Privacy

Lumbus Live Privacy Notice

This notice explains what Lumbus Live collects and why, and adds to the Lumbus Privacy Policy, which covers every Lumbus product and your rights. Lumbus Technologies Limited is the controller for both.

Read together with the Lumbus Privacy Policy. Last updated 28 August 2026.

1. What Lumbus Live collects

  • Your account — email, name and sign-in method, shared with the rest of Lumbus.
  • Your phone number, only if you turn on text alerts. Only you can see it, and switching alerts off removes it.
  • Stream keys for the destinations you add — encrypted at rest with a key specific to your studio, decrypted only for your studio machine, and shown to you only as the last four characters.
  • Your studio set-up: scenes, overlays and media you upload, destinations, automation settings, schedule, team members (including the email address of anyone you invite) and the audit log of who did what.
  • Studio telemetry: bitrate, round-trip time, dropped frames, scene switches, engine status and region — what the dashboard shows you, kept as session history.
  • Recordings, only when you switch recording on.
  • From the Lumbus Live app: a push-notification token and basic device details, so alerts reach you.
  • Data-plan usage per connection and pool, and — when we ship kit — your delivery address and the rental or purchase details.
  • Support conversations with us.

2. What we don’t collect

We don’t keep your video. Your stream passes through your studio to the platforms; nothing of it is stored unless you turn recording on. We don’t watch your stream, and chat commands are acted on by your studio, not stored beyond the audit entry.

3. Why we use it

  • To provide the service you asked for — running your studio, delivering your stream, moving data through your pool, shipping kit (performance of a contract).
  • To keep you streaming — alerts when your signal drops or your pool runs low, fraud and abuse prevention, service health (our legitimate interests, balanced against yours).
  • With your consent — text alerts, and any marketing about Lumbus Live, which you can withdraw at any time.
  • To meet legal obligations — records we must keep as a UK company.

4. Who handles it for us

We use a small number of providers under contract, each only for the purpose named:

  • Supabase — accounts and database.
  • Vercel — hosting of the website, dashboard and the API the app uses.
  • Cloudflare — recordings storage (R2) and the bot check on our forms.
  • Twilio — text alerts, if you turn them on.
  • Expo — push notifications to the Lumbus Live app.
  • Resend — email.
  • The studio machines in the region you choose, run for us by our hosting providers there.
  • Our connectivity supplier and the mobile networks your connections use — connection identifiers and usage, so the data plan works and is billed correctly.
  • A payment processor, once billing launches; we’ll name it here before the first charge.

We don’t sell your data and we don’t share it for anyone else’s marketing.

5. Where it’s kept

Accounts and studio data are held in the UK and the EU. Your studio itself, and any recordings, live in the region you picked for it (for example Tokyo or Frankfurt), because that’s what keeps your stream fast. Where data leaves the UK or EU we rely on adequacy decisions or standard contractual clauses.

6. How long we keep it

  • Recordings: 7 days on Cloud, 30 days on Cloud Pro (longer with a storage upgrade), then deleted; 7 days after a studio ends, all of its recordings are deleted.
  • Stream keys: until you remove the destination or destroy the studio.
  • Phone number: until you switch text alerts off.
  • Session history, telemetry and the audit log: while your studio exists.
  • Push tokens: until you sign out of the app, or 30 days after the app last checked in.
  • Account, billing and kit records: as set out in the Lumbus Privacy Policy and as UK law requires.

7. Your rights

You can ask to see, correct, export or delete your data, object to how we use it, or withdraw consent, as described in the Lumbus Privacy Policy. Write to live@getlumbus.com and we answer within 30 days. You can also complain to the UK Information Commissioner’s Office (ico.org.uk).

8. Security

Everything travels encrypted. Stream keys are encrypted at rest with a per-studio key. Access inside Lumbus is role-based and logged, and your studio’s own audit log shows every action taken on it.

9. Changes and contact

We update this notice when Lumbus Live changes; the date below tells you when. Questions: live@getlumbus.com. Last updated 28 August 2026.