Privacy Policy
Effective October 8, 2026. This policy explains how Loiste processes, retains and deletes your information.
Operator: Songyuan Liu (individual developer).
Luna is an AI host. We use information you choose to share to reply, remember relevant preferences and calculate viewing and interaction progress. You can use a nickname. Do not send identity documents, payment details or sensitive information that is unnecessary for the conversation.
The app generates a random identity on your device. Free viewing and ordinary chat do not require an account. We process nicknames, messages, relevant memories, visit days, viewing time and chat and free-heart totals. The private room also supplies your device time zone to choose the current digital appearance. The app has no microphone input, camera input, location permission or advertising tracking. Optional paid interactions are available only when enabled; the purchase screen shows current StoreKit prices and required coins.
Your nickname and comments are visible to other viewers in the same live room. Luna may refer to a comment in a public reply. Private-room messages are not broadcast to other viewers. Deleting data in the app cannot recall copies of public messages that others have already seen, recorded or saved.
Cloudflare hosts the service. Your nickname, messages, recent conversation and relevant saved memories are sent to DeepSeek to generate replies and memory notes. Dynamic speech text, which can include your nickname, Luna's reply and the message she answers, is sent to ByteDance's Volcengine Doubao Seed service. Songs play from prepared recordings; your messages are not sent to Suno to create new songs. You must expressly agree to this AI data processing before using the service.
Local preferences, older local memories, blocked-viewer lists, private-room reports and dynamic audio caches stay on your device until you delete them or automatic cache management clears or replaces them. The server keeps up to 400 temporary live transcript entries, which expire after 30 days; an extended empty-room period may clear them earlier. Each language room keeps up to 30 extracted memories, replacing older notes when the limit is reached. Memories and familiarity remain until you delete them. Private playback events are limited to 100 per viewer and remain until deletion or replacement by newer events. Complete private conversations are not separately stored as a long-term chat archive; relevant self-disclosures can become memory notes. Server dynamic speech caches expire after 7 days. Background maintenance removes expired records and rechecks them when a room recovers. These periods do not apply to provider processing records or backups.
Private replies use short-term request-rate counters linked to your random identity, based only on requests within the last minute. Expired counters are cleaned up when later valid requests arrive; deleting all data also clears your identity's counter. The room-wide counter contains request times without viewer identities and limits excessive calls.
Settings lets you review and delete individual or all memories. “Delete all my data” clears local information and dynamic audio caches, resets the random identity and restarts the app after both language rooms confirm the request. A failed request shows a retry message. Full deletion covers server memories, private playback events, familiarity and corresponding temporary context and pending speech. Temporary transcripts from older versions that lacked identity labels are also cleared rather than attributing them by nickname.
Live-room reports received by the server expire after 365 days and are automatically removed. They support abuse handling and are not Luna's conversational memory. A ban stops applying at its specified deadline and can also be lifted by an operator. Reports and ban records are not removed early by deleting conversation memories or resetting a random identity, to prevent misuse of deletion to evade moderation. Private-room reports remain on your device, limited to the 20 newest, until deletion or replacement; they are included in a support email only when you choose to send one. Provider processing records, infrastructure backups and support emails follow their own retention arrangements, and in-app deletion cannot immediately recall those copies. Loiste's operator reviews and handles live-room reports. You can also use the public email below to submit reports, appeals or data-deletion requests.
A purchase account uses Sign in with Apple to obtain an app-specific account identifier; this entry point does not request your Apple name or email. The server verifies Apple signatures and authorization codes, stores a hashed account identity, a random purchase-account identifier and sign-in sessions lasting up to 30 days. Tokens used to validate or revoke Apple authorization are encrypted on the server. Local sign-in credentials are stored in Keychain, not ordinary preferences or public chat. Loiste does not collect your Apple password, bank-card details or full payment information.
Apple purchases and the interaction ledger record product and transaction identifiers, purchase times, coin changes, balances and refund or dispute status. Interaction orders also retain the room, nickname, requested song or highlighted message to fulfil the request and calculate this show's support ranking. Coin purchases do not rank directly; cancelled and refunded coin spending is removed from the ranking. Highlighted messages, gift events and your show-support identity may be visible to viewers in the same room.
Coins and purchase account in Settings provides account deletion even outside show hours. Deletion cancels unfulfilled requests, returns their coins and clears associated personal information, memories, temporary text, queued content, nicknames and leaderboard associations in both language rooms and Apple environments. After confirmation, local data is cleared and the random identity changes. If automatic Apple revocation fails, the deletion plan and retry credential remain; deletion is not reported as complete. Legacy accounts without a revocable token have their data deleted and are guided to stop Apple authorization manually.
Necessary hashed account and purchase ownership, Apple transaction identifiers, products, amounts, coin balances and refund-reconciliation records are not automatically removed by conversation or account deletion. The current ledger has no automatic expiry for those records. They prevent duplicate credit and support unused-balance, refund and dispute reconciliation; deleted nicknames, messages and public-viewer identities are removed. For 30 days after completed deletion, an old session hash can only retrieve that deletion receipt, not sign in or spend. Local credentials are removed after confirmation. Returned coins are not a cash refund; Apple cash refunds follow Apple's process. Contact the public support email to request a manual review of retained records or refunds.
We do not use this information for cross-app advertising tracking. Privacy inquiries, data requests and complaints: hello@sieluapp.com. Online privacy policy: https://spotlight-server.spotlight-luna.workers.dev/privacy. We will update this policy when processing changes and seek renewed consent when required.
