Privacy Policy
Effective date: June 11, 2026
Who we are
Luma is a mobile wellness app that helps you build a daily meditation ritual. We are committed
to protecting your privacy. This policy explains what data we collect, why, and how it is stored.
Data we collect
- Email address — used only for authentication (sign-in code or Google OAuth).
- Meditation session metadata — duration, mood rating, date completed, and helpfulness rating.
- Journal / reflection text — text you voluntarily write in the reflection feature.
- Companion name — the name you give your in-app companion.
- Preference settings — tone, duration, intentions, sensitivities, and habit anchor time.
Data we do NOT collect
- Location data
- Contacts or address book
- Browsing history
- Device identifiers for advertising
- Any form of ad-tracking or behavioral profiling
How your data is stored
All user data is stored in Supabase (PostgreSQL database hosted on AWS us-east-1).
Data is encrypted at rest and in transit (TLS 1.2+). Session data and preferences are also
cached locally on your device via localStorage.
Third-party services
-
Supabase — authentication and database storage.
Supabase Privacy Policy.
-
Google — optional sign-in via Google OAuth only.
No Google ad SDK is used. If you sign in with Google, Google's standard OAuth data practices apply.
Google Privacy Policy.
We do not sell, rent, or share your personal data with any other third parties.
Your rights
- Delete your account and data — email [email protected] and we will delete all your data within 30 days.
- Export your data — request a copy of your session and reflection data by emailing us.
- Correct your data — update your email or name at any time in Profile settings.
Children
Luma is not directed at users under 13 years of age. We do not knowingly collect personal
information from children under 13. If you believe a child has provided us with personal data,
please contact us and we will delete it promptly.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes
by updating the effective date at the top of this page. Continued use of Luma after changes
constitutes acceptance of the updated policy.