Privacy Policy
The short version. Your spiritual life stays yours. Your prayer journal, prayer requests, answered-prayer testimonies, habits, favorites, reading-plan progress, and your conversation history with Lumen Guide are stored only on your device — we run no account system and no cloud sync for them. What does leave your device is limited: anonymous usage analytics, anonymous ad-attribution signals for the ads we run to reach new readers, purchase receipts so your subscription works, and — when you chat with Lumen Guide — the messages you send, which are processed to generate a reply and are not stored on our servers. We never sell your data, and Lumen shows no third-party ads.
1. Who we are
Lumen is developed and operated by Emir Güngör (“we”, “us”, “our”). This policy explains what data the Lumen iOS app handles, why, and what choices you have. It applies only to the Lumen app; it does not cover Apple’s own handling of your App Store account or payments.
2. What stays on your device
All of your personal spiritual content is stored locally in a database on your iPhone and is never uploaded to our servers:
- Prayer journal entries, prayer requests, and answered-prayer testimonies
- Habit tracking and streaks
- Favorited verses, devotionals, and Names & Promises
- Reading-plan selections and progress (including Bible in a Year)
- Your Lumen Guide chat history as shown in the app
- App settings, notification preferences, and widget configuration
There is no account, no login, and no cloud backup by us. If you delete the app, this data is deleted with it. (If you use Apple’s device backups, a copy may exist in your own iCloud/computer backup under Apple’s terms — that is between you and Apple.)
Reminders and daily verse notifications are scheduled locally on your device by iOS. We do not operate a push-notification server.
3. What we collect, and why
3.1 Anonymous usage analytics (Google Firebase)
We use Google Analytics for Firebase to understand how the app is used in aggregate — for example, that a reading plan was opened, onboarding was completed, or a subscription screen was viewed. This includes standard analytics data such as event names, coarse device and app-version information, and a random app-instance identifier. It is not tied to your name or email (we never collect those), and we do not log the content of your journal, prayers, or chats to analytics.
3.2 Anonymous sign-in (Firebase Authentication)
To use Lumen Guide, the app silently creates a random anonymous user ID via Firebase Authentication. No email, phone number, name, or password is involved — it is a random identifier for your installation. We use it to verify requests to our AI backend and to enforce fair-use limits.
3.3 Lumen Guide (AI companion)
When you send a message to Lumen Guide, the recent messages of that conversation are transmitted over an encrypted connection to our backend (a Google Cloud Function we operate), which forwards them to Anthropic’s Claude API to generate the reply. Specifically:
- We do not store your chat messages on our servers. The conversation you see in the app lives only on your device.
- Our servers keep only anonymous usage counters (how many messages your anonymous ID sent today and this month), so we can enforce daily and monthly limits. These counters contain no message content.
- Per Anthropic’s commercial terms, data sent to the Claude API is not used to train Anthropic’s models. Anthropic may retain API data for a limited period for trust-and-safety purposes as described in its privacy policy.
- Please chat freely, but know that anything you type in Lumen Guide is processed by these services to produce a response. If you prefer that something never leave your device, the prayer journal is fully local.
3.4 Ad attribution (Meta / Facebook SDK)
We run ads (for example on Facebook and Instagram) to help new readers find Lumen, and we use the Meta SDK to measure whether those ads work. Lumen itself shows no ads and includes no ad-display networks.
- The SDK reports standard app events to Meta — such as app install, app open, and purchase (amount, currency, and product identifier only — never your journal, prayers, or chats).
- If you allow tracking in the iOS App Tracking Transparency prompt, the device advertising identifier (IDFA) is included with these events so Meta can attribute installs and purchases to specific ad campaigns.
- If you decline tracking, no IDFA is read. Attribution then relies on Apple’s privacy-preserving SKAdNetwork, which reports campaign results in aggregate without identifying you or your device.
