Data controller
Who processes the data?
The data controller is wastonny.
For any question or request concerning personal data: contact@lumeobot.com.
Data categories
What data is processed?
Account
Display name, email address, verification status, hashed password, avatar and account preferences.
Security
IP address, user-agent, browser, operating system, device type, sessions, trusted devices, passkeys, two-factor authentication and security events.
Sign-in analysis
Approximate country, region or city, time zone, network, ASN and VPN, proxy, Tor or hosting signals used to assess sign-in risk.
Discord
Discord identifier, account names, avatar, official server, synchronized roles/ranks, OAuth scopes and tokens required for linking when you enable this feature.
Application and push
Device identifier and name, platform, application version, hashed access tokens, push subscription, browser and notification preferences.
Luméo services
Synchronized Pokémon/Quiz progress, publication preferences, beta applications, Wiki contributions, notifications, support requests and disciplinary information when these features are used.
Origin and necessity
Where does the data come from?
Data provided directly: account information, forms, preferences, avatar and content you choose to submit.
Automatic technical data: IP address, user-agent, session and sign-in context produced while using the Website.
Discord data: retrieved only when you request account linking or associated synchronization.
Bot / Discord server data: progress and statistics synchronized to the Website through Luméo’s secure internal interfaces.
Enriched security data: approximate network and location information obtained from the public IP address through the configured geolocation service.
To create an account, the display name, email address and requested authentication method are necessary. Discord linking, push notifications, public statistics and some community features remain optional.
Why?
Purposes and legal bases
| Purpose | Main legal basis |
|---|---|
| Create and manage the account, authenticate the member and provide the personal area. | Performance of the requested service and the Terms of Use. |
| Secure accounts, detect abnormal sign-ins, prevent abuse and maintain administrative traceability. | Luméo’s legitimate interest in securing its service and users. |
| Voluntarily link a Discord account and synchronize requested features. | Performance of the feature enabled by the user. |
| Publicly display certain game statistics when a member authorizes it. | Consent / explicit member choice, revocable in preferences. |
| Send optional push notifications. | Consent, revocable by disabling push or deleting the subscription. |
| Handle support requests, applications and community procedures. | Performance of the request, legitimate interest and, when necessary, compliance with applicable obligations. |
Recipients
Who may receive the data?
People authorized to administer Luméo, only according to their permissions and where access is necessary.
OVH SAS, as infrastructure hosting provider.
Discord, when you link your account or request Discord synchronization.
The email delivery provider configured by Luméo for verification messages and security alerts.
The IP geolocation service configured by Luméo, ipwho.is by default, which receives the public IP address during risk analysis.
Push services used by the browser/device when you voluntarily enable push notifications.
Some providers may process data outside the European Economic Area depending on their infrastructure and their own safeguards. Luméo limits these transfers to features actually enabled and to the data required.
Automated security
Sign-in risk score
Luméo automatically calculates a risk score from the sign-in context: new device or IP address, unusual country, VPN/proxy/Tor/hosting signals and previous sign-in attempts. This mechanism is used to protect the account.
A high risk level may trigger an additional verification step. This score does not, by itself, produce a decision with legal effects on the member; the security and administration tools allow human review of the relevant events.
Retention
How long is the data kept?
Account and related data: for the lifetime of the account, then deleted or anonymized when retention is no longer necessary, subject to information that must be kept for security, evidence or a legal obligation.
Sessions: according to the configured session duration; expired sessions are purged by Laravel.
Temporary sign-in codes: for a very short period; old expired challenges are automatically deleted.
Trusted devices: until expiration, revocation or deletion by the member.
Discord/mobile tokens and push subscriptions: until revocation, disconnection, expiration or deletion of the relevant device/account.
Security, audit, support and disciplinary logs: for a period limited to what remains useful for security, incident management, evidence and service follow-up. Luméo must periodically reassess these periods.
Your rights
Access, rectification, erasure and other rights
Depending on the processing concerned, you may request access to your data, rectification, erasure, restriction of processing, exercise your right to object or request portability where applicable. Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
Several items can already be corrected or deleted from your profile: avatar, trusted devices, mobile devices, Discord connection, push subscriptions and visibility preferences.
For a complete request: contact@lumeobot.com. Reasonable identity verification may be requested to protect the account.
You also have the right to lodge a complaint with the CNIL, the French data-protection authority. CNIL ↗
Changes
Updates to this policy
This policy may evolve with Luméo features. Its version and effective date are displayed at the top of the page. A substantial change may be accompanied by additional information for members.