Privacy Policy
Effective Date: 12 September 2026 · Operational Brand: PiccoLumi
- We never sell, rent, or trade personal data or child data to third parties, data brokers, or advertising networks.
- Zero third-party advertising SDKs and zero cross-app tracking (
NSPrivacyTracking = false). - Customer prompts and care logs are never used to train artificial intelligence foundation models.
- You can delete your account in Settings. Deletion is a resumable in-app process.
1. Operating Identity and Scope
This Privacy Policy explains how PiccoLumi ("we", "us", or "our") collects, uses, stores, and protects personal information through the PiccoLumi iOS application and the piccolumi.com website.
PiccoLumi is an adult-directed routine tracking and family care application. All accounts are created and managed exclusively by adult parents and legal guardians aged 18 and older. PiccoLumi is not directed at children under 13 years of age (or under 16 in the European Economic Area and United Kingdom). Children may not register accounts. All child records are submitted solely by authorized adult caregivers.
PiccoLumi is not listed under Apple's "Made for Kids" or Kids Category. Formal corporate entity registration and registered postal address are open items pending corporate registration. Our designated official operational contacts are [email protected], [email protected], and [email protected].
2. Core Privacy Commitments
We keep four promises:
- Zero data sales: We never sell, rent, or trade personal data or child data to third parties, data brokers, or advertising networks.
- Zero advertising trackers: We do not include third-party advertising SDKs or tracking pixels in our mobile application. Our declared Apple tracking status is false (
NSPrivacyTracking = false). - Zero AI training on your data: Artificial intelligence features operate exclusively under commercial enterprise agreements that prohibit the use of your prompts, notes, or care logs to train foundation models.
- Self-service deletion: You can initiate complete account and data removal directly in the app at any time.
3. Information We Collect
We collect only information necessary to deliver family care tracking, developmental summaries, and routine coordination:
A. Account and Sign-In Data
- Identifiers: Email address, parent and caregiver names, and internal cryptographic User ID.
- Authentication: We support sign-in via email one-time verification code, Sign in with Apple, and optional Google Sign-In. We never receive or store your third-party account passwords.
B. Child Profiles
- Profile attributes: Child first name, sex, date of birth, developmental age stage, language, care focus, family roles, and routine preferences.
- Date of birth handling: The exact date of birth is stored in the database solely to compute age milestones. In AI payloads, exact date of birth is transformed and excluded to protect privacy.
C. Routine Care and Tracker Logs
Timestamped care entries across 10 active hub trackers: Sleep, Bottle, Diaper, Nursing, Pumping, Solids, Temperature, Medicine, Bath, and Activity.
Mood is stored as a structured category, not as an eleventh hub tracker.
Potty is logged within Diaper care.
Height, weight, and head circumference are recorded in growth logs. Growth-chart PDFs may also be stored in the Medical Vault.
D. Medical Vault Documents
Parents may upload pediatric health records, growth charts, and PDF documents into the Medical Vault. Vault file bytes live on encrypted cloud storage and are never sent to artificial intelligence APIs. Your device may cache files locally for parent viewing.
E. Photos and Voice Dictation
- Photos: Parents may optionally attach photos within Lumi Chat or the Medical Vault. Photos attached to chat queries are sent only for the immediate visual inquiry and are never retained for model training.
- Voice dictation: Voice input is processed through two optional paths: on-device Apple Speech recognition, or short audio clips in
audio/mp4format processed by enterprise artificial intelligence solely for speech transcription under paid zero-training terms.
F. Billing and Entitlements
Subscriptions and gift passes are processed through Apple StoreKit. We receive transaction identifiers, product identifiers, and renewal expiration timestamps. We never receive, process, or store credit card numbers.
G. Technical and Diagnostic Information
We process device push tokens via Apple Push Notification service (APNs) to deliver authorized family reminders. Diagnostic telemetry includes minimal product interaction events and declared Apple required-reason APIs: UserDefaults (CA92.1) and FileTimestamp (C617.1).
4. Artificial Intelligence Architecture and Data Boundaries
PiccoLumi keeps Lumi Chat and LumiCast technically separate.
A. Lumi Chat (Interactive Parental Assistant)
- Processing Standard: Processed by enterprise artificial intelligence providers under paid commercial business agreements with zero data retention. Your conversations are never used to train foundation models.
- Strict Allowlist Context: Chat context is strictly bounded. The payload includes, in order: parent prompt; localized timestamp and timezone; child first name; age stage; up to 240 characters of allergy profile text, only if that caregiver can view the health profile; structured medicine facts and notes; sex; language; care focus; routine tracker facts; growth measurements; deterministic LumiCast sleep clocks; active care state; Medical Vault document metadata (file bytes strictly excluded); developmental stage context; active modules; family member names and roles; care preferences; recent chat history; consent-gated memory notes; optional photo or audio for transcription. Exact date of birth is transformed and excluded.
- Family Visibility: Lumi Chat threads are visible to authorized adults in the family circle who have been granted Lumi Chat access. Limited Caregivers are strictly excluded.
B. LumiCast (Sleep and Routine Forecasts)
- Deterministic Engine: Sleep clocks, wake windows, and duration estimates shown to parents are generated by PiccoLumi's own engine.
