Lumen.

Privacy Policy — Lumen

Effective date: September 24, 2026

Lumen ("we", "us") is a spiritual community: a global, public feed of prayer requests on a map, together with friends and private groups. This policy explains what data the app collects, why, and how long it's kept. Anyone can browse the map and feed without an account; signing in (with Google, Apple, or email) is only required to post a prayer, tap "I prayed for this," report a prayer, or use friends and groups. We do not sell or share your data with advertisers — there is no advertising or monetization in this app.

Data we collect

Location. When you post a prayer for everyone (or share a group prayer on the globe too), the app asks for your device location to place your prayer on the map. We store the exact coordinates you submitted along with a reverse-geocoded general region (e.g. "Austin, Texas, United States"). Only the general region is ever shown publicly — exact coordinates are never displayed to other users, though they are retained in our database to render the map marker. A prayer you share only with a group never appears on the map, so for those the app does not ask for your location and we store none.

Account. Signing in creates an account via Google, Apple, or email + password (handled by our backend provider, Supabase — we never see or store your Google/Apple password, and if you sign in with email we store only a securely hashed version of your password, never the password itself). If you sign in with email we send you emails to confirm your address and, if you ask, to reset your password; those emails contain a one-time link that opens the app. Depending on the method you choose, we receive your email address and, for Google/Apple, whatever profile info you grant (typically name and email). This account — not a device — is what we use to apply rate limits and moderation actions (like a temporary or permanent block) to prevent abuse.

Prayer content. The text of any prayer you submit is stored, along with its moderation status and, if applicable, why it was flagged for review. If you edit a prayer, the new text replaces the old and we record that it was edited (other people see the word "edited"); we do not keep the earlier wording available to anyone in the app.

Answered prayers. You can mark a prayer of yours as answered and, optionally, add a short update (up to 280 characters). We store that it was answered, when, and the update. Anyone who can see the prayer can see that it was answered and read the update. Like a prayer, the update is screened automatically before it is saved (see "Content moderation").

Notification settings. If you turn on prayer reminders, we store the times of day you chose, whether each is switched on, and your device's time zone name (e.g. "America/New_York"), tied to your account so your settings survive a reinstall or a second device. These reminders are scheduled and fired entirely on your device — we never send them and we have no way to tell whether one fired or whether you opened it.

Push notification token. If you allow notifications, your device registers with Apple's or Google's push service and we store the resulting token, tied to your account. We use it for two things: to tell you when someone taps "🙏 I prayed for this" on a prayer you posted, to tell you when a member shares a prayer with a group you belong to, and to tell you when a prayer you prayed for has been marked answered. None of these notifications contains a prayer's text; the group one names only the group, and the answered one does not say who posted the prayer. The token is an identifier for your app installation, not for you personally, and it changes if you reinstall.

Display name and friend code. Setting a display name is optional. If you set one, we store it, tied to your account, and give you a short friend code (8 characters) that you can share so someone can add you as a friend. Your display name is visible to your friends and to the members of any group you share with them — it is not public, and it is never shown on the map or in the public feed. Names are screened automatically before they are saved (see "Content moderation").

Friends, blocks, and groups. If you add a friend, we store that connection on both accounts. If you create or join a group, we store the group's name, who its owner is, when each member joined, and who its members are. If you block someone from a prayer, we store that you blocked that account (see "Your choices"); blocking someone also removes them from your friends.

Group prayers. When you post a prayer you can choose to share it with one of your groups instead of everyone. We store which group it was shared with, and — only if you choose to sign it — a copy of your display name as it was when you posted. A prayer shared with a group is visible only to that group's members and never appears on the map or the public feed. If you switch on "Also share on the globe," we create a second, separate, anonymous copy of the prayer for the public map: it carries no name and no link to the group, and it is treated like any other public prayer from then on (including the 30-day expiry and the moderation described below).

Group notification settings. If you turn off notifications for a group, we store that choice (which group and that it is off), tied to your account. Other members cannot see it.

Profile photo. Adding a profile photo is optional. If you choose one, the app opens your phone's own photo picker (Lumen sees only the single photo you pick, not your library), crops it to a square, shrinks it, and sends it to us. It is screened automatically before it is saved (see "Content moderation") and stored privately under your account. Your photo is visible only to your friends and to the members of groups you share with them, next to your display name — never on the map, the public feed, or any public prayer.

Camera. If you choose "Scan a code" to add a friend, Lumen uses your camera to read a QR code. The camera feed is processed on your device to find the code; it is never recorded, stored, or uploaded, and we only use the code it contains. You can decline camera access and type a code instead.

Stored only on your device. The app keeps a few preferences on your phone and never sends them to us: your chosen theme, whether you have seen the welcome tour, whether you dismissed the reminder offer, and when you last opened each of your groups (used to show "new" dots).

Interactions and reports. If you tap "🙏 I prayed for this" or report a prayer, we record that action (tied to your account and the prayer in question) so we can prevent duplicate taps from the same account and route reports to a moderator. Nobody else can read this log. You can see a summary of your own — which days this week you prayed — shown to you in the app; it is never shown to anyone else.

How we use this data

We do not use your data for advertising, and we do not sell it to third parties.

Content moderation

Every prayer you submit is automatically screened using OpenAI's moderation API before it can appear publicly, and the same screening is applied to prayers shared with a group and to edits of a prayer. Display names, group names, answered-prayer updates, and profile photos are screened the same way (a photo is sent to OpenAI's image moderation); names are held to a stricter threshold, and a name, group name, update, or photo that doesn't pass is rejected outright — there is no human review for those. This means the text you submit is sent to OpenAI for automated classification (not stored by them for training, per their moderation endpoint's terms at the time of writing — see OpenAI's own privacy policy for their current practices). If a submission is flagged as involving self-harm, we show you crisis resources and route the post to a human moderator rather than publishing it automatically. Content that a moderator or the automated system rejects is never shown publicly, but the submitted text is retained in our database for moderation and appeals purposes. A prayer held for review is held whatever its audience, so a moderator may read a group prayer that was flagged while it is waiting for a decision.

Who can see what

Data retention

Prayers — public or shared with a group — are automatically archived (removed from view) 30 days after posting, unless a moderator has pinned them, or sooner if you delete them (see "Your choices"). Archived prayers, account records, and moderation history may be retained longer for abuse-prevention purposes (e.g. so an account that was restricted stays restricted) — until you delete your account, which purges them (see "Your choices" below).

Children's privacy

Lumen is not directed at children and we do not knowingly collect data from anyone we know to be under 13. We don't ask for your age, so we have no reliable way to detect a user's age on our own — if you believe a child has submitted content, please report it via the in-app report button or contact us below and we will remove it.

Your choices

Third parties we rely on

We don't use third-party analytics or advertising SDKs in this app.

Changes to this policy

If this policy changes, we'll update the effective date above. Continued use of the app after a change means you accept the updated policy.

Contact

Questions about this policy or requests regarding your data: lumentheapp@gmail.com