Legal
Privacy Policy
How Louma collects, uses, protects, and shares data across the wallet.
Last updated: June 1, 2026
1.Introduction
Louma (“Louma”, “we”, “us”, “our”) provides a digital wallet for holding, sending, and receiving LMA, so account holders can manage their balance, transfers, mining, and history from a single account (the “Service”).
This Privacy Policy explains what data we collect, why we collect it, how we protect it, and the choices you have. It applies to our websites, apps, APIs, and any other product or service that links to this policy. By using the Service, you agree to the practices described here.
2.Data We Collect
We collect three categories of data:
- Account data — name, email address, phone number, account name, billing details, and authentication credentials you provide when you create or manage an account.
- Wallet data — the activity you and your connected services bring into the platform: balances, receiving addresses, transfers, transaction history, mining records, and generated documents such as receipts and statements. This data belongs to you.
- Usage data — log data, device and browser information, IP address, pages viewed, and feature interactions, collected automatically to keep the Service secure and reliable.
3.How We Use Data
We use the data we collect to:
- Provide, operate, and maintain the Service, including syncing your connected services.
- Process transfers and send related notifications (transfer events, settlement updates).
- Detect and prevent fraud and abuse, including our suspicious transfer review.
- Monitor performance, debug issues, and improve product features.
- Communicate with you about updates, security notices, and support requests.
- Comply with legal obligations.
We do not sell your data. We do not use your wallet data to train models for other accounts, and we never share your recipients’ information with advertisers.
4.Account Isolation
Louma is built with strict account boundaries. Every query that touches wallet data is scoped to your account, and access is verified on every request — no account can read, infer, or aggregate another account’s data.
Aggregate, fully anonymized metrics (for example, overall platform uptime or total request volume) may be used internally to operate the Service; these can never be traced back to an individual account or account holder.
6.Security
We apply defense-in-depth across the platform: encryption in transit (TLS) and at rest, scoped API tokens, role-based access control inside accounts, audit logging of sensitive operations, and isolation between the gateway, core, and worker layers of our architecture.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay and share the information you need to respond.
7.Data Retention & Deletion
We retain wallet data for as long as your account is active. When you delete a record, a custom address, or your account, the data is removed from production systems promptly and purged from backups on a rolling schedule (no longer than 90 days).
You can export your data at any time from the wallet, and you may request full deletion by contacting us — we honor deletion requests regardless of your plan.
9.Your Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (“right to be forgotten”).
- Export your data in a portable format.
- Object to or restrict certain processing.
To exercise any of these rights, email [email protected]. We respond to verified requests within 30 days.
10.Changes to This Policy
We may update this policy as the Service evolves. For material changes we will notify account holders by email and show a notice in the wallet at least 14 days before the change takes effect. The “Last updated” date at the top of this page always reflects the current version.
Questions about this document?
We read every message. Reach us any time at [email protected] or through the documentation.