Privacy

Privacy Policy

Lumen Call is designed so that there is as little personal data as possible to protect. This page explains exactly what is processed and why.

Last updated: September 20, 2026

Summary

  • No accounts, emails, passwords, names or profiles.
  • Audio and video travel directly between participants and never reach our servers.
  • Recordings and snapshots are created and kept in your browser only.
  • Rooms are temporary and are deleted automatically.
  • No advertising, no analytics trackers, no sale of data.

1. Data we process to run a call

To connect two browsers, the signaling server temporarily holds:

  • Room ID: a random identifier such as 7f83k2m9. It is not linked to any person.
  • Peer ID and reconnect token: random values that identify a browser within a room for the duration of the call.
  • Connection setup data: WebRTC session descriptions and ICE candidates. These may contain your IP address, because that is how peers find each other. They are relayed to the other participant and are not stored.
  • Timestamps: when a room was created and last active, used only to expire it.

All of this lives in server memory and is discarded when the room expires or the server restarts. Nothing is written to a database or log in production.

2. Data we never receive

  • Your audio or video. Media is sent peer-to-peer over encrypted WebRTC.
  • Recordings, snapshots or any files you download. They are produced by your browser using the MediaRecorder and Canvas APIs and stay on your device.
  • Chat or message content. There is no text chat.
  • Contacts, call history or device identifiers.

3. IP addresses

Like any website, our servers see the IP address of your connection while you are connected. We use it only for rate limiting (to prevent abuse) and it is not stored after the connection ends. Because WebRTC establishes a direct connection, the other participant's browser may also learn your IP address. If a direct connection is not possible, traffic may be relayed through a TURN server, which sees IP addresses but cannot decrypt media.

4. Cookies and local storage

We do not set tracking cookies. The app may keep small, non-identifying preferences in your browser's local storage. Recordings and snapshots are held in memory for the current tab only and disappear when the tab is closed.

5. Camera and microphone

Your camera and microphone are only accessed after you press Allow Camera & Microphone and your browser grants permission. They are never activated silently. You can turn either off at any time during a call, and they are released when you leave.

6. Recording

Recording never starts automatically. When you start a recording, a red indicator and timer are shown on your screen and a notice is shown to the other participant. Depending on where you live, recording a conversation may require the consent of everyone involved; you are responsible for complying with applicable law.

7. Third parties

The service may use a STUN server (for example a public STUN server) so browsers can discover their public address, and optionally a TURN relay. These services see connection metadata but never media content. We do not embed third-party analytics, advertising or social media scripts.

8. Children

The service is not directed at children under 13 (or the age of digital consent in your country) and we do not knowingly process their data.

9. Your rights

Because we hold no persistent personal data, there is nothing to access, correct or delete after a call ends. If you have questions, contact us via the contact page.

10. Changes

We may update this policy as the service evolves. The date at the top shows the current version.