Section 01Who we are.
Lumi is a mental health companion app made by Lumetrix Labs Limited, a company registered in England and Wales. The Lumi website is published at www.talktolumi.app. You can contact us at privacy@talktolumi.app.
Section 02What data we collect.
2.1 · Anonymous user account
When you first open Lumi we create a random ID (a UUID) for your account. No name, no email address, no phone number. This ID is the only way we identify you.
2.2 · Profile information you choose to share
During onboarding we ask optional questions — your age bracket, sex, and whether you have a diagnosis of depression, anxiety, or both. All of these are optional. If you skip them, the app works normally. This information is stored against your anonymous UUID only.
2.3 · Mood logs
Your daily mood entries (Good, Low, Anxious, or Flat) and the date they were recorded.
2.4 · Wellbeing check-in scores
Your weekly S8 PROM responses and calculated scores.
2.5 · Medication diary
Medication names, doses, timing, and any side effect notes you add. We never share this with anyone.
2.6 · Conversation history
Your conversations with Lumi are stored so the app can provide continuity between sessions. Conversations are processed by Anthropic (the company behind the Claude AI model) on our behalf. Anthropic does not use your conversations to train their models. See Section 05 for more.
2.7 · Subscription information
Subscription billing is handled entirely by Apple (App Store) or Google (Play Store) and managed through RevenueCat. We receive only your anonymous subscription status — we do not receive your payment details, card number, or Apple/Google account details.
2.8 · Technical data
Standard app diagnostics (crash reports, performance data) to keep the app running well. These contain no health information.
Section 03What we do not collect.
Face ID and fingerprint authentication are processed entirely on your device by iOS or Android. Lumi never sees them.
Section 04How we use your data.
We use your data only for the following purposes:
| Purpose | Legal basis |
|---|---|
| Providing the Lumi app and its features | Contract — fulfilling our agreement with you |
| Personalising Lumi's responses using your profile | Legitimate interest — improving app relevance |
| Sending optional reminders (wellbeing check-in, trial end) | Consent — you control this in Settings |
| Improving the app through anonymous analytics | Legitimate interest |
| Anonymous research (opted-in users only) | Consent |
| Complying with legal obligations | Legal obligation |
Section 05Where your data is stored.
All data is stored on Supabase servers located in the EU (Ireland). We never store personal or health data outside the UK/EU.
AI conversations are processed by Anthropic (USA), subject to Standard Contractual Clauses that provide adequate safeguards under UK GDPR. Anthropic acts as a data processor on our behalf and does not use conversations to train its models.
Section 06Research opt-in.
If you choose to contribute to research in Settings, your anonymised data may be used to help improve mental health tools and outcomes. When data is used for research, your UUID is replaced with a separate research ID — there is no link table.
Opting in or out at any time has no effect on your access to the app.
Section 07How long we keep your data.
We keep your data for as long as your account is active. If you delete your account (Settings → Delete my account), all your data is permanently erased within 30 days. Backups are purged on the same schedule.
Section 08Your rights.
Under UK GDPR you have the right to:
- Access — download a copy of all your data (Settings → Export all my data).
- Erasure — delete your account and all associated data permanently.
- Rectification — correct inaccurate information by updating your profile.
- Restriction — ask us to stop processing your data while you raise a concern.
- Object — opt out of research data use at any time in Settings.
- Portability — your data export is provided in machine-readable JSON format.
To exercise any right not available directly in the app, contact us at privacy@talktolumi.app. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Section 09Third-party services.
We work with the following third-party services. We do not use advertising SDKs, social media trackers, or analytics platforms that share data with third parties.
| Service | Purpose |
|---|---|
| Supabase | Database and authentication — policy |
| Anthropic | AI conversation processing — policy |
| RevenueCat | Subscription management — policy |
| Apple / Google | App distribution and billing — via App Store / Play Store |
Section 10Children.
Lumi is designed for people aged 18 and over. If you are under 18, please do not use the app. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, please contact us and we will delete it immediately.
Section 11Changes to this policy.
If we make material changes we will notify you in the app before the changes take effect. The "last updated" date at the top of this policy will always reflect the current version. You can always find the current policy at www.talktolumi.app/privacy.html.