隐私政策
生效日期:2026年10月8日。本政策说明 Loiste 如何处理、保存和删除你的信息。
运营者:Songyuan Liu(个人开发者)。
Luna 是 AI 主播。我们使用你主动提供的信息,让她回复消息、记住相关偏好,并计算观看与互动积累。你可以使用昵称;请不要发送身份证号、银行卡号或其他不需要用于聊天的敏感资料。
App在设备上生成随机身份,免费观看和普通聊天不要求注册账户。我们处理昵称、消息、相关记忆、来访天数、观看时长、弹幕及免费爱心的累计信息。小房间还会提供设备时区,用于选择当前数字造型。App没有麦克风输入、相机输入、定位请求或广告追踪。可选付费互动仅在对应功能实际开放时提供;购买前会显示当前商店价格和所需金币。
直播间的昵称和弹幕对同房间的观众公开;Luna 回应弹幕时也可能公开提及相应内容。小房间消息不会向其他观众广播。请在公开直播间分享前考虑这一差别。已经被其他人看到、录屏或保存的公开消息,无法通过 App 删除功能撤回那些副本。
两个房间通过 Cloudflare 服务器提供服务。昵称、消息、近期对话和相关记忆会发送给 DeepSeek,以生成回复或提取记忆笔记。需要动态合成的语音文字可能包含昵称、Luna 的回复和她正在回复的消息,会发送给字节跳动火山引擎的豆包 Seed 服务。歌曲使用已准备的录音播放;你的消息不会作为生成新歌的输入发给 Suno。使用前需要明确同意上述 AI 数据处理。
设备上的偏好、旧版本地记忆、屏蔽列表、小房间举报文本和动态语音缓存保存在本机,直到你删除或缓存管理将其清除或替换。服务器临时直播文字记录最多 400 条,30 天到期;房间长时间无人时可提前清空。提取的记忆每个语言房间最多 30 条,超过数量时较早的记忆会被替换;记忆与熟悉度保留到你删除。私人播放事件最多保留 100 条,直到你删除或被较新事件替换。小房间的完整对话不另存为长期聊天记录,相关自述可能被提取为记忆。服务器动态语音缓存 7 天到期。到期数据由后台定时清理,并在房间恢复时复核;这些期限不适用于第三方服务自己的处理记录或备份。
私人回复还使用按随机身份隔离的短时请求频率计数,只使用最近一分钟的请求时间;过期计数在后续有效请求时清理,删除全部数据会清除本身份的计数。房间总量只保留请求时间,不含观众身份,用于防止过量调用。
在设置的记忆页,你可以查看或删除单条记忆,也可以删除全部记忆。“删除我的全部数据”需要服务器确认两个语言房间都已处理,再清除本机资料和语音缓存、重置随机身份并重新开始。失败时 App 会提示重试,不把未确认的请求显示成成功。全部删除覆盖服务器的记忆、私人播放事件、熟悉度、对应的临时对话及待播回复;旧版没有身份标记的临时直播记录会一并清理,避免按同名昵称猜测归属。
服务器收到的直播间举报用于处理滥用,保存 365 天后到期并自动清理,不作为 Luna 的聊天记忆。封禁状态在设定的截止时间失效,运营者也可以人工解除。举报和封禁记录不因删除聊天记忆或重置随机身份而提前移除,以防止滥用删除功能逃避处理。本机的小房间举报最多保留 20 条,直到你删除或新举报将其替换;只有你主动发送反馈邮件时才随邮件提交。第三方服务自己的处理记录、基础设施备份和客服邮件按各自的保存安排处理,App 内删除不能即时撤回这些副本。直播间举报由 Loiste 运营者审核和处理。你也可以通过下方公开邮箱提交举报、申诉或数据删除请求。
使用购买账户时,通过Apple登录获取本App的账户标识;该入口不请求你的Apple姓名或邮箱。服务端验证Apple签名与授权码,保存散列账户标识、随机购买账户标识和最长30天的登录会话。用于核对和撤销Apple授权的令牌加密保存在服务器;本机登录凭证保存在Keychain,不放入普通偏好或公开弹幕。Apple的密码、银行卡资料和完整支付信息不由Loiste收集。
Apple内购及互动账本记录商品和交易号、购买时间、金币增减、余额、退款或争议状态;互动订单还保存所属房间、昵称、待播歌曲或醒目留言,以履行请求并计算本场消费榜。充值本身不进入应援排名,取消并退回金币的消费会扣回排名贡献。你发出的醒目留言、赠礼动态和本场应援身份可能向同房间观众展示。
设置中的“金币与购买账户”在停播时也可访问账户删除。删除会取消未履行请求、退回相应金币,清除关联中英文房间及两个Apple环境中的个人资料、记忆、临时文字、排队内容、昵称和榜单归属;确认后清除本机资料并更换随机身份。Apple授权自动撤销失败时保留删除计划和凭证以便重试,不显示已删除;历史账户若没有可撤销令牌,会完成数据删除并提示你手动停止Apple授权。
必要的散列账户和购买归属、Apple交易号、商品、金额、金币余额及退款核对记录不会随聊天或账户删除自动清除,当前账本没有自动到期清除;这些记录用于防止重复入账、核对未使用余额、退款和争议,不再保存已删除的昵称、留言或公开观众身份。删除完成后30天内,旧会话散列仅可读取该次删除回执,不能登录或消费;使用完毕后本机凭证清除。金币退回不等于现金退款,Apple现金退款按Apple流程处理。你可以通过公开客服邮箱申请人工核对保留记录和退款。
我们不以这些数据进行跨 App 广告追踪。隐私咨询、数据请求和投诉请联系:hello@sieluapp.com。在线隐私政策:https://spotlight-server.spotlight-luna.workers.dev/privacy。若处理方式改变,我们会更新政策,并在需要时重新取得同意。