Privacy Policy
Last updated: 28 August 2026
In short
Lumeno is a daily introspection app. What you write in it belongs to you. We have built no advertising tracker, no analytics tool, and no resale of data to third parties.
- You can use Lumeno without ever giving your name or your email address: the account is anonymous by default.
- No advertising, no trackers, no behavioural analytics in the app.
- Your reflections are hosted in the European Union.
- To compose your periodic readings, the text of your reflections is sent to OpenAI, in the United States, without your account identifier. The text itself remains personal data. That is section 5, the most important point in this document.
- Lumeno is for people aged 16 and over. That is section 2.
- You can delete your account and all your data from the app, in seconds.
1. Who is responsible for your data
The Lumeno app is published by Matthieu Mary, sole trader, residing at 62 chemin de la Bourière, 85300 Froidfond, France. SIREN 103 707 303, SIRET 103 707 303 00022, EU VAT number FR47103707303. Phone: +33 7 56 93 85 44. As data controller within the meaning of the General Data Protection Regulation (GDPR), he determines why and how your data is processed.
For any question or request about your data: contact@lumeno-app.com.
2. Age requirement
Lumeno is reserved for people aged at least 16. We do not knowingly create an account for anyone younger, and we have deliberately built no feature aimed at children under 16.
If you are the legal guardian of someone under 16 who has used Lumeno, write to contact@lumeno-app.com: the account and all of its data will be deleted without delay.
3. What data is processed, and why
We collect only what the app needs to work. None of this data is used for advertising.
| Data | Why | Legal basis |
|---|---|---|
| Account identifier (automatically generated UUID) | Linking your writings to your account without needing your identity | Performance of the contract |
| Your written reflections | The heart of the service: keeping them and letting you reread them, year after year | Performance of the contract, and your explicit consent for whatever sensitive content they may contain (section 4) |
| The feelings attached to each reflection | Enriching the rereading and composing the periodic readings | Performance of the contract |
| The periodic readings produced for you | Displaying them, and letting you reread them later | Performance of the contract |
| Email address and password (optional) | Only if you choose to secure your account so you can find it again after reinstalling | Performance of the contract |
| First name (optional) | Greeting you by name in the app | Performance of the contract |
| Language and time zone | Showing content in your language and releasing the daily question at the right time | Performance of the contract |
| Subscription status | Giving access to premium features if you subscribe | Performance of the contract |
| Daily reminder time | Scheduling the reminder notification, if you enable it | Consent |
| Report of a reading, and a copy of the reported text | Handling your report, fixing what needs fixing, and meeting the app stores' requirement to allow generated content to be reported (see section 13 of the terms of use) | Legitimate interest, and contractual obligation towards the stores |
| Technical connection logs (IP address, device type, timestamp), produced by our providers | Running and securing the service, detecting abuse and incidents | Legitimate interest in the security of the service |
The anonymous account
On installation, Lumeno creates an anonymous account identified by a random number. We do not know who you are. You can then choose to attach an email address to it, solely so you can find your writings again if you change device. Attaching it remains optional.
Technical logs
Like any online service, Lumeno runs on servers that record connections: IP address, device type, timestamp. These logs are produced by our hosting providers, serve only to run and secure the service, are never cross-referenced with the content of your journal, and feed no analysis of your behaviour. They are kept for a maximum of thirty days.
4. The sensitive data you may write, and your consent
Lumeno is a private journal. So you may write in it, if you wish, things the GDPR treats as sensitive: your health, your beliefs, your personal life, your origins, your orientation. Such data falls under article 9 of the GDPR, and processing it requires your explicit consent.
We never ask you for this information, we do not look for it, we do not categorise it and we build no profile from it. But nor can we prevent it: that is the nature of a free writing space.
Accordingly, if you choose to write such things, you expressly consent to them being treated like the rest of your reflections, that is:
- kept in your journal for as long as your account exists;
- sent, at the moment you open a periodic reading and thereby trigger its production, to the artificial intelligence provider described in section 5.
This agreement is asked for, never assumed. Before your very first periodic reading, the app shows a dedicated screen setting out what is sent, what is not, and how to go back on it. Nothing leaves before you have accepted, and declining is offered in the same place. This agreement is separate from your acceptance of the terms of use, it is asked only once, and its date is kept.
You keep control afterwards. You can write nothing sensitive, never open a periodic reading, delete a reflection, or delete your account: withdrawing your consent is immediate and requires no justification. It applies to the future only and does not affect processing already carried out.
5. Artificial intelligence and your reflections
This is the most sensitive processing in the app. We would rather explain it precisely than bury it in a general formula.
Lumeno composes periodic readings (weekly, monthly, yearly) that interpret what you wrote over the period. To produce them, the text of your reflections, the attached feelings, the questions asked and the theme of the month are sent to OpenAI, a provider established in the United States, through its programming interface.
What to keep in mind:
- No account identifier goes with that text. Neither your identifier, nor your email address, nor your first name is sent. OpenAI receives content, not the identity of the person who wrote it.
- It remains a transfer of personal data. Free text can contain elements that identify you, if you write them. The absence of an identifier reduces the risk; it does not make the text anonymous.
- This processing happens when a reading is produced, that is when you open it. It does not happen every time you write.
- Under OpenAI's data usage policy applicable to its programming interface, content sent through that channel is not used to train its models. It may however be retained by OpenAI for a short period, in the order of thirty days, for abuse detection, before deletion. That policy is OpenAI's and may change independently of us: openai.com/policies/api-data-usage-policies.
- The text produced by the model then passes through an automated moderation filter, at the same provider, before it is shown to you. That filter applies to the model's output, never to what you write.
- Artificial intelligence is used only to compose these readings. It writes neither the questions nor the quotes, which are written or validated by hand, and it never addresses you directly.
- A reading is an automated interpretation, which can be wrong. It produces no legal effect concerning you and determines no decision about you.
6. Who your data is shared with
We use technical providers (processors within the meaning of the GDPR) who process data on our behalf, on our instructions, and cannot use it for their own purposes. Each is bound by a data processing agreement.
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Supabase | Database hosting and account management | All of your account data | Servers in the European Union. Company established in the United States, which may access them for maintenance |
| OpenAI | Production of the periodic readings and moderation filter | Text of reflections, feelings, questions, theme of the month, without account identifier | United States |
| RevenueCat | Subscription management | Account identifier and subscription status. No journal content | United States |
| Apple, Google | Sale and payment processing through their stores | Transaction data, which we never receive | Under their own policies |
| Expo | Building the app and delivering updates | No journal content. Device technical data and IP address when checking for an update | United States |
| Vercel | Hosting Lumeno's web pages (legal documents, password reset, account deletion) | No journal content. Visitor IP address in server logs | United States |
Your data may also be disclosed where the law requires it, for instance under a judicial order. In that case we limit ourselves to what is strictly requested and inform you where the law allows.
If the business is sold, data would be transferred to the acquirer, bound by this policy. You would be informed in the app, and could delete your account before the transfer.
7. Where your data is hosted, and transfers outside Europe
The database holding your reflections is hosted in the European Union, and they remain stored there.
Several of our providers are however established in the United States, which entails transfers outside the European Union. We would rather list them precisely than give a partial picture:
- OpenAI receives the text of your reflections when a reading is produced. This is the most significant transfer, described in detail in section 5.
- RevenueCat receives your account identifier and your subscription status, never the content of your journal.
- Expo receives technical data and your IP address when the app checks for an update.
- Vercel records the IP address of visitors to Lumeno's web pages.
- Supabase hosts the database in Europe, but the company is American and its staff may access the servers for maintenance.
These transfers are governed by the European Commission's standard contractual clauses, the mechanism provided for in article 46 of the GDPR, supplemented where applicable by the provider's certification under the EU-US Data Privacy Framework. You can obtain a copy of the applicable safeguards by writing to contact@lumeno-app.com.
8. How long your data is kept
Your reflections are kept for as long as your account is active. That is the very principle of Lumeno: being able to reread in ten years what you wrote today. We do not erase them after some arbitrary period.
Inactive accounts. An account with no login for five consecutive years is treated as abandoned and deleted, along with all its data. If an email address is attached to the account, we warn you at least thirty days beforehand, and a single login is enough to start another five years. An anonymous account cannot be warned, for lack of any way to reach you: one more reason to attach an email address if your writings matter to you.
Deletion by you. When you delete your account, all of your data is erased immediately and permanently from the active database: your reflections, your feelings, your readings, any reports you filed and any email address. This deletion is irreversible and there is no backup copy we could restore for you.
Other retention periods. Technical logs are kept for a maximum of thirty days. Reports of a reading are kept for up to twelve months after they are handled, and in any event deleted together with the account of the person who filed them.
Backups. Automated technical backups of the database are kept by our host for a maximum of thirty days before being overwritten. They are used only in the event of a major incident, never to restore a deleted account.
9. What we do not do
This list matters as much as the previous ones. Lumeno contains none of the following:
- No advertising, no advertising identifier.
- No audience measurement or behavioural analytics tool (no Google Analytics, Firebase, Facebook SDK or equivalent).
- No sale, rental or exchange of your data.
- No access to your location, your contacts, your microphone, your camera or your photos.
- No profiling and no automated decision producing legal effects concerning you.
- No push notification sent from our servers: reminders are scheduled locally on your phone.
- No human reading of your journal, unless you report a reading yourself, as explained in section 3.
10. Cookies and web pages
Lumeno's web pages, including the one you are reading, set no cookies, use no trackers and embed no audience measurement tool. No consent is therefore required to browse them. The server hosting them records connection IP addresses in its technical logs, under the conditions described in section 3.
11. Security
- All communications between the app and our servers are encrypted (HTTPS).
- Data is encrypted at rest by our host.
- Every table is protected by row level security rules, which technically guarantee that an account can only reach its own data.
- The access key to the artificial intelligence provider lives only on our servers. It is never bundled into the app.
- Your password, if you set one, is never stored in clear text.
- Your session is kept on your phone in the operating system's secure storage.
No system is infallible. In the event of a data breach likely to result in a high risk to your rights, you will be informed in accordance with article 34 of the GDPR, and the supervisory authority will be notified within 72 hours in accordance with article 33.
12. Your rights
Under the GDPR, you have the following rights:
- Access: obtain a copy of the data we hold about you.
- Rectification: correct inaccurate data. Your first name, your language and your reflections can be edited directly in the app.
- Erasure: delete your account and all your data. This can be done immediately from the app, in your profile settings, without writing to us. If you no longer have access to the app, the same deletion is possible from this page, for accounts with an email address.
- Portability: receive your data in a machine-readable format. This export is free and independent of any subscription: it has nothing to do with the premium PDF export, which is a matter of layout comfort, not the exercise of a right.
- Restriction and objection: ask for processing to be suspended or object to it, in particular where it rests on our legitimate interest.
- Withdrawal of consent: withdraw at any time the consent described in section 4, and turn off the daily reminders in the settings, without justification.
- Post-mortem directives: set directives on what happens to your data after your death, under article 85 of the French Data Protection Act, by writing to us.
To exercise these rights, write to contact@lumeno-app.com. We answer within one month. For an anonymous account it is technically impossible for us to verify that you are its holder: in that case, the rights are exercised directly from the app, which is the only place where that proof exists.
If you believe your rights are not being respected, you can lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75334 Paris Cedex 07, www.cnil.fr, or with the supervisory authority of your country of residence.
13. Changes to this policy
This policy may evolve with the app. The last updated date appears at the top of this page. In the event of a substantial change concerning the data processed, its recipients or transfers outside Europe, we will inform you in the app before it takes effect.
14. Contact
A question, a request, a doubt: contact@lumeno-app.com.