メインコンテンツへ移動
ELISoftware Development
BusinessProductsCompanySupport
01Business02Products03Company04Support
プライバシーポリシー利用規約

LUMINA FILES — PRIVACY POLICY

Lumina Files プライバシーポリシー

最終更新日:2026年8月31日 / バージョン:2.9 / 提供者:合同会社ELI(ELI LIMITED LIABILITY COMPANY)

CONTENTS

  1. 適用範囲
  2. 基本方針
  3. 端末内で取り扱う情報
  4. Apple Speechによる文字起こし
  5. Firebase
  6. iCloud Drive
  7. App Storeでの購入
  8. 選択・同意の記録
  9. 保存期間と削除
  10. 安全管理
  11. 販売、広告および追跡
  12. 問い合わせ情報と権利
  13. 子どものプライバシー
  14. 変更・連絡先・準拠法
  15. 変更履歴
  16. English Reference

本文の日本語版を正本とします。英訳は参考として後半に掲載しています。

01

適用範囲

本プライバシーポリシーは、合同会社ELI(以下「当社」)が提供するiOS・iPadOSアプリ「Lumina Files」(以下「本アプリ」)における情報の取扱いを説明するものです。

本アプリは、原則としてファイル管理、文字認識、検索、要約その他の主要な処理を端末内で行います。当社は、ユーザーのファイルまたはAI入力を保存する独自のクラウドサーバーを運営していません。過去の版に存在したGoogle Gemini APIを利用するクラウドAI機能は、2026年7月24日に本アプリから削除しました。

02

基本方針

  • 本アプリは、広告配信、広告プロファイルの作成または複数事業者のアプリ・Webサイトをまたぐ行動追跡を行いません。
  • ファイル内容、ファイル名、検索文、OCR結果または文字起こし結果を、AI処理のために当社または第三者のAIサービスへ送信しません。ただし、動画・音声の文字起こしについては、端末、言語または実行環境がオンデバイス音声認識に対応しない場合に限り、文字起こし対象の音声がAppleの音声認識サービスへ送信されることがあります(第4項)。当社はAppleへ送信された音声を受け取りません。
  • Apple VisionによるOCR、Appleの端末内言語モデルによる要約および文字起こし結果の文章整理、ならびに端末内の検索用索引に対応する処理は、対応端末上で行われます。このうち端末内AIによる要約と文字起こし結果の文章整理(句読点の補正、誤変換の修正、言い淀みの除去)は、iOS 26以降またはiPadOS 26以降で、かつApple Intelligence(端末内AIモデル)を利用できる端末および設定でのみ動作します。
  • Firebase Remote Configは、安全停止設定および処理上限等を取得するために利用します。
  • Crashlytics、AnalyticsおよびPerformance Monitoringによる任意の品質診断は、ユーザーが許可するまで無効です。
  • Apple Speech、iCloud Drive、App StoreおよびFirebaseには、各サービス提供者の規約とプライバシー情報が適用されます。
03

端末内で取り扱う情報

3.1 「ファイルの中身を読み取る」設定

設定画面の「ファイルの中身を読み取る」は、画像・PDFの文字、動画・音声の話し声、および対応する文書の本文を読み取り、その内容による検索または要約等に利用するための設定です。

対応する処理は原則として端末内で行われ、ファイル内容を外部のAIサービスへ送信しません。動画・音声の文字起こしについては、第4項の例外をご確認ください。この説明は処理場所についてのものであり、各機能を利用できる無料版またはLumina Files Premiumの範囲は、アプリ内の購入画面およびApp Storeに表示される内容に従います。

この設定は既定でオンです。端末内処理自体は当社または第三者への情報送信を伴わないため、オンにする際の契約同意や同意日時の記録は行いません。設定をオフにすると、それ以降の内容読み取り(画像・PDFのOCR、音声・動画の文字起こし、検索可能PDFの作成、端末内AIによる要約、およびテキスト形式のファイルからの本文の一括抽出)を停止します。ただし、テキスト形式のファイルを本アプリで開いたり保存したりした場合は、この設定に関わらず、本文の先頭部分を端末内へ保存し、検索用索引へ取り込みます。すでに作成されたOCR結果、文字起こし結果または索引は、個別に削除するか「すべてのデータを削除」を実行するまで残る場合があります。

3.2 保存・一時処理する情報

情報利用目的
ファイル名、保存場所、拡張子、種類、サイズ、作成・更新日時一覧表示、並べ替え、検索、変更検知
登録フォルダ情報およびSecurity-Scoped Bookmarkユーザーが許可したフォルダへの継続アクセス
ファイル本文の抽出結果、本文プレビュー、OCR結果、文字起こし結果プレビュー、内容検索、ユーザーが選択した処理
端末内で作成した検索用の索引(過去の版で作成された数値ベクトルが残っている場合はこれを含みます)内容検索
テキスト系ファイルをアプリ内で保存したときの本文のコピー(圧縮して1ファイルあたり最大5世代)編集内容の版の確認と復元
PDFへの署名機能で保存した手書き署名の画像署名の再利用
ウィジェットへ渡す表示用データ(参照中フォルダのMarkdownファイルについて、更新の新しいものと最近開いたものを合わせて最大80件分のファイル名、フォルダの表示名、本文の先頭1500字、更新日時等)ホーム画面・ロック画面ウィジェットの表示
タグ、お気に入り、閲覧位置、ゴミ箱状態、スマートフォルダ、仕分けルールファイル管理
検索入力端末内検索
表示設定、診断設定、購入画面の初回選択状態アプリ設定と画面状態の維持
サムネイル、一時ファイル、Spotlight索引高速表示、編集、ドラッグ&ドロップ、システム検索

内容検索用の索引は、本アプリのデータベースとは別の索引ファイルとして端末内に作成し、抽出した本文およびOCR結果の写しを保持します。ウィジェット向けの表示用データは、本アプリとウィジェットが共有する端末内のApp Group領域に保存します。ウィジェットを配置した場合、対象ファイル本文の先頭部分がホーム画面またはロック画面に表示されることがあります。

3.3 ファイル、カメラ、クリップボードおよび共有

  • 本アプリは、ユーザーがファイル選択画面等で許可したローカルストレージ、iCloud Driveまたは外部ストレージ上のファイルとフォルダへアクセスします。
  • 書類を撮影して取り込む場合、カメラへのアクセス許可を求めます。撮影結果はユーザーが選択した保存先または本アプリの作業領域で処理します。
  • コピー、ペースト、ドラッグ&ドロップまたは共有をユーザーが実行した場合、クリップボード、Item ProviderまたはAppleの共有画面を介して、選択されたテキスト、パスまたはファイルを処理します。
  • Appleの共有画面からiCloud上のファイルまたはフォルダを共有した場合、その共有と参加者の管理はAppleの仕組みにより行われます。当社は独自のユーザー間共有サーバーを運営しません。
  • 本アプリが求める端末機能の権限は、カメラ(書類の撮影取り込み用)と音声認識(文字起こし用)の2つだけです。マイクによる録音は行いません。写真ライブラリ、位置情報、連絡先、生体認証およびプッシュ通知の権限は求めません。
04

Apple Speechによる文字起こし

本アプリは、動画・音声ファイルの文字起こしにAppleのSpeechフレームワークを使用します。利用前にiOSまたはiPadOSの音声認識権限を求めます。

端末がオンデバイス音声認識に対応する場合、本アプリはオンデバイス認識を要求します。端末、言語または実行環境が対応しない場合、Appleの音声認識サービスがネットワークを必要とし、文字起こし対象の音声がAppleへ送信される場合があります。当社はAppleへ送信された音声を受け取りません。

文字起こしの結果は、端末内AI(Appleの端末内言語モデル)を利用できる場合に限り、端末内で文章整理(句読点の補正、誤変換の修正、言い淀みの除去)を行うことがあります。この処理は端末内で完結し、当社または第三者のAIサービスへ送信しません。文章整理を利用できない場合または処理に失敗した場合は、音声認識の結果をそのまま表示します。

