Lumen

Lumen — Privacy Policy

The short version

Lumen is a private journal. Your entries, photos, voice notes, letters, and your conversations with Lumi are end-to-end encrypted on your device before they ever leave it. We cannot read them. Nobody at Lumen can read them. If you lose your key and your recovery phrase, even we cannot get your journal back — that is the trade-off that makes the privacy real.

We run no servers of our own. Lumen has no analytics, no advertising, no tracking, and no third-party SDKs of any kind. Sync uses your own iCloud account through Apple's CloudKit.

Who we are

Lumen is developed by Space Impactor. Contact: lumensupport@spaceimpactor.com

What Lumen stores, and where

1. End-to-end encrypted (we cannot read this)

The following are encrypted on your device with keys that never leave it, and are stored either on your device or in your private iCloud database:

Encryption uses AES-256-GCM with keys held in your device's Secure Enclave–backed Keychain, marked device-only and non-syncing. Apple stores the resulting ciphertext but has no key to it.

2. Visible in the public Circle directory (only if you use Circle)

Circle is Lumen's optional friends feature. It is off until you claim a username. If you do, these items are written to a shared public CloudKit directory so that other people can find and securely reach you:

That is the complete list. Your display name, status, journal, letters, and friend list are not in the public directory — they are encrypted. Friend requests are sealed so that only the intended recipient can open them.

Because this directory lives in Apple's CloudKit public database, the developer can technically view these specific fields in Apple's CloudKit console, and so can other signed-in Lumen users (that is what makes discovery work). Assume your username is public. Everything else is not.

3. Never leaves your device

4. What we do not collect

No analytics. No crash-reporting SDK. No advertising identifiers. No location tracking (location is attached only if you explicitly choose "Add Location", and it is encrypted with your entry). No behavioural profiling. No data sales. No data sharing with third parties. Lumen contains no third-party code.

Apple's role

Sync, push notifications, and the Circle directory run on Apple iCloud/CloudKit under your Apple Account. Apple processes this data as described in Apple's own privacy policy. Apple can see service metadata — that records exist, their size, and when they changed — but not the contents of your encrypted records. Push notifications are deliberately written to be content-free: a lock-screen banner never contains journal text or another person's username.

Your controls

Data retention

We hold no data on our own infrastructure, so there is nothing for us to retain. Encrypted records persist in your iCloud account until you delete them or erase your account. Retired usernames stay reserved so that nobody else can claim your former handle and impersonate you; a retired reservation carries no personal data beyond the handle itself.

If you email us a report of abuse, we retain that email and whatever you chose to include in it for as long as needed to act on it.

Children

Lumen is not directed at children under 13, and we do not knowingly collect information from them. See the App Store age rating for the current rating.

Security, honestly stated

Strong encryption is not the same as invulnerability. Lumen cannot protect you against a compromised or jailbroken device, someone who knows your passcode, or your own choice to export your journal as readable text. Lumen shows an advisory warning and pauses sensitive operations if it detects signs that the device has been modified.

Changes

We will update this page when the data handling changes, and change the "last updated" date. Material changes will be surfaced in the app.

Contact

Questions, privacy requests, or abuse reports: lumensupport@spaceimpactor.com