Privacy Notice (KVKK) - Lumia

1. Data controller

Under KVKK, the data controller is:

Legal name Neural Academy Ltd. Şti.
Address Çukurambar mah. Zeki Ergezen cad. 2/4, Çankaya/Ankara
Contact destek@lumiaapp.net

In this notice, "Lumia" or "we" means the controller above, and "the App" means the Lumia mobile application.

2. What data do we process?

The App can be used without creating an account (anonymously). Even in anonymous use, an anonymous user ID is assigned to your device.

2.0 First, the most important thing: where your data lives

Your health records are not kept on our servers; they stay only on your device. The only things on the server are your account (your email address, your nickname, your session and security logs, and a copy of your language preference) and your consent record.

Where What it covers
Your health records Only in a database on your phone Your symptoms, your cycle, your hormone/medication regimen and dose records, your sleep diary, your reminders, the articles you read, your stage and your stage assessment
Your account On the server (cloud) Your email address (if any), your user ID, the hash of your password, your session information, and a record of the consents you have given

What this means in practice: when you log a symptom, mark a dose time, or fill in your sleep diary, that data does not reach us. There is no copy of it on our server. That is why the tracking side of the App works without an internet connection as well.

Why we keep the consent record on the server: we have to be able to demonstrate that you gave your explicit consent to the processing of health data, and that you withdrew it if you do (Article 6/2 of KVKK). That record consists of which consent, which version, and when. It contains none of your health entries.

If you lose or replace your phone, or delete the App, your health records are lost with it. Because your data is held locally, we have no copy. We recommend taking a backup at regular intervals (§6).

2.1 Special category data; health data

Data considered special category under Article 6 of KVKK, which we process only with your explicit consent. All of your tracking records are kept on your device. None of them has a copy on our servers.

Data What it contains Where
Stage assessment Your assessment answers and the calculated stage On your device
Menopause stage The stage you selected or that was calculated: pre-perimenopause · perimenopause · postmenopause · undetermined On your device
Symptom entries The symptoms you logged, their severity, and any notes you wrote On your device
Cycle entries Period start/end marks, spotting, display preferences, and any notes you wrote On your device
Hormone/medication regimen The name and form of your regimen, the dose note you wrote yourself, its times, and whether you took each dose On your device
Sleep diary and program progress Bedtime, wake time, number of night wakings, time to fall asleep, which day of the program you are on On your device
Reminders The type and time of the reminders you set, and the title you wrote yourself On your device
Reading record Which article you read, how much of it, and when On your device

An honest note about free-text fields: we cannot control what you type into a reminder title or a dose note. If you write a diagnosis, a doctor's name, or information belonging to another person there, that is saved too. These fields never leave your device; but when you take a backup, they are included in it in encrypted form (§6).

2.2 Data we keep on the server

Data What it contains Note
User ID A randomly generated identifier (UUID) Assigned in anonymous use as well
Email address · Only if you upgrade to a permanent account
Password hash · We do not see your password itself; the authentication infrastructure manages it
Nickname · May be left empty
Your language preference tr or en Your actual preference is kept on your device (§2.3); this copy on the server exists so that we can send the identity emails (verification, password reset) in your language
Account state and timestamps Whether the account is anonymous, whether the email is verified, sign-up/sign-in times, session information Required for session management
Your consent record Which consent, which version, whether granted, and when Evidence for legal purposes: we keep this on the server so that we can demonstrate that you gave or withdrew consent (Article 6/2 of KVKK)

The App does not ask for or hold your full name, date of birth, national ID number, phone number, location or profile photo.

2.3 Data that stays on your device and never reaches us

This is the App's largest data set:

One important exception: if your phone's iCloud/iTunes backup is enabled, the database file holding your health records is included in that backup and goes to Apple's servers. This is not a transfer we initiate; it depends on your device's operating system setting. Even so, it is the one exception you do not start yourself to the statement "your data does not leave your device" (the other path is a backup you create yourself).

2.4 What the underlying infrastructure keeps on its own

We do not write most of these records; the cloud infrastructure we use does. The last two rows, however, are written by our own server. We are the data controller, so we list them all:

Data Where/why
Your IP address and browser/device information (user-agent) Recorded in the authentication infrastructure's security logs during sign-in, sign-up, email verification and password reset events
Session and refresh token records Technically required to keep your session open
Platform/request logs The infrastructure provider's own operational logs
Database backups The infrastructure provider's disaster-recovery backups
Backup delivery error record If the email provider rejects the request while sending your backup, the server writes a single-line error entry: the HTTP status code and the provider's error code. The following are NOT written to this record: your email address, your password, the contents of your backup, and the provider's descriptive message. In other words, the record does not say whose backup it was
Identity email error record If the email provider rejects the request while your verification or password-reset email is being sent, the server likewise writes a single-line entry: the HTTP status code, the provider's error code, the type of the email (verification or reset) and the sending language. The following are NOT written to this record: your email address, the verification link/token in the email, and the provider's descriptive message

How long they are kept:

3. Why do we process your data?

  1. To provide the core function of the App: to store your symptom, cycle, regimen and sleep entries on your device and show them back to you.
  2. Personalization: to suggest content and tools based on your stage and the symptoms you log. This computation happens on your device.
  3. Reminders: to deliver the reminders you set, on time.
  4. Account security and management: sign-in, email verification, password reset, account deletion. So that we can send these emails in the language you chose, a copy of your language preference is kept in your account metadata (§2.2, §2.3).
  5. Delivering your backup to you: creating your encrypted backup file when you ask for it and sending it to your verified email address (§6).
  6. Meeting legal obligations: retaining consent records and responding to requests from competent authorities.

