8 Total
0 High severity
6 Medium severity
2 Low severity
Summary

This document establishes Luma AI's data collection and processing practices for users of its AI video and image generation services. The policy authorizes Luma to collect and use images, videos, text, and other personal data submitted by users to train and improve its AI models. Users in the EU and UK are entitled to exercise data subject rights including access, correction, deletion, and portability by contacting hello@lumalabs.ai.

Technical / Legal Breakdown

This document governs Luma AI's collection, use, disclosure, and processing of personal information from users of its website, applications, and AI-powered services, with stated legal bases including consent, contractual necessity, legal obligation, and legitimate interests for EEA/UK users under GDPR. The policy asserts that Luma collects a broad range of data including user-uploaded images and videos, AI conversation inputs and outputs, device identifiers, location inferred from IP address, collaboration data including real-time cursor position, and third-party sourced data from marketing partners and data providers; notably, the terms authorize use of this information to train and improve Luma's AI models and machine learning systems. The explicit authorization to use user-uploaded content and conversation inputs for AI model training is an operationally significant provision that may engage user expectations around content ownership and consent, particularly given that inputs may include personal images, videos, and text; the policy does not specify an opt-out mechanism for AI training use specifically, which may create tension with GDPR legitimate interests balancing requirements and emerging AI-specific regulatory frameworks. The policy engages GDPR and UK GDPR for EEA and UK users, CCPA and similar US state privacy laws for California and other US residents, and may require evaluation under the EU AI Act given Luma's AI model development activities; the explicit carve-out for enterprise processor relationships means enterprise-context users are governed by separate contractual arrangements rather than this policy.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

2 important changes detected

2 versions captured · Last updated: May 2026

What changed Luma AI added a navigation link to 'API' in the header of their privacy policy page on May 5, 2026. This is a minor website navigation change with no impact on the actual privacy practices, data handling, or rights described in the policy itself.
Why this matters This change adds a website navigation link and has no material impact on consumer privacy rights, data handling practices, or policy terms. The underlying privacy policy language and protections remain unchanged.
View full change record →
What changed Luma AI removed the word 'API' from the navigation menu in its privacy policy header on April 29, 2026. The previous version listed 'Product Pricing API Enterprise News' while the updated version states 'Product Pricing Enterprise News'. This is a formatting or navigation change with no operational effect on the privacy practices described in the policy itself.
Why this matters This change does not affect consumer rights, data handling, or privacy practices. The updated policy describes the same privacy practices as before. The modification is limited to the website navigation menu presented at the top of the policy document.
View full change record →

Medium — 6 provisions
Low — 2 provisions

Monitoring

Luma AI has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle AI Model Training Use of User Content and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 13:08 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000497
Version ID CA-V-002211
SHA-256 87648a1b74cf9feda16f5627b0c595e4ace1c8359d928efedc67041de96aaf81
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans