Luma Way

Luma WayLuma WayLuma Way

Luma Way

Luma WayLuma WayLuma Way
  • Home
  • Privacy Policy
  • More
    • Home
    • Privacy Policy

  • Home
  • Privacy Policy

Privacy Policy


Privacy Policy for Luma Rise

Last Updated: March 26, 2026

1. Introduction

Welcome to Luma Way, the builders of the Luma Rise app. We are committed to protecting your privacy and being transparent about how we handle your personal information. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our mobile applications on iOS and Android. This policy describes how your information is handled when you use Luma Rise.


2. Information We Collect

2.1 Information You Provide to Us

Account Information: When you create an account, we collect your email address, password (encrypted), and optional profile information such as your name and profile photo.

User Content: We collect and store messages, photos, videos, and other content you send via our in-app messaging features to facilitate communication between family members.

AI Assistant Data: When you use our AI-powered scheduling assistant, we collect your text messages, any images you attach (up to 3 per message), and session context including which child's schedule you are viewing. Chat sessions and messages are stored in our database to maintain conversation history. Child names are anonymized (replaced with pseudonyms such as "Child 1") before being sent to the AI provider for processing.

Voice Data: If you use our voice-to-text features, we access your device's microphone and use your device's native speech recognition services (Apple Speech Recognition on iOS, Google Speech Recognition on Android) to convert your speech into text. Audio is processed locally on your device or through the platform provider's services and is not permanently stored by Luma Rise.

Photos and Camera: We access your device's photo library and camera when you choose to share photos or set a profile picture.

Customer Support Data: If you contact us for support, we collect information you provide including your email, description of the issue, and any screenshots or additional information to help us diagnose and resolve problems.

2.2 Information We Collect Automatically

Usage Data: We use Google Analytics for Firebase to understand how you use our app, including features accessed, session duration, screen views, and user interactions. This helps us improve our services.

Device Information: We collect information about your device including device model, operating system version, unique app instance identifiers, language settings, and time zone.

Crash Data: We use Firebase Crashlytics to collect diagnostic data when the app crashes, including stack traces, device state at the time of crash, and app version information. This helps us identify and fix bugs.

Location Data: With your explicit permission, we collect your device's precise location (GPS) and approximate location (network-based) for location-based features such as sharing your location with family members or organizing location-specific plans. Location tracking can be disabled at any time through your device settings or in-app preferences.

Push Notification Tokens: We collect device tokens to send you push notifications about messages, shared content, and app updates. You can disable notifications through your device settings.

2.3 Information We Do Not Collect

Contact Information: We do not access or collect your device contacts.

Advertising Identifiers: We do not collect or use advertising identifiers for advertising purposes. We do not track you across third-party apps or websites for advertising.

3. How We Use Your Information

We use the collected information for the following purposes:

Service Provision: To provide, maintain, and improve the Luma Rise app and its features.

Communication: To facilitate in-app messaging, content sharing, and communication between family members.

AI-Assisted Planning: To process your natural language requests through our AI scheduling assistant, including interpreting your instructions, querying your existing schedule data, and proposing actions such as creating events, setting goals, or managing school schedules. Proposed changes require your confirmation before being applied.

Voice Processing: To process audio for voice-to-text functionality using device-based speech recognition.

Technical Support: To diagnose technical issues, respond to support requests, and fix bugs.

Analytics: To analyze usage trends, understand user behavior, and enhance user experience.

Security: To detect, prevent, and address fraud, abuse, security issues, and technical problems.

Notifications: To send you push notifications about messages, shared content, and important app updates (if you have enabled notifications).

Legal Compliance: To comply with applicable laws, regulations, and legal processes.

3.1 Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), UK, and Switzerland, we process your personal data based on the following legal grounds:

Consent: When you provide explicit consent (e.g., for location access, push notifications).

Contractual Necessity: To provide the services you've requested through your use of the app.

