API terms and your data

The developer platform (the API, AI assistant connections and the CLI) is part of Lumeta, so our Terms of Service and Privacy Policy apply to it just as they do to the website, and they are what counts. This page adds what is specific to using Lumeta from code and other apps, in plain words.

The short version. Your work is yours, whichever way you made it. We never train AI on your uploads, prompts or results, and we never sell your data. Keep your keys secret, set limits you're comfortable with, and you can switch any key or app off in one click.

Keys and connections

  • A key is like a password. Keep it on your own server or computer, never in a web page or an app you hand out. We store only a fingerprint of it, so we can't show it to you again; make a new one if you lose it.
  • You're responsible for what your keys and connected apps do, including the credits they spend. Limits on each key and each connection help keep that predictable.
  • If a key leaks, revoke it under Account → Developer. It stops working at once. If you see spending you don't recognize, write to us right away.
  • We may switch off a key or connection that is being misused or puts the service or other people at risk. When we can, we'll tell you why.

Credits and limits

  • Everything you make through the platform spends the same credits as the website, at the same prices. POST /v1/estimate (or asking your assistant) gives the exact price before you spend.
  • If a provider fails to deliver a result, the credits come back to you automatically.
  • Credit limits you set on a key or connection are checked before anything is spent. Automatic top-up only happens on keys and connections where you switched it on.
  • Rate limits keep the service fast and fair for everyone. The current numbers are in the API docs; we may adjust them as we grow.

What you can build

  • Use Lumeta in your own products, scripts and workflows, for yourself or for clients. What you generate is yours to use, publish and sell, as the Terms say.
  • The website's content rules apply to everything sent through the platform, including what your own users send through your app. Be especially careful with photos of real people: only with their permission.
  • Keep your key to yourself. Don't give it to other people or sell access to it; build your own product on top instead.
  • Don't use the platform to get around limits, moderation or another account's restrictions, and don't load-test or probe it. Found a security problem? Tell us and we'll thank you.

AI assistants

When you connect an assistant such as Claude, ChatGPT or Cursor, it sends your requests to Lumeta, and what Lumeta answers goes into your chat: results and their previews, prices, your balance, and the names on your Shelf when the assistant looks them up. The assistant's company handles that under its own privacy terms, like anything else you share in that chat. You choose what each connection may do when you press Allow, and you can disconnect it any time under Account → Developer.

Changes to the API

  • Version 1 of the API is stable. We add models, fields and endpoints as we go, so please ignore fields you don't recognize rather than fail on them.
  • When we have to change or remove something you may rely on, we'll tell you ahead of time by email.
  • Models come and go as providers update them. GET /v1/models is always the live list.

What we keep, and for how long

WhatHow long
Your creations and uploadsExactly as on the website: kept while a paid plan is active; on a Free account they may be removed after 90 days; when a paid plan ends you get a fresh 90-day window. Very large files have shorter limits (see the Privacy Policy). You can delete anything yourself, any time.
Run history (prompt, settings, which key or app started it)With your account, so you can always see what you made and how, until you delete it or your account.
API keysOnly a fingerprint, never the key itself. A revoked or expired key stays listed in your account's history, so past spending stays explainable.
Assistant connectionsAccess passes last 1 hour and renew themselves. A connection unused for 90 days asks you to sign in again.
Idempotency keys24 hours, then forgotten
Webhook delivery records30 days. We keep the record of each attempt (event id, status, your server's answer code), not a copy of your results.
Technical logs (request id, time, IP address, status)For a limited time, for security and to fix problems you report.

Prompts and files are sent to the AI provider behind the model you run, exactly as on the website. Deleting your account switches off every key and connection at once and removes your webhook endpoints along with the rest of your data.

Contact

Questions about the platform: [email protected]. Misuse or a security problem: [email protected]. Legal: [email protected].