Lumagrow
Privacy Policy

Privacy Policy

Effective date: June 13, 2026

Who we are

Lumagrow is a mobile wellness app that helps you build a daily meditation ritual. This policy explains what personal data we collect, why, and how it is stored. We are the data controller for the data described here. You can contact us at [email protected].

Lumagrow is available in the United States and Taiwan. This policy is written to comply with the California Consumer Privacy Act (CCPA), the Taiwan Personal Data Protection Act (PDPA), and the European Union General Data Protection Regulation (GDPR) where it applies.

Data we collect

Data we do NOT collect

Lawful basis for processing (GDPR)

If you are in the EU/UK/EEA, we rely on the following lawful bases:

We do not process special-category data (health data, religious beliefs, etc.) under GDPR Article 9.

How your data is stored

Account data, session history, and reflections are stored in Supabase (PostgreSQL database hosted by Amazon Web Services in the United States, region us-east-1). Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Session data and preferences are also cached on your device via your browser's localStorage so the app works offline. Clearing your browser data or uninstalling the app removes the local copy.

We retain your data for as long as your account is active. If you delete your account (via email request to [email protected]), we delete all personal data within 30 days, except where law requires longer retention (e.g., tax records of paid subscriptions).

International data transfers

Our database is in the United States. If you use Lumagrow from Taiwan, the EU/UK/EEA, or any other jurisdiction outside the US, your personal data is transferred to and processed in the US. This is necessary to provide the service.

For users in the EU/UK/EEA: this transfer is covered by the Standard Contractual Clauses approved by the European Commission, which our sub-processor Supabase has executed.

For users in Taiwan: this transfer complies with the Taiwan PDPA. Your data is processed under Taiwan PDPA-aligned safeguards, and you may exercise your PDPA rights by emailing [email protected].

Third-party services

We do not sell, rent, or share your personal data with any other third parties for advertising or marketing.

Cookies and local storage

Lumagrow does not use tracking cookies on the marketing site or in the app. The web app uses the browser's localStorage to cache your session state, companion choice, and preferences so the app works without a network connection. This local cache is accessible only to the Lumagrow app on your device.

The marketing site (lumagrow.app) uses only a single Cloudflare cookie required for the CDN to serve content securely. No analytics, advertising, or third-party cookies are set.

Your rights

You can exercise the following rights at any time by emailing [email protected]. We will respond within 30 days.

EU/UK/EEA users also have the right to lodge a complaint with their local data protection authority. For California residents, the CCPA grants equivalent rights to access, deletion, and opt-out of sale (we do not sell data, so the opt-out always applies).

Taiwan PDPA notice

Under the Taiwan Personal Data Protection Act, you have the right to:

To exercise any of these rights, email us at [email protected]. We will respond within the timeframe required by law.

The legal basis for our collection of your data is the contract you accept by using Lumagrow, and our legitimate interest in providing a wellness service that works for you.

Children

Lumagrow is not directed at users under 13 years of age in the United States, or under 15 in Taiwan. We do not knowingly collect personal information from children below these ages. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

In the EU, the GDPR sets the minimum age for digital consent at between 13 and 16 depending on member state. If you are in the EU and below your country's age threshold, please do not use Lumagrow without a parent or guardian.

Security

We protect your data with industry-standard safeguards: TLS in transit, AES-256 at rest, Supabase Row-Level Security policies on the database, restricted production access, and no third-party data sharing for marketing purposes.

Despite our efforts, no system is 100% secure. If we become aware of a breach affecting your data, we will notify you within 72 hours of discovery, as required by applicable law.

Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page and, where reasonable, by an in-app notice. Continued use of Lumagrow after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy? Email us at [email protected].

Lumagrow operates as a solo-founder venture. There is no separate Data Protection Officer or EU representative; the founder is the data controller and reachable at the email above. We aim to respond to all privacy inquiries within 7 business days.