← Back to LUMINA
Legal Document

Privacy Policy

Last updated: 1 April 2026  ·  Effective: 1 April 2026  ·  Version 1.0

Controller: USHVIBES OÜ (Estonia)
Operated from: Vienna, Austria
Applies to: All LUMINA users worldwide
GDPR: Fully compliant

LUMINA is built on trust. We collect only what we need to make your experience genuinely personal. We never sell your data. We never show you ads. We never share your conversations with third parties except as required to deliver the service. Your data is yours — you can export or delete it at any time, instantly.

Contents
  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Legal basis for processing (GDPR)
  5. Who we share data with
  6. How long we keep your data
  7. Your rights
  8. How we protect your data
  9. Children and minors
  10. International data transfers
  11. AI and automated processing
  12. Mental health data — special category
  13. Changes to this policy
  14. Contact and DPA

1. Who We Are

LUMINA is operated by USHVIBES OÜ, a private limited company registered in Estonia under the e-Residency programme. Our registered address is in Estonia; operations are managed from Vienna, Austria by Emmanuel Iorkase, founder.

LUMINA is a product of USHVIBES. For the purposes of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (Datenschutzgesetz, DSG), USHVIBES OÜ is the data controller. We are responsible for deciding how and why your personal data is processed.

Contact us at: privacy@ushvibes.com

2. What Data We Collect

Data you provide directly

Data collected automatically

Data we do NOT collect

3. How We Use Your Data

PurposeData usedWhy necessary
Deliver the LUMINA serviceAll conversation data, profile, goals, mood logsCore service — without this, LUMINA cannot personalise your experience
Generate Morning IlluminationLife scores, recent conversations, goals, mood dataTo create a personalised daily briefing for you
LUMINA Companion proactive messagesRelationship data, goals, mood patterns, conversation historyTo reach out to you with relevant, timely nudges
Life Scores calculationConversation content, mood logs, activity dataTo compute your 8-dimension life scores
Crisis detection and safetyConversation content (scanned in real time)To protect your safety — this cannot be disabled
Account managementEmail, name, plan, payment statusTo manage your subscription and account
PaymentsPayment data (handled by Stripe — we never see your card number)To process subscriptions
Security and fraud preventionIP address, usage patterns, request logsTo protect you and other users from attacks
Product improvementAnonymised usage analyticsTo understand how to make LUMINA better
Legal complianceAs required by applicable lawTo comply with our legal obligations

Under Article 6 of the GDPR, we rely on the following legal bases:

For special category data (mental health content under Art. 9 GDPR), we rely on your explicit consent, which you provide when you first use LUMINA's wellbeing features.

5. Who We Share Data With

We never sell your data. We never share conversation content with advertisers. We share data only with the technical service providers listed below, and only to the extent necessary to deliver the LUMINA service.

ProviderPurposeLocationSafeguards
Anthropic (Claude AI)AI conversation processingUSAData Processing Agreement, Standard Contractual Clauses
ElevenLabsVoice audio generationUSAData Processing Agreement
Supabase (PostgreSQL)Database hostingEU (Paris, France)GDPR compliant, EU-based hosting
Auth0 (Okta)User authenticationUSA/EUData Processing Agreement, SCCs, EU data residency option
StripePayment processingUSA/EUPCI DSS Level 1, Data Processing Agreement
AWS S3Audio file storageEU (Paris, France)EU-based region, encrypted at rest and in transit
RailwayBackend hostingEUGDPR compliant infrastructure
CloudflareDDoS protection, CDNGlobal (edge)Data Processing Agreement, GDPR compliant
SentryError monitoring (technical only)USAData Processing Agreement, SCCs
MixpanelUsage analytics (anonymised)USAData Processing Agreement, SCCs, anonymisation
Firebase (Google)Push notificationsUSA/EUData Processing Agreement, SCCs

We may also disclose data if required by law, court order, or to protect the safety of our users or others.

6. How Long We Keep Your Data

Data typeRetention periodReason
Account informationUntil account deletion + 30 daysTo allow account recovery
Conversation contentUntil account deletionCore service — LUMINA's memory depends on it
Life scores and mood logsUntil account deletionTo track your progress over time
Payment records7 years after last transactionLegal obligation under Austrian and Estonian tax law
Security logs (IP, request logs)90 daysSecurity investigation purposes
Crisis logs2 yearsUser safety and legal liability
GDPR request logs3 yearsTo demonstrate GDPR compliance
Anonymised analytics3 yearsProduct improvement

7. Your Rights Under GDPR

If you are in the EU or UK, you have the following rights. We will respond within 30 days (usually much faster):

To exercise any right, go to Settings → Privacy in the LUMINA app, or email privacy@ushvibes.com. If you believe we have violated your rights, you may lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde) at www.dsb.gv.at.

8. How We Protect Your Data

9. Children and Minors

LUMINA is intended for users aged 18 and over. We verify age during onboarding. If we discover that a user is under 18, we will immediately restrict their account and, where required by law, seek parental consent or delete the account.

If you believe a child has created a LUMINA account without appropriate consent, please contact us immediately at privacy@ushvibes.com.

10. International Data Transfers

Some of our service providers are based outside the EU/EEA (notably in the United States). When we transfer data outside the EEA, we ensure adequate protection through:

11. AI and Automated Processing

LUMINA uses Claude (Anthropic) to generate personalised responses, Morning Illumination briefings, Echo poetry, Life Chapters, and Companion messages. This constitutes automated processing of personal data.

Your conversation content is sent to Anthropic's API to generate responses. Anthropic's privacy policy governs their handling of this data. LUMINA has a Data Processing Agreement with Anthropic.

LUMINA's AI does not make decisions that produce legal or similarly significant effects on you without human oversight.

12. Mental Health Data — Special Category

Some data you share with LUMINA — about your mental health, emotional state, or wellbeing — may constitute special category data under GDPR Article 9. This includes mood logs, responses to check-in questions, and conversations about mental health.

We process this data only with your explicit consent, which you provide when you first use LUMINA's wellbeing features. You may withdraw this consent at any time by contacting privacy@ushvibes.com.

Important: LUMINA is not a medical device, not a healthcare provider, and not a substitute for professional mental health support. If you are in crisis, please contact a crisis helpline. In Austria: call 142 (Telefonseelsorge, free, 24/7).

13. Changes to This Policy

We will notify you of material changes to this Privacy Policy via email and in-app notification at least 30 days before the changes take effect. Your continued use of LUMINA after the effective date constitutes acceptance of the updated policy.

14. Contact and Data Protection Officer

Privacy questions or GDPR requests

Email: privacy@ushvibes.com
Response time: within 72 hours (GDPR requests within 30 days)

USHVIBES OÜ · Registered in Estonia
Operated by Emmanuel Iorkase · Vienna, Austria

Austrian Data Protection Authority (Datenschutzbehörde):
www.dsb.gv.at · +43 1 531 15-202525