LumaRelay · Privacy

LumaRelay privacy notice

Draft privacy information for LumaRelay local-network lighting control and synchronisation.

Status
Draft — final capture, network and dependency audit required
Effective
Not yet effective
Last reviewed
25 July 2026
Product status
In development

Status and scope

This is a draft privacy notice based on the inspected macOS and Android TV development implementations. It is not yet effective. The exact signed release, locked dependencies, screen/audio pipelines, runtime network traffic, Bridge discovery route, credential storage, logs and store services must be audited before publication.

LumaRelay is an independent utility. It is not affiliated with or endorsed by Signify or Philips Hue.

Data accessed

To provide selected features, LumaRelay may access:

  • local-network information used to discover and communicate with a compatible Bridge;
  • Bridge, light, room, zone, scene and Entertainment-area identifiers/configuration;
  • screen samples for display synchronisation;
  • system-audio or microphone samples for audio-responsive modes;
  • locally selected colours, settings and lighting preferences; and
  • app/device information a user chooses to include in a support email.

Screen or audio access can incidentally expose sensitive content to the app process. The product should request it only for the chosen mode.

Local processing and storage

In the inspected implementation, screen and audio samples are analysed locally for real-time lighting output. They are not intended to be saved as recordings or uploaded to Netro Labs. This boundary must be reverified against the release build and logs.

Bridge credentials, pairing keys, device identifiers, preferences and allowance state may be stored locally, including in platform credential storage. Exact files, Keychain/keystore persistence and backup behaviour remain to be documented.

Data transmitted from the device

Lighting commands and configuration requests are sent to the user’s compatible Bridge over the local network.

The macOS implementation may contact a Signify/Philips Hue discovery endpoint to find Bridges when local discovery is insufficient. The payload, IP/network metadata, provider role, retention and App Store classification must be verified. A manual local address path may reduce—but does not automatically eliminate—external processing.

No Netro Labs analytics, advertising or crash-reporting provider is currently claimed for the proposed release. The final archive and runtime traffic must confirm this.

Permissions

Local network

Local-network access is required for Bridge discovery, pairing, control and synchronisation. Denying it prevents those features.

Screen recording or capture

Screen access is required for display synchronisation and may be used by some system-audio capture paths. Colour and basic Home controls should remain available without it. The app should not capture a screen until the user intentionally starts the relevant mode.

Microphone

Microphone access is optional and should be requested only for microphone or clap-responsive features. System-audio modes must not be described as microphone recording unless that is how the final implementation works.

Android TV notifications

Android TV may require a visible notification for a foreground synchronisation service. That notification communicates that capture/sync is active; it is not advertising.

Third-party hardware and services

The final notice will identify the exact Signify/Hue services, Apple/Google platform services, dependencies, network endpoints and processors used by each distributed build.

Philips Hue is a third-party trademark. Compatibility language does not imply a partnership, certification or endorsement.

Retention and deletion

Pairing credentials and preferences are expected to remain until the user forgets the Bridge, resets local data or removes the app. Platform credential stores may persist differently from ordinary app files.

Before release, a visible “Forget Bridge and delete local data” path must be tested to confirm it removes pairing keys, Bridge identifiers, preferences, cached configuration and allowance state as intended. Screen and audio samples should be short-lived in memory only; logging and crash capture must be checked.

No account-deletion page is provided because no Netro Labs account is currently claimed. A cloud entitlement or account system would trigger a separate deletion process and policy update.

Your rights and contact

For local information, practical controls include stopping capture, changing system permissions, forgetting the Bridge, resetting the app and uninstalling it.

The final notice will identify the legal controller, correspondence address, privacy email, lawful bases, recipients, retention criteria, transfer safeguards, rights and regulator details. Those facts are not invented here.

Revisions

This permanent URL will be reviewed whenever LumaRelay changes its hardware support, discovery, capture, microphone, credentials, accounts, analytics, purchases, SDKs or data transmission.