Legal
Last updated: September 7, 2026
Lumavo Inc. ("Lumavo," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at lumavo.ai, lumavostudio.com, and all related services.
Lumavo serves three groups of people: Photographers — real estate photographers who hold a Lumavo account and use it to run their business; Agents — real estate agents and brokerages who receive delivered media, book shoots, and may hold their own Lumavo agent account; and End clients and visitors — property owners, buyers, and anyone who opens a booking page, a delivery portal, or a published listing website. This policy applies to all three.
Much of the personal information in Lumavo is entered by a photographer about their own clients — agent names, emails, phone numbers, property addresses, and shoot notes. For that information the photographer decides what is collected and how it is used, and Lumavo processes it on their behalf to run the platform. If you are an agent or end client and want your information corrected or removed, you can contact your photographer directly or write to us at hello@lumavo.ai.
From Photographers (account holders):
From Agents and end clients:
Collected automatically:
This is the most important disclosure in this policy, so we will be direct about it. Lumavo does not build or train its own AI models. Every AI feature in the product is delivered by third-party providers under contract with us. To use those features, your photos, video frames, and the text you type are transmitted to those providers for processing and are handled under their terms in addition to ours.
Depending on which features are used, media and text may be sent to:
Some features also send your business context to an assistant so it can answer usefully — for example, Juno receives the message you type, your services, and the date and time zone in order to draft a booking for you to confirm. Juno never completes an action without your explicit confirmation.
We do not sell or license your photos, and we do not share them with anyone other than the providers above and the people you deliver them to.
We do not use your photos to identify individuals and we do not build biometric or facial-recognition profiles. Photo enhancement includes an optional privacy blur that detects and blurs faces and license plates so they are less identifiable; it is a blurring tool, not identification.
When a shoot is delivered, Lumavo records a reference to the delivered photo alongside the original it came from, and keeps an internal quality signal about how that photo performed — for example, whether a photographer downloaded it as delivered, or corrected it afterward with an editing tool. When an editing tool is used, we also record the before and after pair for that edit. This is how we measure whether our processing is getting better or worse.
These records are held in our own systems and are used to evaluate processing quality and improve the service. They are not sold, not shared with advertisers, and not published. We do not train our own models on them, because we do not build models. If a sample were ever to be used to improve a third-party model, that would require review and approval on our side first, and we will update this policy before any such use begins.
If you would prefer your media excluded from this quality-signal collection, email hello@lumavo.ai and we will handle it for your account.
Delivered photos and video are stored on Cloudflare R2 object storage and served from a Lumavo media domain, with some media held in Supabase Storage. Media links are long, unguessable web addresses rather than password-protected files — this is what allows an agent to open a delivery link without an account. Anyone you forward a media link to will be able to open it, so treat those links as you would the photos themselves.
Delivered media does not stay online forever. Each delivered shoot is stamped with a retention date when it is delivered, based on the photographer's plan at that time. As currently configured that is approximately twelve months by default, eighteen months on the legacy Signature plan, thirty-six months on Pro, and effectively unlimited while an Archive Storage add-on is active. An agent media renewal, where purchased, extends the date for that shoot.
We email the photographer roughly thirty days before a shoot's media is due to expire. After the date passes, the stored files are deleted. The record of the shoot — filenames, order history, invoices, and edit history — remains in the account; only the image and video files are removed. Deleted files cannot be restored, so download or renew anything you need to keep.
Raw source clips uploaded to the video editor are working files, not deliverables, and are removed after a short period once they are no longer in active use.
All card processing is handled by Stripe, a PCI-DSS compliant payment processor. Lumavo does not store card numbers or bank account details on our servers. Payment details are transmitted directly to Stripe under their privacy policy and terms, available at stripe.com/privacy. We store references Stripe gives us — a customer identifier, a payment method identifier, the card brand and last four digits, and whether a card is on file.
When a photographer connects their own Stripe account, payments from their agents and clients are charged directly on that connected account, and the customer and payment details for those charges live in the photographer's Stripe dashboard. Where a card is saved for future charges, it is stored by Stripe and charged only for the purposes described at the time it was saved.
We keep our own records of what was charged — amounts, dates, line items, and status — for billing, invoicing, tax, and accounting purposes.
These integrations are optional and are off until a photographer connects them. Connecting one authorizes Lumavo to exchange data with that service on your behalf. You can disconnect any of them from your settings, which revokes our stored access token.
We share information with the following providers solely to operate the platform:
We may also disclose information where required by law, to enforce our Terms of Service, or in connection with a merger, acquisition, or sale of assets, in which case we will notify photographers.
We do not sell your personal information. We do not use the data you put into Lumavo — your photos, your clients, your listings, your invoices — for advertising, and we do not share it with advertisers or data brokers.
One exception, on our marketing pages only. Our public pages — the home page, pricing, comparisons, and the sign-up flow — can load the Meta Pixel, which measures whether our own advertising works. It only loads if you accept advertising cookies when we ask; if you decline, or simply do not answer, it is never loaded and no advertising cookie is set. You can change your mind at any time through Cookie Preferences in the footer, which also deletes the cookies it set.
If you accept, Meta receives what any web page receives — the page address you are on, your IP address, your browser and device type, the referring page, and a randomly generated identifier (_fbp) stored as a cookie in your browser. We send two events and nothing more: a page view, and a one-time signal that an account was created. Neither event carries anything we add about you or your work.
