Privacy Policy
Last updated: 25 September 2026
This policy explains what Lumivite stores, why it is stored and what control you have over it. We keep the amount of personal data to the minimum the service needs to work.
What we store
- Account details: your name, your email address and a hashed version of your password.
Passwords are hashed with PHP's
password_hash()and cannot be read by anyone, including us. - Widget content: the names, headings, dates, timezones, links and style settings you enter when you build a widget.
- Sign in attempts: the email address and IP address used for each sign in attempt. These records protect accounts against password guessing and are deleted automatically after 24 hours.
- Password reset requests: a one way hash of the reset link, its expiry time and whether it was used.
What we do not store
- No payment details. The service is free and has no paid plans.
- No music or video files. Your widgets link to YouTube and Spotify, which serve the media themselves.
- No advertising or tracking profiles.
Cookies
One cookie is used, the PHP session cookie, and only to keep you signed in. It is marked HttpOnly and SameSite so it cannot be read by scripts or sent from other sites. Public widget pages do not set any cookie at all, which is why they can sit safely inside a Canva page.
Third party players
When a visitor taps the play button on a music widget, the official YouTube or Spotify player loads in an
iframe. At that moment the visitor's browser connects to that platform directly, and the platform's own
privacy policy applies to that connection. YouTube is loaded through
youtube-nocookie.com, which limits what YouTube stores before playback starts.
Public widget pages
Anything you place on a widget - headings, completion messages, song links - is visible to anyone who has the widget's public address. Widget addresses contain a random identifier and are not listed anywhere, but they are not secret. Do not put private information into a widget.
Keeping data
Your widgets stay in place until you delete them. Deleting a widget removes it immediately and its public link stops working. Deleting your account from the Account settings page removes your profile and every widget attached to it.
Your choices
- Edit or correct your details at any time on the Account settings page.
- Delete any widget from your dashboard.
- Delete your whole account, which removes all associated data.
Contact
This installation of Lumivite is operated by the person or organisation that hosts it. For any privacy question, contact the operator of this site.