Luma Privacy Notice
Luma is offered by individual developer Maksim Yaromau, identified as the seller on Luma's App Store page. Luma is a private, local-first reflection app for adults aged 18 or older.
What stays on your device
Journal entries, situations, observations, support phrases, follow-ups, personal learnings, local clarity/readiness ratings, and local safety-scan matches are stored encrypted on your device. They are not sent to ordinary analytics or diagnostics. Luma does not collect your date of birth, contacts, precise location, microphone recordings, HealthKit data, or advertising identifier. When you tap the microphone, iOS transcribes live audio on device into an editable draft. Luma does not save or upload the audio.
Optional AI processing
AI is optional and starts only when you request it. Before the first AI request in a session, Luma shows the exact context preview and asks for session consent. The preview identifies the categories being sent. Depending on your choice, this may include an edited excerpt of up to 6,000 characters, confirmed structured context, selected prior situations or learnings, locale, and operation metadata.
The selected context is sent through the Luma backend to OpenAI to perform the requested operation. After the situation core is confirmed, Luma sends only the structured context needed for that operation. OpenAI states that API data is not used to train its models by default. Provider data may be retained for up to 30 days unless a verified shorter-retention arrangement applies. Luma does not use AI context for ordinary analytics.
Consent ends when the session completes, you revoke it, or after 30 minutes of inactivity. Luma shows a new preview if the consent expired, the app locked in the background, a new context category or past record is added, or the operation or safety scope changes. Luma does not run background AI.
Safety boundary
A mandatory safety scan runs locally on your device. It does not send matched text or log matches. Remote AI is available only for the standard reflection route. Crisis, under-18, abuse/stalking/coercive-control, grounding, medical, legal, and financial routes remain local. Luma does not monitor you, contact emergency services, or guarantee detection of danger.
Operational data and purchases
The Luma backend processes a pseudonymous installation identifier, App Attest/DeviceCheck evidence, short-lived session information, usage counters, entitlement status, and minimal security data. Backend operational metadata is retained on a rolling basis for a maximum of 90 days. A longer hold is permitted only when legally required. Request bodies, authorization headers, journal content, and raw client IP addresses must not be written to application logs.
Apple and RevenueCat process purchase and entitlement information. Their records are governed by their own legal and retention requirements. Luma does not receive your full payment-card details.
Optional analytics and diagnostics
After you receive initial local value, Luma may separately ask you to opt in to PostHog product analytics and Sentry diagnostics. Both are off until you agree, independent, and reversible. Luma disables autocapture, session replay, person profiles, advertising identifiers, IP geolocation, screenshots, view hierarchy, request bodies, and user-text breadcrumbs. Journal text, emotions, local ratings, safety routes, and record-derived categories are never permitted telemetry properties.
Approved PostHog and Sentry projects retain allowed events for no more than 90 days. Revoking consent stops new collection, clears local SDK identifiers/queues, and requests deletion of the corresponding provider data where supported.
Reporting AI output
You may submit an AI-output report by choosing one structured reason. The report contains that reason and non-content operation/version identifiers only. It has no free-text field and never attaches journal text, model output, safety route, or surrounding context. Feedback records are retained for no more than 90 days.
Export, deletion, and retention limits
You can create a password-encrypted local archive. Luma cannot recover a forgotten archive password.
Delete All immediately removes the local encrypted content and its journal key, then requests deletion from the Luma backend and opted-in analytics/diagnostics services. If offline, the app shows Remote deletion pending and retries using a separate protected deletion credential. Luma will not claim remote completion until an in-scope processor confirms the outcome. Apple/App Store purchase history, RevenueCat records required for entitlement or legal purposes, OpenAI temporary provider records, security records, and data legally required to be retained may remain under their respective rules.
Availability and contact
Luma is offered only in App Store countries approved for the current release and backed by a verified local safety-resource pack. General global guidance is not a substitute for a verified country pack.
Privacy questions and deletion support: inmyfridge.app/apps/luma/support.
User-initiated support email and its reply history are retained for no more than 12 months after the last support response, then deleted unless a longer hold is legally required.