lumiara

Privacy Policy

Last updated: March 2026

Lumiara is a personalised bedtime story platform for families, operated by Lumiara (“we”, “us”, “our”). We take privacy seriously — especially when it comes to children.

What We Collect

We collect the minimum information needed to make stories personal and save your progress:

  • Your email address (when you create an account)
  • Your child's first name or nickname and age bracket (e.g. "3–4 years") — never their full name or date of birth
  • Story preferences you choose (themes, moods, occasions)
  • Basic usage data (pages visited, stories generated) via PostHog analytics

We never collect your child's photo, location, school, or any identifying information beyond a first name.

How We Use Your Data

  • To generate and save personalised stories
  • To remember your child's preferences for future stories
  • To send you account-related emails (confirmation, password reset)
  • To improve Lumiara based on how it's used

We never sell your data. We never use your data for advertising. Lumiara products are ad-free.

Your Children's Data

We treat children's data with the highest care:

  • We only collect a first name or nickname — never a full name
  • Age is stored as a bracket (e.g. "2–3 years"), never a date of birth
  • Stories are stored against your account, not your child's identity
  • You can delete all stories and child profiles at any time from your account settings

Story Content and Safety

Every story generated by Lumiara passes through an automated safety pipeline before it reaches you:

  • We filter for age-appropriate language and themes
  • We block any attempt to include personal data beyond first names
  • Inappropriate content requests are refused and logged

Data Storage and Retention

Your data is stored securely via Supabase (EU region). Stories saved to your account are retained until you delete them. Guest stories (no account) are automatically deleted after 30 days.

Your Rights

You have the right to:

  • Access all data we hold about you
  • Delete your account and all associated data
  • Export your stories
  • Withdraw consent at any time

To exercise any of these rights, email us at hello@lumiara.live and we will respond within 7 days.

Sub-Processors

We use the following trusted services:

  • Supabase (database and authentication)
  • Anthropic (AI story generation)
  • Vercel (hosting)
  • PostHog (analytics, anonymised)
  • Stripe (payments, when applicable)

Lawful Basis

We process your data under the lawful basis of contractual necessity (to provide the service you signed up for) and legitimate interests (to improve the product). Payment data is processed under contractual necessity.

Jurisdiction

Lumiara is operated from the United Kingdom. We comply with UK GDPR and, where applicable, the EU GDPR.

Contact

For any privacy questions: hello@lumiara.live
We aim to respond within 2 business days.

Changes to This Policy

We will notify you by email of any material changes to this policy before they take effect.