Privacy policy
What we collect when you use the Pixel City mobile app, Luma World on the desktop and pixelcity.world — why, where it is kept, and how to delete it.
Effective 1 October 2026
The short version.
- You have one Pixel City account, shared by the desktop and mobile apps.
- The phone app shows short status updates about agents running on your desktop. It does not receive your terminal output, your files or your API keys.
- Your AI requests go straight from your computer to the AI provider you chose. They do not pass through our servers.
- The apps have no ads and no analytics or crash-reporting SDKs. The website's sign-in and download pages count visits with Google Analytics, but only if you say yes. There is no tracking across other companies' apps or websites, and we do not sell your data.
- You can delete your account in the mobile app or by emailing us.
1. Who we are
This policy is from Pixel City, the operator of pixelcity.world ("we", "us"). It covers the Pixel City mobile app for iOS and Android, the Luma World desktop app, your Pixel City account, and the pixelcity.world website. Contact: privacy@pixelcity.world.
2. Your Pixel City account
Your account is managed by Google Firebase Authentication. The mobile app and the desktop app use the same account. You can sign in with email and password or with Google, and the desktop app also offers GitHub. For your account we keep:
- your email address, and a display name if you give one;
- a user ID we generate;
- if you sign in with Google or GitHub, the basic profile that provider shares (name, email address, profile picture link);
- sign-in records Firebase keeps to run and secure the account, such as when you signed in and when the account was created.
Your password is handled by Firebase; we never see it. We use this information to sign you in, keep your desktop and phone connected to the same data, send account emails you ask for (verification and password reset) and protect the service against abuse.
3. The mobile app
Agent status from your desktop
When Luma World is running on your computer and you are signed in, it sends short status snapshots about your agents so the phone can show them. A snapshot contains:
- a random ID for your desktop installation, and a label for it;
- each agent's ID, name and a small (64-pixel) portrait image;
- the building the agent is in;
- whether it is working, idle, waiting for you, offline or unknown, and a short status note;
- conversation titles, short finish summaries and up to twelve recent status notes;
- questions an agent is waiting for you to answer, with their options;
- labels of tasks it has handed to helper agents.
It does not contain terminal output, file contents, command arguments, environment variables or your credentials. Before sending, the desktop strips common secret patterns (such as API-key-shaped strings) and replaces local file paths with "[local path]", and every text field is length-limited. Status notes are written by the agent, so we cannot guarantee a note never mentions something sensitive you typed.
Snapshots travel over an encrypted (TLS) connection to our message relay, which runs on Google Cloud in Singapore. The relay only accepts a connection that proves it is signed in as you (with a Firebase ID token), and only your own devices can read your snapshots. It keeps the latest snapshot only, not a history: agent snapshots expire after about two minutes unless refreshed, portraits after one day, and nothing is kept longer than seven days. The relay is not backed up.
The phone app is read-only: it cannot run commands, type into your terminals or reply to agents.
Notifications
If you allow notifications, the app gets a push token from Firebase Cloud Messaging (and, on iPhone, Apple Push Notification service) and stores it in our Firebase Realtime Database with your phone type, the app environment and the time it was updated. We use it only to send you alerts about your own agents, such as "an agent is waiting for you". The alert title and text pass through Google's and Apple's notification services to reach your phone. The token is deleted when you sign out, when it stops working, or when you delete your account. You can turn notifications off at any time in your phone's settings.
Stored on your phone
The app stores your signed-in session (managed by Firebase), a random installation ID, and your appearance choice (light, dark or system). Live agent data is kept in memory only and is not saved to your phone.
What the app does not use
The app does not ask for your location, contacts, photos, camera or microphone. It contains no advertising, analytics or crash-reporting SDKs, and it does not use the advertising identifier or track you across other apps and websites.
4. Luma World on the desktop
Most of what Luma World does stays on your computer: your projects, agent terminals, agent memory, and settings including your API keys (kept in local files and, for the Claude Code login, the macOS Keychain). What leaves your computer:
- Your workspace, synced to your account. City and office layouts, floors, the employees (agents) you set up, task boards, plugin settings, folder listings you add, your handle and your theme choice are saved in our Firebase Realtime Database under your account, so they follow you between installs. Only you can read or write them.
- Agent status for your phone, as described in section 3.
