Lumisia Stories
Privacy Policy
Last updated: August 28, 2026
EISOL LLC (“we”) handles information in the Lumisia Stories iOS app (the “App”) as described below. This policy applies only to the App. Other Lumisia services provided by EISOL LLC involve separate data processing.
1. Information we process
- Account information: an anonymous account ID issued by Firebase Authentication. If a parent chooses Sign in with Apple, the Apple authentication credential and an email address only if Apple provides one.
- Purchase information: StoreKit transaction information and a one-way account-binding token used to verify App Store purchases, restoration, and entitlements.
- Your Series selections: the age band, interest, and series selected by a parent.
- Legacy series information: if a series made in an earlier Lumisia Stories experience remains linked to the same account, the protagonist name a parent entered at that time may remain in that saved series. The current iOS App does not newly request or collect a name in Your Series.
- Limited product events: an allowlisted event name such as reading started or completed, the anonymous account ID, a random per-session ID, language, app version, and, when applicable, catalog, page, choice, or product identifiers.
- Apple aggregate advertising measurement: to measure campaign installs or redownloads and aggregate progress to a newly secured account, purchase initiation, and a server-verified new subscription, the App may register staged numeric conversion values with Apple SKAdNetwork (interoperable with AdAttributionKit). The registration passes no event name, account ID, advertising ID, or device ID.
Resume state, including the position within prose and selection state needed to resume, is stored on the device. Separately, the limited product events described above may send the story and page type, page number and count, and choice ID to our server. Story text, free-form input, and audio are not sent.
To prevent duplicate or decreasing aggregate advertising updates, the App stores only the highest numeric value Apple accepted and the highest pending value needed for retry after a temporary failure.
2. Why we use information
We use the information above to provide reading and parent-facing features, verify and restore purchases, display Your Series options suited to the selected age band and interest and any saved legacy series, understand product use, review aggregate advertising effectiveness from install through a new subscription, investigate failures, prevent abuse, and fulfill account-deletion requests.
The product-event endpoint is restricted so that it cannot accept names, free-form text, audio, advertising identifiers, device identifiers, IP addresses, or user-agent strings in an event payload.
3. Advertising, tracking, and analytics
The App displays no in-app advertising and has no ad-network SDK, ad-attribution SDK, IDFA access, App Tracking Transparency prompt, third-party analytics SDK, Firebase Analytics, Firebase Crashlytics, or Sentry iOS SDK.
We do not sell information from the App or use account information or limited product events to serve third-party or personalized ads, track anyone across apps or websites, or train AI models. Limited product events go only to an API we control and are used for our own product improvement.
Apple aggregate advertising measurement is an operating-system service. The App raises a numeric low, medium, or high milestone after first launch, a new Apple-authenticated account is secured, StoreKit checkout starts, or our server verifies a new subscription. A restoration, existing-entitlement check, renewal, or a child’s reading behavior is not registered as a new subscription. The numeric registration includes no name, anonymous account ID, product ID, price, transaction ID, IDFA, device ID, story information, or event name. Apple may send a postback, subject to privacy thresholds and delay, to the ad network for the relevant campaign. We do not use this mechanism to identify or profile a person or to track anyone across apps or websites.
4. Service providers and storage locations
- Google Firebase Authentication: processes the anonymous account and, if chosen by a parent, Sign in with Apple. Firebase Authentication operates from data centers in the United States.
- Google Cloud: hosts our API and Firestore. Application, profile, series, and product-event data is stored in Firestore in the Tokyo region (asia-northeast1).
- Apple App Store / StoreKit / SKAdNetwork: processes purchases, restoration, transaction verification, and privacy-preserving aggregate advertising measurement.
- Sentry (server side only): our API may send technical exception information to its U.S. service when a request fails. Default PII transmission is disabled, and we do not intentionally attach names, story text, authentication tokens, or device identifiers. The App binary does not contain a Sentry SDK, and product events are not sent to Sentry.
During ordinary network communication, hosting providers may temporarily process an IP address and standard network metadata for routing, security, and abuse prevention. We do not store that information as a Stories product event.
5. Children’s information and parental controls
Stories in the App are pre-authored. Your Series displays options from a predefined catalog using an age band and interest selected by a parent. The current iOS App does not generate a story from a name or photo. Even if a name remains in a saved legacy series, the current iOS App does not send a child’s information to a third-party AI service.
Account settings, purchases, and Your Series selection are shown only after a grown-up check. The App does not collect location, contacts, photos, videos, microphone audio, health information, web-browsing history outside the App, IDFA, IDFV, or hardware-specific device identifiers.
6. Retention and deletion
Account, profile, and series information is kept while the account remains active. Product events expire no later than 400 days after creation and are also deleted when the account is deleted.
A parent can delete the account from Settings in the App. Deletion removes the authentication account and linked profile, series, and product events. Purchase and grant ledger entries may be retained only after removing their direct account link where necessary for transaction integrity, fraud prevention, accounting, or legal obligations.
7. Contact and changes
For questions about information handling in the App, contact privacy@lumisia.world.
If the App’s features, SDKs, or data processing change, we will review this policy and the App Store privacy disclosures. Material changes will be posted on this page.