Legitimate Interests: To improve our services, ensure security, and analyze usage (where not overridden by your privacy rights).

Legal Obligation: To comply with applicable laws and regulations.

4. Data Sharing and Third Parties

We do not sell, rent, or share your personal data for advertising or marketing purposes to third parties. We do not use your personal data for third-party advertising.

We may share data with the following trusted service providers who help us operate our app, subject to strict confidentiality obligations:

Firebase (Google LLC): For analytics (Google Analytics for Firebase), crash reporting (Firebase Crashlytics), cloud messaging (Firebase Cloud Messaging for push notifications), and user authentication (Firebase Authentication). Data is processed according to Google's privacy policies.

Google (Gemini AI): For AI-powered scheduling assistant functionality. Text messages and attached images from your AI chat sessions are sent to Google's Gemini API for processing. Child names are anonymized before transmission. Data is processed according to Google's privacy policies and AI data usage terms. Google may process this data on servers located outside your jurisdiction.

Supabase: For secure database services, backend infrastructure, and data storage including user profiles, messages, AI chat sessions, and shared content. Supabase provides encrypted storage and access controls.

Apple/Google: For platform-specific services including speech recognition on their respective platforms. Voice data is processed according to Apple's and Google's privacy policies.

Cloud Infrastructure Providers: For secure hosting and data storage with encryption in transit and at rest.

We may also disclose your information:

With Your Consent: When you explicitly authorize us to share information.

For Legal Reasons: To comply with legal obligations, court orders, or government requests; to protect our rights, privacy, safety, or property; or to enforce our Terms of Service.

Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred (users will be notified of any such change).

5. Your Privacy Rights

5.1 General Rights

Depending on your location, you may have the following rights regarding your personal data:

Access: Request a copy of the personal data we hold about you.

Correction: Request correction of inaccurate or incomplete data.

Deletion: Request deletion of your account and associated data (see section 5.4 below).

Portability: Request your data in a structured, commonly used format.

Restriction: Request that we limit how we use your data.

Objection: Object to our processing of your data for certain purposes.

Withdraw Consent: Withdraw previously given consent at any time.

5.2 California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

Right to Know: Request disclosure of the categories and specific pieces of personal information we collect, use, and disclose.

Right to Delete: Request deletion of your personal information (subject to certain exceptions).

Right to Opt-Out: We do not sell personal information, but if we did, you would have the right to opt out.

Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

Shine the Light: Request information about data shared with third parties for their marketing purposes (we do not share data for such purposes).

5.3 European Privacy Rights (GDPR)

If you are located in the EEA, UK, or Switzerland, you have rights under the General Data Protection Regulation:

  • All rights listed in section 5.1 above
  • Right to Lodge a Complaint: File a complaint with your local data protection authority
  • Automated Decision-Making: We do not use automated decision-making or profiling that produces legal effects

5.4 How to Exercise Your Rights

To exercise any of these rights:

In-App: Use the account settings within the Luma Rise app to access, modify, or delete your data.

Email: Contact us at privacy@luma-way.com

Response Time: We will respond to verified requests within 30 days (or as required by applicable law).

For deletion requests, we will delete your account and associated personal data within 30 days of verification, except where retention is required by law or for legitimate business purposes (such as resolving disputes or enforcing agreements).

6. Data Security

We take the security of your personal information seriously and implement industry-standard security measures:

Encryption: All data is encrypted in transit using industry-standard encryption protocols and encrypted at rest.

Access Controls: Strict access controls and authentication mechanisms limit who can access your data.

Secure Infrastructure: We use secure cloud infrastructure with regular security audits and monitoring.

Password Protection: User passwords are securely hashed using industry-standard practices.

AI Data Anonymization: Child names are replaced with pseudonyms before being transmitted to third-party AI services, minimizing the exposure of identifiable information.

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

7. International Data Transfers

Your information may be transferred to and processed on servers located outside your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.

