✨ Lumea

Privacy Policy — Lumea

Last updated: July 2, 2026

This Privacy Policy explains what personal data is processed when you use the Lumea mobile app ("Lumea", the "App", "we", "us"), why, and what rights you have. Lumea is a skincare companion offering AI-assisted skin analysis, a photo journal, routine and symptom tracking, and a food log.

Lumea is offered primarily in the United States and also in Germany. This policy is written to satisfy the EU General Data Protection Regulation (GDPR) and applicable US privacy law. A German version (Datenschutzerklärung) is available in the App; both describe the same processing.


1. Who Is Responsible (Data Controller)

The controller responsible for processing your personal data within the meaning of Art. 4(7) GDPR is:

Elena Frei Professor Bachofer Strasse 2 21509 Glinde Germany Email: frei.alex@gmx.de

Lumea is operated by a private individual, not a company. For any question about this policy or your data, contact the address above.


2. The Short Version

The rest of this policy provides the full detail.


3. Data That Stays on Your Device

The following is stored only in the App's private storage on your device. It is never uploaded to or stored on our servers, and we have no access to it:

Deleting this data: You can delete your photos and scan history in the App under Profile → Privacy & data. Uninstalling the App removes all of its on-device data.

Camera and photo library: The App asks for permission to use your camera and photo library so you can take or select photos. You control these permissions in iOS Settings.


4. Data That Leaves Your Device

4.1 AI skin, food, and product analysis (photos → Anthropic)

When you run an AI analysis, the App sends the analysis photo to Anthropic PBC (USA), our AI processor, routed through our own server proxy (a Supabase Edge Function, hosted in the EU/US). This happens only with your prior explicit consent, which you give once through a consent screen before your first scan and can withdraw at any time under Profile → Privacy & data.

What happens to the photo:

Legal basis: your consent (Art. 6(1)(a) GDPR) and, because skin analysis can reveal health-related information, your explicit consent (Art. 9(2)(a) GDPR).

4.2 Optional account

You can use Lumea fully without an account. If you choose to create one, you can sign up with:

We store only your email address. You can delete your account at any time in the App under Profile → Account; this triggers a server function that deletes your account data on our side.

Legal basis: performance of the user agreement (Art. 6(1)(b) GDPR).

4.3 Anonymous usage analytics

To understand which features are used and keep the App working well, the App records simple usage events in our own Supabase database — no third-party analytics or advertising SDK is involved. Each event contains only:

No photos, no emails, no tracking across apps or websites, no advertising, no sale of data. The App does not use Apple's App Tracking Transparency framework because it performs no tracking.

Legal basis: our legitimate interest in understanding and improving the App (Art. 6(1)(f) GDPR).

4.4 Purchases and subscriptions

Lumea is free to download; premium features require a subscription purchased through Apple In-App Purchase:

Prices are shown in your local App Store currency. Subscriptions auto-renew until cancelled at least 24 hours before the end of the current period; billing, cancellation, and refunds are handled entirely by Apple (Settings → Subscriptions on your device).

To manage subscription entitlements, our processor RevenueCat, Inc. (USA) processes purchase receipts and entitlement status, identified only by a random app user ID — no name or email is needed or shared. Apple processes your payment as an independent controller under its own privacy policy; we never receive your payment card details.

Legal basis: performance of the user agreement (Art. 6(1)(b) GDPR).

4.5 Weather and UV (city you type — no location permission)

For local weather, UV, and air-quality information, you type a city name — the App never requests GPS or device-location permission. The coordinates of the chosen city are sent to Open-Meteo (an open weather API) to retrieve the data. No personal identifiers are transmitted.

Legal basis: performance of the user agreement (Art. 6(1)(b) GDPR).

4.6 Food barcodes

When you scan a food barcode, the barcode number is queried against Open Food Facts (an open food database). No personal identifiers are transmitted.

