1. Scope and who we are
This Privacy Policy applies to Luxa Studio and Luxa Office, related websites, applications, and user-facing services (collectively, the “Service”). Luxa Studio (“Luxa,” “we,” “us,” or “our”) provides creative production, project, file, communication, and business-workspace tools.
Questions or privacy requests may be sent to elijahisrael@luxastudiocos.net.
2. Information we collect
Account and profile information
Name, email address, profile image, authentication identifiers, account preferences, workspace memberships, roles, and related account settings.
Content and project information
Files, documents, images, video, audio, prompts, messages, project records, comments, and other content a user creates, uploads, imports, or intentionally saves in the Service.
Workspace and collaboration information
Personal or Team workspace selection, project relationships, invitations, permissions, sharing choices, and activity needed to provide collaboration features.
Transaction information
Subscription, plan, credit, and transaction status. Payment-card details are handled by payment processors and are not intended to be stored directly by Luxa.
Technical and usage information
Browser and device information, IP address, timestamps, request and error logs, feature interactions, and security events needed to operate, protect, diagnose, and improve the Service.
Connected-service information
Information a user authorizes Luxa to receive from a connected service such as Google. Google-specific access is described below and on our Google API Data Use page.
3. How we use information
- Provide, maintain, secure, and troubleshoot the Service.
- Authenticate users and preserve Personal versus Team workspace boundaries.
- Process user-directed creation, editing, communication, import, export, and collaboration actions.
- Save project content and maintain the relationships a user creates between assets, projects, and workspaces.
- Send transactional, security, support, and service communications.
- Administer subscriptions, credits, fraud prevention, and legal compliance.
- Improve user-facing reliability and functionality using operational information that does not violate connected-service restrictions.
4. Google user data
Google access is optional. Luxa requests access only after a signed-in user selects a Google feature and completes Google’s consent process.
Google Drive
Luxa uses the drive.file scope to work with Drive files created by Luxa or explicitly selected or authorized by the user. User-facing features include file and folder search, upload, download, move, rename, sharing, and copying a selected file into the active Luxa workspace or project.
Gmail
Luxa uses the gmail.modify scope so a user can search and read mail, view selected message content, create drafts, send, reply, forward, attach authorized Drive files, and save a selected Gmail attachment into Luxa. Luxa does not provide a feature that permanently deletes Gmail messages while bypassing Gmail Trash.
Google identity
OpenID, email, and profile information are used to identify the connected Google account and show the user which account is connected.
Luxa’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
5. Google data limitations
Luxa does not:
- Sell Google user data.
- Use Google user data for advertising, retargeting, or personalized advertising.
- Use Google user data to determine creditworthiness or for lending.
- Allow humans to read Google message or file content except with the user’s affirmative permission for a specific support purpose, when necessary for security, or when required by law.
- Use Google Workspace API data to train generalized or personalized artificial-intelligence or machine-learning models.
If a user affirmatively sends a copied file or other saved Luxa content to a visible AI feature, it is processed only to provide the requested user-facing result and is not used by Luxa to train a generalized or personalized model.
6. Storage, retention, and deletion
- Google OAuth access and refresh tokens are encrypted before database storage and retained while the Google connection remains active.
- Disconnecting Google asks Google to revoke the authorization and deletes Luxa’s stored Google connection and encrypted tokens.
- Message bodies and Drive file contents fetched for viewing or an immediate action are not intentionally retained as OAuth connection records.
- When a user explicitly imports a Drive file or Gmail attachment, Luxa creates a separate copy in private Luxa storage and records its workspace or project context. That copy remains until the user deletes it or requests deletion.
- Operational and security records are retained only as reasonably necessary for service operation, security, dispute resolution, and legal obligations.
Instructions for disconnecting Google, deleting imported copies, and requesting full account deletion are available on the Data Controls and Deletion page.
7. When information is shared
We may share information only as needed with:
- Infrastructure, database, storage, authentication, email, payment, security, and support providers acting on our behalf.
- AI or media-processing providers when a user intentionally requests a feature that requires that processing.
- Other members of a Team workspace according to the user’s workspace selection, permissions, and sharing actions.
- Authorities or other parties when required by law, necessary to protect rights or safety, or connected to a merger, financing, acquisition, or sale subject to applicable notice and consent requirements.
We do not authorize service providers to use Google user data for their own advertising or independent model training.
8. Security
Luxa uses administrative, technical, and organizational safeguards designed to protect information. Google tokens are encrypted with authenticated encryption, token-bearing operations run on the server, private API responses are marked not to be cached, and database access is scoped to authenticated users and server-side services. No security method is perfect, and we cannot guarantee absolute security.
Additional information is available on our Security page.
9. User choices and rights
- Review and update account or workspace information available in the Service.
- Disconnect Google inside Luxa and separately revoke Luxa from the Google Account permissions page.
- Delete Luxa files and imported copies using available workspace controls.
- Request access, correction, export, restriction, objection, or deletion where applicable by law.
- Opt out of non-essential communications using the instructions in those communications.
We may need to verify a requester’s identity before completing a privacy request.
10. Children, international use, and changes
The Service is not directed to children under 13, and Luxa does not knowingly collect personal information from children under 13. Users are responsible for using the Service consistently with laws that apply to them and their content.
Information may be processed in countries where Luxa or its service providers operate. We will update this policy when practices materially change and will provide additional notice when required.
11. Contact
Privacy questions and requests: elijahisrael@luxastudiocos.net