- Contextual AI Evaluations: Periodic evaluations are processed by enterprise artificial intelligence providers under commercial zero-training agreements.
- Stripped Instruments Payload: The AI provider receives only a privacy-stripped payload containing event count tallies across sleep; feeds combining bottle, nursing, and pumping; diaper; temperature; medicine; solids; mood; activity; bath; growth; active care; and profile completion; plus timestamp envelope; current state; longitudinal memory counts and dates; previous anchor; unusual day flag; critical signal tokens; timezone; and developmental stage context.
- Excluded from LumiCast AI: Child name, Medical Vault files, allergy and medication free-text, raw routine notes, and raw timeline logs are completely excluded.
5. Third-Party Service Providers
We work with vetted infrastructure and platform providers to deliver PiccoLumi under strict data protection agreements:
- Cloud Database and Encrypted Storage Providers: Relational database hosting, user authentication, encrypted file storage for private records and Medical Vault documents, and secure edge function execution.
- Apple Platform Services: Application distribution via the App Store, Sign in with Apple authentication, StoreKit subscription billing, Apple Push Notification service (APNs), and optional on-device Apple Speech.
- Enterprise Artificial Intelligence Providers: Lumi Chat processing, voice dictation transcription, and contextual forecast evaluations under paid enterprise terms prohibiting provider data retention and forbidding foundation model training on customer data.
- Website Delivery and Security Networks: Content delivery network, edge caching, and DDoS mitigation for our public marketing website.
- Customer Communication Services: Transactional email infrastructure for marketing waitlist confirmation notices only. Account sign-in verification codes are managed via secure backend channels.
For questions about specific service providers or processing locations, please contact our privacy team at [email protected].
6. Family Sharing and Caregiver Permissions
A family circle may include up to 6 adult caregivers per child profile. Family invitations are initiated by the family Owner via a revocable bearer link shared through the native iOS share sheet. We do not use third-party email invitation services.
Access is governed by three distinct role levels:
- Owner: Complete administrative control, subscription management, caregiver invitations, role assignments, and account deletion.
- Full Caregiver: May view and log routine care entries. Access to Lumi Chat requires an explicit grant from the Owner and the caregiver's active AI consent.
- Limited Caregiver: May view deterministic LumiCast clocks (provided personal AI consent is granted). Limited Caregivers cannot start new forecast evaluations, and are blocked from Lumi Chat, Medical Vault files, and sensitive health profile fields (such as allergy notes).
7. Data Retention, AI Consent, and Account Deletion
A. Retention Schedules
- Chat Threads: Maximum of 40 active chat threads per child, with up to 100 messages per thread. Older threads are closed, and older messages are pruned.
- Deleted Chats: When a chat is deleted, the text is removed immediately. A deletion tombstone record is retained for 30 days to synchronize deletion across family devices, after which it is permanently purged.
- Server Ceilings: Daily digests are retained up to 8 weeks. Sleep decision records are kept up to 14 days. Privacy-minimized forecast evaluations and anonymous merchant click tallies are kept up to 90 days.
- Disaster Recovery Backups: System backups are rotated on standard operational schedules. Final backup retention duration is an open item pending infrastructure finalization.
B. AI Consent and Memory Management
Parents can inspect and clear Lumi memory notes at any time using the in-app memory review sheet. Withdrawing AI consent in Settings stops new AI processing and clears stored memory notes for that caregiver. Previously saved Lumi Chat threads remain visible to authorized family members unless explicitly deleted by the author or Owner, or upon account deletion.
C. Resumable Account Deletion
Account deletion can be initiated at any time directly in the app at Settings → Account → Delete Account. The deletion workflow executes a multi-stage resumable sequence: revoking Apple authorization tokens, cascading database deletion across family and child records, purging stored vault files from encrypted cloud storage, and scheduling background reconciliation tasks to verify complete removal.
8. Regulatory Rights and International Transfers
- GDPR and UK Data Protection: Legal bases for processing are contract performance (Article 6(1)(b)) and explicit parental consent (Article 9(2)(a)) for child care observations, routine logs, and Medical Vault records. You have the right to access, rectify, erase, export your data, or withdraw consent at any time. In accordance with GDPR Article 15(1)(c), you may request the specific identities of all service providers processing your data by emailing [email protected].
- International Data Transfers: PiccoLumi operates using secure cloud infrastructure with facilities located in the United States and other regions. Cross-border transfers from the European Economic Area and United Kingdom rely on standard contractual clauses (SCCs) and contractual commitments ensuring equivalent data protection.
- CCPA and CPRA: California residents have the right to know what personal information is collected, request its deletion, and correct inaccuracies. We do not sell or share personal information as defined by California law.
- COPPA: PiccoLumi is designed for adult parents and guardians. We do not knowingly collect personal information directly from children under 13. Child records are maintained exclusively under parental custody.
- Security Safeguards: All data is encrypted in transit using modern TLS and encrypted at rest using industry-standard cryptography.
9. Updates to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated through an in-app notice requiring parental re-acknowledgement prior to continued use.
10. Contact Us
For questions or privacy requests, please contact our operational team:
Privacy Officer and legal inquiries: [email protected]
Technical Support: [email protected]
General Inquiries: [email protected]