Section 01Who we are.
Lumi is a general wellness and mental-wellbeing companion app operated by Lumetrix Labs Limited ("Lumetrix", "we", "us"). Lumi is not a medical device, a therapy service, a diagnostic tool, or a crisis service, and it does not provide medical advice.
If you are in crisis, call or text 988 (the 988 Suicide & Crisis Lifeline), text HOME to 741741 (Crisis Text Line), or call 911.
This policy explains what information Lumi collects from users in the United States, how we use it, who we share it with, and the rights you have. It supplements the in-product disclosures and our separate Consumer Health Data Privacy Policy (required for Washington residents and applied by us to all US users).
Section 02Our privacy-by-design approach.
- Lumi accounts are anonymous. We do not ask for or store your name, email address, or phone number to create or use an account.
- We do not sell your personal information, and we do not use it for cross-context behavioral ("targeted") advertising.
- We use no third-party advertising SDKs and no third-party analytics SDKs.
- Lumi is for adults 18 and older. We do not knowingly collect information from anyone under 18.
Section 03Information we collect.
You provide most of this information directly, and all health-related fields are optional.
| Category | Examples | Required? |
|---|---|---|
| Anonymous identifier | A randomly generated account UUID | Required |
| Optional profile | Age bracket, sex, region, self-reported diagnosis status | Optional |
| Consumer health data | Daily mood logs; weekly S8 wellbeing self-assessment scores; medication names, doses and timing; free-text side-effect and diary notes | Optional |
| Chat content | Your messages to Lumi and Lumi's replies | Optional |
| Voice input | Audio recorded with Voice mode — processed in real time and not stored; only the transcribed text is kept | Optional |
| Purchase status | Whether you have an active trial, subscription, or top-up | Only if you subscribe |
| Technical data | Crash logs and performance diagnostics (contain no health data) | Required |
We do not collect the following:
Face ID and fingerprint authentication are processed entirely on your device by iOS or Android. Lumi never sees them.
Section 04How we use information.
- To provide the app's features: the Lumi companion chat, mood and S8 tracking, the medication diary, lifestyle tips, and the exportable self-report ("Doctor PDF Report").
- To personalize your experience (e.g., tailoring tips and helpline resources to your region).
- To operate the optional subscription and process in-app purchases.
- To keep the service secure, prevent fraud and abuse, and diagnose crashes.
- To comply with law and enforce our terms.
We do not use your personal or health information to serve ads, and our AI provider does not use your conversations to train its models.
Section 05How information is shared.
We share information only with service providers (processors) acting on our behalf under contract, never as independent sellers of your data:
| Service provider | Role | Data it processes |
|---|---|---|
| Supabase (EU/Ireland) | Database & authentication | All stored app data |
| Anthropic (Claude API) | Powers the Lumi companion | Your chat messages and context; not used for model training |
| Groq / Whisper | Speech-to-text | Voice audio, processed ephemerally and not stored |
| ElevenLabs | Text-to-speech | Lumi's already-generated reply text only |
| RevenueCat + Google Play Billing | Subscriptions & purchases | Purchase/entitlement status; payment-card details never reach us |
We may also disclose information if required by law, to protect safety, or in connection with a corporate transaction (with notice and continued protection of your data). Transfer of data to a processor is not a "sale" or "share" under US privacy laws.
Section 06Where your data is stored and transferred.
Your data is stored on Supabase servers in the EU (Ireland) and is encrypted in transit (TLS) and at rest. If you use Lumi in the United States, your information is transferred to and processed in the EU and other countries where our processors operate. We rely on contractual safeguards with our processors for these transfers.
Section 07Data retention and deletion.
We keep your data while your account exists. You can export all of your data as JSON (Settings → Export all my data) and delete your account and all associated data at any time (Settings → Delete my account → Delete everything). Most data is erased immediately and all of it within 30 days. You can also request deletion at talktolumi.app/delete.html or by emailing hello@talktolumi.app.
Section 08Your US privacy rights.
Depending on your state of residence (including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others), you may have the right to:
- Know / access the personal information we hold about you;
- Delete your personal information;
- Correct inaccurate personal information;
- Port a copy of your information;
- Opt out of sale, targeted advertising, and certain profiling — note that we do not sell personal information, do not engage in targeted advertising, and do not profile in ways that produce legal or similarly significant effects;
- Be free from discrimination for exercising these rights.
Because Lumi accounts are anonymous, you can exercise access, export, and deletion rights directly in the app without contacting us. You may also contact hello@talktolumi.app. We will not deny you goods or services for exercising your rights. If we deny a request, you may appeal by replying to our decision; California residents may also contact the California Privacy Protection Agency or Attorney General.
California "shine the light": We do not disclose personal information to third parties for their own direct-marketing purposes.
Section 09Consumer health data.
Your mood logs, S8 scores, medication entries, diary/side-effect notes, and the mental-health nature of your use of Lumi are consumer health data. We treat this data with heightened protection and obtain your consent before collecting it. Our handling of consumer health data — including the right to withdraw consent and to have this data deleted — is described in our separate Consumer Health Data Privacy Policy, which forms part of this policy. We do not sell consumer health data and would never do so without the separate valid authorization the law requires.
Section 10Security.
We use anonymous accounts, encryption in transit and at rest, row-level security so each user can access only their own data, an optional biometric app lock, and server-side handling of all AI and voice keys. No method of transmission or storage is perfectly secure, but if a breach of unsecured health data occurs we will notify affected users and regulators as required (including under the FTC Health Breach Notification Rule).
Section 11Children.
Lumi is intended only for adults 18 and older. The app applies an age gate during onboarding and we do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact hello@talktolumi.app and we will delete it.
Section 12Changes to this policy.
We will post any changes here with a new effective date and, for material changes, provide in-app notice.
Section 13Contact us.
Lumetrix Labs Limited
Operated from the United Kingdom, serving users in the United States.
Privacy questions: hello@talktolumi.app
Technical support: support@talktolumi.app