Account and data
Privacy policy
App concerned: Lumixi (be.fobdev.lumixi), available on Google Play. This policy describes the data processed by the app and by the service behind it.
About this translation
This is a courtesy translation. The French version is the authoritative text. Lumixi is published from Belgium and the policy that legally binds us is lumixi.app/confidentialite. If the two versions ever differ, the French one prevails.
That French page is also the URL declared to Google Play. Your rights are identical whichever version you read.
The essentials
- Video and sound are stored nowhere. They travel encrypted from one phone to the other and are recorded on no Lumixi server, neither by us nor by any provider.
- No account is required. Lumixi works with an anonymous technical identity. Signing in with Google is optional.
- No advertising, no advertising trackers, no data resale. The app contains no advertising kit and no behavioural analytics. This website measures its audience and its speed without cookies and without profiling — see measurement on this site.
- Service data is hosted in the European Union (Sweden), with Supabase.
- You can delete everything yourself, immediately, from the app or from lumixi.app/en/delete-account.
Who is responsible
The data controller is Florian Parduyns, a natural person, publisher of the Lumixi app and holder of the Google Play developer account under which it is published. The controller's postal address is the one Google shows in the “Developer contact” section of the Lumixi listing on the Play Store; it is provided on request.
For any question about your data, or to exercise your rights: privacy@lumixi.app. No data protection officer is appointed: the nature and volume of the processing do not require one within the meaning of Article 37 GDPR.
Lumixi is a monitoring aid intended for adults. It is not a medical device, not an alarm system, and it never replaces the presence of an adult.
Video and sound: the most important point
Lumixi establishes a direct WebRTC connection between the Camera phone and the Monitor phone. Image and sound pass from one device to the other, encrypted end to end by the DTLS-SRTP protocols. They are not recorded, copied or analysed on any server. Lumixi has no recording, export or stream-sharing function.
Two honest qualifications. First, so that the two phones can find each other, technical signalling messages (session descriptions and network candidates, which contain IP addresses) pass through our real-time channel at Supabase. They contain neither image nor sound, and do not outlive the session.
Second, when the two phones cannot reach each other directly — some mobile or corporate networks prevent it — a TURN relay server forwards the packets. It relays them encrypted, unable to read their content, and does not keep them. Sound, motion, cry and covered-face detection run entirely on the Camera phone: only the result (an event type and its timestamp) is sent, never the excerpt that triggered it.
What is processed, why, and for how long
| Data | Why | Legal basis | Retention |
|---|---|---|---|
| Technical identity Random installation identifier, anonymous Supabase session |
Tell one installation apart, apply access controls, run the service | Performance of the contract (Art. 6(1)(b)) | Until the account is deleted. An anonymous account left inactive for 7 days is deleted automatically. |
| Google account Only if you connect it: email address, Google identifier, account name and profile picture address, sent by Google at sign-in |
Recover your subscription and your cameras after reinstalling, share Premium within the household. Lumixi uses only the email address and the identifier; the name and picture are neither displayed nor used. | Performance of the contract (Art. 6(1)(b)), for a feature you enable freely | Until the account is deleted, which you trigger yourself |
| Devices and pairings Device name, camera/monitor role, internal identifiers, camera labels, household |
Recognise authorised devices, manage the household and the selected camera | Performance of the contract (Art. 6(1)(b)) | Until the account or the device concerned is deleted |
| Pairing code The temporary code behind the QR code |
Pair a monitor with a camera | Performance of the contract (Art. 6(1)(b)) | 10 minutes. After that, the code is deleted from the database. |
| Connection signalling WebRTC session descriptions and network candidates (IP addresses included) |
Establish the direct link between the two phones | Performance of the contract (Art. 6(1)(b)) | For the duration of the handshake. Nothing is written to the database: these messages pass through a real-time channel and disappear with the session. |
| Detection events Type (sound, motion, crying, covered face, disconnection, reconnection), timestamp, measured level |
Show activity on the monitor and trigger alerts | Performance of the contract (Art. 6(1)(b)) | Until the pairing or the account is deleted. No audio or video excerpt is attached to them. |
| Notification token Push token of the monitor device |
Alert you when a detection triggers | Consent (Art. 6(1)(a)), given through the Android permission and revocable at any time | Until notifications are refused, the token becomes invalid, or the account is deleted |
| Lumixi Premium subscription Product, status, start and expiry dates, renewal, fingerprint of the Google Play purchase token |
Verify the trial or the subscription, authorise the right monitor, prevent fraud | Performance of the contract (Art. 6(1)(b)) and legitimate interest in fraud prevention (Art. 6(1)(f)) | Until the account is deleted. We keep a fingerprint of the purchase token, never the token itself. |
| Operational measurement First and last activity dates of a device, monitoring sessions (start, end, connection type), with no content |
Check that the service works, size the infrastructure, diagnose outages | Legitimate interest (Art. 6(1)(f)): knowing whether the service holds up, with no profiling and no advertising tracking | Until the account or the device is deleted |
| Technical logs Timestamps, error codes, IP addresses used to connect to the servers |
Security, diagnostics, abuse prevention | Legitimate interest (Art. 6(1)(f)) | Kept by our hosting providers according to their technical cycle, in the order of a few days to a few weeks, then erased |
Lumixi collects no advertising identifier, no permanent hardware identifier, no location data, no contacts and no health data. No automated decision producing legal effects is taken about you.