Legal basis: performance of the user agreement (Art. 6(1)(b) GDPR).


5. What We Do NOT Do


6. Processors and Recipients

We share data only as described below and have data processing agreements (Art. 28 GDPR) in place with our processors.

RecipientCountryWhat they receivePurposeRoleSafeguard
Anthropic PBCUSAThe photo you submit for an AI scan (transient; no training use; deleted after at most ~30 days)AI skin/food/product analysisProcessorEU Standard Contractual Clauses (SCCs) under Anthropic's Data Processing Addendum; transfer also covered by your explicit consent (Art. 49(1)(a) GDPR)
Supabase, Inc.EU/US hostingAccount email (if you create an account); anonymous usage events; AI requests pass through in transit only and are never storedAuthentication, our own database, server proxyProcessorSCCs / EU–US Data Privacy Framework where applicable
RevenueCat, Inc.USARandom app user ID and purchase receipt/entitlement data (no name or email)Subscription entitlement managementProcessorSCCs / EU–US Data Privacy Framework where applicable
Apple Inc.GlobalPurchase and billing data; Sign in with Apple identity tokenApp Store billing; Apple ID authenticationIndependent controllerApple's own privacy policy and terms
Open-MeteoOpen APICoordinates of the city you typed (no personal identifiers)Weather/UV/air-quality dataIndependent data sourceNo personal data transmitted
Open Food FactsOpen databaseBarcode numbers (no personal identifiers)Food product lookupIndependent data sourceNo personal data transmitted

7. International Data Transfers

Some of our processors are located in the United States (Anthropic, RevenueCat; Supabase uses EU/US hosting). Where personal data is transferred to the US, the transfer is protected by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) agreed in the respective data processing agreement, and/or the EU–US Data Privacy Framework where the provider is certified. The AI-analysis transfer additionally rests on your explicit consent. You can request more information about these safeguards using the contact details in Section 1.


8. How Long We Keep Data


9. Deleting Your Data and Withdrawing Consent

Everything below works directly in the App — no email needed:

For anything you cannot do in-app, email frei.alex@gmx.de.


10. Your Rights (GDPR)

Subject to the conditions of the GDPR, you have the right to:

To exercise any right, contact frei.alex@gmx.de. We respond within the legal time limits (generally one month).

Right to complain (Art. 77 GDPR): You may lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA member state of your residence or workplace. Our competent supervisory authority is:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD) Holstenstraße 98, 24103 Kiel, Germany https://www.datenschutzzentrum.de


11. Note for Users in the United States

We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising. The App performs no tracking as defined by Apple's App Tracking Transparency framework. If your US state's privacy law grants you rights of access, deletion, or correction, you can exercise them through the in-app controls described in Section 9 or by emailing frei.alex@gmx.de — we honor such requests regardless of formal applicability thresholds.


12. Children

Lumea is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data, contact us (Section 1) and we will delete it.


13. Health Data and "Not Medical Advice"

Lumea provides non-medical, wellness-oriented skincare guidance only. It is not a medical device and does not provide medical advice, diagnoses, or treatment recommendations. Always consult a qualified healthcare professional — such as a dermatologist — for persistent or severe skin symptoms or any medical question.

Because facial photos and skin-related self-reports can reveal health-related information, they are treated as special-category data under Art. 9 GDPR. We process such data for AI analysis only with your explicit consent (Art. 9(2)(a) GDPR); everything else stays on your device (Section 3).


14. Security

We take appropriate technical and organizational measures to protect your data, including:

No method of transmission or storage is completely secure, but we work continuously to protect your data.


15. Changes to This Policy

We may update this policy when the App, our processors, or the law changes. We will update the "Last updated" date above and, for material changes, provide a more prominent notice in the App.


16. Contact

For any privacy question or to exercise your rights:

Elena Frei Professor Bachofer Strasse 2, 21509 Glinde, Germany Email: frei.alex@gmx.de