← Home
EN FR ES PT

Privacy Policy — Lumira

Last updated: May 8, 2026 Effective date: May 8, 2026 Version: 1.0


1. Introduction

This Privacy Policy (the "Policy") describes how personal data of users of the Lumira mobile application (the "App" or the "Service") is collected, used, shared and protected.

It has been drafted in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the French Data Protection Act of 6 January 1978 (as amended), as well as other applicable regulations (notably ePrivacy and CCPA for California residents).

By using the App, you acknowledge that you have read this Policy.


2. Core principle: everything stays on your device

Lumira is designed to process the maximum amount of data locally, on your device:

The App does, however, rely on a limited set of third-party services — Google Firebase and Google AdMob for analytics, crash diagnostics and ad serving, and Nominatim (OpenStreetMap Foundation) for birth-place lookup during onboarding. These services may process certain technical data described below.


3. Data controller

The controller of your personal data is:

The processing does not require the appointment of a Data Protection Officer (DPO) under Article 37 GDPR. You may nonetheless contact the controller at any time at the above address for any data-related question.


4. Categories of data

Lumira applies the data minimization principle: only the data strictly necessary is collected.

4.1 Data stored only on your device (never transmitted)

Category Data
Birth data Date, time (optional), place of birth, associated latitude/longitude
Life context Onboarding answers (themed tags: career, relationships, etc.)
Preferences Language, notification time, time zone
Reading history Readings opened (kept for 7 days by default)

This data lives in the App's local SQLite database (Drift) and local preferences (SharedPreferences). It does not leave your device. The Publisher has no access to it.

4.2 Technical data processed by third-party services

Category Data Third-party service involved
Firebase install identifier Pseudonymous identifier tied to the App install Firebase Analytics, Crashlytics
Advertising identifier AAID (Android) — only with consent Google AdMob
Technical data Device model, OS and version, language, approximate country, carrier Firebase Analytics, Crashlytics, AdMob
Usage events Anonymous events: onboarding started and completed, daily reading opened, save tapped, tarot card drawn, voluntary rewarded-ad view to unlock an extra draw, cosmos tradition viewed, language changed Firebase Analytics
Crash data Stack trace, app state at crash, device type Firebase Crashlytics
IP address Connection IP (automatically collected server-side by Google) Firebase, AdMob
Ad consent status Your choice in the UMP dialog Google User Messaging Platform
Geocoding query When you manually type your birth place, the search term and your IP address are sent to the Nominatim server. The response (latitude / longitude / city name) is used locally and is not reused for tracking. Nominatim (OpenStreetMap Foundation)

4.3 Data Lumira never collects


5. Purposes and legal bases

In accordance with Article 6 GDPR, each processing operation relies on a specific legal basis.

Purpose Legal basis Data involved
Computing the natal chart and providing personalized readings Performance of the Service requested by the User (Art. 6.1.b) Birth data, life context (processed locally only)
Sending daily notifications Consent (Android system permission) Time preference, time zone
Audience measurement and product analytics (Firebase Analytics) Legitimate interest (Service improvement) — opt-out available Install identifier, events
Bug diagnosis and fix (Firebase Crashlytics) Legitimate interest (security and stability) — opt-out available Crash reports
Personalized ad serving (AdMob) Consent collected via Google UMP Advertising identifiers, display context
Non-personalized ad serving Legitimate interest when consent is denied Non-identifying contextual data
Legal obligations Legal obligation (Art. 6.1.c) As required

You may withdraw your consent at any time when processing relies on it, without affecting the lawfulness of prior processing.


6. Recipients of the data

Your data is never sold. It may be communicated to the following recipients, strictly within the described purposes:

6.1 Technical processors (Article 28 GDPR)

Processor Service used Country / Region
Google Ireland Limited / Google LLC — Firebase Analytics, Crashlytics EU (primary) + transfers to United States
Google Ireland Limited / Google LLC — AdMob Ad serving EU + United States
Google Ireland Limited / Google LLC — User Messaging Platform Ad consent collection and storage EU + United States
Google Play (Google Ireland Limited) Android distribution EU + United States
OpenStreetMap Foundation — Nominatim Geocoding service queried when searching a birth place (one-off transmission of the typed term + IP address) United Kingdom + Germany

6.2 International transfers safeguards

Some transfers occur to the United States. They are framed by:

6.3 Public authorities

Data may be transmitted to administrative or judicial authorities under a duly issued legal request (court order, statutory obligation).


7. Retention periods

Data category Period
Local data on the device (profile, answers, preferences) Until App uninstall or manual reset from Settings
Local reading history Rolling 7 days (automatic purge)
Aggregated analytics data (Firebase Analytics) 14 months max (Firebase default)
Crash reports (Crashlytics) 90 days
Ad consent status (UMP) Until you revoke or reset
Advertising identifier (AAID) Under your control in your phone's system settings (resettable at any time)
Data needed for litigation Until limitation periods expire

After these periods, data is irreversibly deleted or anonymized by the processors.


8. Your rights

Under Articles 15 to 22 GDPR, you have the following rights:

How to exercise your rights

The Publisher will respond within one month, extendable by two months in case of complexity.

Complaint with a supervisory authority

If you believe your rights are not respected, you may lodge a complaint with the French Data Protection Authority (CNIL):

You also have the right to lodge a complaint with the supervisory authority of your country of residence within the EEA.


9. Third-party SDKs

The App does not use HTTP cookies in the classic sense (it is not accessed via a web browser). It does, however, integrate third-party software development kits (SDKs) that may read or write information on your device:

SDK Function Type of information
Firebase Analytics Audience measurement Install identifier, events
Firebase Crashlytics Diagnostics Crash reports
Google AdMob Advertising Advertising identifier (AAID)
Google User Messaging Platform (UMP) Ad consent collection Local consent status

On first launch in the European Economic Area, the United Kingdom, Switzerland and certain U.S. states, an ad-consent screen (Google UMP) is presented, compliant with GDPR and IAB TCF v2 requirements. You may revisit your choices at any time from "Settings → Ad preferences" in the App.


10. Data security

The Publisher implements appropriate technical and organizational measures:

No system being infallible, in case of a security incident affecting your data, the Publisher is committed to meeting its notification obligations (CNIL and affected users) within the timeframes set by GDPR.


11. Protection of minors

The Service is forbidden to persons:

Users below these thresholds may only use the Service with the express consent of their legal representatives. The Publisher does not knowingly collect any data from minors without such consent. Given the absence of a user account, the Publisher relies on the User's commitment at first launch and invites any parent observing unauthorized use to report it to lumira.app.contact@gmail.com so that any associated analytics data can be purged.


12. Automated decisions and profiling

Lumira personalizes content based on your natal chart and onboarding answers. This processing consists of a deterministic selection of pre-written texts from an internal library; it uses no generative AI model at runtime, runs entirely on your device, and produces no legal or similarly significant effect on you. You retain control over your input data at all times (editable or deletable from the App).


13. Specific rights for California residents (CCPA / CPRA)

If you are a California resident, you also have the following rights:

To exercise these rights: lumira.app.contact@gmail.com.


14. Changes to the Policy

The Publisher may amend this Policy to keep up with changes in the Service or in applicable law. Material changes will be notified:

The date of the latest update appears at the top of this document.


15. Contact

For any question relating to this Policy or to the processing of your personal data:


End of Privacy Policy — Lumira v1.0 — May 8, 2026