Never on a property website. The listing sites we host for photographers — including any at a custom web address such as 123MainStreet.com — carry no Lumavo advertising cookie, show no cookie banner, and load no pixel, whether or not you have accepted advertising cookies elsewhere. Those pages belong to the photographer and their client, and we do not measure our advertising on someone else’s marketing.
What is never sent, in any event, at any time: your name, your email address, your telephone number, your photos or videos, your clients’ details, and the addresses of properties you have shot. The pixel does not run inside your dashboard, on an agent gallery, or on any listing page — the places where that information exists — so it cannot observe them. This is enforced in our code by an allow-list of public marketing pages rather than by policy alone.
Nor do we use your work in our own advertising. We will not use your photos or videos, your name, your business name or logo, or the addresses of properties you have shot, in any marketing, promotional or sales material of ours — our site, social accounts, case studies, decks or press — without your prior express written permission, specific to that use and withdrawable at any time. Terms of Service, Section 17 states this as a binding term; it is repeated here because it is a privacy question as much as a licensing one.
Lumavo sends SMS through Twilio only where the recipient has explicitly opted in — for example by checking the SMS consent box on a booking form. Opting in means consenting to transactional messages such as booking confirmations, on-the-way notices, and delivery notifications.
Message frequency varies with booking activity — typically 1–2 messages per booking. Standard message and data rates may apply.
You can opt out at any time by replying STOP to any message, which removes your number from future notifications. For help, reply HELP or contact hello@lumavo.ai.
We send transactional email — confirmations, invoices, delivery notices, reminders, and account and security notices. These are part of the service and are not marketing.
Announcement and outreach email sent from Lumavo, such as a product update to account holders, includes a small invisible tracking image that tells us whether the message was opened and how many times. We use this only to judge whether an announcement reached people. Open tracking is not included in ordinary transactional email such as a delivery notification or an invoice. Blocking remote images in your email client prevents the tracking image from loading.
Photographers can also send email to their own contacts through Lumavo. Those messages are sent on the photographer's behalf, carry their branding, and reply to their address.
Lumavo uses cookies that are necessary to run the platform: a session cookie that keeps you signed in, and short-lived cookies that indicate an active support session. We also store preferences in your browser's local storage — things like your dashboard view settings and dismissed prompts.
Our analytics are first-party and stored in our own database. We do not use Google Analytics, advertising pixels, or third-party behavioral tracking, and we do not set advertising cookies. What we record is:
You may block or clear cookies in your browser settings, but signing in will not work without the session cookie.
Because Lumavo schedules shoots at physical properties, it handles location data. Property addresses are geocoded to coordinates so they can be mapped, drive time estimated, and a day's route planned. A photographer's home base address is used as the start and end point of that route. Weather forecasts for a shoot are looked up from the property coordinates.
When a photographer taps arrive, start, or finish in the app, we record that event with a timestamp against the order. This is entered by the photographer — Lumavo does not track a photographer's location in the background, and there is no continuous or passive location tracking anywhere in the product.
Photos may contain GPS coordinates written by the camera. Where present, that metadata travels with the file to our processing providers and may remain in the delivered file.
Authorized Lumavo staff can open a support session and view a photographer's dashboard as that photographer, in order to reproduce and fix a problem. We use this only to operate, maintain, and support the platform.
During a support session:
To be accurate about the limits: masking is applied to list views, so client contact details may still be visible on an individual record a member of staff opens while diagnosing an issue. Support sessions can be disabled platform-wide, and you may ask us not to use one on your account by writing to hello@lumavo.ai.
Photographer account data is retained for the duration of the account and for a reasonable period afterward to allow recovery and to meet legal obligations. On account deletion, personal data is removed within 30 days, except where we are required to keep it — for example financial and tax records of payments that were actually made.
Agent and end-client records — contacts, bookings, orders, and invoices — are retained for as long as the associated photographer account is active. Photographers can delete contacts, orders, and listings from their dashboard at any time.
Delivered media is retained on the schedule described in Section 6 and is deleted when that window closes. Records that a shoot occurred, and its billing history, persist after the files are removed. Agents and end clients can request deletion of their information by contacting their photographer or emailing hello@lumavo.ai.
Data is transmitted over TLS/HTTPS. Our database runs on Supabase with row-level security policies that scope records to the account that owns them, and privileged operations run through server-side routes rather than the browser. Media is stored with our infrastructure providers, Supabase and Cloudflare, which provide encryption at rest as part of their platforms. Administrative actions, including support sessions and account changes, are recorded in an internal audit log.
As noted in Section 6, delivered media is served from unguessable public links rather than password-protected files, so anyone holding a link can open it. We take security seriously, but no system is completely immune to unauthorized access and we cannot guarantee absolute security.
Lumavo is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, please contact us immediately at hello@lumavo.ai.
You can ask us to:
You can opt out of SMS at any time by replying STOP, disconnect any integration from your settings, and decline or revoke browser location permission at any time.
To exercise any of these, contact us at hello@lumavo.ai. If you are an agent or end client, the photographer who entered your information can also action most of these requests directly from their dashboard.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify photographers via email for material changes. Continued use of the platform after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy, how we handle your data, or you want to exercise any of the rights in Section 18, please contact us at:
Lumavo Inc.
Email: hello@lumavo.ai
Website: lumavo.ai / lumavostudio.com
✦ Hi, I'm Juno — Lumavo's AI.
Ask me anything, or just say hi.