Privacy Policy
How LumiList handles your data — transparently and responsibly.
Last updated: July 12, 2026
What LumiList Collects
The LumiList browser extension collects only what is necessary to provide reading progress tracking:
- Reading data — novel titles, chapter numbers, reading timestamps, and source site URLs for novels you choose to track.
- Your writing — journal entries, selected highlights and their notes, reviews, and profile details you choose to provide.
- Authentication token — stored locally to communicate with your LumiList account.
- Website content — the extension reads novel titles and chapter numbers from supported sites when you visit them. It also reads passages you explicitly select to save as highlights.
What LumiList Does NOT Collect
- Account information includes your email, username, and optional profile details you supply.
- No health, financial, or payment information. Payment data is processed by Paddle — LumiList never sees your card details.
- No browsing history outside of supported novel sites.
- No keystrokes, mouse movements, or scroll tracking beyond chapter completion detection.
- No communications, messages, or social media data.
How Data Is Used
All collected data is used solely to provide the reading tracking service:
- Display your reading progress on the dashboard.
- Send chapter update notifications (if enabled).
- Sync progress across devices.
- Generate reading insights and AI recommendations (if subscribed).
Data Storage & Retention
Data is stored on LumiList servers hosted via Railway. You can delete your account and all associated data at any time from the Settings page. Extension-local data (cached novels, auth token) can be cleared by removing the extension or using the Clear Data option in the extension popup.
Third-Party Sharing
LumiList does not sell user data. Railway hosts application data, and Cloudflare processes network requests for DNS/CDN services. Paddle processes payments and transaction information. Configured email and notification providers process the destinations and content needed to deliver notifications you enable. When you request an AI feature and OpenRouter is configured, relevant reading metadata and, for note synthesis and novel recaps, your journal entries and highlights are sent to OpenRouter and its selected model provider to generate the response. Avoid submitting sensitive information in writing you ask AI to process. Your public profile and content you choose to publish can be viewed by others.
Data Certification
LumiList certifies that:
- User data is not sold. Service-provider processing is described above.
- User data is not used for purposes unrelated to the extension's single purpose.
- User data is not used for creditworthiness or lending purposes.
Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your data. To exercise these rights, contact us or use the account deletion option in Settings.
Contact
For privacy concerns, contact us.