  • Siri、音声入力とプライバシー(Apple)
  • Apple Privacy Policy
05

Firebaseを利用した運用設定と任意の品質診断

5.1 Firebase Remote Config

製品版の本アプリは、OCR・索引処理の安全停止、処理上限等のパラメータを取得するため、Google Firebase Remote Configを利用します。この通信は任意の品質診断への同意とは別に行われます。

Firebase Remote Configは、Firebase Installation ID、国コード、言語、タイムゾーン、OS・SDK・アプリのバージョン、Firebase App ID、Bundle ID等の技術情報を処理する場合があります。本アプリは、Remote Configの取得のためにファイル名、ファイル内容または検索文を送信しません。

5.2 ユーザーが許可した場合だけ送信する品質診断

次の品質診断は、ユーザーが許可するまで無効です。

サービス主な情報と目的
Firebase Crashlyticsクラッシュスタック、エラーの種類・コード、アプリのバージョン・ビルド等を障害修正に利用
Firebase Analytics起動、バックアップ作成、バックアップ復元に関する限定的なイベントを品質改善に利用。Firebase SDKが初回起動、セッション開始、アプリ更新等の標準イベントを自動収集する場合があります
Firebase Performance Monitoring起動時間、処理時間、ネットワーク応答時間、CPU・メモリ等の性能情報を速度改善に利用。Firebase SDKがアプリの起動、画面の描画およびHTTP・HTTPS通信の応答を自動計測する場合があります。本アプリが明示的に計測するのは、バックアップの作成と復元の2つです

本アプリが診断情報へ付加する値には、ファイル名、絶対パス、ファイル本文または検索文の本文を含めない設計です。エラー説明や付加文字列は送信前に除去または制限します。Firebase SDKが管理するインストール識別子およびアプリが生成した匿名UUIDが利用される場合がありますが、広告追跡には使用しません。

  • Privacy and Security in Firebase
  • Firebase SDKのApp Store向けデータ開示情報
06

iCloud Driveおよびアプリ専用iCloud領域

本アプリはCloudKitデータベースを使用せず、iCloud DriveおよびAppleが提供するアプリ専用のiCloudコンテナを次の目的で利用します。当社はユーザーのApple Accountへログインできず、これらの内容を当社サーバーへ複製しません。

6.1 ユーザーのファイル

ユーザーがiCloud Drive上のフォルダを選択した場合、本アプリはOSから与えられた権限の範囲でファイルへアクセスします。保存先、同期、共有および削除は、ユーザーの操作、Apple Accountの設定、端末とAppleのサービス状態に依存します。

6.2 バックアップ

ユーザーが手動でバックアップを作成した場合、または「自動バックアップ(1日1回)」を有効にした場合、本アプリのデータベースおよびLumina FilesのDocuments領域にあるユーザーファイルのコピーを含む.luminaBackupをiCloudへ保存します。バックアップ機能は無料版でも利用でき、自動バックアップは既定で無効です。

バックアップは原則として直近7件の日次バックアップと直近3か月分の月次バックアップを残す世代管理を行います。「すべてのデータを削除」では削除されず、「バックアップと復元」画面から個別に削除できます。

6.3 文字起こし本文の端末間共有

ユーザーがこの機能を有効にした場合、文字起こし結果の本文を平文JSONとしてiCloudのアプリ専用領域へ保存し、同じApple Accountの端末間で再利用します。既定では無効です。

通常の保守処理では、最終更新から約60日を超えた共有文字起こしを削除対象とします。

iCloudの保護方式はApple Accountの設定によって異なります。AppleのiCloudデータセキュリティ概要をご確認ください。

07

App Storeでの購入と購入状態

本アプリは、Lumina Files Premiumの自動更新サブスクリプションおよび買い切り版(コミュニティ特典としてのコード引き換えを含む)を提供するため、AppleのStoreKitを使用します。