The child being filmed
Lumixi is designed to be used by adults and is not intended for children. When you film your child, you decide what is filmed and who watches it: the image and the sound stay between your devices, and we have no access to them. We therefore do not process data about the child: what we see are events of the kind “a sound exceeded the threshold at 3:12 a.m.”.
If you place a camera in a space where other people may be filmed, it is up to you to inform them.
Who else is involved
We do not sell your data and do not pass it to anyone for commercial or advertising purposes. The providers below act on our behalf, on our instructions, under a processing agreement:
| Provider | Role | Data concerned | Location |
|---|---|---|---|
| Supabase | Database, authentication, real-time channel, server functions | All the data in the previous table, except video and sound | European Union — Stockholm, Sweden |
| Expo and Google Firebase Cloud Messaging | Delivery of push notifications to the monitor | Notification token, title and minimal text of the alert | United States — standard contractual clauses and the EU–US Data Privacy Framework |
| Metered | TURN relay server, used only when the direct link fails | Encrypted audio and video packets, unreadable by the relay, and the network metadata needed to relay them | Global network; the nearest relay is used. No storage. |
| Google Play | Purchase, trial and verification of Lumixi Premium | Transaction data processed by Google, purchase token sent for verification | Google acts as the seller and as a separate controller for the transaction |
| Vercel | Hosting of this site, and measurement of its audience and speed | Site access logs, and the measurement data detailed in the next section; no app data, no video, no sound | United States — standard contractual clauses |
We may also have to disclose data where the law requires it, or to establish or defend a legal claim.
Measurement on this site
Since 9 August 2026, this website uses two measurement tools provided by Vercel, our host: Web Analytics, to know which pages are viewed, and Speed Insights, to measure the real speed of pages on your device. They concern this website only: the Lumixi app itself contains no measurement tool.
No cookie is set and nothing is stored on your device. That is why this site does not ask you for consent: with no storage on your terminal and no profiling, the measurement rests on our legitimate interest in understanding the site's audience and performance (Art. 6(1)(f)). You are not tracked from one site to another, no profile is built, and this data is neither sold nor used for advertising.
| Tool | What is collected | Retention |
|---|---|---|
| Vercel Web Analytics Audience |
Page viewed and its generic form, referring page if you arrive from a link, filtered URL parameters, country, region and city, operating system, browser and device type, timestamp. The visitor is told apart by a fingerprint computed from the request, never by an identifier stored on your device. | The session fingerprint is destroyed after 24 hours. Only aggregated statistics remain. |
| Vercel Speed Insights Speed |
Page viewed and its generic form, performance metrics measured by your browser (display time, visual stability, responsiveness) and the page element they relate to, connection speed, browser, device type, operating system, country. | Aggregated statistics; no reconstruction of your journey is possible. |
Your IP address is not retained by either tool, and no measurement data is attached to an identifiable person. This measurement covers the public pages only; the administration dashboard is excluded.
If you would rather not be counted, a content blocker or your browser's tracker-blocking option is enough to prevent these two scripts from loading. The site works normally without them.
How it is protected
- Every row in the database is protected by access rules at database level: an account can read only what belongs to it, even if the app misbehaves.
- The real-time channel is private and reserved for devices that are genuinely paired.
- The pairing code is temporary, single-use, and a camera accepts only one active pairing.
- Secrets — Google Play keys, TURN relay credentials — stay on the server side and are never embedded in the app. The monitor receives a short-lived relay credential.
- We keep a fingerprint of the Google Play purchase token, never the token itself.
- All network communications are encrypted: HTTPS to our servers, DTLS-SRTP for audio and video.
No measure makes a service infallible. If a data breach were to pose a risk to your rights, we would inform the supervisory authority within 72 hours and, where the risk is high, inform you directly.
Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time for the processing that depends on it — notifications, simply by turning off the permission in Android.
The most direct of these rights is built into the app: Settings → Account and household → Delete my account immediately and permanently erases your account and everything attached to it. If you no longer have the app, write to privacy@lumixi.app from the address of the Google account used: the full procedure is at lumixi.app/en/delete-account.
Two limits are worth knowing before you delete: deletion does not cancel your Google Play subscription, which belongs to your Google account and is cancelled in Google Play; and if your account carries the household's shared subscription, the second phone loses Lumixi Premium at the same moment.
For any other request, write to privacy@lumixi.app. We reply within one month, extendable by two months for complex requests, in which case we tell you. We never ask for identity documents or passwords.
If our answer does not satisfy you, you may lodge a complaint with the Belgian Data Protection Authority — Rue de la Presse 35, 1000 Brussels, autoriteprotectiondonnees.be — or with the authority of your country of residence in the European Economic Area.
Updates to this policy
This page shows its version and effective date at the top. In the event of a significant change — a new purpose, a new provider, stream recording, a change of business model — we will update this policy before it takes effect, and inform you in the app where the law requires it.
History: version 1.1, 9 August 2026 — addition of audience and speed measurement for this website (Vercel Web Analytics and Speed Insights), without cookies. Version 1.0, 5 August 2026 — first publication.
Do you want to delete your account?
See the procedure