3.5 Purchases (RevenueCat and Apple)
Your payment is processed entirely by Apple — we never see your card number, billing address, or Apple ID credentials. To activate and maintain your subscription across launches, we use RevenueCat, which receives the App Store purchase receipt and a random anonymous app user ID, and tells the app whether your subscription is active. RevenueCat’s handling of this data is described in its privacy policy.
3.6 Remote configuration
The app fetches feature flags from Firebase Remote Config (for example, to adjust screens between app updates). This works with the same anonymous instance identifiers as analytics and involves no additional personal data.
4. What we do not collect
- No location. Lumen does not use location services at all.
- No contacts, photos, microphone, or health data.
- No name, email address, or phone number. There is no account to create. (If you email us for support, we see the email you send us — that’s all.)
- No third-party ads inside the app, and no data broker relationships. We do not sell your personal data.
5. App Tracking Transparency (ATT)
Under Apple’s rules, “tracking” means linking data from this app with third-party data for advertising measurement — in our case, sharing the device advertising identifier and app events with Meta to measure our ad campaigns. iOS will ask for your permission before this happens. Your choice:
- Allow — the IDFA is shared with Meta for campaign attribution.
- Ask App Not to Track — the IDFA is never read; only aggregate, non-identifying SKAdNetwork reporting remains. Every feature of Lumen works exactly the same either way.
You can change this anytime in iOS Settings → Privacy & Security → Tracking.
6. Third-party services
| Service | What it receives | Their policy |
|---|---|---|
| Google Firebase (Analytics, Authentication, Remote Config, Cloud Functions, Firestore) | Anonymous analytics events and instance IDs; anonymous auth ID; AI usage counters | firebase.google.com/support/privacy |
| Meta Platforms (Facebook SDK) | App events (install, open, purchase amount/currency/product ID); IDFA only with ATT consent | facebook.com/privacy/policy |
| RevenueCat | App Store purchase receipts; anonymous app user ID | revenuecat.com/privacy |
| Anthropic (Claude API) | Your Lumen Guide messages, relayed by our backend to generate replies; not used for model training | anthropic.com/legal/privacy |
7. Data retention
- On-device content — kept until you delete it in the app or delete the app.
- Lumen Guide messages — processed to generate a reply and not stored on our servers; Anthropic retains API data only for a limited period under its commercial terms.
- AI usage counters — rolling daily/monthly counts tied to your anonymous ID; superseded as each period rolls over.
- Analytics — retained under Firebase’s retention controls (user-scoped analytics identifiers for at most 14 months).
- Purchase records — retained by RevenueCat and Apple for as long as needed to service your subscription and meet legal/accounting obligations.
8. Children
Lumen is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will address it promptly.
9. Security
All network traffic between the app and our backend uses encrypted connections (HTTPS/TLS). Our AI backend verifies each request, applies strict usage limits, and keeps API credentials in a managed secret store. No method of transmission or storage is 100% secure, but we design for the minimum data leaving your device in the first place.
10. Your choices
- Tracking — decline the ATT prompt, or turn it off later in iOS Settings → Privacy & Security → Tracking.
- Notifications — manage or disable in iOS Settings → Notifications, or inside the app.
- Your local data — delete entries inside the app, or delete the app to remove all locally stored data.
- Subscription — manage or cancel anytime in iOS Settings → your name → Subscriptions.
- Questions or requests — email us (below) about any data question, including asking us to delete the anonymous usage counters associated with your installation.
Depending on where you live (for example the EEA, UK, or California), you may have additional legal rights such as access, correction, deletion, and objection. Because we hold almost no server-side data about you — and none of it is tied to your identity — most of these rights are satisfied by the on-device controls above, but you are always welcome to contact us and we will help.
11. Changes to this policy
If we change how Lumen handles data, we will update this page and its effective date. Material changes will be highlighted in the app or in release notes.
12. Contact
Questions, concerns, or requests:
lumendailybible@gmail.com