- AI requests go directly to the provider you choose — for example Anthropic, OpenAI, OpenRouter, Google or Alibaba Cloud — using your own key, subscription or command-line tool, under that provider's terms and privacy policy. This includes voice: if you use voice features, your microphone audio is sent to the speech provider you configured. These requests do not pass through Pixel City's servers, and we do not receive or store your keys.
- Update and configuration checks. The app reads public release notes, feature switches and a list of supported AI tools from our servers. These requests carry nothing about your work.
Luma World contains no advertising, analytics or crash-reporting SDKs.
5. The website
pixelcity.world is hosted on Firebase Hosting and uses fonts from Google Fonts, so
Google receives your IP address and browser details when you load a page. We do not
use advertising cookies on it. The sign-in, download and add-on pages (/login,
/get, /client and /chrome) and
luma.pixelcity.world ask first: a bar at the bottom of the page offers Google Analytics
for Firebase, and nothing is loaded until you choose Accept. If you do,
it sets cookies such as _ga to count visits and see which pages are used.
Decline sets no analytics cookies, and removes any that are there. Your
answer is kept in your browser's local storage on that site, and Cookie
settings in the page footer lets you change it at any time. If you join the waitlist we store what
you enter in the form (such as name, email, role and the tools you use); if you file a
bug report while signed in we store the report with your name and email. Only our team
can read either.
6. What we do not do
- We do not sell or rent your personal information.
- We do not show ads or share your data with advertisers or data brokers.
- We do not track you across other companies' apps or websites.
- We do not use your agent status, workspace or AI conversations to train AI models.
7. Who processes your data
We use a small number of service providers, each only to run the service:
- Google (Firebase and Google Cloud) — accounts, database, file storage, cloud functions, website hosting and analytics, push notifications and the message relay.
- Apple — delivering notifications to iPhones.
- Cloudflare (R2) — hosting the Luma World download files. When you download the app, Cloudflare receives your IP address and browser details.
- Google and GitHub — only if you choose to sign in with them.
AI providers you connect to Luma World are chosen and paid for by you, and your relationship with them is governed by their own terms. We may also disclose information if the law requires it, or to protect the safety of our users or the service.
8. Where your data is stored
Our database and message relay are in Google Cloud's Singapore region (asia-southeast1). Firebase Authentication and push delivery are global Google services. If you live elsewhere, your information is transferred to and processed in Singapore and other countries where Google and Apple operate, which may have different data-protection laws from yours. We rely on these providers' contractual and security commitments for those transfers.
9. How long we keep it
- Account and synced workspace — until you delete them or your account.
- Agent status snapshots — the latest state only; minutes for status, a day for portraits, never more than seven days.
- Push tokens — until you sign out, the token stops working, or you delete your account.
- Waitlist entries and bug reports — until they are no longer needed, or you ask us to delete them.
- Emails you send us — as long as needed to answer you and keep a record of the request.
10. Deleting your account
In the mobile app, open Your account → Delete account. You can also email privacy@pixelcity.world from the address on your account. Deleting your account removes:
- your Pixel City sign-in (Firebase Authentication account), so you can no longer sign in to either app;
- everything stored under your account in our database — your synced cities, offices, floors, employees, boards, plugin settings, profile, handle, theme choice and phone push registrations.
Agent status snapshots on the relay are no longer refreshed and expire on their own within minutes (at most seven days). A relay connection that is already open may keep working until its sign-in token expires, normally within an hour. Waitlist entries and bug reports are removed when you ask by email. Deleting your Pixel City account does not delete files on your computer or accounts you hold with AI providers, Google or GitHub.
11. Your rights
You can ask us to give you a copy of your data, correct it, or delete it, and, where the law gives you these rights, to restrict or object to how we use it. You can delete your account yourself from the mobile app. For anything else, email privacy@pixelcity.world; we will reply within 30 days. You may also complain to the data-protection authority where you live.
12. Security
Data between the apps and our services travels over TLS. Database access is limited by rules that let only you read and write your own records, and the relay checks your Firebase sign-in on every connection. No system is perfectly secure, so please use a strong password and tell us about anything suspicious.
13. Children
Pixel City is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us information, email privacy@pixelcity.world and we will delete it.
14. Changes to this policy
If we change what we collect or how we use it, we will update this page and the date at the top. For material changes we will also tell you in the app or by email before they take effect.
15. Contact
Privacy questions and requests: privacy@pixelcity.world
General help: pixelcity.world/support