Back

Privacy Policy

Last updated · July 10, 2026 · Lumina (Beta)

This page is maintained by the Lumina team to answer common privacy questions about the Lumina app. It reflects app-visible controls and current operating practices, and is not an independent certification.

1. Who we are

Lumina is an AI-assisted fitness, nutrition and wellness companion built for serious athletes. We minimize data collection by design and surface every sharing control directly inside the app.

2. Identity & Name Transparency

Real names are masked by default. Your public surface is your unique handle. Your legal display name is only revealed to other users when you persistently enable the Name Transparency toggle in Settings — the choice is stored on your profile and applied consistently across every screen until you turn it off.

3. Media — Profile Pictures & Daily Recaps Vault

Profile pictures, workout photos and diet recap snapshots uploaded to the Daily Recaps Vault are hosted on our secured cloud storage. Exposure is user-controlled: the photo only becomes visible to others when the matching Circular Data Sharing scope (Workout Recaps or Diet Recaps) allows it. Deleting a recap removes the underlying media from the vault.

4. Circular Data Sharing

Visibility of Workout Recaps, Diet Recaps and your Current Diet Plan is governed dynamically by you through the 3-way capsule selectors — Private · Friends · Everyone. Each category is sovereign and independent; changes apply immediately and are honored everywhere your profile is rendered.

5. Direct Messaging (MSG)

The MSG direct chat feature runs over an authenticated channel and persists only the minimum metadata needed to render conversations between mutually connected users. Message bodies are sanitized client-side before transmission, and local message caches are cleared when you sign out, block a user, or delete a conversation. Frozen and blocked conversations are removed from both sides.

6. Automated safety processing

Text you type into chats, handles, search and community fields is screened locally by the Lumina moderation engine before it reaches the network. Detected matches are used only to mask profanity, intercept extremist or threatening payloads, or apply an account-level strike — they are not used for advertising or third-party profiling.

7. UAE data protection & TDRA compliance

For users in the United Arab Emirates, Lumina aligns its data handling with Federal Decree-Law No. 45 of 2021 on the protection of personal data (PDPL) and the published guidance of the Telecommunications and Digital Government Regulatory Authority (TDRA). All transit data layers ride over authenticated TLS channels, real identities stay aggressively masked behind custom @handle layouts by default, and biometric or health inputs are processed only for the in-app coaching features you actively use. Lawful data subject requests (access, rectification, deletion, withdrawal of consent) can be submitted through in-app support and are honored within the statutory timeframe.

7. Personally Identifiable Information

We process the minimum PII needed to run your account: email, handle, optional display name, and biometric inputs you choose to log. Real names stay masked unless Name Transparency is explicitly on. Health, training and nutrition data is yours — you can export or request deletion at any time via in-app support.

8. Third parties

Lumina is built on Lovable Cloud (our managed backend, auth and storage layer). We do not sell personal data, run third-party ad networks, or share recap media with external partners.

9. Retention & deletion

You can delete recap media, conversations and your account from inside the app. On account deletion we remove your profile, recap vault and message records. Backups age out on a rolling schedule.

10. Legal bases (GDPR / UK GDPR)

Where EU or UK data protection law applies, we process your data on these legal bases: (a) contract — to provide the app you signed up for; (b) legitimate interests — to secure the service, prevent abuse, and improve reliability; (c) consent — for optional features such as notifications, precise location, or biometric-style inputs, which you can withdraw at any time from Settings; and (d) legal obligation — when required to comply with the law.

11. Your rights

Depending on where you live, you may have rights to access, correct, export, restrict or delete your personal data, to object to certain processing, and to lodge a complaint with your local data-protection authority. California residents have rights under the CCPA/CPRA including the right to know, delete and opt out of "sale" or "sharing" of personal information — we do not sell or share personal information for cross-context behavioural advertising. Submit requests through in-app support; we may need to verify your identity before acting.

12. Children

Lumina is not directed to children under 16 (or the digital-consent age in your country, whichever is higher). We do not knowingly collect personal data from children below that age. If you believe a child has provided us data, contact support and we will delete it.

13. International data transfers

Your data may be processed in countries other than your own, including where our cloud and AI providers operate. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and equivalent mechanisms.

14. Security

We use industry-standard measures — encryption in transit, hashed credentials via our managed auth provider, row-level access controls on the database, and least-privilege server functions — to protect your data. No online service can be guaranteed 100% secure; you use Lumina at your own risk and should keep your device and Google account credentials protected.

15. Changes

We may update this policy as the app evolves out of beta. Material changes will be announced in-app; continued use after the effective date means you accept the updated policy.

16. Contact

Questions, data access, correction or deletion requests? Reach out via the in-app support option.