account holders can switch off at any time), the optional ratings and the guest run inputs stored at a bonus unlock (both in section 2.1, with a "Don't store" control at the button), your data is processed solely to generate the specific recommendations you request.

11. Children's Privacy

The Service is not intended for children under 16. We do not knowingly process data of children under 16; if you believe we have, contact us and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes are indicated by the "Last Updated" date above. Continued use of the Service after changes constitutes acceptance.

13. Contact

Lumitone, Data Protection
Email: [email protected]
Website: lumitone.io