Privacy
Privacy Policy
This policy explains website and support processing separately from the private data handled by the Lumefide iOS app.
Last updated: August 14, 20261. Controller
The controller under the General Data Protection Regulation (GDPR) is:
Lumefide – an offering by Valentin SpöthValentin Spöth, sole proprietor
Turnhallestrasse 31
77654 Offenburg
Germany
Phone: +49 152 29262825
Email: privacy@lumefide.com
No data protection officer has been appointed because no statutory appointment obligation currently applies.
2. Website
Hosting and delivery
This static website is hosted through Netlify, Inc. To deliver and secure the site, technically necessary server logs may process the IP address, request time, requested resource, referrer where transmitted, browser or user-agent information, and error data. The purposes are reliable delivery, security, abuse prevention, and troubleshooting. The legal basis is Article 6(1)(f) GDPR; our legitimate interests are a secure and technically stable public information service.
Lumefide does not add analytics, tracking pixels, advertising, cookies, forms, JavaScript, local storage, or other browser storage. Netlify processes hosting and request data on our behalf under its data-processing terms to the extent it acts as a processor; it can process certain service data under its own Privacy Statement. Processing can involve the United States or other countries outside the EEA. Depending on the processing and legal situation, safeguards may include an adequacy decision such as the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses. See Netlify’s Privacy Statement and GDPR information.
We do not receive or maintain a separate visitor log or create user profiles from hosting data. Netlify determines technical retention periods within its service. We retain operator-side diagnostic information only for as long as it is needed for security, troubleshooting, or legal claims.
3. Support communication
If you contact us by email or telephone, we process your contact details, message, technical context you choose to provide, and our correspondence so we can respond. Depending on the request, the legal basis is Article 6(1)(b) GDPR (contract or pre-contractual communication), Article 6(1)(c) GDPR (legal obligation), or Article 6(1)(f) GDPR (efficient support, security, and defense of legal claims).
Support and privacy email is handled using Apple’s iCloud Mail service. Email metadata and content may therefore be processed by Apple under the applicable service and privacy terms, including possible international processing. See Apple’s Privacy Policy. Please do not send sensitive details about your faith, mood, journal, or temptations. Technical details such as iOS version, device model, app version, and a description of the error are usually sufficient.
Support requests are generally deleted no later than twelve months after final resolution, unless statutory retention duties or legal claims require longer storage.
4. Lumefide app
No Lumefide account or content backend
Lumefide does not require a Lumefide account and does not operate a backend for personal entries. The release design contains no advertising, behavioral tracking, profile-image function, or third-party analytics of faith, mood, journal, or habit content. The app does not request access to location, contacts, camera, or microphone.
Local technical counters
For a limited set of onboarding, paywall, purchase, activation, and subscription-lifecycle events, the release build stores one aggregate integer counter per event and, where applicable, a local one-time marker in iOS UserDefaults. It does not store an event timeline or metadata payload and does not include personal entries or their content. These counters and markers remain on the device, are not transmitted to Lumefide or a third-party analytics platform, and are removed by the in-app function for deleting all personal data.
Personal app data
Goals, goal progress, daily check-ins, mood, gratitude, reflections, journal entries, temptations and habits, streak restorations, focus history, faith-journey selection, progress, completed days and reward choices, and an optional display name are stored locally on the iPhone. App records use the local app database; settings and transient state use local app storage such as iOS UserDefaults. These personal app data are not sent to Lumefide or RevenueCat.
These personal app data are not visible to the operator when they remain on the device or in the user’s private iCloud database. Lumefide does not include complete Bible texts or licensed Bible translations in the current release.
Private iCloud and CloudKit synchronization
If iCloud is available for Lumefide and enabled in the user’s Apple Account settings, supported database records, including the optional display name and faith-journey records, automatically synchronize through Apple CloudKit in the user’s private iCloud database. If iCloud is unavailable or disabled, the data remains only on the device. Private CloudKit records are associated with the Apple Account and are not exposed through a Lumefide account or operator dashboard.
Apple processes iCloud data under its own service and privacy terms, and international processing may occur. Users control whether an app can use iCloud in iOS settings. Apple explains these controls in its iCloud support guidance. No system can offer an absolute security guarantee.