  • 購入、請求、無料体験、自動更新、解約および返金はAppleが処理します。当社は本アプリを通じてクレジットカード番号、銀行口座またはApple Accountの認証情報を取得しません。
  • 本アプリはAppleから商品情報および署名済みの購入資格情報を取得し、商品ID、利用資格、有効期限、取消・返金、アップグレード等の状態をPremium機能の提供に利用します。
  • 購入資格の正本はAppleが提供する署名済みTransactionです。WidgetおよびApp Intentが参照できるよう、検証結果から生成したPremium利用可否の値をApp Groupの端末内設定に保存します。この派生値は購入記録の正本ではなく、当社サーバーへ送信しません。
  • Appleは、App Store Connectを通じて当社へ売上、取引および財務に関するレポートを提供する場合があります。具体的な処理はAppleの規約とプライバシーポリシーに従います。

利用可能なプラン、価格、無料体験、自動更新その他の購入条件は、購入時に本アプリの購入画面およびApp Storeへ表示される内容をご確認ください。

08

選択・同意の記録

  • 品質診断を送信するかどうかの選択は端末内設定として保存します。この選択について、規約への同意、同意日時または規約バージョンの記録は行いません。
  • 「ファイルの中身を読み取る」設定はオン・オフの値だけを保存し、契約同意として扱いません。
  • 初回購入画面で無料版または購入を選んだかどうかを端末内設定として保存します。購入資格そのものはAppleの署名済みTransactionから再構築します。
  • 買い切り版の購入確認画面では、表示した告知文の全文、確認日時、アプリのバージョン、選択の結果、および表示時点のサブスクリプション残存期間を端末内に保存します。この記録に個人情報は含まれず、外部へ送信しません。「すべてのデータを削除」で削除できます。
  • 過去の版でGoogle Gemini API利用に同意した記録またはAPIキーがKeychainに残っている場合、「すべてのデータを削除」で消去できます。現行版は新しいGemini API同意記録またはAPIキーを作成しません。
09

保存期間、削除およびアンインストール後に残る情報

  • 端末内の索引、OCR、文字起こし、ベクトル、設定等は、対応する削除操作またはアプリ内のデータ削除まで保存される場合があります。
  • 本アプリの「最近削除した項目」に入れたファイルは、その期間中もファイル本体は元の保存場所に残り、アプリ内で削除済みとして扱われます。30日を経過した項目は、次回のアプリ起動後に実行する整理処理で、ファイル本体と管理情報をあわせて完全削除の対象となります。この完全削除は、iOSの「ファイル」App側の「最近削除した項目」を経由せずディスクから直接消去するため、以後、本アプリから復元することはできません。iCloud Driveまたは外部ストレージ上の登録フォルダ内にあるファイルも対象です。
  • iCloud共有文字起こしは通常、最終更新から約60日を超えると削除対象です。
  • バックアップは世代管理またはユーザーによる個別削除まで保持されます。

「すべてのデータを削除」は、端末内の索引、OCR・文字起こし、ベクトル、本文のコピー(版履歴)、アプリ設定、旧同意記録、買い切り版の購入確認の記録、スマートフォルダ・仕分けルール、サムネイル、Spotlight索引、iCloud共有キャッシュ、ウィジェット向けの表示用データ、旧版のGemini APIキー、およびWidget等のPremium派生値を削除し、現在のFirebase Installation IDの削除をGoogleへ依頼します。削除依頼が失敗した場合、本アプリは失敗を表示します。

次の情報は同操作では削除しません。

  • ユーザーが所有するローカルストレージ、外部ストレージまたはiCloud Drive上の元ファイル
  • iCloud上の.luminaBackup
  • PDFへの署名機能で保存した手書き署名の画像(本アプリのDocuments領域に保存され、アプリを削除すると消去されます)
  • ホーム画面ウィジェットで選択していた表示タブの番号(App Groupの端末内設定に保存される数値と、表示対象を区別するための識別子の一部です。ファイル名、保存場所およびファイルの内容は含みません)
  • Appleが管理する購入履歴、サブスクリプションおよび返金情報
  • FirebaseまたはAppleへすでに送信され、各事業者が保持している情報

