Lumen — Privacy Policy
Data Controller: Michał Dobrzański, operating as "Oscillator Michał Dobrzański," ul. Św. Wincentego 110/65, 03-291 Warszawa, Poland.
Last revised: 23 May 2026.
This privacy notice explains how Oscillator Michał Dobrzański ("we," "us," "our") processes personal data in connection with the Lumen application and its supporting services (the "Services"). It is written for compliance with the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the United Kingdom Data Protection Act 2018, the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), the Polish Act on the Protection of Personal Data (10 May 2018), and Apple App Store / Google Play platform requirements.
If you have any question or want to exercise a right described below, write to lumen.prayer.app@gmail.com or by post to the controller's address above.
1. Information we collect
We process the following categories of personal data, grouped by source. Where a category is collected only conditionally, the condition is named in parentheses.
- Identifiers. An anonymous account UUID created on first launch, and — if you choose to sign in — your Apple ID or Google account identifier. We never receive your Apple ID password or Google password; we only receive the opaque identifier those providers issue to us.
- Prayer prompts. The free-text or transcribed-speech input you submit when generating a prayer. The transcription happens on your device (or via Apple/Google speech APIs); we receive the resulting text.
- Saved intentions. The labels and optional context you create for Quick Pray (e.g. "Mom Linda — health").
- Prayer library. The text of each generated prayer, the tone and length you chose, the voice you chose, the timestamp, and whether you marked the prayer as a favorite.
- Subscription state. Your current tier (Free / Standard / Pro), the count of generations you have used in the current billing period, and subscription-event metadata received from RevenueCat (which itself receives the underlying event from Apple or Google).
- Diagnostic data (only if you have not opted out under Settings → Privacy). Anonymised stack traces, device model, OS version, app version, screen-view counts, and lifecycle event names ("onboarding_completed," "generate_started," "paywall_shown" etc.). Never the content of your prompts, never your names, never audio.
- Crisis-pipeline flag — a single boolean indicating that the crisis-resources screen fired during a session. Never the input text that triggered it.
How the data reaches us. Most of it comes directly from your interactions with the Services (you type a prompt; you tap a tile). Subscription state is forwarded server-to-server by RevenueCat from Apple/Google. We do not buy personal data from third parties and we do not use third-party advertising trackers; the app does not show ads.
2. Why we process the data, and on what legal basis
Each entry below identifies a purpose, the data categories used for that purpose, and the legal basis under Article 6(1) GDPR. Where a basis is "consent," you may withdraw consent at any time without affecting the lawfulness of earlier processing.
- Generating prayers (the core service). Categories: prompts, intentions, library, identifiers. Legal basis: Article 6(1)(b) GDPR — performance of the contract you accepted by installing the app.
- Storing your library for replay. Categories: library, identifiers. Legal basis: Article 6(1)(b) GDPR.
- Enforcing the per-tier generation cap. Categories: subscription state, identifiers. Legal basis: Article 6(1)(b) (performance of contract) and Article 6(1)(c) (legal obligations to App Store / Play Store).
- Stable operation, bug-fixing. Categories: diagnostic data. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in operating a working product. We have weighed this against your interests; the impact is minimal because the data is pseudonymised and never includes prompt content. You can object — see Section 5.
- Aggregated product analytics. Categories: diagnostic-data event counts only. Legal basis: Article 6(1)(f) GDPR. Same balancing as above.
- Operating the crisis-safety pipeline. Categories: crisis-pipeline flag. Legal basis: Article 6(1)(f) GDPR — operating a safety control on a product accessible to potentially vulnerable users.
- Complying with our own legal obligations (tax, accounting, consumer-protection record-keeping). Categories: minimum necessary, primarily subscription state + identifiers. Legal basis: Article 6(1)(c) GDPR.
- Responding to data-subject requests and legal claims. Categories: as needed to respond. Legal basis: Article 6(1)(c) and (f).
We do not process special categories of personal data (Article 9 GDPR) as a defined input. We acknowledge that using a Catholic-tradition prayer app may itself be considered an inference about your religious beliefs; we therefore treat the existence of your account as sensitive and limit its disclosure as described in Section 3.
3. Sub-processors — who else handles your data
We share personal data only with the sub-processors listed below. Each acts under a written data-processing agreement, uses the data solely for the purposes we direct, and applies equivalent or stronger security measures.
- Anthropic, PBC (United States) — generates the prayer text from your prompt. Processes prompts for the duration of one generation. Operates under Anthropic's published commercial terms; does not use the data to train models. International-transfer safeguard: EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).
- ElevenLabs Inc. (United States) — converts the prayer text to streaming audio. Processes the prayer text for the duration of one generation. International-transfer safeguard: EU SCCs.
- Supabase, Inc. (United States; data stored in an EU-region instance) — stores your account row, intentions, prayer library, and subscription state at rest. International-transfer safeguard: EU SCCs.
- Cloudflare, Inc. (United States; edge nodes globally) — runs the proxy that routes your requests to the providers above. May briefly process request metadata (IP address, user-agent) for security and rate-limiting. International-transfer safeguard: EU SCCs.
- RevenueCat, Inc. (United States) — receives subscription events from Apple / Google and forwards them to us. Processes a hashed user identifier plus subscription metadata. International-transfer safeguard: EU SCCs.
- Apple Inc. and Google LLC — handle in-app payments and act as the distribution channels. Each is an independent controller for its own purposes (billing, fraud prevention, store analytics) under its respective privacy policy.
