LumiCore Privacy Policy — External Beta

Maintainer: DEEPAI
Contact: zhyi@dpai.com
Version: 2026-10-06.1

1. Product and data flows

LumiCore App connects to a computer workstation you select. The assistant's execution, history and long-term memory primarily reside there. Messages, recordings, images, files and context you choose to share may be sent to the workstation and then processed by its configured model, speech or network services.

Before sending relevant new content from this phone, the App displays known recipients and purposes and requests consent. Updated Servers report their configuration; for older Servers you must provide the actual service information. Changes to the service disclosure or policy version require renewed confirmation. Connecting and reading history do not by themselves authorize new AI submissions.

2. Information stored on this phone

The App stores assistant entries, preferences, conversation caches, drafts, recordings, attachments, speech caches and consent records locally. Pairing private keys and security-proof material use system secure storage. Model and ASR API keys are managed by the workstation and are not provided to the phone.

Clearing phone caches does not delete computer-side history or memory. Removing an assistant entry is not deletion of its workstation. Workstation data must be managed on that workstation.

3. Connect service

QR enrollment and pairing provide the selected Connect service with a public-key identity, security proofs, pairing relationships, necessary device names and connection information. The service processes source IP addresses, connection times, traffic and security records for enrollment, signaling, relay, rate limiting and abuse prevention. The official Connect service currently runs in Germany; self-hosted services are the responsibility of their operators.

QR session content uses end-to-end encryption. Connect does not store plaintext message, recording or attachment bodies. Connection and pairing metadata are separate from encrypted content. Protection for ordinary WS connections depends on WSS and the selected network; not every WS connection is end-to-end encrypted.

Unpairing removes the corresponding access relationship. Device enrollment, security proofs and necessary security records may remain. Temporary challenges and invitations are cleaned up according to expiry. Contact us to request deletion of persistent enrollment records; we verify requests and exclude records required by law or necessary to handle security incidents.

4. Model, speech and other services

Models may receive messages, relevant history, memory, attachment content and enabled context. Speech recognition receives recordings you submit; speech synthesis receives text to be spoken. Search and other tools may share information needed for your task with relevant websites or services.

Review each assistant's Data processing and consent page. Custom proxies and workstation-local endpoints may call other upstream services; a local endpoint does not establish that processing is entirely offline. Disclosures come from the workstation or your declaration. We cannot independently verify every downstream destination of a self-hosted service.

Third-party retention, processing locations and model-improvement practices are governed by their policies and your arrangements with them. Do not submit content unsuitable for those services. DEEPAI does not sell personal data or use it for cross-app advertising tracking.

5. Optional permissions and sharing

Camera access supports QR scanning; microphone access supports intentional speech input. Location, calendar events, step counts and now-playing information are controlled by their system permissions and App sharing settings. You may leave optional sharing disabled and use features that do not depend on it. Device-status sharing can be disabled in settings.

Model, OS and App version information identifying a paired terminal is provided to the connected workstation. The terminal number reuses the existing pairing identity, not a hardware serial number or advertising identifier. These details are not used for cross-app tracking.

6. Retention, deletion and withdrawal

Phone data remains until you clear it, remove the relevant entry or uninstall the App. System secure storage, backups and workstation copies may not be deleted at the same time. Workstation history, memory, files and logs are controlled by its administrator.

Withdraw consent for an assistant entry in Data processing and consent to stop subsequent messages, recordings, uploads and speech-synthesis requests from this phone. Withdrawal does not recall previously transmitted or processed data or automatically stop work initiated through other clients or background tasks. Third-party deletion may also require contacting that provider.

DEEPAI processes data necessary for Connect operations, security and support requests you voluntarily submit. Contact zhyi@dpai.com to request access to or deletion of records we maintain, identifying the relevant terminal or workstation. Do not email API keys, private pairing keys or passwords. We verify requests and communicate the outcome.

7. Review demonstration environment

DEEPAI may provide a review workstation isolated from personal workstations. The maintainer manages its conversations and logs to verify functionality and troubleshoot issues. Use only demonstration data, not personal or sensitive information. Demo data is removed during environment resets, post-review cleanup or verified deletion requests. Do not publicly redistribute review access credentials.

8. Feedback and updates

DEEPAI uses feedback you intentionally email to respond and troubleshoot. Review email content and attachments before sending; the App does not automatically upload full conversations or recordings as feedback. We update this policy when services or purposes change and request renewed consent when required.