← Lumen

Lumen — Privacy Policy

Data Controller: Michał Dobrzański, operating as "Oscillator Michał Dobrzański," ul. Św. Wincentego 110/65, 03-291 Warszawa, Poland.
Last revised: 23 May 2026.

This privacy notice explains how Oscillator Michał Dobrzański ("we," "us," "our") processes personal data in connection with the Lumen application and its supporting services (the "Services"). It is written for compliance with the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), the United Kingdom Data Protection Act 2018, the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), the Polish Act on the Protection of Personal Data (10 May 2018), and Apple App Store / Google Play platform requirements.

If you have any question or want to exercise a right described below, write to lumen.prayer.app@gmail.com or by post to the controller's address above.

1. Information we collect

We process the following categories of personal data, grouped by source. Where a category is collected only conditionally, the condition is named in parentheses.

How the data reaches us. Most of it comes directly from your interactions with the Services (you type a prompt; you tap a tile). Subscription state is forwarded server-to-server by RevenueCat from Apple/Google. We do not buy personal data from third parties and we do not use third-party advertising trackers; the app does not show ads.

2. Why we process the data, and on what legal basis

Each entry below identifies a purpose, the data categories used for that purpose, and the legal basis under Article 6(1) GDPR. Where a basis is "consent," you may withdraw consent at any time without affecting the lawfulness of earlier processing.

We do not process special categories of personal data (Article 9 GDPR) as a defined input. We acknowledge that using a Catholic-tradition prayer app may itself be considered an inference about your religious beliefs; we therefore treat the existence of your account as sensitive and limit its disclosure as described in Section 3.

3. Sub-processors — who else handles your data

We share personal data only with the sub-processors listed below. Each acts under a written data-processing agreement, uses the data solely for the purposes we direct, and applies equivalent or stronger security measures.

We do not sell or "share" personal data within the meaning of the CCPA/CPRA. We do not place third-party advertising trackers in the app. We do not show ads.

Public authorities may require us to disclose data under a binding legal order (court order, subpoena, lawful regulator request). We disclose only the minimum necessary and, where lawful, notify you so you can challenge the order.

4. International data transfers

Some sub-processors are based outside the European Economic Area, primarily in the United States. Where personal data is transferred to a country outside the EEA that the European Commission has not recognised as providing an adequate level of protection, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), supplemented by additional technical and organisational measures: TLS 1.3 in transit, encryption at rest, strict access controls, contractual audit rights. A copy of the relevant clauses is available on request at the contact above.

5. Your rights

Under the GDPR you have the following rights. You can exercise any of them, free of charge, by writing to lumen.prayer.app@gmail.com. We respond within 30 days (extendable by a further 60 days for complex requests, in which case we will tell you within the first 30 days).

California residents (CCPA/CPRA). You have parallel rights of access, deletion, correction, and the right to limit the use of sensitive personal information. We honour them via the same email path. We do not sell or share personal information for cross-context behavioural advertising; there is therefore no "Do Not Sell or Share" link.

6. Retention

We keep data only as long as needed for the purpose for which it was collected:

7. How to delete your account

Apple App Store and Google Play both require app developers to provide an in-app account-deletion path. In Lumen this is at Settings → Account → Delete account. Deletion is permanent and immediate; we do not maintain a "recoverable" state.

If you cannot reach the in-app screen (e.g. you have lost device access), email lumen.prayer.app@gmail.com from the address linked to your Apple/Google sign-in. We will process deletion within 30 days.

8. Children

Lumen is not directed to children. We do not knowingly collect personal data from anyone under the age of 16, which is the GDPR default age for digital-services consent (Article 8 GDPR). Where Polish or other applicable local law lowers this threshold to 13, the local threshold applies. If we become aware that we have collected data from a child without verified parental consent, we will delete it without undue delay. Parents and guardians can contact us at the email above to request review or deletion of any account they believe relates to a child.

9. Crisis-safety treatment

If your prompt contains language indicating thoughts of suicide or self-harm, the app intentionally does not generate a prayer. It surfaces the phone numbers of crisis hotlines for the user's region instead (e.g. 988 in the United States, 116 123 in the United Kingdom and Ireland). Calls are routed by your device's dialer; they do not pass through our infrastructure. We record only an anonymous boolean indicating that the crisis screen fired — never the input text that triggered it.

10. Security

We apply industry-standard technical and organisational measures: TLS 1.3 for data in transit; AES-256 at rest in Supabase; row-level security so each user can only access their own rows; least-privilege service-account keys; no hard-coded credentials in the mobile binary; two-factor authentication on all maintainer accounts. No system is perfectly secure; if a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and you without undue delay, as required by Articles 33–34 GDPR.

11. Cookies and similar technologies

The Lumen mobile app does not use cookies or third-party tracking SDKs. The marketing website does not set cookies; the only third-party request it makes is to Google Fonts to load Lora, Inter, and UnifrakturMaguntia. Google may receive your IP address as part of that request under its own privacy policy.

12. Changes to this notice

We update this notice when our processing changes. The "Last revised" date at the top moves with every revision. Material changes will additionally be flagged in the app on the next launch and announced in the App Store / Play Store release notes. For changes that require fresh consent under GDPR, we will ask for it explicitly inside the app.

13. Contact

For any privacy question, complaint, or data-subject request:

Oscillator Michał Dobrzański
ul. Św. Wincentego 110/65
03-291 Warszawa
Poland
Email: lumen.prayer.app@gmail.com