Privacy Policy
Most of what you do in Lumavra never leaves your phone. This page is about the part that does.
1. Overview
Lumavra is an iPhone app for finding and deciding on names. It processes as little as it can: the candidate lists you build, your favourites and your ratings are stored by the app on your device and are not uploaded.
This policy describes what is processed, where, and why.
2. Data controller and contact
The provider of Lumavra can be contacted at the address in the Imprint.
3. Your account
Lumavra requires an account. You create one with Sign in with Apple.
We never see your Apple password. From the sign-in we receive a stable identifier for your account and the email address Apple releases to us - which, if you chose to hide it, is one of Apple's forwarding addresses rather than your own.
We store that identifier, that address, and the name you give yourself in the app. There is no password to store, and no way to set one.
4. What stays on your device
Your judgement is what never leaves the device:
- Which names you kept, discarded or shortlisted
- Your favourites and your ratings
- Your own tags and the terms you choose to block
- The history of suggestion lists you generated
Names themselves can go to an AI provider when you ask for one of the AI features - see section 6. What is never sent is the fact that you liked one.
Deleting the app removes them. They are not backed up to a server, so they cannot be restored by us either.
5. What is processed on our servers
- Your projects - their name, description and kind
- Your suggestion requests - the description you provide is sent to an AI provider to generate candidates
- Invitations and shared lists - when you invite someone, the email address you enter and the names you chose to share with them
- Technical records needed to run the service: how often an account calls the API, and whether a request was refused
6. AI generated suggestions
Lumavra uses AI across the naming flow: generating ideas, enriching a name with its meaning and origin, comparing candidates. For that, the project context a given request needs is sent to an AI provider - only when you use a feature that says so, and never your sign-in credentials.
The providers are OpenAI and Google (Gemini). The app never contacts them directly; requests go through the Lumavra backend, which sends no account identifier, no name and no address along with them.
What you type travels with the request. A description like "a name for our daughter, due in March" says something about you even though nothing attached to it does. Write what the name has to suit, not who is waiting for it.
We use the providers on paid plans, where the requests are not used to train models. What applies in detail is something they state themselves:
A record of each generation - the request and its outcome, not your judgement of it - is kept for seven days and then deleted.
7. Collaboration
When you invite someone to judge a list, they receive the names you shared and an invitation at the address you enter. They do not receive your other projects, your ratings or anything stored on your device.
You enter their address; please only enter one you are entitled to use.
8. Content checks
Generated and adopted names are checked against a list of terms that must not appear. The check runs over the name, not over you, and its results are not kept against your account.
9. Records we keep to run the service
Decisions about access - a refused request, a rate limit reached, an account restricted - are recorded. Records of access decisions are kept for 365 days; routine operational records, such as a rate limit being hit, for 90 days.
These records exist so that a restriction can be explained and reviewed. They do not contain the content of your projects.
10. Restrictions on an account
An account can be restricted, temporarily or permanently, if it is used in a way the terms forbid. A restricted account keeps everything already on the device readable; what stops is the ability to generate and to share.
11. Google user data
Where you sign in with Google, Lumavra receives data from Google APIs. This section says what, and is the disclosure Google's API Services User Data Policy requires.
What is accessed. Only what signing in with Google releases: your email address and the basic profile. Lumavra asks for no Google scope beyond sign-in - no Drive, no contacts, no calendar.
How it is used. Only to provide the features you asked for. Nothing else.
Who it is shared with. Nobody. It is not passed to third parties, not sold, and not combined with data from other sources.
How it is protected. It travels over TLS and is held only where this policy says it is held.
How long it is kept. For as long as the connection exists. Disconnecting Google, or deleting your account, removes it.
Limited Use
Lumavra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is not used for:
- targeted advertising, or building advertising profiles
- selling or transferring to data brokers, information resellers, or any third party
- determining creditworthiness, or lending purposes
- training or improving generalized AI or machine learning models
12. What we do not do
- No advertising, and no advertising profiles
- No sale of personal data
- No tracking across other apps or websites
- No reading of the shortlist on your device
13. Your rights
You may request access to the data held about your account, its correction, or its deletion. Deleting your account removes your projects, your invitations and your account record. Data stored by the app on your device is removed by deleting the app.
Requests go to the address in the Imprint.
14. Changes
This policy changes when the app does. The date at the top is the version that applies.