8 Total
0 High severity
6 Medium severity
2 Low severity
Summary

This document establishes Luma AI's data collection and processing practices for users of its AI video and image generation services. The policy authorizes Luma to collect and use images, videos, text, and other personal data submitted by users to train and improve its AI models. Users in the EU and UK are entitled to exercise data subject rights including access, correction, deletion, and portability by contacting hello@lumalabs.ai.

Technical / Legal Breakdown

This document governs Luma AI's collection, use, disclosure, and processing of personal information from users of its website, applications, and AI-powered services, with stated legal bases including consent, contractual necessity, legal obligation, and legitimate interests for EEA/UK users under GDPR. The policy asserts that Luma collects a broad range of data including user-uploaded images and videos, AI conversation inputs and outputs, device identifiers, location inferred from IP address, collaboration data including real-time cursor position, and third-party sourced data from marketing partners and data providers; notably, the terms authorize use of this information to train and improve Luma's AI models and machine learning systems. The explicit authorization to use user-uploaded content and conversation inputs for AI model training is an operationally significant provision that may engage user expectations around content ownership and consent, particularly given that inputs may include personal images, videos, and text; the policy does not specify an opt-out mechanism for AI training use specifically, which may create tension with GDPR legitimate interests balancing requirements and emerging AI-specific regulatory frameworks. The policy engages GDPR and UK GDPR for EEA and UK users, CCPA and similar US state privacy laws for California and other US residents, and may require evaluation under the EU AI Act given Luma's AI model development activities; the explicit carve-out for enterprise processor relationships means enterprise-context users are governed by separate contractual arrangements rather than this policy.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

3 important changes detected

3 versions captured · Last updated: June 2026

June 10, 2026

unknown
What changed Luma AI updated their Luma AI Privacy Policy on June 10, 2026. Change detected: 1 sentence(s) modified. Document contained 145 sentences after update.
View full change record →
What changed Luma AI added a navigation link to 'API' in the header of their privacy policy page on May 5, 2026. This is a minor website navigation change with no impact on the actual privacy practices, data handling, or rights described in the policy itself.
Why this matters This change adds a website navigation link and has no material impact on consumer privacy rights, data handling practices, or policy terms. The underlying privacy policy language and protections remain unchanged.
View full change record →

April 29, 2026 low

Luma AI removed the word 'API' from the navigation menu in its privacy policy header on April 29, 2026. The previous version listed 'Product Pricing API Enterprise News' while the …

View change record →

Recent Provision Changes Jun 10, 2026

Added (4)
Enterprise Processor Carve-Out Medium

New provision creates a significant carve-out where enterprise customers' own privacy policies supersede Luma's stated commitments, limiting user protections in B2B contexts.

Third-Party Data Sourcing Medium

New provision explicitly authorizes data collection from external third parties and data brokers, expanding the sources of personal information beyond direct user interactions.

Conversation and Input Data Collection Medium

Separates and reframes conversation data collection into a distinct provision with reduced severity, making it less prominent despite the sensitivity of chat content including multimedia materials.

Data Retention Policy Low

New provision articulates data retention and deletion practices, providing transparency about how long personal information is retained.

Removed (4)
Open-Ended Affiliate and Partner Data Sharing

Removal of explicit partner and affiliate data sharing clause may represent narrowing of permitted disclosures or reframing under different provisions.

No Do Not Track Response

Removal of the explicit Do Not Track disclaimer may indicate compliance improvement or simply streamlining of privacy policy language.

Children's Data Exclusion (COPPA)

Removal of COPPA compliance statement may obscure the service's position on child data protection or indicate the policy was relocated elsewhere in the document.

Legitimate Interests as Legal Basis for Processing

Removal of the high-severity 'Legitimate Interests' legal basis provision eliminates transparency around broad processing justifications, potentially obscuring reliance on legitimate interests for data use.

Modified (4)
AI Model Training on User Content

Severity downgraded from high to medium, and the provision was split—conversation/input data collection details moved to separate 'Conversation and Input Data Collection' provision, removing the explicit statement about Outputs reproducing Input information.

Business Transfer Clause

Text is identical; provision retained with no changes.

Broad Device and Usage Data Collection

Provision name slightly revised from 'Broad Data Collection — Device, Location, and Usage Tracking' to 'Broad Device and Usage Data Collection' but excerpt text appears identical.

European Privacy Rights

Text is identical; provision retained with no changes.

2 provisions unchanged.

View full change record →
Medium — 6 provisions
Low — 2 provisions

Monitoring

Luma AI has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle AI Model Training Use of User Content and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 10, 2026 01:03 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000497
Version ID CA-V-003616
SHA-256 cc1e24d66f8f9d0b97fa8d40c974d12ea48d78e6d116ace6f92eda0217c0a625
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans