Privacy Policy
Lume - Audio Journal Last updated: September 28, 2026
Arnav Puri ("we", "us", or "our") operates the Lume mobile application (the "App"). This Privacy Policy explains how we collect, use, and protect your information when you use our App.
Information We Collect
Account Information
When you create an account, we collect:
- Email address (via Google Sign-In or Apple Sign-In)
- Display name (if provided by your sign-in provider)
- A unique user identifier
Journal Content
When you use the App, you may provide:
- Audio recordings of journal entries
- Text-based journal entries
- Photos and images attached to entries
AI-Generated Data
Our AI services process your entries to generate:
- Transcriptions of audio recordings
- Summaries, mood analysis, tags, and action points
- OCR text from uploaded images
This processing occurs on our secure cloud servers. When you ask for a transcript or insights, that single entry is sent over an encrypted connection to our processing function and forwarded to a third-party AI provider (ElevenLabs for live speech-to-text while you record; Sarvam AI for transcribing the finished recording; Google Gemini for insights, OCR and fallback transcription) solely to generate the result. The content is handled in memory for the duration of the request and is not stored, logged or cached by our servers. The only record kept of an AI request is a monthly usage counter (a number). Your content is not used to train AI models and is not reviewed by people.
You can see the current data-handling policy declared by our servers at any time from Settings → Privacy & Security → How your data is handled.
Automatically Collected Data
- App usage analytics (screen views, feature usage) via Firebase Analytics
- Crash reports and diagnostics via Firebase Crashlytics
- Device type and operating system version
- Subscription status
How We Use Your Information
We use your information to:
- Provide and maintain the App's core journaling features
- Transcribe and analyze your journal entries using AI
- Sync your data across devices when you enable cloud sync
- Process subscriptions and manage your account
- Improve app stability and fix bugs
- Send you optional reminders (with your permission)
Data Storage and Sync
- Local storage: Journal entries are stored locally on your device in the App's private storage, protected by your device's built-in storage encryption. You can additionally require Face ID, fingerprint or a PIN to open the App (App Lock).
- Cloud sync: If you are signed in, the text of your entries, their AI-generated insights, your commitments and weekly reviews are synced to Firebase Cloud Firestore, hosted by Google Cloud Platform. Audio recordings and photos are not uploaded; they stay on your device.
- End-to-end encryption (optional): You can turn on end-to-end encryption from Settings → Privacy & Security. Your entries are then encrypted on your device with a key that only you hold before they are synced, and our servers store only unreadable ciphertext plus the entry date. A copy of the key, locked with a passphrase you choose, is stored so you can unlock your journal on another device. We never receive the key or the passphrase, which also means we cannot recover your encrypted backup if you forget the passphrase.
- You control your data: You can use the App without signing in, keeping all data local to your device.
Third-Party Services
We use the following third-party services:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Firebase (Google) | Authentication, cloud storage, analytics, crash reporting | Google Privacy Policy |
| Google Gemini | AI transcription and analysis | Google AI Privacy |
| ElevenLabs | Live speech-to-text while recording | ElevenLabs Privacy Policy |
| Sarvam AI | Transcription of recorded audio | Sarvam Privacy Policy |
| RevenueCat | Subscription management | RevenueCat Privacy Policy |
| Apple Sign-In | Authentication (iOS) | Apple Privacy Policy |
Data Retention
- Your journal data is retained as long as you maintain an active account.
- You can delete individual entries at any time from within the App.
- You can delete your account and all associated data at any time from Settings > Delete Account. This removes your journal data, usage counters and encryption key backup from our servers, your sign-in account, and the journal data stored on that device. You can also request deletion by contacting us at the email below.
- Crash reports and analytics data are retained for up to 90 days.
Data Security
We implement appropriate technical measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS)
- Optional end-to-end encryption of synced journal content (AES-256-GCM with a device-generated key)
- Firebase Security Rules restricting data access to the signed-in owner
- Secure token-based authentication
- AI responses marked
no-storeso they are not cached by intermediaries
Your Rights
You have the right to:
- Access your personal data through the App
- Export your journal entries
- Delete your data and account
- Opt out of analytics collection
Children's Privacy
The App is not intended for children under 13. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy within the App and updating the "Last updated" date.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Email: arnavpurig@gmail.com