Legal

Privacy Policy

Last updated: July 22, 2026

Summary: Luma Player is a media player that does not require a personal account. We process only the limited pseudonymous device and playlist information needed for device activation, the web dashboard, and core app functionality. We do not sell personal data or use it for advertising or behavioral tracking.

1. Who We Are (Data Controller)

Luma Player is a product of Fenixer Labs LLC. The app lets users play video playlists and manage their content through a personal web dashboard at lumaplayer.app. We do not provide, host, or distribute any media content ourselves.

For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent privacy laws, the data controller is:

Fenixer Labs LLC

A Delaware Limited Liability Company

254 Chapman Rd, Suite 101-B, Newark, DE 19702, United States

Privacy contact: privacy@lumaplayer.app

For any privacy-related questions or concerns, you can contact us at: privacy@lumaplayer.app

2. Data We Do Not Collect

Except for the limited service data described in Sections 3 and 4, Luma Player does not collect or store the following on our servers:

We have deliberately designed Luma Player to operate without registration and without connecting service data to your real-world identity.

IP address & weather widget: When the optional weather widget is enabled on the home screen, your device makes a standard HTTPS request to ip-api.com. As with any network request, ip-api.com receives your IP address in order to derive your approximate city and return a weather result. Luma Player itself does not store or log your IP address. This network call is only made when the weather widget is active. See Section 6 for full details.

3. Data Stored Locally on Your Device

The following information is stored in the app's private storage on your Android, Android TV, or Samsung Smart TV device. Some items are also stored in our cloud backend (Supabase) strictly to provide device activation and the web dashboard — see Section 4 for details:

You can clear all locally stored data at any time via Device Settings → Apps → Luma Player → Clear Data. Dashboard data can be removed by deleting your playlists through the web dashboard.

4. Web Dashboard (lumaplayer.app/dashboard)

The Luma Player web dashboard allows you to manage your playlists remotely. Authentication uses your Device ID and Device Key. These values do not directly identify you by name, but they are persistent pseudonymous identifiers and may be considered personal data under applicable privacy laws.

The following data is stored in Supabase (our cloud database provider) to enable the dashboard:

We use this data only to provide activation, playlist synchronization, device status, and dashboard functionality. We do not use it for advertising or behavioral profiling. Supabase processes the data on our behalf as a cloud service provider. Playlist information is also sent directly to the external provider selected by you when the app loads that playlist.

5. App Permissions

Luma Player requests only permissions necessary for core functionality. The exact permissions depend on the platform:

Luma Player does not request and has no access to your camera, microphone, precise location, or contacts. Storage permissions are scoped to the minimum Android version range where they are technically required and are used exclusively for local file import/export — not for browsing, reading, or transmitting any personal files.

6. Third-Party Services

Luma Player contains no advertising networks or behavioral-tracking SDKs. The Android version uses Firebase Crashlytics only for stability diagnostics; the Samsung Smart TV version does not use Firebase Crashlytics. Specifically:

The following third-party services are used for specific, limited purposes:

ServicePurposeData sentPrivacy policy
Supabase Web dashboard backend — stores your Device ID, Device Key, and playlist URLs so you can manage playlists remotely. Data is synced both when you add playlists from the app and when you use the web dashboard. Pseudonymous Device ID, Device Key (6-digit PIN), playlist URLs and connection details you add, last-seen timestamp supabase.com/privacy
Google Firebase Crashlytics (Android only) Identifies crashes, startup failures, and playback stability problems so we can diagnose and improve the Android app. Crash stack traces, app version and state, Firebase installation identifier, device model, OS/SDK and architecture, memory class, and limited technical playback diagnostics such as engine, content type, URL scheme, phase, fallback state, and timing. We deliberately do not add playlist URLs, provider hosts, usernames, passwords, channel names, Device ID, or Device Key to Crashlytics reports. firebase.google.com/support/privacy
ip-api.com Weather widget (optional) — derives your approximate city from your IP address Your IP address (standard HTTP request) ip-api.com/docs/legal
Open-Meteo Weather widget (optional) — fetches current weather for the city detected above Approximate latitude/longitude (city-level, not precise) open-meteo.com/en/terms

The weather widget does not request your device's GPS location. City-level geolocation is derived server-side from your IP address by ip-api.com — Luma Player never reads or transmits your device's precise location. If you prefer not to share this, there is no account or registration that ties these requests to your identity.

Playlists you add to the app are loaded directly from the servers of the provider you choose. Luma Player has no relationship with and no control over those external servers or their privacy practices. Any interactions with those servers are governed by the respective provider's own terms and privacy policy.

7. Security

Luma Player limits cloud processing to the service data described in Section 4. Network requests to our backend use HTTPS, and locally stored data is protected by the application sandbox and security mechanisms provided by Android, Android TV, or Samsung Tizen. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

We strongly recommend keeping your Device ID and Device Key private and not sharing them with anyone you do not trust.

8. Children

Luma Player is not directed at children under the age of 13. We do not knowingly connect the limited service data described in this policy to a child's real-world identity. If you are a parent or guardian and have a privacy concern, contact us using the address below.

9. Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of personal data, and to lodge a complaint with a data protection authority. You can also:

If you have any specific privacy concerns or requests, contact us at privacy@lumaplayer.app and we will respond promptly.

10. Changes

We may update this Privacy Policy occasionally to reflect changes in the app or applicable regulations. Any updates will be reflected by a revised "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of the Application following any changes constitutes acceptance of the updated policy.

11. Contact

For any questions, concerns, or requests related to this Privacy Policy, please contact us at:

privacy@lumaplayer.app