Lumbus Live Privacy Notice
This notice explains what Lumbus Live collects and why, and adds to the Lumbus Privacy Policy, which covers every Lumbus product and your rights. Lumbus Technologies Limited is the controller for both.
Read together with the Lumbus Privacy Policy. Last updated 3 September 2026.
1. What Lumbus Live collects
- Your account — email, name and sign-in method, shared with the rest of Lumbus.
- Your phone number, only if you turn on text alerts. Only you can see it, and switching alerts off removes it.
- Stream keys for the destinations you add — encrypted at rest with a key specific to your studio, decrypted only for your studio machine (which keeps a copy of its current settings on its own disk so it can keep streaming without us), and shown to you only as the last four characters.
- Your studio set-up: scenes, overlays and media you upload, destinations, automation settings, schedule, team members (including the email address of anyone you invite) and the audit log of who did what.
- Studio telemetry: bitrate, round-trip time, dropped frames, scene switches, engine status, what the machine reports as degraded, and region — what the dashboard shows you, kept as session history.
- Recordings, only when you switch recording on.
- From the Lumbus Live app: a push-notification token and basic device details, so alerts reach you.
- SIM usage per connection and per allowance, and the traffic volumes our bonding provider measures when you combine connections (your bonding allowance), and — when we ship hardware — your delivery address and the purchase details.
- Your country, taken from your IP address on the website only to show prices in your currency. It is not stored. A currency you choose yourself is remembered on your own device, not by us.
- Support conversations with us.
2. What we don’t collect
We don’t keep your video. Your stream passes through your studio to the platforms; nothing of it is stored unless you turn recording on. We don’t watch your stream, and chat commands are acted on by your studio, not stored beyond the audit entry.
3. Why we use it
- To provide the service you asked for — running your studio, delivering your stream, carrying the data on your Lumbus SIMs, shipping hardware (performance of a contract).
- To keep you streaming — alerts when your signal drops or an allowance runs low, fraud and abuse prevention, service health (our legitimate interests, balanced against yours).
- With your consent — text alerts, and any marketing about Lumbus Live, which you can withdraw at any time.
- To meet legal obligations — records we must keep as a UK company.
4. Who handles it for us
We use a small number of providers under contract, each only for the purpose named:
- Supabase — accounts and database.
- Vercel — hosting of the website, dashboard and the API the app uses.
- Cloudflare — recordings storage (R2) and the bot check on our forms.
- Twilio — text alerts, if you turn them on.
- Expo — push notifications to the Lumbus Live app.
- Resend — email.
- The studio machines in the region you choose, run for us by our hosting providers there.
- Our connectivity supplier and the mobile networks your connections use — connection identifiers and usage, so the data plan works and is billed correctly.
- Our bonding provider — the servers that combine your connections when you use Lumbus Connect: the sign-in set up on your encoder, connection identifiers and traffic volumes, so the bonding allowance works and is metered.
- A payment processor, once billing launches; we’ll name it here before the first charge.
We don’t sell your data and we don’t share it for anyone else’s marketing.
5. Where it’s kept
Accounts and studio data are held in the UK and the EU. Your studio itself, and any recordings, live in the region you picked for it (for example Tokyo or Frankfurt), because that’s what keeps your stream fast. When you combine connections, the stream passes through our bonding provider’s servers; the location used for your account is confirmed with you at onboarding. Where data leaves the UK or EU we rely on adequacy decisions or standard contractual clauses.
6. How long we keep it
- Recordings: 14 days on Studio, 30 days on Studio Pro, then deleted; 7 days after a studio ends, all of its recordings are deleted.
- Stream keys: until you remove the destination or destroy the studio.
- Phone number: until you switch text alerts off.
- Session history, telemetry and the audit log: while your studio exists.
- Push tokens: until you sign out of the app, or 30 days after the app last checked in.
- SIM and bonding traffic volumes: for the life of the allowance they belong to, then as billing records.
- Account, billing and hardware records: as set out in the Lumbus Privacy Policy and as UK law requires.
7. Your rights
You can ask to see, correct, export or delete your data, object to how we use it, or withdraw consent, as described in the Lumbus Privacy Policy. Write to live@getlumbus.com and we answer within 30 days. You can also complain to the UK Information Commissioner’s Office (ico.org.uk).
8. Security
Everything travels encrypted. Stream keys are encrypted at rest with a per-studio key. Access inside Lumbus is role-based and logged, and your studio’s own audit log shows every action taken on it.
9. Changes and contact
We update this notice when Lumbus Live changes; the date below tells you when. Questions: live@getlumbus.com. Last updated 3 September 2026.