Privacy Policy
Last Updated: 04/22/2026
LumiMind ("Lumi," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, share, and protect your information when you use the Lumi application and website (the "Service").
1. Information We Collect
Information You Provide
- Account information: Name, email address, password (managed via our authentication provider, Clerk)
- Profile and onboarding responses: Information about your ADHD experience, preferences, and goals
- User content: Conversations with Lumi, mood check-ins, brain dumps, notes, and reflections
- Payment information: Billing details processed by Stripe (we do not store your full card details)
- Communications: Messages you send to our support team
Information Collected Automatically
- Usage data: Features used, session duration, interaction patterns
- Device information: Device type, operating system, browser, IP address
- Cookies and similar technologies: For authentication, analytics, and Service functionality
Information from Third Parties
- Authentication providers: Clerk provides basic account information
- Payment processors: Stripe shares billing status and transaction data
- Analytics providers: We use analytics tools (e.g., Google Analytics, Vercel Analytics) to understand usage patterns
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Personalize Lumi's responses to your needs
- Process payments and manage subscriptions
- Communicate with you about updates, features, and support
- Analyze usage patterns to improve the Service
- Detect, prevent, and address security issues
- Comply with legal obligations
3. AI Processing
To provide Lumi's companion features, we send your input (conversations, mood check-ins, context) to Anthropic's Claude API. This means:
- Your input is transmitted to Anthropic for AI processing
- Anthropic's privacy practices apply to this processing (see Anthropic's privacy policy)
- We do not permit Anthropic or any AI provider to train models on your personal content
- AI providers may temporarily retain data for abuse prevention, per their terms
We choose AI providers that align with strict data privacy standards.
4. How We Share Your Information
We do not sell your personal information.
We share information only with:
- Service providers: Vendors that help operate the Service (Clerk for authentication, Supabase for database, Stripe for payments, Anthropic for AI, Vercel for hosting, analytics providers)
- Legal requirements: When required by law, court order, or to protect rights, property, or safety
- Business transfers: In connection with a merger, acquisition, or sale of assets (you'll be notified)
- With your consent: When you explicitly authorize sharing
5. Data Storage and Security
Your data is stored in secure, encrypted databases (currently Supabase). We use industry-standard security practices including:
- Encryption in transit (TLS) and at rest
- Authentication via Clerk
- Limited access controls
- Regular security reviews
No system is perfectly secure. You use the Service at your own risk.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account:
- Account and user content data is deleted within 30 days
- Anonymized or aggregated data may be retained for analytics
- Certain records may be retained longer for legal, tax, or compliance purposes
7. Your Rights
Depending on your location, you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and data
- Portability: Request a portable export of your data
- Opt-out: Opt out of certain data processing
- Withdraw consent: Withdraw consent where processing is based on consent
California Residents (CCPA/CPRA)
You have the right to know what personal information we collect, request deletion, opt out of the sale of personal information (we do not sell), and not be discriminated against for exercising your rights.
EU/UK Residents (GDPR)
You have additional rights under GDPR, including the right to lodge a complaint with a supervisory authority. Our legal bases for processing include your consent, contractual necessity, and legitimate interests.
To exercise any rights, contact: hello@lumimind.app
8. Cookies
We use cookies and similar technologies for:
- Essential cookies: Authentication, security, Service functionality
- Analytics cookies: Understanding how the Service is used
- Preference cookies: Remembering your settings
You can control cookies through your browser settings. Disabling essential cookies may affect Service functionality.
9. Third-Party Links
The Service may include links to third-party websites. We are not responsible for their privacy practices. Review their policies before providing any information.
10. Children's Privacy
Lumi is not intended for individuals under 18. We do not knowingly collect information from anyone under 18. If you believe we have collected such information, contact us immediately.
11. International Users
Lumi is operated from the United States. If you use the Service from outside the US, your information will be transferred to, stored, and processed in the US. By using the Service, you consent to this transfer.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email or in-app notice. Continued use of the Service after changes constitutes acceptance.
13. Contact Us
Questions, concerns, or requests regarding your privacy?
LumiMind
Email: hey@lumimind.app
Website: https://lumimind.app