What we do not do: We do not use your data for advertising or marketing, we do not sell it to third parties, and we do not build profiles to share with ad networks. The App contains no ad network, analytics tool or crash-reporting tool. The App does not diagnose and does not recommend doses or prescriptions. The emails we send load no remote images; meaning we do not track whether you opened them.

4. Lawful bases

How we collect it: your personal data is collected electronically, by wholly or partly automated means, through the App and the server infrastructure attached to it. The lawful basis for each data type is below:

Data type Lawful basis
Health data (§2.1) Explicit consent (KVKK Art. 6/2). You may withdraw your consent at any time (§11).
Email address Establishment/performance of a contract (Art. 5/2-c)
User ID (UUID), account state and timestamps Establishment/performance of a contract (Art. 5/2-c); required for your account and session to work
Consent records Necessary for the establishment, exercise or protection of a right (Art. 5/2-e); proving that consent was given and withdrawn
Nickname Legitimate interest (Art. 5/2-f); operating the core function
The server-side copy of your language preference (§2.2) Legitimate interest (Art. 5/2-f); being able to send the identity emails in your language
Session, IP and security logs Legitimate interest (Art. 5/2-f); account security

5. Who do we share your data with?

Recipient Purpose What is transferred
Supabase (infrastructure/hosting) Database, authentication, server functions Only the data in §2.2 (your account, your consent record) and the infrastructure records in §2.4. Your tracking records (symptoms, cycle, regimen, sleep; §2.1) do not go here
Brevo (email delivery) Delivering your backup file to you by email (a) your email address, (b) the subject line of the email, (c) your encrypted backup file. Details in §6
Brevo (EU; GCP Belgium) Email verification and password reset emails Your email address only
Competent public authorities Where required by law Limited to the scope of the request

Beyond these, we make no transfer to any other third party. No ad network, analytics provider or data broker is used.

Apple is not in this table, because that is not a transfer we make: if your phone's iCloud/iTunes backup is on, the operating system backs up your health database file to Apple. That depends entirely on your own device setting and is stated plainly in §2.3.

Honesty note: the data processing agreements (DPAs) with the providers above are annexes to their terms of service and are in force upon acceptance of those terms; there is no separate wet signature.

6. Backups and exporting your data

Because your tracking records (symptoms, cycle, regimen, sleep…) exist only on your device, the App gives you a way to take your own backup against the risk of losing your phone.

You create the backup:

You can obtain the backup in two ways:

  1. By sharing the file; you save it from your phone's share sheet to a destination you choose (Files, a cloud service, another device). On this path the file never passes through us.
  2. By sending it to your own email address; our server takes the file and sends it to your address via our email provider (Brevo).
What is sent Your encrypted backup file, your email address, and the subject line of the email
Who it is sent to Only the verified email address of your own account. If you have not verified your email address, this path does not work
Can we open the file No; the password is only yours. Neither we nor the provider can read the contents
Do we keep a copy No. It is written to no storage and to no database table, and its contents are recorded in no log
Where it is processed Our email provider is located in Belgium

Points we want to draw your attention to:

7. Cross-border transfer

8. How long do we keep your data?

9. How is your data protected?

For the data on your device:

For the data on the server:

We do not promise absolute security for any system; the above are the concrete measures we take.

10. Your rights under Article 11 of KVKK

By applying to the data controller, you may request to:

  1. Learn whether your personal data is being processed,
  2. Request information if it has been processed,
  3. Learn the purpose of processing and whether it is used accordingly,
  4. Know the third parties to whom it is transferred, in Türkiye or abroad,
  5. Request correction if it is incomplete or inaccurate,
  6. Request erasure or destruction,
  7. Request that corrections/erasures be notified to third parties to whom the data was transferred,
  8. Object to a result against you produced solely by automated analysis,
  9. Claim compensation if you suffer loss due to unlawful processing.

How to apply: by email from the email address registered to your account to destek@lumiaapp.net, or in writing to Çukurambar mah. Zeki Ergezen cad. 2/4, Çankaya/Ankara. Your request will be concluded within 30 days at the latest.

From within the App you can also:

Withdrawing your consent now happens inside the App. Earlier versions announced this screen as "upcoming"; it has now shipped and the first item in the list above tells you where to find it. The application address above has not closed; it stays open for your other Article 11 rights and for any problem you run into.

11. What happens if you withdraw consent?

What is deleted:

What is not deleted; and why:

Withdrawal does not affect processing that was lawful before the date of withdrawal. You can change your mind again. After withdrawing, the App takes you back to the consent screen; if you want, you can consent again from there and start over. But the deleted records will not come back.

Backup files you took earlier remain in your hands; deleting them is up to you.

12. Changes

When we update this notice we will change the effective date and announce significant changes from within the App. If a change broadens the scope of health data processing, we will ask for fresh explicit consent.


This document is issued under the disclosure obligation in Article 10 of KVKK and should be read together with the Privacy Policy (privacy-policy.md).