アプリをアンインストールしても、iCloud Drive上のファイル、.luminaBackup、Appleの購入履歴、iCloud上の共有情報またはKeychainの一部が残る場合があります。これらを削除する場合は、アプリ内の削除機能、Files、Apple Account、App StoreまたはiCloudの管理画面を利用してください。

10

安全管理

本アプリは、外部サービスへの通信にHTTPSを利用します。Firebaseへ送るエラー情報から、ファイル名、パス、検索文または本文が混入し得る説明文字列を除去または制限します。

本アプリは、Documents領域等に保存するファイルへiOSのファイル保護(端末の初回ロック解除後にアクセスできる保護レベル)を適用し、手書き署名の画像には端末のロック中はアクセスできない保護レベルを適用します。Keychainへ保存する項目は、この端末でのみ利用する設定とし、iCloudキーチェーンへ同期しません。

一方、本アプリは、端末内に保存するデータについて、iOSの端末バックアップ(iCloudバックアップまたは暗号化ローカルバックアップ)からの除外指定を行っていません。そのため、本アプリのデータベース、検索用の索引、Documents領域、およびウィジェット向けの表示用データを置くApp Group領域を含め、OCR結果、文字起こし結果および本文プレビューが端末バックアップに含まれる場合があります。

インターネット通信およびクラウド保存に絶対的な安全性はありません。機密情報を扱う場合は、文字起こし共有や品質診断を無効にする、必要に応じてiCloudの高度なデータ保護を有効にする等の設定をご検討ください。

11

販売、広告および追跡

当社は、ユーザーデータを販売しません。本アプリの情報を広告配信、複数事業者をまたぐ行動追跡、広告プロファイル作成またはマーケティングに利用・提供しません。

本アプリには、広告SDK、第三者の解析SDKおよび第三者のクラッシュレポータを組み込んでいません。本アプリが情報を送信する先は、Googleが提供するFirebase(第5項)およびAppleが提供するサービス(第4項、第6項、第7項)です。Firebase Analyticsは広告識別子を扱わない構成を選択しており、広告識別子(IDFA)を読み取る機能を組み込んでいません。

12

問い合わせ情報とユーザーの権利

ユーザーがメールまたはサポートページから問い合わせた場合、当社は送信者の氏名または表示名、メールアドレス、問い合わせ本文、ユーザーが自ら添付したファイル、および対応履歴を、本人確認、回答、障害調査、品質改善および法令上必要な記録のために取り扱います。

問い合わせ情報は対応および必要な記録のために合理的に必要な期間保存し、その後削除または匿名化します。法令上の保存義務、紛争対応またはセキュリティ上の必要がある場合は、その期間保存することがあります。

当社が管理する情報について、開示、訂正、利用停止または削除の相談を希望する場合は、第14項の連絡先へご連絡ください。Apple Account、iCloudまたはApp Store内の情報については、Appleの管理画面および手続も利用してください。

13

子どものプライバシー

本アプリは13歳未満の子どもを主な対象として設計されたものではなく、当社は13歳未満であることを認識しながら個人情報を収集することを意図していません。未成年者が本アプリを利用する場合は、必要に応じて保護者または教育機関の管理者が購入、音声認識、iCloud共有および診断送信の設定を確認してください。

14

ポリシーの変更、連絡先および準拠法

本アプリの機能、第三者サービスまたは法令の変更に応じて、本ポリシーを改定することがあります。変更後のポリシーには更新日とバージョンを表示します。重要な変更がある場合は、本ページまたは本アプリ内でお知らせします。

合同会社ELI
所在地:〒225-0002 神奈川県横浜市青葉区美しが丘1丁目13番地10 吉村ビル107号
Email:info@eli-co.jp
Web:https://eli-co.jp/

