Privacy policy
Last updated 4 October 2026
Lumo is a private, invitation-only app. This page explains what it stores, why, who processes it, and how to remove it.
What we store
- Your email address, used to sign in.
- Profile details you enter: family members (names, relations, birth dates, notes) and preferences.
- Documents you upload (for example IDs, passports, tickets, bookings, insurance policies, receipts): the original file, stored in private file storage, and the details read from it (such as names, numbers and dates), stored as text in the database.
- Your conversations with the assistant, which can include details from your documents.
- Your shopping lists.
- If you connect Google Calendar: an encrypted access token and the ID of the calendar the app created.
- Daily usage counts, used to enforce usage limits.
How it is used
- Only to provide the app's features to you. It is not sold, shared for advertising, or used to build profiles.
Who can see your data
- In the app, only you. Other users can't see or change your data; this is enforced by access rules in the database itself, and files are never available through public links. (If shared family spaces are added later, only the people you invite to a space will see that space.)
- The app's operator has technical access. As the administrator of the hosting accounts (Supabase), the operator can technically open stored files and data through the hosting dashboard, which bypasses the app's access rules. The operator does not do so except to provide support you ask for, to fix a problem affecting your account, or with your permission. Access to these accounts is protected with two-factor authentication and not shared.
- Data is encrypted at rest by the hosting providers. It is not end-to-end encrypted: the app has to read your documents to work. Only upload what you're comfortable storing on these terms.
Services that process data
- Supabase: database, file storage and sign-in (data encrypted at rest, servers in the EU).
- Vercel: hosting the app.
- Anthropic (Claude): reads your messages and documents to answer you and extract details. Under Anthropic's commercial API terms this data is not used to train models.
- Google: only if you connect Google Calendar.
Google user data
- The app requests only permission to create its own “Lumo” calendar and manage events in it. It cannot read or change your other calendars, and it reads your Google email address only to show which account is connected.
- An event is added only after you review it and tap Add. Event descriptions never include ID numbers.
- Google data is used only to provide this feature and is not shared with anyone else.
- Lumo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- You can disconnect at any time in Settings → Google Calendar, which revokes the app's access and deletes the stored token. Events already added stay in your calendar until you delete them.
Deleting your data
- You can delete documents, people, preferences and list items in the app at any time. Deleting a document also deletes its file.
- To delete your account and everything in it, contact the owner at chenackerman@gmail.com.