Privacy Policy - Lumia

A summary in a few sentences

Your health records stay on your phone. Your symptom, cycle, regimen, sleep and stage records are not sent to our servers. The server holds only your account (your email address, your nickname, your session and security logs, and a copy of your language preference) and your consent record.


1. Who we are

Company Neural Academy Ltd. Şti.
Address Çukurambar mah. Zeki Ergezen cad. 2/4, Çankaya/Ankara, Türkiye
Contact destek@lumiaapp.net

In this text, "Lumia" or "we" means the company above; "the App" means the Lumia mobile application.

Lumia is a tracking and information app for people in menopause and perimenopause. It is not a medical device; it does not diagnose, and it does not recommend medication or dosage.


2. What data do we process?

2.1 Data that stays on your phone (never sent to us)

All of this lives in a local database file on your device, and we have no access to it:

The one exception is your own setting: if your phone's iCloud backup is on, the operating system backs this file up too. That backup sits in Apple's infrastructure and is outside our control.

2.2 Data held on the server

2.3 Data we do NOT process


3. Why do we process it?

Purpose Which data
Creating your account and signing you in Email, password hash
Being able to prove you allowed us to process health data Consent record
Delivering your backup file to you by email Your email address
Account security and abuse prevention Session/security logs
Sending the identity emails (verification, password reset) in your language The server-side copy of your language preference
The app's core function (tracking, content, reminders) §2.1; on your device, without access by us

What we do not do: no profiling, no automated decision-making, no behavioural advertising.


4. Who do we share it with?

Recipient Where What goes there
Supabase (database, authentication, server functions) Frankfurt, Germany (EU) Only the data in §2.2
Brevo (email delivery) EU (Belgium) Your email address; for backup delivery also the email subject line and your encrypted backup file
Competent public authorities · Only upon a lawful request, limited to its scope

We transfer data to no other third party.

Apple is not in this table, because that is not a transfer we make: if your phone's iCloud backup is on, the operating system backs up the local database file in §2.1 to Apple. That depends entirely on your own device setting (see the note in §2.1).

A note on honesty: the data processing agreements (DPAs) with these providers are annexes to their terms of service and are in force upon acceptance of those terms; there is no separate wet signature.


5. Where is your data processed?

Our servers are currently in Frankfurt, Germany. This means the data in §2.2 is processed outside Türkiye.

Your health records (§2.1) stay on your phone; they are not sent to our servers.

The fact that "this email address is registered with Lumia" can itself amount to a health inference in context; that is why the transferred set is deliberately kept minimal. The legal basis for this limited transfer is your explicit consent (asked as a separate item on the consent screen); the details are in §7 of the Privacy Notice.


6. Backups and exporting your data

From the Export my data screen you can create an encrypted backup of the records on your device.

Keeping the backup file in your own mailbox is your responsibility. Do not share the password through the same channel as the file.


7. How long do we keep it?

Data Period
Your account details Until you delete your account
Your consent record For 5 more years after you delete your account (as evidence; it holds no health data and no email; Privacy Notice §8); the record remains even if you withdraw consent
Records on your device Until you delete them, withdraw your consent, or uninstall the app
Session/security logs At most 90 days. Technical logs held by our infrastructure and email providers are deleted under their own retention periods; we do not archive them separately

8. Where your controls are in the app

What you want Where
Withdraw my consent Profile → Privacy and data → Consent preferences
Get a copy of my data Profile → Privacy and data → Export my data
Delete my account and records Profile → Privacy and data → Delete account
Change my language Profile → Personalization → Language

Signing out does not delete the records on your device; it only ends your session.

For anything else (requests for information, correction, learning which third parties received your data, and so on), write to destek@lumiaapp.net. We respond within 30 days at the latest. Your statutory rights under KVKK Article 11 are set out in §10 of the Privacy Notice.


9. How is your data protected?

An honest limit: the local database file on your device is not separately encrypted; it is protected by your phone's own screen lock and disk encryption. We recommend keeping your phone locked.


10. Children

Lumia is not designed for anyone under 18, and we do not knowingly collect data from children. If we learn that we have processed a child's data, we delete the account and records on the server (we have no remote access to the records on the device).

By using the App and when you create an account, you confirm that you are at least 18 (Terms of Use §1); our store age rating reflects this. We do not ask for an identity document or a date of birth; doing so would mean collecting more personal data about you in order to verify your age.


11. If this policy changes

When we update this text we change the effective date and announce significant changes inside the app. If a change broadens the scope of health-data processing, we ask for fresh explicit consent.


12. Contact

For any privacy question or request: destek@lumiaapp.net


This document should be read together with the KVKK Privacy Notice.