- Sentry (Functional Software, Inc.) (United States) — receives crash diagnostics if you have not opted out. International-transfer safeguard: EU SCCs.
- PostHog Inc. (United States / EU instance) — receives anonymised product-analytics events if you have not opted out. International-transfer safeguard: EU SCCs where applicable.
We do not sell or "share" personal data within the meaning of the CCPA/CPRA. We do not place third-party advertising trackers in the app. We do not show ads.
Public authorities may require us to disclose data under a binding legal order (court order, subpoena, lawful regulator request). We disclose only the minimum necessary and, where lawful, notify you so you can challenge the order.
4. International data transfers
Some sub-processors are based outside the European Economic Area, primarily in the United States. Where personal data is transferred to a country outside the EEA that the European Commission has not recognised as providing an adequate level of protection, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), supplemented by additional technical and organisational measures: TLS 1.3 in transit, encryption at rest, strict access controls, contractual audit rights. A copy of the relevant clauses is available on request at the contact above.
5. Your rights
Under the GDPR you have the following rights. You can exercise any of them, free of charge, by writing to lumen.prayer.app@gmail.com. We respond within 30 days (extendable by a further 60 days for complex requests, in which case we will tell you within the first 30 days).
- Access (Article 15) — obtain a copy of the personal data we hold about you.
- Rectification (Article 16) — have inaccurate data corrected.
- Erasure / "right to be forgotten" (Article 17) — have your data deleted. The in-app shortcut is Settings → Account → Delete account; it is irrevocable.
- Restriction of processing (Article 18) — require us to pause processing while a dispute is resolved.
- Data portability (Article 20) — receive your library and intentions as a plain-text export under Settings → Account → Export.
- Object (Article 21) — object to processing based on legitimate interests (analytics + crash diagnostics). You can switch these off under Settings → Privacy.
- Not be subject to automated decision-making (Article 22) — Lumen does not make decisions producing legal or similarly significant effects on you solely by automated means.
- Withdraw consent (Article 7(3)) — where processing is based on consent, you can withdraw it at any time.
- Lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office — Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. Residents of other EU/EEA member states may lodge a complaint with their local supervisory authority — see the EDPB list at edpb.europa.eu.
California residents (CCPA/CPRA). You have parallel rights of access, deletion, correction, and the right to limit the use of sensitive personal information. We honour them via the same email path. We do not sell or share personal information for cross-context behavioural advertising; there is therefore no "Do Not Sell or Share" link.
6. Retention
We keep data only as long as needed for the purpose for which it was collected:
- Account, intentions, library: until you delete the item or delete your account.
- Subscription state: for the duration of your subscription plus the period required by Polish accounting / tax law (currently 5 calendar years under the Polish Accounting Act of 29 September 1994).
- Diagnostic data, product analytics: 90 days (crash diagnostics); 12 months in aggregated form (product analytics); 12 months for the crisis-pipeline flag.
- Backup copies roll on a 30-day cycle; once an item is deleted from the primary store, copies are overwritten within 30 days.
7. How to delete your account
Apple App Store and Google Play both require app developers to provide an in-app account-deletion path. In Lumen this is at Settings → Account → Delete account. Deletion is permanent and immediate; we do not maintain a "recoverable" state.
If you cannot reach the in-app screen (e.g. you have lost device access), email lumen.prayer.app@gmail.com from the address linked to your Apple/Google sign-in. We will process deletion within 30 days.
8. Children
Lumen is not directed to children. We do not knowingly collect personal data from anyone under the age of 16, which is the GDPR default age for digital-services consent (Article 8 GDPR). Where Polish or other applicable local law lowers this threshold to 13, the local threshold applies. If we become aware that we have collected data from a child without verified parental consent, we will delete it without undue delay. Parents and guardians can contact us at the email above to request review or deletion of any account they believe relates to a child.
9. Crisis-safety treatment
If your prompt contains language indicating thoughts of suicide or self-harm, the app intentionally does not generate a prayer. It surfaces the phone numbers of crisis hotlines for the user's region instead (e.g. 988 in the United States, 116 123 in the United Kingdom and Ireland). Calls are routed by your device's dialer; they do not pass through our infrastructure. We record only an anonymous boolean indicating that the crisis screen fired — never the input text that triggered it.
10. Security
We apply industry-standard technical and organisational measures: TLS 1.3 for data in transit; AES-256 at rest in Supabase; row-level security so each user can only access their own rows; least-privilege service-account keys; no hard-coded credentials in the mobile binary; two-factor authentication on all maintainer accounts. No system is perfectly secure; if a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and you without undue delay, as required by Articles 33–34 GDPR.
11. Cookies and similar technologies
The Lumen mobile app does not use cookies or third-party tracking SDKs. The marketing website does not set cookies; the only third-party request it makes is to Google Fonts to load Lora, Inter, and UnifrakturMaguntia. Google may receive your IP address as part of that request under its own privacy policy.
12. Changes to this notice
We update this notice when our processing changes. The "Last revised" date at the top moves with every revision. Material changes will additionally be flagged in the app on the next launch and announced in the App Store / Play Store release notes. For changes that require fresh consent under GDPR, we will ask for it explicitly inside the app.
13. Contact
For any privacy question, complaint, or data-subject request:
Oscillator Michał Dobrzański
ul. Św. Wincentego 110/65
03-291 Warszawa
Poland
Email: lumen.prayer.app@gmail.com