Under KVKK, the data controller is:
| Legal name | Neural Academy Ltd. Şti. |
| Address | Çukurambar mah. Zeki Ergezen cad. 2/4, Çankaya/Ankara |
| Contact | destek@lumiaapp.net |
In this notice, "Lumia" or "we" means the controller above, and "the App" means the Lumia mobile application.
The App can be used without creating an account (anonymously). Even in anonymous use, an anonymous user ID is assigned to your device.
Your health records are not kept on our servers; they stay only on your device. The only things on the server are your account (your email address, your nickname, your session and security logs, and a copy of your language preference) and your consent record.
| Where | What it covers | |
|---|---|---|
| Your health records | Only in a database on your phone | Your symptoms, your cycle, your hormone/medication regimen and dose records, your sleep diary, your reminders, the articles you read, your stage and your stage assessment |
| Your account | On the server (cloud) | Your email address (if any), your user ID, the hash of your password, your session information, and a record of the consents you have given |
What this means in practice: when you log a symptom, mark a dose time, or fill in your sleep diary, that data does not reach us. There is no copy of it on our server. That is why the tracking side of the App works without an internet connection as well.
Why we keep the consent record on the server: we have to be able to demonstrate that you gave your explicit consent to the processing of health data, and that you withdrew it if you do (Article 6/2 of KVKK). That record consists of which consent, which version, and when. It contains none of your health entries.
If you lose or replace your phone, or delete the App, your health records are lost with it. Because your data is held locally, we have no copy. We recommend taking a backup at regular intervals (§6).
Data considered special category under Article 6 of KVKK, which we process only with your explicit consent. All of your tracking records are kept on your device. None of them has a copy on our servers.
| Data | What it contains | Where |
|---|---|---|
| Stage assessment | Your assessment answers and the calculated stage | On your device |
| Menopause stage | The stage you selected or that was calculated: pre-perimenopause · perimenopause · postmenopause · undetermined | On your device |
| Symptom entries | The symptoms you logged, their severity, and any notes you wrote | On your device |
| Cycle entries | Period start/end marks, spotting, display preferences, and any notes you wrote | On your device |
| Hormone/medication regimen | The name and form of your regimen, the dose note you wrote yourself, its times, and whether you took each dose | On your device |
| Sleep diary and program progress | Bedtime, wake time, number of night wakings, time to fall asleep, which day of the program you are on | On your device |
| Reminders | The type and time of the reminders you set, and the title you wrote yourself | On your device |
| Reading record | Which article you read, how much of it, and when | On your device |
An honest note about free-text fields: we cannot control what you type into a reminder title or a dose note. If you write a diagnosis, a doctor's name, or information belonging to another person there, that is saved too. These fields never leave your device; but when you take a backup, they are included in it in encrypted form (§6).
| Data | What it contains | Note |
|---|---|---|
| User ID | A randomly generated identifier (UUID) | Assigned in anonymous use as well |
| Email address | · | Only if you upgrade to a permanent account |
| Password hash | · | We do not see your password itself; the authentication infrastructure manages it |
| Nickname | · | May be left empty |
| Your language preference | tr or en |
Your actual preference is kept on your device (§2.3); this copy on the server exists so that we can send the identity emails (verification, password reset) in your language |
| Account state and timestamps | Whether the account is anonymous, whether the email is verified, sign-up/sign-in times, session information | Required for session management |
| Your consent record | Which consent, which version, whether granted, and when | Evidence for legal purposes: we keep this on the server so that we can demonstrate that you gave or withdrew consent (Article 6/2 of KVKK) |
The App does not ask for or hold your full name, date of birth, national ID number, phone number, location or profile photo.
This is the App's largest data set:
One important exception: if your phone's iCloud/iTunes backup is enabled, the database file holding your health records is included in that backup and goes to Apple's servers. This is not a transfer we initiate; it depends on your device's operating system setting. Even so, it is the one exception you do not start yourself to the statement "your data does not leave your device" (the other path is a backup you create yourself).
