Privacy
Luma is operated by HANS Society. This notice explains the information used by Luma at withluma.app. For questions or account-data requests, contact support@joinhans.io.
HANS login and wallet identity
When HANS login is enabled, HANS Society authenticates your Luma login. Luma receives your HANS person identifier, username, Hansian image, X handle and X account identifier, linked wallet addresses and their proof levels, and reward information. Luma and IRIS use the same HANS person identifier. Luma does not receive your Google identity from HANS.
Luma keeps a local view of your login and wallet membership to authorize access to wallet workspaces and subscription coverage. Linking a wallet that already has Luma data can require a separate wallet confirmation. HANS login can authorize private Luma reads and account changes; sensitive billing actions additionally require a signature from the paying wallet. A HANS login does not sign transactions or give Luma your wallet private keys.
If you choose to link your HANS X account to Charles, Luma stores its identifier and handle with the chosen wallet. Reading a page does not create or move this link. You can unlink it in Charles.
Trading, subscriptions and public profiles
Luma processes public blockchain wallet activity together with the journals, notes, reports, alert settings and other data you save in its workspace. Subscription and payment records belong to the paying wallet. Card checkout and billing are handled through Stripe; crypto payments are recorded from public blockchain transactions. Luma uses infrastructure, blockchain data and AI service providers to deliver the features you request.
For wallets that trade vaults, Luma may store a public byline snapshot containing the HANS person identifier, username, Hansian image and X handle. The snapshot appears on that wallet’s vault pages; the X handle is shown only when its display setting allows it. Snapshots expire from public display after 29 days without refresh, and are cleared when the wallet leaves the HANS profile. Logging out does not remove a public byline.
Cookies, logout and security records
Luma uses secure login cookies and a local login record. HANS has its own cookies. “Log out of Luma” ends the Luma login; “Log out of all apps on this device” ends HANS-connected app logins on that device; “Log out everywhere” ends them across devices. Revocation reaches apps when they check HANS. If HANS is unavailable, an existing Luma login can continue for up to 24 hours after its last successful check, within its hard expiry. Your connected wallet stays connected until you disconnect it separately.
Luma records login, logout, wallet confirmation and relevant failed proof events for security review, including a hashed IP address when configured. Security cleanup deletes audit records older than 400 days and expired or ended login records older than 30 days when later login activity runs that cleanup. Other account, journal and payment records have their own operational and recordkeeping purposes. Contact support to request access, correction or deletion; some records may need to remain for security or payment obligations.
Read the HANS Society privacy policy for HANS profile information and sharing with other connected apps.