Lumee is built on the belief that your inner world is yours alone. This policy explains exactly what data we collect, how we use it, who we share it with, and what rights you have over it. We have written it to be readable — not to obscure anything.

The data controller for Lumee is Nadav Gelbard, an individual operating Lumee, based in Israel. You can reach us at hello@withlumee.com.

1. What data we collect and why

We collect only what is necessary to operate the app and improve your experience.

Account identifier. When you first open Lumee, Firebase Authentication automatically creates an anonymous account and assigns you a unique user ID. This ID is used to link all your content to your session. It does not contain your name, email address, or any other identifying information. If you later choose to link a Google or Apple account, we receive a name and email address from that provider, which we store as part of your profile.

Profile data. During onboarding, we ask for an optional display name, age range, gender, manifesting experience level, and focus areas. This information is used to personalize your experience and is stored in Firestore under your account. Providing it is voluntary — the app functions without it.

User content. Everything you create in Lumee — your intentions, journal entries (gratitude, process, and signs), affirmation preferences, and vision board content — is stored in Google Cloud Firestore under your account. Vision board images you upload are stored in Firebase Cloud Storage. This content is private to you and is used solely to operate the app on your behalf.

Notification preferences and device token. If you enable push reminders, we store your preferred notification times, frequency settings, and a Firebase Cloud Messaging (FCM) device token. The device token is used only to deliver reminders to your device. It is deleted when you disable notifications or delete your account.

Subscription and purchase data. When you subscribe, the Apple App Store or Google Play Store processes your payment. We use RevenueCat to manage your subscription state. RevenueCat receives your anonymous user ID, purchase receipt metadata, subscription status, and trial dates. RevenueCat does not receive or access any of your content.

Crash and diagnostic data. We use Firebase Crashlytics to automatically collect crash reports when the app encounters an unexpected error. These reports include device type, operating system version, app version, and a stack trace. They do not include your content or personal information beyond what is necessary to diagnose the crash.

Usage analytics. We use Firebase Analytics to understand aggregate usage patterns — for example, which features are used most. This data is collected at an aggregate level and is not used to identify individual users or read their content. You can opt out of analytics collection through your device settings (iOS: Settings → Privacy & Security → Apple Advertising; Android: device-level ad personalization settings).

2. Legal basis for processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):

3. Third-party services and data sharing

We do not sell your personal data. We do not share your content with advertisers or data brokers. We share limited data only with the following service providers who help us operate Lumee:

Beyond the above, we do not transfer your data to any other third parties.

4. International data transfers

Lumee is operated from Israel. Our primary service providers — Google Cloud and RevenueCat — are based in the United States and process data on servers that may be located in the United States or other countries outside your own. Where these transfers involve personal data from the EEA or UK, they are conducted under Google's and RevenueCat's Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms as required by GDPR Chapter V.

Israel has been recognized by the European Commission as a country that provides an adequate level of data protection under Commission Decision 2011/61/EU, meaning transfers of personal data from the EEA to Israel are permitted without additional safeguards.

5. Data retention

We retain your data for as long as your account is active. Specifically:

6. Your rights

Depending on where you are located, you may have the following rights regarding your personal data:

For users in the EEA and UK (GDPR / UK GDPR)

For users in California (CCPA / CPRA)

To exercise any of these rights, contact us at hello@withlumee.com. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before fulfilling certain requests.

7. Security

We take reasonable technical and organizational measures to protect your data. Your data is encrypted in transit using TLS and encrypted at rest on Google Cloud infrastructure. Firestore security rules ensure that only your authenticated session can read or write your data. No authentication system is perfect, however, and we cannot guarantee absolute security.

If you are using an anonymous account (no linked Google or Apple account), note that your data is tied to your device session. If you uninstall the app or lose access to your device without having linked an account, we cannot recover your data.

8. Children's privacy

Lumee is not directed at children under 13 years of age, and we do not knowingly collect personal information from children under 13. If you are under 13, please do not use Lumee or provide any information to us. If we become aware that we have inadvertently collected personal information from a child under 13, we will delete it promptly. If you believe a child under 13 has created an account, please contact us at hello@withlumee.com.

9. Cookies and tracking

Lumee is a mobile app and does not use cookies. The app does not embed web browsers or run web-based tracking. Firebase Analytics uses a randomly generated app instance ID (not a cookie) to associate usage events with a session. This identifier does not contain personally identifiable information and is reset if you uninstall and reinstall the app.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. If we make material changes — particularly changes that affect how we use your content or with whom we share it — we will notify you through the app before the changes take effect. Continued use of Lumee after the effective date of a revised policy constitutes your acceptance of the changes.

11. Contact

If you have questions about this Privacy Policy, wish to exercise your data rights, or have a concern about how we handle your information, please contact:

Nadav Gelbard
Lumee
Israel
hello@withlumee.com

We aim to respond to all privacy inquiries within 30 days.