Effective date: July 4, 2026
Lumi ("we," "us") is built for minds that carry a lot. That includes carrying your trust — this policy explains, in plain language, what data Lumi handles and why. The short version: your tasks are yours, we don't sell data, we don't run ads, and we collect only what the app needs to work.
Account information. When you create an account we store your email address (and your name, if you sign in with Apple or Google and choose to share it). This is used to sign you in and sync your data across devices.
Your content. Tasks, check-ins, daily anchors (wake, meals, sleep times), and preferences you set. This is the heart of the app — it syncs to our servers (hosted by Supabase) so your data follows you across devices and survives a lost phone. On your device, this content is additionally encrypted at rest.
Learning signals. Lumi learns how you work — which times of day you complete things, what you tend to put off, how you correct its suggestions. These signals are derived from your own activity, stored with your account, and used only to personalize your experience.
Subscription status. If you subscribe, the purchase is processed entirely by Apple. We receive subscription status (active, trial, expired) via our payments partner RevenueCat — never your payment details.
Diagnostics. Basic crash and error information to keep the app working.
When you use Lumi's AI features (sorting a brain dump, the Untangle conversation), the text you write or speak is sent through our own secure server to Anthropic (the AI provider) to be understood and organized. Your API traffic is not used to train Anthropic's models per their commercial API terms. Lumi also works without AI — the app includes a fully offline understanding engine, and no AI request ever happens without you actively using an AI feature.
Your synced data is stored with Supabase (cloud infrastructure), protected by row-level security — meaning your account can only ever read its own rows. On-device data is encrypted with keys stored in your phone's secure enclave (iOS Keychain).
We share data only with the processors that make the app function: Supabase (database & authentication), Anthropic (AI processing of text you submit to AI features), RevenueCat (subscription status), and Apple (payments, sign-in). We never sell your data. We never share it for advertising.
Lumi is not directed at children under 13, and we do not knowingly collect data from them.
If this policy changes materially, we'll note it in the app and update the date above.
Questions or requests: support@lumitasks.app