Skip to content
LUMA

Luma

Privacy policy

How Luma handles information from the app and this website.

Last updated: August 4, 2026

This policy describes how Luma handles information in the app and website. It is updated when the distributed version’s data practices change.

Data handled by the app

Luma stores routines, schedules, progress, preferences, and opaque selections provided by Screen Time APIs locally. It does not read content from other apps, your messages, visited pages, or what you type.

If you choose Sign in with Apple, we process the account identifier, email, and name Apple allows you to share, if provided, and the information needed to maintain the session. The first routine can be used without an account. The editable profile name can be an alias chosen by you and does not need to be your legal name.

Purchases and subscription status are processed by Apple and RevenueCat. Luma receives the status required to enable features, not your complete payment-card information.

When you have an account, Supabase is used to sync and restore product data across installations. This may include profile, email, alias or name, language, routines, schedules, selection configuration, closed sessions, terminal occurrences, derivable progress, Lumens, inventory, equipped items, plant name, observable plan state, and minimal device metadata such as app version, build, platform, and a random Luma installation identifier. Screen Time remains local, and Supabase does not apply real-time blocking.

Screen Time selections may include Apple opaque tokens or domains you enter as part of a routine. We use this data to restore your configuration when possible. If a selection cannot be restored safely, Luma will ask you to select it again.

Website and feedback

Cloudflare hosts the website and may process technical data needed for security, delivery, and aggregate analytics. If you send website feedback, we process the message, language, and optional email to reply. The email provider processes the message only for delivery.

In-app feedback can be used with or without an account. We process the report type, message, app version, build, language, and optional email. If you have a valid session, the report is linked to your account. Only with your consent will it include the iOS version, device model, and general permission, plan, and synchronization states. We do not attach your selected apps, categories, domains, routines, Screen Time tokens, or complete logs.

To limit abuse, we temporarily process the random installation identifier and network address. The server transforms them with HMAC before storing them in rate-limit buckets that expire within two days; we do not retain the raw values.

We do not sell personal data or use behavioral advertising.

Retention and deletion

Local data stays on your device until you remove it in the app or uninstall Luma. If you have an account, some synchronized data remains in Supabase for restore until you use Delete account or request deletion. Linked reports are deleted when the account is deleted. Closed reports are deleted after 12 months. Account data is removed through the in-app flow, except where retention is required for law, security, fraud prevention, or compliance.

Your choices

You can withdraw Screen Time authorization in iOS, avoid creating an account, request access or deletion, and choose not to send feedback. See Privacy choices for available channels.

Changes

We will publish the update date and describe material changes when this policy changes.