Back to Luumo
LUUMO

COPPA & DPDP Compliance Statement

A plain-language account of what we've built to protect children's data, and what's still in progress.

Last updated: August 19, 2026

On this page

Our approach

Rather than bolt privacy on at the end, every one of the modules below was built directly into the product — the consent gate, the safety scanner, and the data controls are not settings buried in a menu; they run automatically, on every session, for every child.

PII Redaction Before Storage & Before Reaching Our AI Provider

Implemented
  • An automated filter attempts to redact names, phone numbers, emails, addresses, and school names from every message before it is sent to our AI provider.
  • The redacted version — not the original — is what gets saved in our database.
  • This is a real-time heuristic filter, not a certified enterprise DLP scanner; we recommend children avoid sharing sensitive personal details regardless.

Data Minimization by Default

Implemented
  • Session history is off by default for every new child profile.
  • When off, we don't generate learning-insight reports, and we delete a session's conversation content the moment that session ends.
  • Parents can turn session history on or off, per child, at any time.

Real-Time Safety & Distress Escalation

Implemented
  • Every message your child sends is screened by automated content moderation before Luumo replies.
  • A flagged message pauses the lesson, shows your child a calm and reassuring message, and emails you immediately.
  • Safety records are kept regardless of your session-history setting — you can always see safety history for your child.

Right to Access, Export, and Erasure

Implemented
  • Export a full copy of everything we hold for a child — profile, transcripts, insight reports, and safety records — at any time.
  • Delete a child's profile to immediately and permanently remove every session, message, insight report, and safety record tied to it.
  • No voice audio is ever stored — recordings are transcribed in real time and discarded, so there is nothing to purge on that front.

Zero/Reduced AI Data Retention

Partially implemented
  • Every request to our AI provider is sent with a per-request flag asking the provider not to retain it for training or default storage.
  • A per-request flag is a meaningful technical step, but it is not the same as a signed enterprise Zero Data Retention agreement — we are pursuing that agreement separately, and we do not claim a stronger guarantee than the technical flag currently provides.

Full data-handling details

For the complete picture of what data we collect, why, and how long we keep it, see our Privacy Policy. For the account-level terms governing your use of Luumo, see our Terms of Service.

Questions or concerns

If you have a question about how Luumo handles your child's data, or want to report a concern, reach us directly at privacy@theluumo.com — a real person reads every message.

We'll update this page as each module matures — most recently, the Zero Data Retention agreement work described above.
© 2026 www.theluumo.com. Questions about this page? privacy@theluumo.com