Privacy Policy
Privacy Policy
Effective: 2026-08-01
Your privacy is a core part of Lumio. This policy explains in plain language what personal data we process, why we use it, and which rights you have under the GDPR. It applies to the Lumio app, the public legal pages on lumio-mind.de, and all functions provided through the Lumio API.
1. Controller
Controller under the GDPR:
Dr. Stephan Tilke, Sollnerstr. 82, 81479 Munich, Germany
Privacy contact: lumioapps.de@gmail.com
Contact form: https://lumio-mind.de/feedback?lang=en
2. Data we process
- Account: email for registered accounts, username, first name, optional profile data such as goals, birth date and language.
- Verification data: During email signup we store the submitted registration details only as a pending registration. A real Lumio account is created only after the email code is successfully verified.
- Authentication and security: password hashes, public passkey keys and technical passkey identifiers, active device sessions, IP address, timestamps, device/client information and security events. We do not receive or store biometric data such as your face or fingerprint; it remains on your device or with the operating system.
- Content: journal and mood entries, course progress, breathing and meditation sessions, favorites, coins/XP, collection and shop progress. Free text may contain sensitive details depending on what you enter. Lumio is not intended to store diagnoses, treatment records or another person's data.
- Optional analysis features: This setting is off by default. Only after you actively turn it on does the Lumio server process moods, activities, course progress and journal content that is not end-to-end encrypted to create an algorithmic summary. End-to-end encrypted text is excluded. Results may be stored in your account.
- Friends and sharing: If you actively use these features, we process usernames, friend requests and progress information you choose to share.
- Legal acceptance records: the version and time of your acceptance, confirmation method, IP address and device/browser information where needed to evidence the agreement.
- Previous purchase data: If you purchased a subscription or in-app item in an earlier app version, we process the related status and technical transaction records. Lumio currently offers no new paid subscriptions or in-app purchases. We do not receive full payment details.
- Feedback: If you use the voluntary feedback form, we store your message, selected category and language, plus only the contact details you choose to provide.
3. Purposes & legal bases
- Providing the app and your account – Art. 6(1)(b) GDPR (contract).
- Security, abuse prevention, stability – Art. 6(1)(f) GDPR (legitimate interest).
- Optional analysis and personalization – after you actively enable it, on the basis of your consent under Article 6(1)(a) GDPR and, where health data is processed, Article 9(2)(a) GDPR. This consent can be withdrawn at any time. For users under 16, this processing remains disabled without verifiable parental authorization.
- Friends and sharing – Art. 6(1)(b) GDPR or Art. 6(1)(a) GDPR for voluntary sharing.
- Evidence of Terms acceptance and legal defense – Art. 6(1)(b) and (f) GDPR.
- Sending verification and security codes by email – contract/legitimate interest.
- Reviewing voluntary feedback and improving Lumio – Art. 6(1)(a) or (f) GDPR.
4. Hosting, domain and central legal pages
Lumio is provided through the domain lumio-mind.de. The Privacy Policy, Terms of Service and Imprint are served centrally by the Lumio server, so the app and website show the same current version.
The Lumio API is hosted on a server in Germany / the EU. This server is the central technical place for accounts, sync, courses, progress, historical purchase status, legal documents and privacy controls.
5. End-to-end encryption
You can enable end-to-end encryption for sensitive free text in journal and mood entries. The app creates a random data key. The server stores that key only wrapped by a key derived from your password and separately wrapped for your recovery code. After encryption succeeds, we cannot read the protected free text. Functional metadata such as timestamps, mood score or activities remains available to the server. If you lose both your password and recovery code, the encrypted text is permanently lost. After a password reset, the recovery code will usually be required for content encrypted earlier.
6. Security and data breaches
We use appropriate technical and organizational measures to protect personal data, including encrypted transport, access controls, secure password storage, revocable device sessions and abuse controls. Absolute security cannot be guaranteed for internet-connected systems.
If a security incident occurs, we investigate, contain and document it. We notify the competent authority and affected people where and to the extent required by law. This Privacy Policy does not exclude or limit statutory claims, including under Article 82 GDPR.
7. Recipients & processors
We share personal data only where necessary for operation or where there is a legal basis:
- Hosting/server operation for Lumio.
- Email delivery through Brevo/Sendinblue for verification, security and system emails.
- Apple App Store and Google Play only where required to verify, manage or restore previous store purchases.
Where required, processors are bound by data processing agreements under Art. 28 GDPR. We do not share data for advertising.
8. Retention
We store your data while your account exists or as long as it is required for the relevant function. Expired pending email registrations are deleted no later than one additional day later. If the user agreement is not confirmed within 24 hours of a new registration, we delete that account and all data stored for it completely and without further notice; you can register again at any time. Existing accounts are not affected by this. Expired passkey requests are removed in the regular maintenance run. Authentication and throttling events are normally deleted after two days. Revoked device sessions are deleted after 90 days, and sessions inactive for 180 days are deleted regardless of status. Archived feedback messages are deleted after no more than twelve months; you can request earlier deletion at any time. After account deletion, personal data is deleted unless legal retention duties, such as purchase or tax records, or the lawful establishment, exercise or defense of legal claims apply.
9. Your rights
Subject to the statutory requirements, you have the right to access, rectification, erasure, restriction, data portability and objection, and to withdraw consent at any time with future effect. In the app, under "Data & Privacy", you can delete individual areas or your whole account and export your data. You can also request deletion of your account and selected data areas at any time through https://lumio-mind.de/konto-loeschen.
How to delete your account in practice:
- Guest account: A guest account belongs solely to the device it was created on. Simply signing out under "Data & Privacy" in the app deletes the account and all associated data immediately and completely. If you want to keep your data, add an email and password first.
- Account with an email address: Use "Data & Privacy → Delete account & all data" in the app (confirmed with your password), or the online account center at https://lumio-mind.de/konto-loeschen. That route also works for accounts created only through Google or Apple, using a confirmation code sent to the registered email address.
You also have the right to lodge a complaint with a data protection authority. For private providers based in Bavaria, you may in particular contact the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, https://www.lda.bayern.de.
10. Processing location and third countries
Lumio runs on servers in Germany; the database is reachable only locally. Our email service provider also processes data within the EU. We do not routinely transfer data to a third country. Where a third-country element arises exceptionally — for example because you obtain the app through an app store or use your device's operating-system services — this takes place on the basis of an adequacy decision, appropriate safeguards such as standard contractual clauses, or your explicit consent under Articles 44 et seq. GDPR. Apple's and Google's own privacy notices apply to processing carried out by them.
11. No automated decision-making within the meaning of Article 22 GDPR
Lumio shows you automatically generated summaries, patterns and suggestions based on your entries. These serve your own reflection only. There is no automated decision in an individual case, including profiling, that produces legal effects concerning you or similarly significantly affects you (Article 22(1) GDPR). In particular, there is no diagnosis, no risk assessment of you as a person and no disclosure of analyses to third parties. The optional processing behind this is switched off by default and can be withdrawn at any time under "Data & Privacy".
12. In-app data control
Under "Data & Privacy" you can control what is shared, enable two-factor security and encryption, export your data after a fresh security confirmation and delete individual categories (e.g. only journal or only mood) or everything. The online account center also supports accounts created only through Google or Apple by sending a fresh code to the verified email address.
13. Minors
Lumio may be used from age 13. Where required by applicable law, users under 16 need consent from a parent or guardian. We do not knowingly collect data from younger children.
14. Changes
We update this notice as needed. The current version is available in the app and publicly on lumio-mind.de. We provide appropriate notice of material changes.