If you are located in the EEA, UK, or Switzerland, we ensure that any international transfers are protected by appropriate safeguards such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions where the destination country has been deemed to provide adequate protection
  • Other legally approved transfer mechanisms

8. Data Retention

We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy:

Account Data: Retained while your account is active and for a limited period after account deletion (generally up to 90 days) to allow for account recovery.

Messages and Content: Retained while your account is active; deleted within 30 days of account deletion.

AI Chat Data: Chat sessions, messages, and attached images are retained while your account is active. All AI chat data is deleted within 30 days of account deletion.

Analytics Data: Aggregated and anonymized data may be retained indefinitely for statistical purposes.

Crash Logs: Retained for up to 90 days for debugging purposes.

Support Data: Retained for up to 2 years to maintain support history and comply with legal obligations.

You may request deletion of your account and associated data at any time by using the account deletion feature within the app or by contacting us at privacy@luma-way.com. Deletion will occur within 30 days of your verified request.

9. Children's Privacy

Our services are designed for families, and we take children's privacy seriously.

9.1 Parental Consent and Control

  • Accounts for children under 13 (or the applicable age of digital consent in your jurisdiction) are intended to be created and managed by a parent or legal guardian.
  • Parents must provide verifiable consent before creating an account for a child.
  • Parents can review, modify, or delete their child's information at any time through the family management features in the app.

9.2 Information Collected from Children

We collect only the minimum information necessary from children's accounts:

  • Basic profile information (name, age-appropriate username)
  • Content shared within the family (messages, photos)
  • Usage data necessary to provide the service

We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you believe we have collected information from a child without proper consent, please contact us immediately at privacy@luma-way.com, and we will delete such information promptly.

9.3 Parental Rights

Parents have the right to:

  • Review the personal information collected from their child
  • Request deletion of their child's information
  • Refuse to allow further collection or use of their child's information
  • Contact us with questions about our children's privacy practices

9.4 AI Assistant Age Restrictions

Our AI-powered scheduling assistant is available only to users aged 13 and older. Children under 13 cannot directly interact with the AI assistant. Parents and guardians may use the AI assistant to manage their children's schedules on their behalf. When the AI assistant processes requests related to a child's schedule, the child's name is anonymized (replaced with a pseudonym) before being sent to the third-party AI provider. No child's personal information is shared with the AI provider in directly identifiable form.

10. Cookies and Similar Technologies

Our mobile app does not use cookies. However, we use similar technologies including:

Device Identifiers: Unique identifiers to recognize your device across sessions.

Local Storage: To store preferences and app data locally on your device.

SDKs: Third-party software development kits (Firebase, analytics tools) that may use similar tracking technologies solely to provide app functionality, analytics, and security—not for advertising.

You can manage these through your device settings and in-app preferences.

11. Your Choices and Controls

  • Location Services: Enable or disable location access through your device settings or in-app preferences.
  • Push Notifications: Manage notification preferences through your device settings.
  • Analytics: Opt out of analytics collection through in-app privacy settings.
  • Camera and Photos: Manage permissions through your device settings.
  • Microphone: Manage permissions through your device settings.

12. Third-Party Links and Services

Our app may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will update the "Last Updated" date at the top of this policy.
  • We will notify you through the app via push notification or in-app message.
  • For significant changes, we may require you to review and accept the updated policy.

Your continued use of Luma Rise after changes become effective constitutes acceptance of the revised policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Email: contact@luma-way.com

Support: contact@luma-way.com

For GDPR-related inquiries (EEA, UK, Switzerland users):
Data Protection Officer: contact@luma-way.com

For CCPA-related inquiries (California residents):
California Privacy Requests: contact@luma-way.com

We will respond to all legitimate requests within 30 days (or as required by applicable law).

Your privacy matters to us. Thank you for trusting Luma Rise with your family's communication.

Luma Way

Copyright © 2026 Luma Way - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept