Privacy Policy — Lumen
Effective date: September 24, 2026
Lumen ("we", "us") is a spiritual community: a global, public feed of prayer requests on a map, together with friends and private groups. This policy explains what data the app collects, why, and how long it's kept. Anyone can browse the map and feed without an account; signing in (with Google, Apple, or email) is only required to post a prayer, tap "I prayed for this," report a prayer, or use friends and groups. We do not sell or share your data with advertisers — there is no advertising or monetization in this app.
Data we collect
Location. When you post a prayer for everyone (or share a group prayer on the globe too), the app asks for your device location to place your prayer on the map. We store the exact coordinates you submitted along with a reverse-geocoded general region (e.g. "Austin, Texas, United States"). Only the general region is ever shown publicly — exact coordinates are never displayed to other users, though they are retained in our database to render the map marker. A prayer you share only with a group never appears on the map, so for those the app does not ask for your location and we store none.
Account. Signing in creates an account via Google, Apple, or email + password (handled by our backend provider, Supabase — we never see or store your Google/Apple password, and if you sign in with email we store only a securely hashed version of your password, never the password itself). If you sign in with email we send you emails to confirm your address and, if you ask, to reset your password; those emails contain a one-time link that opens the app. Depending on the method you choose, we receive your email address and, for Google/Apple, whatever profile info you grant (typically name and email). This account — not a device — is what we use to apply rate limits and moderation actions (like a temporary or permanent block) to prevent abuse.
Prayer content. The text of any prayer you submit is stored, along with its moderation status and, if applicable, why it was flagged for review. If you edit a prayer, the new text replaces the old and we record that it was edited (other people see the word "edited"); we do not keep the earlier wording available to anyone in the app.
Answered prayers. You can mark a prayer of yours as answered and, optionally, add a short update (up to 280 characters). We store that it was answered, when, and the update. Anyone who can see the prayer can see that it was answered and read the update. Like a prayer, the update is screened automatically before it is saved (see "Content moderation").
Notification settings. If you turn on prayer reminders, we store the times of day you chose, whether each is switched on, and your device's time zone name (e.g. "America/New_York"), tied to your account so your settings survive a reinstall or a second device. These reminders are scheduled and fired entirely on your device — we never send them and we have no way to tell whether one fired or whether you opened it.
Push notification token. If you allow notifications, your device registers with Apple's or Google's push service and we store the resulting token, tied to your account. We use it for two things: to tell you when someone taps "🙏 I prayed for this" on a prayer you posted, to tell you when a member shares a prayer with a group you belong to, and to tell you when a prayer you prayed for has been marked answered. None of these notifications contains a prayer's text; the group one names only the group, and the answered one does not say who posted the prayer. The token is an identifier for your app installation, not for you personally, and it changes if you reinstall.
Display name and friend code. Setting a display name is optional. If you set one, we store it, tied to your account, and give you a short friend code (8 characters) that you can share so someone can add you as a friend. Your display name is visible to your friends and to the members of any group you share with them — it is not public, and it is never shown on the map or in the public feed. Names are screened automatically before they are saved (see "Content moderation").
Friends, blocks, and groups. If you add a friend, we store that connection on both accounts. If you create or join a group, we store the group's name, who its owner is, when each member joined, and who its members are. If you block someone from a prayer, we store that you blocked that account (see "Your choices"); blocking someone also removes them from your friends.
Group prayers. When you post a prayer you can choose to share it with one of your groups instead of everyone. We store which group it was shared with, and — only if you choose to sign it — a copy of your display name as it was when you posted. A prayer shared with a group is visible only to that group's members and never appears on the map or the public feed. If you switch on "Also share on the globe," we create a second, separate, anonymous copy of the prayer for the public map: it carries no name and no link to the group, and it is treated like any other public prayer from then on (including the 30-day expiry and the moderation described below).
Group notification settings. If you turn off notifications for a group, we store that choice (which group and that it is off), tied to your account. Other members cannot see it.
Profile photo. Adding a profile photo is optional. If you choose one, the app opens your phone's own photo picker (Lumen sees only the single photo you pick, not your library), crops it to a square, shrinks it, and sends it to us. It is screened automatically before it is saved (see "Content moderation") and stored privately under your account. Your photo is visible only to your friends and to the members of groups you share with them, next to your display name — never on the map, the public feed, or any public prayer.
Camera. If you choose "Scan a code" to add a friend, Lumen uses your camera to read a QR code. The camera feed is processed on your device to find the code; it is never recorded, stored, or uploaded, and we only use the code it contains. You can decline camera access and type a code instead.
Stored only on your device. The app keeps a few preferences on your phone and never sends them to us: your chosen theme, whether you have seen the welcome tour, whether you dismissed the reminder offer, and when you last opened each of your groups (used to show "new" dots).
Interactions and reports. If you tap "🙏 I prayed for this" or report a prayer, we record that action (tied to your account and the prayer in question) so we can prevent duplicate taps from the same account and route reports to a moderator. Nobody else can read this log. You can see a summary of your own — which days this week you prayed — shown to you in the app; it is never shown to anyone else.
How we use this data
- To place your prayer on the map and show it to other users as a general region.
- To screen submitted content for policy violations before it's shown publicly (see "Content moderation" below).
- To rate-limit posting (currently one post per account per 60 seconds) and to identify accounts that repeatedly post content that gets flagged or rejected, so we can restrict their ability to post further.
- To let you and other users mark that you prayed for a specific request, without letting either of you see who else did.
- To let you sign in the same way across devices, so your posting history and abuse-prevention status follow your account rather than resetting on reinstall.
- To remind you to pray at times you chose, and to let you know when someone has prayed for something you posted.
- To let you add friends, form groups with them, and share prayers privately with a group, and to show your display name to the people you have chosen to share it with.
- To let a group's owner remove members from it, hand ownership to another member, or delete it, and to let you pray for, report, or block the author of a prayer shared with a group you're in.
- To tell the people who prayed for a prayer when its author marks it answered.
- To let a group's members know when a prayer is shared with it, unless they've turned that off.
We do not use your data for advertising, and we do not sell it to third parties.
Content moderation
Every prayer you submit is automatically screened using OpenAI's moderation API before it can appear publicly, and the same screening is applied to prayers shared with a group and to edits of a prayer. Display names, group names, answered-prayer updates, and profile photos are screened the same way (a photo is sent to OpenAI's image moderation); names are held to a stricter threshold, and a name, group name, update, or photo that doesn't pass is rejected outright — there is no human review for those. This means the text you submit is sent to OpenAI for automated classification (not stored by them for training, per their moderation endpoint's terms at the time of writing — see OpenAI's own privacy policy for their current practices). If a submission is flagged as involving self-harm, we show you crisis resources and route the post to a human moderator rather than publishing it automatically. Content that a moderator or the automated system rejects is never shown publicly, but the submitted text is retained in our database for moderation and appeals purposes. A prayer held for review is held whatever its audience, so a moderator may read a group prayer that was flagged while it is waiting for a decision.
Who can see what
- Everyone (no login required): the text and general region of any public prayer with "live" status, on the map — and, if its author marked it answered, that fact and their update. Public prayers are always anonymous.
- Your friends: your display name, profile photo, and friend code.
- Members of a group you belong to: the group's name, its owner, and member list (display names and profile photos), and the prayers shared with that group — with your name on them only if you signed them, otherwise as "Anonymous".
- Nobody, including us in the normal course of using the app: your exact submitted coordinates, your account identity behind a public prayer, your report history, or your "prayed for this" history — these are not exposed through the app to any user, including you. The identity behind a prayer is withheld at the database level, not just hidden in the app.
- A trusted moderator: prayers pending review (flagged content awaiting a decision), for the purpose of approving or rejecting them.
Data retention
Prayers — public or shared with a group — are automatically archived (removed from view) 30 days after posting, unless a moderator has pinned them, or sooner if you delete them (see "Your choices"). Archived prayers, account records, and moderation history may be retained longer for abuse-prevention purposes (e.g. so an account that was restricted stays restricted) — until you delete your account, which purges them (see "Your choices" below).
Children's privacy
Lumen is not directed at children and we do not knowingly collect data from anyone we know to be under 13. We don't ask for your age, so we have no reliable way to detect a user's age on our own — if you believe a child has submitted content, please report it via the in-app report button or contact us below and we will remove it.
Your choices
- You can browse the map and feed without ever signing in.
- You can decline location access. You will not be able to post a prayer to the map without it, since placement on the map is what a public prayer is, but you can still share prayers with your groups, which need no location.
- You can edit or delete any prayer you posted at any time (open it from You → Your prayers). An edit is screened again before it shows. Deleting removes it for everyone straight away — including the anonymous public copy of a prayer you also shared on the globe — along with the taps and reports attached to it.
- You can turn prayer reminders off at any time (You → Prayer reminders), or decline notification permission altogether — the rest of the app works normally without it. Turning reminders off cancels everything scheduled on your device immediately. You can also revoke notification permission for Lumen in your device's own Settings at any time, which stops both kinds of notification regardless of your in-app settings.
- Your display name and profile photo are optional, and you can post to a group anonymously even if you have them. You can change or remove your photo at any time (You → your photo).
- You can block the author of a prayer you don't want to see. That hides their prayers from you and removes them from your friends; it does not remove the prayer for anyone else. You can unblock everyone from the You tab.
- You can leave any group at any time, and turn off notifications for any group you're in without leaving it.
- If you own a group, you can remove its members, hand ownership to another member, or delete it. Removing someone doesn't delete prayers they already shared with the group; deleting the group deletes every prayer shared in it, for everyone. If an owner leaves the group or deletes their account, ownership passes to the member who has been in it longest; if nobody else is left, the group and its prayers are deleted.
- You can delete your account at any time from within the app (You tab → Delete account). This immediately and permanently deletes your account, your display name and friend code, your friendships, your profile photo, your group memberships, the prayers you've posted (including prayers you shared with groups), your "prayed for this" history, your reports, your reminder settings, and your push token — this cannot be undone and does not require contacting us. A group you owned keeps existing for its other members, under a new owner, but the prayers you shared in it are deleted with you.
Third parties we rely on
- Supabase — hosts our database and backend functions, and sends the confirmation and password-reset emails.
- OpenAI — provides the moderation API used to screen prayers, display names, group names, answered-prayer updates, and profile photos before they are saved or shown.
- Google and Apple — if you choose "Sign in with Google" or "Sign in with Apple", they authenticate you and tell us your email address (and name, if you share it). Their own privacy policies govern what they collect when you sign in.
- Expo — operates the push notification service we send notifications through, and issues the push token described above. Only the token and the short notification text pass through it; your prayer content does not.
- Apple (APNs) and Google (FCM) — the operating-system push services that actually deliver a notification to your device. Delivering any push notification on iOS or Android necessarily goes through them.
We don't use third-party analytics or advertising SDKs in this app.
Changes to this policy
If this policy changes, we'll update the effective date above. Continued use of the app after a change means you accept the updated policy.
Contact
Questions about this policy or requests regarding your data: lumentheapp@gmail.com