We do not write most of these records; the cloud infrastructure we use does. The last two rows, however, are written by our own server. We are the data controller, so we list them all:
| Data | Where/why |
|---|---|
| Your IP address and browser/device information (user-agent) | Recorded in the authentication infrastructure's security logs during sign-in, sign-up, email verification and password reset events |
| Session and refresh token records | Technically required to keep your session open |
| Platform/request logs | The infrastructure provider's own operational logs |
| Database backups | The infrastructure provider's disaster-recovery backups |
| Backup delivery error record | If the email provider rejects the request while sending your backup, the server writes a single-line error entry: the HTTP status code and the provider's error code. The following are NOT written to this record: your email address, your password, the contents of your backup, and the provider's descriptive message. In other words, the record does not say whose backup it was |
| Identity email error record | If the email provider rejects the request while your verification or password-reset email is being sent, the server likewise writes a single-line entry: the HTTP status code, the provider's error code, the type of the email (verification or reset) and the sending language. The following are NOT written to this record: your email address, the verification link/token in the email, and the provider's descriptive message |
How long they are kept:
What we do not do: We do not use your data for advertising or marketing, we do not sell it to third parties, and we do not build profiles to share with ad networks. The App contains no ad network, analytics tool or crash-reporting tool. The App does not diagnose and does not recommend doses or prescriptions. The emails we send load no remote images; meaning we do not track whether you opened them.
How we collect it: your personal data is collected electronically, by wholly or partly automated means, through the App and the server infrastructure attached to it. The lawful basis for each data type is below:
| Data type | Lawful basis |
|---|---|
| Health data (§2.1) | Explicit consent (KVKK Art. 6/2). You may withdraw your consent at any time (§11). |
| Email address | Establishment/performance of a contract (Art. 5/2-c) |
| User ID (UUID), account state and timestamps | Establishment/performance of a contract (Art. 5/2-c); required for your account and session to work |
| Consent records | Necessary for the establishment, exercise or protection of a right (Art. 5/2-e); proving that consent was given and withdrawn |
| Nickname | Legitimate interest (Art. 5/2-f); operating the core function |
| The server-side copy of your language preference (§2.2) | Legitimate interest (Art. 5/2-f); being able to send the identity emails in your language |
| Session, IP and security logs | Legitimate interest (Art. 5/2-f); account security |
| Recipient | Purpose | What is transferred |
|---|---|---|
| Supabase (infrastructure/hosting) | Database, authentication, server functions | Only the data in §2.2 (your account, your consent record) and the infrastructure records in §2.4. Your tracking records (symptoms, cycle, regimen, sleep; §2.1) do not go here |
| Brevo (email delivery) | Delivering your backup file to you by email | (a) your email address, (b) the subject line of the email, (c) your encrypted backup file. Details in §6 |
| Brevo (EU; GCP Belgium) | Email verification and password reset emails | Your email address only |
| Competent public authorities | Where required by law | Limited to the scope of the request |
Beyond these, we make no transfer to any other third party. No ad network, analytics provider or data broker is used.
Apple is not in this table, because that is not a transfer we make: if your phone's iCloud/iTunes backup is on, the operating system backs up your health database file to Apple. That depends entirely on your own device setting and is stated plainly in §2.3.
Honesty note: the data processing agreements (DPAs) with the providers above are annexes to their terms of service and are in force upon acceptance of those terms; there is no separate wet signature.
Because your tracking records (symptoms, cycle, regimen, sleep…) exist only on your device, the App gives you a way to take your own backup against the risk of losing your phone.
You create the backup:
You can obtain the backup in two ways:
| What is sent | Your encrypted backup file, your email address, and the subject line of the email |
| Who it is sent to | Only the verified email address of your own account. If you have not verified your email address, this path does not work |
| Can we open the file | No; the password is only yours. Neither we nor the provider can read the contents |
| Do we keep a copy | No. It is written to no storage and to no database table, and its contents are recorded in no log |
| Where it is processed | Our email provider is located in Belgium |
Points we want to draw your attention to:
For the data on your device:
For the data on the server:
We do not promise absolute security for any system; the above are the concrete measures we take.
By applying to the data controller, you may request to:
How to apply: by email from the email address registered to your account to destek@lumiaapp.net, or in writing to Çukurambar mah. Zeki Ergezen cad. 2/4, Çankaya/Ankara. Your request will be concluded within 30 days at the latest.
From within the App you can also:
Withdrawing your consent now happens inside the App. Earlier versions announced this screen as "upcoming"; it has now shipped and the first item in the list above tells you where to find it. The application address above has not closed; it stays open for your other Article 11 rights and for any problem you run into.
What is deleted:
What is not deleted; and why:
Withdrawal does not affect processing that was lawful before the date of withdrawal. You can change your mind again. After withdrawing, the App takes you back to the consent screen; if you want, you can consent again from there and start over. But the deleted records will not come back.
Backup files you took earlier remain in your hands; deleting them is up to you.
When we update this notice we will change the effective date and announce significant changes from within the App. If a change broadens the scope of health data processing, we will ask for fresh explicit consent.
This document is issued under the disclosure obligation in Article 10 of KVKK and should be read together with the Privacy Policy (privacy-policy.md).