LumaBeat
Privacy Policy
Last updated: 23 August 2026
LumaBeat turns a room full of phones into one synchronised light show. It has no user accounts, no advertising, and no analytics or tracking of any kind. This policy explains, in plain terms, exactly what the app and our server do and do not handle.
- No accounts. You never create one. Neither do your guests.
- Microphone audio never leaves your phone. It is analysed on the device to find the beat and is never recorded, saved, or transmitted.
- Camera images never leave your phone. They are analysed on the device and discarded immediately.
- No advertising, no analytics, no third-party trackers.
- We never sell or share your data. There is nobody to sell it to.
- Everything we do store expires by itself — within 24 hours for a light show, within 30 days for a party invite.
Who this policy covers
It covers everyone who touches LumaBeat: hosts running the mobile app, guests joining a show from their browser, and anyone who responds to a LumaBeat party invitation. Wherever this policy says “we” it means the operators of the LumaBeat app and its server (the “relay”).
There are no accounts
LumaBeat has no sign-up, no login, no password, and no profile. There is nothing to delete because there is nothing to create.
Instead, access works through capability tokens. When a host starts a show, the relay issues two short-lived signed tokens for that specific room: a host token that permits sending cues and blacking out the room, and a join token that lets a device receive the show. Tokens are scoped to one room, expire after 12 hours, and carry no information about who you are — only which room they belong to and what they are allowed to do. Anyone holding the join token can join that show, which is why the QR code should be shared with your guests and nobody else.
Microphone
Audio is never recorded and never transmitted. It is processed moment-to-moment in memory on your own device and then discarded.
The host device listens to the music in the room so the show can follow it. Short chunks of audio (about 21 milliseconds each) are handed straight to the beat-detection engine running on the phone, which measures tempo and energy and then throws the audio away. No audio is written to storage, buffered for playback, or sent over the network — not to us, not to anyone.
The only things derived from sound that ever leave the device are numbers:
- an estimated tempo in beats per minute,
- a timestamp marking where a beat falls,
- energy levels expressed as values between 0 and 1, and
- flags such as “the track is building” or “a drop just happened”.
Those numbers are used only to keep the other phones in the room in time. They cannot be turned back into sound, and nothing about the content of the music, speech in the room, or the identity of a track is captured or inferred.
The microphone is optional. If you decline the permission, the app still works — you tap the beat yourself, or lock a tempo by hand.
Camera
No photo or video is saved to your device or uploaded anywhere. Camera frames are analysed in memory and immediately discarded.
The camera is used for two things, both optional, both entirely on-device:
Joining a show
Scanning a host's QR code to read the join link. Nothing is captured beyond the text encoded in the code.
Light Scan
A host can point the camera around the room while each phone lights up in turn, so the show knows where each phone physically sits and effects can sweep across the real space. Each frame is decoded on the phone into a grid of brightness values, the brightest spot is located, and everything is reduced to a single pair of coordinates between 0 and 1 describing where that phone appeared within the camera frame. The image itself is never written to your photo library or to storage, and is never uploaded. Only the coordinate pair is shared with the room, so the light show can place that phone in the layout.
These coordinates describe a position inside a camera picture. They are not a geographic location. LumaBeat does not request, use, or store location data of any kind.
What the relay stores
The relay is the small server that hands out room codes, keeps the phones' clocks aligned, and forwards the host's cues to the other devices. It stores as little as possible, and everything it stores expires automatically.
| What | Why | How long |
|---|---|---|
| Room record — the room code, its capacity, and the room's capability tokens | So a show survives a server restart or a phone briefly losing signal, and guests can rejoin without a new QR code | 24 hours, then deleted automatically |
| Party record — the party name, its date if you set one, capacity, and whether the host asked guests to bring ID | So an invite link keeps working between the day you send it and the party | 30 days after the party date (or after creation if undated), then deleted automatically |
| RSVP record — the display name a guest typed, and an optional free-text contact string if they chose to add one | So the host can see who is coming and tick guests off at the door. Visible only to that party's host | 30 days, matching the party. Deleted immediately if the guest cancels their RSVP |
| Live show state — each phone's role, battery level, thermal state, and position in the room layout | To run the show and apply the safety limits described below | Held in memory only. Never written to the database; gone when the room ends |
Records are held in a database (Amazon DynamoDB) in the operator's own cloud account, with expiry timestamps enforced both by the database and on every read. All traffic between your devices and the relay is encrypted in transit (HTTPS and secure WebSockets).
Party invitations and RSVPs
RSVPs are accountless. A guest types a name — a first name or a nickname is fine, and it is shown only to the host of that party — and may optionally add a phone number or social handle so the host can reach them. That contact field can be left blank and the RSVP still works.
Each guest receives a private token for their own RSVP, which lets them edit or cancel it later. Cancelling deletes the record straight away. A host holds a separate key for their party; only that key unlocks the guest list.
Battery and thermal information
Each phone in a show reports its battery level, its thermal state, and whether its flashlight is working. This exists purely for safety and for the show: it lets the app stop driving the camera flash on a phone below 20% battery, ease off when a phone is getting warm, and hand flash duty to a cooler, better-charged phone instead. This information lives in the relay's memory for the duration of the show and is never stored in the database, never associated with a person, and never used for anything else.
IP addresses and server logs
Connecting to any server on the internet necessarily reveals your device's IP address. We use it transiently, in memory, to rate-limit public RSVP submissions and prevent abuse. IP addresses are not written to our database and are not used to profile, identify, or track anyone. Ordinary infrastructure logs kept by our cloud provider for operational security are retained on a short rolling basis.
What stays on your device
Some things are stored locally on your own phone or in your browser and are never sent to us:
- A randomly generated identifier created the first time you open the app, used to tell the phones in one room apart. It is not an advertising identifier, is not derived from any hardware serial number, and cannot be used to recognise you in another app or on another website.
- Your preferences — whether you have acknowledged the photosensitivity warning, whether you join without strobe by default, your chosen vibe, and similar settings.
- In the browser guest page, the join credentials for the show you are currently in, so a reload does not kick you out.
Deleting the app, or clearing your browser's site data, removes all of it.
No advertising, analytics, or tracking
LumaBeat contains no advertising SDK, no analytics SDK, no attribution or install-tracking SDK, and no crash-reporting service. Nothing you do in the app is measured, profiled, or reported. There are no cookies used for tracking on the guest web page, and no third-party scripts run on it.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, under the California Consumer Privacy Act or any comparable law. We have never done so and have no mechanism to do so.
The app communicates with exactly one service that we operate — the LumaBeat relay — and with nothing else.
Children
LumaBeat is not directed at children under 13 and we do not knowingly collect personal information from them. The app has no accounts, no advertising, no profiling, and no messaging between users, and the only personal information it can receive at all is a display name someone chooses to type when responding to a party invitation.
If you believe a child has submitted a name or contact detail through a LumaBeat party invite, contact us at the address below and we will delete it promptly. A host can also delete any RSVP from their own guest list, and every RSVP record expires within 30 days regardless.
Your choices and rights
- Permissions. The microphone and camera are both optional and can be refused or revoked at any time in your device settings. The app remains usable without them.
- Your RSVP. If you responded to a party invite, you can edit or cancel it from the same link. Cancelling deletes the record immediately.
- Deletion. Everything expires on its own — 24 hours for a room, 30 days for a party. If you want something removed sooner, email us and we will do it.
- Access. Because there are no accounts, we generally hold nothing tied to you as an individual. If you believe we hold something about you, write to us and we will look, tell you what we find, and delete it on request.
Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA — including access, correction, deletion, and the right to complain to a supervisory authority. Where the GDPR applies, our lawful basis for handling the small amount of data described here is legitimate interest in operating the service you asked for, and, for a party RSVP, performance of that request. Contact us using the address below and we will honour any such request.
Photosensitivity
LumaBeat produces rapid flashing light. A small number of people may experience seizures or migraines when exposed to flashing lights, even with no previous history. A warning is shown before any strobing content is reachable, and every device can join in a no-strobe mode that renders soft, non-flashing effects instead. The host can black out every phone in the room instantly at any time.
This is a safety note rather than a privacy matter, but it belongs anywhere the app is described. Your choice to join without strobe is stored on your own device only.
Where data is handled
The relay runs on cloud infrastructure operated by Amazon Web Services. Depending on where you are, the limited data described above may be processed in a country other than your own. It is encrypted in transit, and none of it is shared with third parties for their own purposes. Our cloud provider acts solely as a processor on our behalf.
Changes to this policy
If this policy changes in a way that affects what we handle, we will update the date at the top of this page and, where the change is significant, note it in the app's release notes. This page always carries the current version.
Contact
Questions, deletion requests, or anything else about privacy: privacy@<domain>
Before publishing: replace privacy@<domain> above
(and the mailto: link) with the real contact address, and confirm the same
address is entered in App Store Connect and the Google Play Console.