The short version
Lumie exists to protect your attention, not to sell it. We collect what the app needs to work, we protect it in transit and at rest, we don't sell it, and you can delete all of it whenever you want.
What we collect
- Account basics — your identity from Sign in with Apple or Google, handled by Firebase Authentication (name, email, user ID). We never see your password. If you use Apple's "Hide My Email", we only ever see the private relay address Apple gives us.
- Profile choices — your name, pronouns, your Lumie's name and appearance, your goals and preferences from onboarding.
- Focus activity — session lengths, completions, breaks, and totals, used for your stats, heatmap, and journal.
- Conversations — transcripts and summaries of voice and text sessions with Lumie, used to give Lumie continuity and to generate your journal.
- Spoken intentions — short audio you record before a focus room, transcribed to text on our servers.
- Notifications — a push token, only if you opt into notifications. We use it solely to tell you when something of yours is ready (like your morning intention or evening journal). No marketing pushes.
- App analytics — usage events (which screens and features you use), crash reports, performance data, and app-level identifiers, tied to your account so we can debug problems you report. Conversation, journal, and intention content is never included in analytics.
What we don't do
- We don't sell your data or share it with advertisers.
- We don't read your journal for anything other than showing it to you and generating the next one.
- We don't keep raw audio longer than needed for transcription.
- We don't track you across other companies' apps or websites, and we don't use advertising or tracking identifiers.
- We don't collect anything from this website beyond standard, aggregate traffic logs. Chat, journal, and intention content never enters website analytics.
Who processes it
Lumie runs on trusted service providers who process data only to operate the service, never for their own advertising:
- Sign-in — Firebase Authentication (Google), plus Apple for Sign in with Apple.
- Hosting & storage — our backend and database run on major cloud providers (Google Cloud and partners).
- Voice & AI — your conversation audio and text are processed by the speech and AI model providers that power Lumie's voice and responses.
- Analytics — app usage and crash data go to our analytics provider.
- Notifications — delivered through Apple's and Google's push services.
How it's protected
- All traffic uses HTTPS. There are no unencrypted endpoints.
- Protected data requires your Firebase-authenticated identity; other users can never access it.
- Voice sessions run through our backend — API keys and session credentials are never exposed to your device or browser.
Memory, honestly
Lumie's "memory" is a set of summaries and highlights, not a total recording of your life. Older raw transcripts are condensed over time. This is a product decision as much as a privacy one: friends remember the gist, not the tape.
Deleting your data
Delete your account in-app (Profile → Account → Delete account) or by emailing hello@lumie.work from the address you signed in with (Google or Apple — private relay addresses work too). Deletion removes your profile, focus history, journals, conversation summaries, and voice logs. Full instructions are on the support page.
Children
Lumie is for ages 13 and up. We ask your age at sign-up and don't allow accounts for children under 13. If you believe a child has created an account, contact us and we'll remove it.
Changes
If this policy changes materially, we'll say so in the app and on this page before the change takes effect.
Contact
Privacy questions: hello@lumie.work