← Back to LumaDeck

Privacy Policy

Last updated: 21 August 2026 · Effective date: 12 August 2026

This Privacy Policy explains how CJ Development ("we", "us", "our"), the operator of LumaDeck, collects, uses, and protects your personal data when you use the LumaDeck web application and related services (the "Service"). We comply with the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and Spanish data protection law (LOPDGDD).

1. Data Controller

Jaime Constán Nava, trading as CJ Development (sole trader)
Tax ID (NIF): 73998352S
Address: Cantarrana 1, 46137 Playa de la Pobla de Farnals, Valencia, Spain
Email: privacy [at] lumadeck.app
Website: lumadeck.app (also reachable via lumadeck.es)

2. What data we collect

2.1 Account data

2.2 Usage data

2.3 Newsletter and launch-list data

If you voluntarily join a LumaDeck newsletter or launch list, we store your email address, language, signup source, the consent wording version, consent and withdrawal timestamps, and random internal identifiers. We also keep an append-only history of consent and unsubscribe events so we can demonstrate and respect your choice. Registration for a LumaDeck account or receipt of the welcome gift does not subscribe you to marketing.

Every marketing or launch email includes a signed unsubscribe link. The link contains no email address or other direct personal data. Opening it does not unsubscribe you; the confirmation button or a standards-compliant one-click request does. After withdrawal, we keep the minimum suppression record needed to ensure that we do not send further marketing to that address unless you explicitly subscribe again.

2.4 Payment data

We do not store your card details. Payments are processed directly by Stripe, a PCI-DSS Level 1 provider. We only retain a Stripe customer ID and subscription status to manage your account.

2.5 Audio and microphone

If you grant microphone access, the audio is processed locally in your browser for visual reactivity. No audio is transmitted, recorded, or stored on our servers.

2.6 Cookies and local storage

LumaDeck does not set first-party cookies, does not show ads, and does not use advertising cookies. Stripe's payment library is not loaded during normal use of the visual engine. If you are signed in and choose to start a payment, Stripe.js is loaded for Checkout and Stripe may use cookies or similar technologies and receive transaction, device and connection information for fraud prevention, authentication, security, and payment-service analytics. Stripe states that these fraud signals are not sold or shared with advertisers. See Stripe's Privacy Center.

What we do use is first-party local storage, kept in your own browser:

2.7 Analytics

We measure how the Service is used so we can improve it. Both analytics systems run on our own infrastructure (OVH, France), under CJ Development's direct control. No analytics data is sent to Google, Meta, or any advertising network.

Neither system records the audio from your microphone, and neither uploads your media. See 2.5 and 2.6.

3. Legal basis for processing

4. How we use your data

5. Data sharing

We share data only with processors necessary to deliver the Service:

Your account database and our analytics remain on our own servers. We run Supabase as self-hosted software on our OVH machine in France — we do not use Supabase's cloud, so your data is not sent to Supabase as a company. The same goes for our analytics, which run on our own infrastructure. Email recipient data and message content are sent to Resend only when an email must be delivered. (Previous versions of this policy listed Supabase as an external processor. That was inaccurate: the data has always stayed on our own server.)

We never sell your personal data, and we do not share it with advertising networks.

6. International transfers

Your account database and our analytics are stored in the EU (France). Data may reach the United States through Stripe when you start a payment, through Resend when we deliver an email, and through Google only if you sign in with Google. Resend states that its primary processing takes place in the United States and incorporates the European Commission's Standard Contractual Clauses into its DPA for transfers not covered by an adequacy decision; it also states participation in the EU-US Data Privacy Framework. Stripe describes its applicable transfer safeguards in its privacy documentation.

7. Data retention

8. Your rights (GDPR)

You have the right to:

To withdraw marketing consent, use the unsubscribe link included in every launch or product email; the change is applied immediately by our system. To exercise any other right, or if the link does not work, email privacy [at] lumadeck.app. We respond within 30 days.

9. Security

We use industry-standard measures: TLS 1.3 in transit, Row-Level Security on the database, signed webhooks for payment events, and secrets kept out of the code base. No system is 100% secure, but we work continuously to protect your data.

10. Children

LumaDeck is not directed at children under 16. We do not knowingly collect data from minors. If you believe a child has registered, contact us.

11. Changes to this policy

We may update this policy. Material changes that reduce your rights or expand how we process personal data will be announced via email or in-app notification at least 30 days before they take effect. Accuracy corrections and clarifications may apply when published.

12. Contact

Questions? Email privacy [at] lumadeck.app or visit our contact page.