Luma
Privacy policy
How Luma handles data across our mobile app and website.
Last updated: August 12, 2026
This Privacy Policy explains how Vicente Franco B (“Service Provider”, “we”, “us”, or “our”) collects, uses, stores, and safeguards personal data when you use the Luma: App & Site Blocker mobile application and our website growluma.net (collectively, the “Service”).
We respect your privacy. Luma is built around privacy-by-design and a local-first architecture.
1. Screen Time Privacy and On-Device Data
Luma utilizes Apple frameworks (Screen Time, Family Controls, Managed Settings, and Device Activity) to enforce voluntary blocking on apps, app categories, and web domains during focus routines.
On-Device Processing (Local-First):
- App & Category Selection: The exact titles of blocked applications and your detailed app usage metrics remain strictly on your iPhone. Luma does not upload or store your individual app selections or detailed daily usage history on remote servers.
- Private Content: Luma never accesses, reads, or transmits your messages, emails, browsing history outside of specified blocked domains, photos, or keystrokes.
2. Information We Process
We only collect data necessary to provide the Service, synchronize your progress across devices if you choose to create an account, process subscriptions, and maintain application stability.
A. Data Collected Automatically in the App
- Focus Metrics & Progress: Total focus minutes (
Recovered Life), completed session counts, virtual currency balance (Lumens), equipped plant skins, and assigned plant name. - Routine Configurations: Routine title, focus goals, scheduled days/times, blocking mode (Relaxed or Full), and explicit custom web domains entered for blocking.
- Technical Metadata: App version, build number, iOS platform, device model, and a random Luma installation identifier.
B. Account Data (Optional)
You can use Luma without an account. If you choose to sign in via Sign in with Apple to enable cloud backup or multi-device sync, we process:
- Apple user identifier token.
- Email address (either your actual email or an Apple Private Relay address).
- Name or editable profile alias.
C. Subscriptions and Financial Data
Purchases are processed by the Apple App Store. Via RevenueCat, we handle:
- App User ID.
- Subscription status, expiration dates, renewal state, and entitlement IDs.
- We do not collect or store full credit card numbers or financial account details.
D. Crash Diagnostics and Analytics (Sentry & PostHog)
To ensure system stability, diagnose bugs, and improve user experience:
- Sentry: Collects crash reports, error stack traces, and system performance metrics (including device model, iOS version, and crash details). Data is not linked to your personal identity or blocked app selections.
- PostHog: Collects pseudonymized in-app event telemetry (e.g., screen views, routine starts, feature interactions) to understand user engagement and optimize functionality. PostHog does not track activity across third-party apps or perform ad targeting.
E. Website & Feedback
- Website: Hosted on Cloudflare, which temporarily processes IP addresses for security, DDoS protection, and aggregated web analytics.
- Feedback Submissions: If you send in-app or website feedback, we process your message, language, optional email address, and basic diagnostic state to respond.
1. Legal Bases for Data Processing (GDPR)
We process your data under the following legal bases:
- Contractual Performance: To deliver app functionality, sync your progress via Supabase, and manage Pro subscriptions via RevenueCat.
- Consent: For optional feedback submissions and opt-in telemetry. You may withdraw consent at any time.
- Legitimate Interests: To secure app infrastructure, diagnose errors via Sentry, and improve user experience through PostHog analytics.
4. Third-Party Service Providers and International Transfers
We share data only with trusted infrastructure providers bound by strict confidentiality and privacy obligations:
| Provider | Function | Privacy Policy |
|---|---|---|
| Apple Inc. | Authentication, Screen Time APIs, App Store | Privacy Policy |
| Supabase Inc. | Cloud database and sync | Privacy Policy |
| RevenueCat Inc. | Subscription entitlement management | Privacy Policy |
| Sentry (Functional Software, Inc.) | Crash reporting and error diagnostics | Privacy Policy |
| PostHog Inc. | Product analytics and usage telemetry | Privacy Policy |
| Cloudflare Inc. | Web hosting and CDN security | Privacy Policy |
International Data Transfers
Your data may be transferred to and processed in servers outside your country of residence, including the United States. Transfers from the European Economic Area (EEA) rely on Standard Contractual Clauses (SCCs) approved by the European Commission or legally recognized adequacy mechanisms.
5. Data Retention
- Local Device Data: Stored locally until you delete your routines or uninstall Luma.
- Cloud Account Data (Supabase): Retained while your account remains active. Utilizing
Delete Accountimmediately purges your cloud data permanently. - Diagnostics & Telemetry (Sentry & PostHog): Retained for up to 12-24 months on a rolling basis before automated deletion.
- Feedback Messages: Retained for up to 12 months following resolution.
6. Your Privacy Rights (GDPR, CCPA/CPRA, and International Rights)
Regardless of your location, you have the following rights:
- Access and Portability: Request a copy of your personal data held by us.
- Correction: Request rectification of inaccurate or incomplete data.
- Erasure (“Right to Be Forgotten”): Delete your account directly in the app (
Settings > Account > Delete Account) or emailinfo@growluma.net. - California Privacy Rights (CCPA/CPRA): California residents have the right to know what personal data is collected, request deletion, and opt-out of data sales. We do not sell or share your personal information for cross-context behavioral advertising.
To exercise any privacy rights, contact us at info@growluma.net.
7. Children’s Privacy
Luma is not intended for children under 13 years of age (or the minimum legal age of digital consent in your jurisdiction). We do not knowingly collect personal data from children without verifiable parental consent. If we learn that personal data from a child under 13 has been collected, we will immediately delete it from our servers.
8. Data Security
We implement technical and organizational measures to safeguard your information:
- End-to-end encryption in transit (HTTPS/TLS).
- Row Level Security (RLS) policies in Supabase ensuring data is restricted exclusively to authenticated users.
- Secure token authentication via Sign in with Apple without password storage.
In the event of a security breach affecting your personal data, we will notify you and relevant authorities in compliance with applicable laws.
9. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our data practices or legal obligations. The revised version will be published on this page with an updated effective date.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
- Data Controller: Vicente Franco B
- Email:
info@growluma.net - Website: https://growluma.net