Lumina is self-hosted. Your photographs and the data derived from them stay on infrastructure controlled by the person who runs this instance. They are never sent to us, because there is no “us” to send them to.
Last updated 12 September 2026.
All of it is held in this instance's own database and object storage.
If you connect Google Drive or Google Photos, Lumina requests read-only access:
drive.readonly — to read the folder you point it at.photospicker.mediaitems.readonly — to read only the photographs you
select in Google's own picker.Lumina reads images so it can copy them into your library. It never writes to, alters or deletes anything in your Google account. Access tokens are stored on this server and used for nothing else.
Lumina's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
This instance is restricted to a single signed-in owner. Photographs are served only to that authenticated session.
Disconnect a source at any time from the Sources page, which deletes its stored authorization. Deleting photographs removes them and their derived data from the library. To revoke Lumina's access to your Google account entirely, visit Google account permissions.
Data is kept until you delete it or the instance is shut down. There is no separate archive and no backup held by anyone else.
Questions about this policy: csa_rv@outlook.com.