Apple purchases and RevenueCat
Lumefide uses Apple’s In-App Purchase system for subscriptions. Apple displays and processes the purchase, manages billing through the Apple Account, and does not provide Lumefide with payment-card details. Apple processes purchase and account data under its terms and Privacy Policy.
RevenueCat, Inc. is used as the technical subscription and entitlement service and generally processes end-user information for Lumefide as a processor. Because Lumefide does not supply a Lumefide account identifier, the SDK generates an anonymous app user identifier. RevenueCat can process this identifier, technically necessary IP and network information, approximate location derived from the IP address, device, operating-system and app metadata, product and offering information, communication or usage timestamps, transaction or receipt information, purchase history, subscription status, and Plus entitlement status to load offers, validate purchases, restore access, prevent misuse, provide app functionality, and analyze subscription operation. The legal bases are Article 6(1)(b) GDPR for providing purchased Plus access and Article 6(1)(f) GDPR for reliable entitlement management, fraud prevention, and service analysis. RevenueCat does not receive personal faith, mood, gratitude, reflection, journal, temptation, or habit entries.
RevenueCat is based in the United States and uses service infrastructure including Amazon Web Services in the United States. International processing can therefore occur, subject to applicable contractual and legal safeguards, including the applicable data-processing terms. Details are available in RevenueCat’s Privacy Policy. RevenueCat data is retained as required to provide and document purchase entitlements, comply with legal obligations, resolve disputes, and under the applicable service configuration. Contact privacy@lumefide.com for requests concerning Lumefide-controlled RevenueCat data; an anonymous app user identifier or purchase context may be needed to identify the relevant record.
Local notifications
Notifications are optional and require iOS permission. Morning, evening, weekly, streak, goal, trial, habit, and focus reminders are scheduled locally on the device. Notification settings and times stay local. Sensitive habit names are not required in notification text.
Widgets, App Group data, and Live Activities
Widgets receive only a compact App Group snapshot required to display progress, the next steps, theme, language, Plus entitlement state, whether today’s Lumi thought is unread, the aggregate mindful-day count, and milestone unlock state. Journal, mood, gratitude, reflection, prayer, and temptation texts are not copied to that shared snapshot. Custom goal names are hidden by default and shared only if the user enables the relevant setting. Focus Live Activities use the minimum local session state necessary for the Lock Screen and Dynamic Island; custom focus titles remain private.
5. Deletion and retention
Lumefide includes a two-step “delete all personal data” function. It removes app-managed records, local settings, notifications, focus state, widget snapshots, local thoughts, and local release state. Where private iCloud synchronization is enabled, corresponding app-managed deletions are synchronized through CloudKit. Apple-controlled backups and transaction history, and RevenueCat purchase and entitlement records, are separate and may follow their own retention rules.
Uninstalling the app removes local app data from that device but does not necessarily delete data already synchronized through iCloud or transaction records held by Apple or RevenueCat. Users can manage iCloud and Apple Account data in Apple settings and services. Requests concerning Lumefide-controlled RevenueCat records can be sent to privacy@lumefide.com.
6. Your rights
Subject to the statutory conditions, you may have rights to access, rectification, erasure, restriction, data portability, and objection, and the right to withdraw consent for the future. The official GDPR text is available on EUR-Lex.
Contact privacy@lumefide.com for data controlled by Lumefide, including RevenueCat records processed for Lumefide. Because the operator cannot access entries stored only on your device or in your private iCloud database, requests about those entries normally need to be handled through the app, device, or Apple Account. Requests concerning Apple-controlled data should be directed to Apple.
You may lodge a complaint with a data protection supervisory authority. The authority responsible for our establishment is The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany.
7. Minors
Lumefide is intended for people aged 13 and older. It does not ask for a date of birth on this website. Minors should involve a parent or guardian where required, particularly for purchases. Apple’s account, family, and purchase-approval rules can vary by country and account.
8. Changes to this policy
We update this policy when the app, website, service providers, or legal requirements change. The date at the top identifies the current version. Material changes are communicated in an appropriate way.