Privacy Policy

Effective: July 27, 2026

The short version

Your memories are yours. Everything you create in Lumoria (tickets, moods, notes, voice memos) is encrypted on your device before it reaches our servers. We cannot read it. Nobody can except you, and the people you invite into a shared memory, who hold that memory’s key.

What we collect

When you use the app

Account. Your email address, display name, username, and avatar. Your avatar is encrypted before it leaves your device. We store the ciphertext, not the image.

Tickets and memories.The content you create: ticket details, locations, event dates, memory names, emojis, date ranges, and linked music. All of this is encrypted on your device using AES-256 before it is sent to our servers. We store ciphertext. We cannot read your ticket destinations, your memory names, or anything you’ve written.

Mood entries. When you log a mood, it is stored on our servers as an encrypted blob. The server receives a valence level, a set of emotion labels (as numeric codes), and a timestamp, all encrypted. We cannot read your mood entries.

Notes. Title and body text, encrypted before upload. We cannot read your notes.

Voice memos.Transcription always happens on your device, using Apple’s on-device speech recognition model, and no audio is ever sent to Apple. In a memory only you can see, the recording never leaves your device either: we store only the transcript text, duration, and waveform shape, all encrypted. In a shared memory the audio travels with the rest of it, encrypted under that memory’s key.

Photos and videos. In a memory only you can see, they are never uploaded anywhere. We store only an opaque local identifier (a string Apple assigns to each asset in your library), and the files themselves stay on your device.

A shared memory works differently, because the people you invite have to be able to see what you added. When you make a memory collaborative, or add something to one that already is, the files are encrypted on your device and uploaded to private storage. They are sealed with that memory’s own key, which only its members hold, so we still cannot open them. The app tells you this before you convert a memory, and it applies to photos, videos, voice recordings, and the photo on any ticket you add.

Music. When you link an Apple Music playlist or song to a memory, we store only its metadata (title, artist name, artwork URL, and catalog link), encrypted. We do not access your listening history, your full library, or your play activity.

Push notification token. Your APNs device token, used to deliver notifications. It is deleted from our servers when you sign out.

Notification preferences. Four boolean toggles controlling which notification types you receive.

Subscription status. If you subscribe to Lumoria+, we store your App Store product ID and transaction ID to verify your entitlement. No payment or card data is ever handled by us. All payments go through Apple.

How we use it

  • To store and sync your memories across your devices
  • To deliver push notifications you’ve opted into
  • To verify your subscription or early adopter status
  • To understand aggregate usage trends, never individual profiling

Encryption

All sensitive content is encrypted on your device using AES-GCM-256 before it is transmitted or stored. Your encryption key is generated on your device and stored in your iCloud Keychain; it syncs to your other devices so your memories are accessible everywhere, but it never reaches our servers. This means we are technically unable to read your ticket content, memory names, mood entries, notes, voice memo transcripts, or avatar.

Analytics

We use Amplitude to understand how people use Lumoria in aggregate. Here is exactly what we send:

  • An anonymous identifier derived from your account ID (never your email)
  • Your email domain at sign-up only (e.g. gmail.com, not your full address)
  • App version and build number
  • Behavioral events (which screens you visit, which actions you take) with no content attached. When you log a mood, we record that a mood was logged and how many labels were selected. We never send the labels themselves.
  • User property flags: whether you’ve created your first ticket, your appearance mode, whether push is enabled, your export preferences

IP address tracking is explicitly disabled. Session replay is not active. We do not send your email, your ticket content, your memory names, or any personally identifiable information to Amplitude.

Feedback surveys on our website

On our website’s ticket builder, we use Contentsquare (formerly Hotjar) to run a short, optional survey at the end of the flow, so you can tell us about your experience or report a problem. We only receive the answers you choose to give, plus basic technical information such as your browser type, approximate (coarse) region, and which steps of the builder you visited.

We do not use session recordings or heatmaps, and we never send your ticket content, photos, or anything you type into the builder to Contentsquare. Like our analytics, Contentsquare only loads after you choose Accept on our consent banner, runs only inside the web ticket builder, and never on our other pages. You can withdraw at any time via Cookie settings in the footer.

Who we share it with

ServiceWhat they receiveWhy
SupabaseEncrypted content blobs, account metadataDatabase and authentication
AmplitudeAnonymous usage events (see above)Product analytics
ContentsquareOptional survey answers, basic technical data (see above)Website feedback surveys
AppleMapKit search queries, Sign in with Apple tokenMaps autocomplete, authentication
GoogleOAuth token (Sign in with Google only)Authentication

We do not sell, rent, or trade your data to any third party, ever.

Location

Lumoria never requests or tracks your GPS location. The only location data we store is coordinates you manually enter when creating a ticket, for example, the origin and destination of a flight. These coordinates are encrypted before upload.

Voice and microphone

Voice memo transcription uses Apple’s on-device speech recognition model. No audio is sent to Apple’s servers, for transcription or for anything else. In a memory only you can see, your .m4a recording stays on your device and reaches us at no point. In a shared memory it is encrypted on your device and uploaded, so the other members can play it back; the key is theirs, not ours.

Cookies & analytics storage

We don’t use advertising or cross-site tracking cookies. Strictly necessary storage (keeping you signed in, remembering your language) works without asking, as the law allows.

Our product-analytics tool, Amplitude, stores an anonymous identifier in your browser’s localStorage. Because that still means storing information on your device, we ask first: Amplitude only loads after you choose Accept on our consent banner, and not at all if you choose Reject. You can change your choice at any time via Cookie settings in the footer.

On our website’s ticket builder we also use Contentsquare for optional feedback surveys. It too only loads after you choose Accept, sets its cookies only then, and never runs on our other pages.

Retention

When you delete your account, your data is removed from our servers immediately, including anything held in the private storage a shared memory uses. Voice recordings kept on your own device are not ours to delete: deleting a voice memo removes its file, and removing the app removes whatever is left. Analytics events in Amplitude are anonymised and cannot be linked back to you once your account is deleted.

Your rights

You have the right to access, correct, or delete the information we hold about you. To exercise these rights, email us at privacy@getlumoria.app. We’ll respond within 30 days.

If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.

Changes

If we materially change this policy, we’ll update the effective date above. We won’t retroactively change how we use data we’ve already collected.