本ポリシーは日本法に準拠します。

履歴

変更履歴

  • 2.9(2026年8月31日): 買い切り版の一般販売開始に伴い、StoreKitの利用目的を「自動更新サブスクリプションおよび買い切り版(コミュニティ特典としてのコード引き換えを含む)」へ表記合わせ。買い切り版の購入確認画面で端末内に保存する記録(告知文の全文、確認日時、アプリのバージョン、選択の結果、表示時点のサブスクリプション残存期間)と、その記録に個人情報が含まれず外部送信されないこと、「すべてのデータを削除」で削除できることを追記
  • 2.8(2026年8月28日): 文字起こし時にAppleへ音声が送信されうる例外を明記し、バックアップが無料版でも利用できる旨へ訂正。「最近削除した項目」を30日経過後にファイル本体ごと完全削除する動作、版履歴・手書き署名・ウィジェット表示用データ・端末バックアップの取扱い、および「すべてのデータを削除」で消えない情報を追記。あわせて、「ファイルの中身を読み取る」をオフにしても、テキスト形式のファイルを本アプリで開いたり保存したりした場合は本文の先頭部分を端末内へ保存し検索用索引へ取り込むことを明記し、端末内AIによる文字起こし結果の文章整理とその動作条件を追記
  • 2.7(2026年8月13日): 提供を終了した機能に関する記載を削除し、端末内言語モデルの用途および「ファイルの中身を読み取る」設定の説明を現行の機能に合わせて整理
  • 2.6(2026年8月13日): 提供を終了した機能に関する記載を削除し、文字起こし本文の端末間共有および安全管理に関する説明を現行の機能に合わせて整理
  • 2.5(2026年7月29日): 本ページを全面改訂し、記載を全体にわたって整理
EN

Lumina Files Privacy Policy — English Reference Translation

Last updated: August 28, 2026 — Version: 2.8 — Provider: ELI LIMITED LIABILITY COMPANY

The Japanese version above is the governing version. This English section is provided for reference.

1. Scope and core approach

This policy explains how the Lumina Files app for iOS and iPadOS (“Lumina”) handles information. Lumina generally performs file management, text recognition, search, summaries, and other main processing on the device. ELI does not operate a proprietary cloud server that stores users’ files or AI inputs. The former Google Gemini cloud AI feature was removed from Lumina on July 24, 2026.

Lumina does not use advertising or cross-company tracking and does not send file content, file names, search text, OCR results, or transcripts to ELI or a third-party AI service for AI processing. One exception applies to transcription: if the device, language, or environment does not support on-device speech recognition, the audio being transcribed may be sent to Apple’s speech recognition service (section 3). ELI does not receive that audio. Lumina does not embed any advertising SDK, third-party analytics SDK, or third-party crash reporter, and does not include a module that reads the advertising identifier (IDFA). Firebase Remote Config is used for operational safety settings. Optional Crashlytics, Analytics, and Performance Monitoring remain disabled until the user permits them.

2. Information processed on the device

Lumina may store or temporarily process file names and locations, file metadata, security-scoped bookmarks, extracted text, previews, OCR results, transcripts, an on-device search index (including numerical vectors created by earlier versions if any remain), tags, favorites, reading positions, search input, thumbnails, temporary files, app settings, and Spotlight data. It also stores compressed copies of the file body for up to five versions when a text-based file is saved in the app, handwritten signature images saved in the PDF signing feature, and display data for the widget (for up to 80 Markdown files in referenced folders — those most recently modified together with those most recently opened: file name, folder display name, the first 1,500 characters of the body, and timestamps).

The content search index is created as a separate index file on the device and holds a copy of extracted text and OCR results. Widget display data is stored in an App Group area shared between Lumina and its widget; if a widget is placed, the beginning of a file’s body may appear on the Home Screen or Lock Screen.

Lumina requests only two device permissions: camera (for document capture) and speech recognition (for transcription). It does not record audio through the microphone, and it does not request photo library, location, contacts, biometric, or push notification permissions.

The “Read file contents” setting permits Lumina to extract text or speech for search and summaries. Supported processing generally occurs on the device and is not sent to an external AI service; see section 3 for the transcription exception. This describes where processing occurs; availability in the free version or Lumina Files Premium is governed by the purchase screen and App Store listing.

Turning the setting off stops subsequent content reading (OCR of images and PDFs, transcription of audio and video, creation of searchable PDFs, on-device AI summaries, and bulk extraction of text from text-based files). However, when a text-based file is opened or saved in Lumina, the beginning of its body is stored on the device and added to the search index regardless of this setting. OCR results, transcripts, or index entries that already exist remain until they are deleted individually or with “Delete All Data.”

Lumina accesses only files and folders the user selects or otherwise permits through the operating system. Camera access is requested for document scanning. User-initiated copy, paste, drag-and-drop, and sharing may process selected text, paths, or files through the clipboard, item providers, or Apple’s share sheet.

3. Apple Speech

Lumina requests Speech Recognition permission before transcribing audio or video. When on-device recognition is supported, Lumina requires it. If the device, language, or environment does not support on-device recognition, Apple’s Speech service may require a network connection and the audio may be sent to Apple. ELI does not receive that audio. See Siri, Dictation & Privacy.

When Apple’s on-device language model is available — iOS 26 or later or iPadOS 26 or later on a device and configuration where Apple Intelligence can be used — Lumina may clean up the transcript on the device (fixing punctuation, correcting obvious misconversions, and removing fillers). That processing is completed on the device and is not sent to ELI or a third-party AI service. If it is unavailable or fails, the raw speech recognition result is shown as is.

4. Firebase

Firebase Remote Config may process a Firebase Installation ID and technical information such as country, language, time zone, OS, SDK and app version, Firebase App ID, and bundle ID. Lumina does not provide file names, file content, or search text to obtain Remote Config values.

Optional Crashlytics, Analytics, and Performance Monitoring remain disabled until permitted. They may process crash, performance, product-interaction, app-version, device, and installation-identifier information for app functionality and analytics. Once permitted, the Firebase SDKs may automatically collect standard events and automatically instrument app start, screen rendering, and HTTP/HTTPS request traces; the only traces Lumina measures explicitly are backup creation and backup restore. Lumina removes or restricts developer-supplied strings that could contain file names, paths, content, or search text. These identifiers are not used for advertising tracking. See Privacy and Security in Firebase.

5. iCloud

Lumina uses iCloud Drive and an app-specific iCloud container, not a CloudKit database. It may access files and folders the user selects in iCloud Drive, store .luminaBackup packages, and store a plain-text transcript cache when the user explicitly enables cross-device transcript sharing.

Backup is available in the free version: neither manual backup nor the once-daily automatic backup is a Premium feature, and automatic backup is off by default. Backups are not removed by “Delete All Data” and must be deleted separately. Transcript sharing is off by default and shared transcript data is generally eligible for cleanup approximately 60 days after its last update. iCloud protection depends on the user’s Apple Account settings. ELI cannot sign in to the user’s Apple Account or copy these files to an ELI server.

6. App Store purchases

Lumina uses Apple StoreKit for auto-renewable Lumina Files Premium subscriptions and a non-consumable one-time purchase (also redeemable via community offer codes).

Apple processes purchases, billing, free trials, renewals, cancellations, and refunds. ELI does not obtain payment-card, bank-account, or Apple Account authentication information through the app. Lumina receives product information and Apple-signed entitlement information, including the product ID, access status, expiration, revocation or refund, and upgrade state, to provide Premium features.

Apple-signed transactions are the authoritative entitlement source. Lumina stores a derived Premium-access value in an App Group setting for its Widget and App Intents. This value is not an authoritative purchase record and is not sent to an ELI server. Apple may provide ELI with sales, transaction, and financial reports through App Store Connect under Apple’s terms and privacy policy.

7. Retention, deletion, and user choices

Lumina stores the diagnostics choice, the “Read file contents” setting, and whether the initial purchase screen choice was completed as on-device settings. These are not records of agreement to independent terms. Purchase entitlement is rebuilt from Apple-signed transactions.

A file placed in Lumina’s “Recently Deleted” keeps its actual file at its original location while it is there. After 30 days, a cleanup that runs on the next app launch permanently deletes both the file itself and its management data. That deletion erases the file directly from disk without passing through the Files app’s “Recently Deleted,” so it cannot be restored from Lumina afterwards; files inside registered folders on iCloud Drive or external storage are included.

“Delete All Data” removes Lumina’s local index, OCR and transcript data, embeddings, stored copies of file bodies (version history), app settings, legacy consent records, saved filters and rules, thumbnails, Spotlight data, iCloud shared caches, widget display data, legacy Gemini API keys, and the derived Premium value, and requests deletion of the current Firebase Installation ID. It does not delete user-owned files, .luminaBackup packages, handwritten signature images saved in Lumina’s Documents area (removed when the app is deleted), the tab number last selected in the Home Screen widget (a number and part of an identifier stored in an App Group setting, containing no file name, location, or file content), Apple purchase history, or information already retained by Firebase or Apple.

Lumina applies iOS file protection to the files it stores (accessible after the device is first unlocked), applies a protection level that is inaccessible while the device is locked to signature images, and stores Keychain items as this-device-only so they are not synced to iCloud Keychain. However, Lumina does not exclude any of the data it stores on the device from iOS device backups — including its database, search index, Documents area, and the App Group area holding widget display data — so OCR results, transcripts, and body previews may be included in an iCloud or encrypted local device backup.

Uninstalling Lumina may leave iCloud Drive files, backups, Apple purchase history, shared iCloud information, or certain Keychain items. Users should use Lumina, Files, Apple Account, App Store, or iCloud management tools as applicable.

8. Support inquiries, children, and contact

If a user contacts ELI by email or through the support page, ELI may process the sender’s name or display name, email address, message, user-provided attachments, and support history to verify the request, respond, investigate issues, improve quality, and retain legally required records. This information is retained only as reasonably necessary for those purposes, legal obligations, disputes, or security, and is then deleted or anonymized.

Lumina is not primarily directed to children under 13. A parent, guardian, or educational administrator should review purchases, Speech Recognition, iCloud sharing, and diagnostics settings when appropriate.

9. Change history

  • 2.9 (August 31, 2026): Updates the StoreKit description to cover the non-consumable one-time purchase now sold in the app (also redeemable via community offer codes), and documents the on-device record saved by the one-time purchase confirmation screen (full disclosure text, timestamp, app version, the user’s choice, and the remaining subscription period shown), which contains no personal information, is never transmitted, and can be removed with “Delete All Data.”
  • 2.8 (August 28, 2026): States the exception under which audio may be sent to Apple during transcription; corrects that backup is available in the free version; describes the permanent deletion of files after 30 days in “Recently Deleted”; adds how version history, signature images, widget display data, and device backups are handled; expands the list of data that “Delete All Data” does not remove; states that the beginning of a text-based file’s body is stored on the device and added to the search index when the file is opened or saved even while “Read file contents” is off; and adds on-device AI clean-up of transcripts and the conditions under which it runs.
  • 2.7 (August 13, 2026): Removed descriptions of a discontinued feature and aligned the description of the on-device language model and the “Read file contents” setting with the current feature set.
  • 2.6 (August 13, 2026): Removed descriptions of a discontinued feature and aligned the descriptions of cross-device transcript sharing and security with the current feature set.
  • 2.5 (July 29, 2026): Full revision of this page.
ELI LIMITED LIABILITY COMPANY
Yoshimura Bldg. 107, 1-13-10 Utsukushigaoka, Aoba-ku, Yokohama, Kanagawa 225-0002, Japan
Email: info@eli-co.jp
Web: https://eli-co.jp/

This policy is governed by the laws of Japan.

Lumina Files ご利用上の重要事項特定商取引法に基づく表示
ELI

ソフトウェアの受託開発と、自社プロダクト開発。

Products

CoreNexus FlashcardLumina Files

Company

会社情報サポートお問い合わせ

© 2026 合同会社ELI — Yokohama, Japan

PrivacyTermsLumina Notices