Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your data.

1. Introduction and Responsible Body (Data Controller)

Welcome to LuminaOS by Bright Minds. We take the protection of your personal data very seriously. This Privacy Policy informs you about the nature, scope, and purpose of the collection and use of personal data on our website and in connection with our services, including our online programs and the LuminaOS application.

The data controller responsible for data processing is:

Bright Minds
Tilman Resch
Knoebelstr. 30
80538 Munich
Germany

Email: legal@luminaos.app
Website: https://luminaos.app

We treat your personal data confidentially and in accordance with the statutory data protection regulations, in particular the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the Telecommunications Telemedia Data Protection Act (TTDSG), as well as this privacy policy.

2. Data Collection and Processing

a) When Visiting Our Website (Server Log Files)

When you access our website, our hosting provider automatically collects and stores information in server log files, which your browser transmits to us. This includes:

  • Browser type and version
  • Operating system used
  • Referrer URL (the previously visited page)
  • Hostname of the accessing computer
  • Time of the server request
  • IP address (anonymized or shortened)

This data is not merged with other data sources. The basis for this data processing is our legitimate interest (Art. 6(1)(f) GDPR) in ensuring the security, stability, and error-free operation of our website.

b) Cookies

Our website uses cookies. Cookies are small text files that are stored on your device.

  • Essential Cookies: We use technically necessary cookies to make our website user-friendly and functional (e.g., for login sessions). The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) and, where applicable, § 25(2) TTDSG.
  • Non-Essential Cookies: Other cookies (e.g., for analytics, marketing) are only used with your explicit consent, which we obtain via a cookie consent banner. The legal basis for this is your consent (Art. 6(1)(a) GDPR and § 25(1) TTDSG). You can withdraw your consent at any time through the cookie settings on our website.

c) Contacting Us (Email or Contact Form)

If you contact us via email or a contact form, the information you provide (e.g., name, email address, your message) will be stored by us to process your request and for any follow-up questions. We process this data based on Art. 6(1)(b) GDPR if your request is related to the fulfillment of a contract or for pre-contractual measures. In all other cases, the processing is based on our legitimate interest (Art. 6(1)(f) GDPR) in effectively handling the inquiries addressed to us.

d) Account Registration and Use of Services

To use our online programs or the LuminaOS app, you must register an account. We collect data such as your name, email address, and a password. This data is necessary to provide and manage your account and deliver the services you have purchased. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

e) Data Processing within the LuminaOS Application

The LuminaOS web and mobile applications are designed for personal growth and involve the processing of highly personal data you provide. This includes:

  • Profile Information: Your name and email address.
  • User-Generated Content: Goals, journal entries, daily notes, habit tracking data, reflections, OBS categories, Prime Time scheduling data, and other text, images, audio, or files you input into the app.
  • People, Team, and Community Data: People/contact records, relationship notes, accountability-group participation, team or community content, and other collaboration data you choose to create or share.
  • AI Coach and AI-Assisted Features: The prompts you enter, the responses generated by AI Coach, and text, audio, images, files, or context you choose to submit for AI-assisted journaling, reflection, coaching, transcription, or extraction features.
  • Google Integrations: Data synchronized with Google services that you choose to connect, such as Google Tasks, Google Calendar, Google Contacts / Google People, and Google Docs backup.
  • Optional Wearable Integrations: If you explicitly connect a supported wearable provider such as Oura, we process the health and wellness records you authorize the provider to share. Depending on the permissions you grant, this may include sleep, readiness, activity, recovery and stress indicators, oxygen saturation, temperature deviation, heart-rate variability, resting heart rate, respiratory rate, and workout summaries. LuminaOS does not request detailed heart-rate time-series data for the initial Oura integration.
  • Export and Backup Data: Data included when you use export, backup, or connected-document features made available in the Services.

This data is processed solely to provide you with the functionality of the app. The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR). We treat this data with the highest level of confidentiality.

f) Google API Services User Data

Google sign-in and each Google productivity integration are optional. LuminaOS asks for access only when you start the corresponding connection and uses the resulting Google user data as follows:

  • Google account identity: Your email address identifies and displays the Google account connected to a LuminaOS integration.
  • Google Calendar: Read-only calendar-list metadata populates and validates the writable-calendar selector. Event access reads, creates, updates, and deletes Prime Time events in the calendar you select. App-created-calendar access lets LuminaOS create and manage its dedicated fallback calendar.
  • Google Tasks: Task lists and tasks are read and written to provide user-initiated and background synchronization of titles, notes, due dates, completion state, priority markers, categories, and remote links.
  • Google Contacts: Contact data is read only for the import screen. LuminaOS stores only the contacts you explicitly select for import and does not write changes back to Google Contacts.
  • Google Drive and Google Docs backup: The limited drive.file permission lets LuminaOS create and update only its app-managed backup folders and documents. LuminaOS does not request general access to all files in your Google Drive.

LuminaOS stores OAuth credentials and the minimum identifiers, mappings, timestamps, and user-selected or synchronized records needed to operate these features. Production data is transmitted over encrypted connections and stored in access-controlled systems with encryption at rest. Google user data is used only to provide or improve the user-facing integration you selected. It is not sold, used for advertising, or used to train generalized or non-personalized AI or machine-learning models.

We do not transfer or disclose Google user data except to infrastructure processors needed to provide the selected feature, for security purposes, when required by law, or with your explicit consent. Human access is prohibited except with your affirmative permission for specific data, when necessary for security, when required by law, or for appropriately aggregated internal operations.

Disconnecting a Google integration removes its stored authorization credentials. Records already imported into LuminaOS and files, tasks, or events already created in Google may remain until you delete them in the relevant service or use the applicable LuminaOS deletion controls. Google user data otherwise follows the account, retention, export, and deletion rules described in this policy.

LuminaOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

g) AI-Powered Features

Our AI Coach currently uses OpenAI-powered services to provide responses and related AI-assisted functionality. When you use these features, the data you submit, including prompts and any supported text, image, file, audio, or voice content, may be sent to those AI service providers for processing.

  • We have data processing agreements (DPAs) in place with our AI service providers.
  • According to these agreements, your data is not used to train their public models.
  • AI Coach conversations, tool activity, and related context may be stored in LuminaOS systems so that the service can provide continuity, auditability, and user-controlled memory.
  • Where enabled, AI Coach may use OpenAI response-state continuation and optional rich context profiles to improve coaching continuity. The LuminaOS database remains the primary record for user-accessible export and deletion workflows.
  • AI Coach Voice Mode may process live microphone audio, final user and assistant transcripts, tool activity, call identifiers, quota metadata, and diagnostic metadata needed to operate the realtime voice session. Raw live voice audio is not intended to be stored as a canonical chat record.
  • Composer dictation and reflection features may temporarily process audio recordings, transcripts, OBS category context, timelines, and draft reflection content to produce text, structured reflection updates, or other app content requested by you.
  • We urge you not to enter any sensitive personal data (e.g., health information, financial details, government IDs) that you would not want a third party to process.

The legal basis for this processing is the performance of the contract (Art. 6(1)(b) GDPR), as it is an integral part of the service.

Where we offer user controls for AI memory, rich context profiles, or related AI settings, you can adjust those controls in the app settings. Some operational records may remain where required for security, billing, abuse prevention, legal compliance, or deletion-job auditability.

h) Optional ChatGPT and Codex MCP Connection

You can optionally connect your LuminaOS account to ChatGPT or Codex through our MCP integration. Before the connection is approved, the LuminaOS authorization screen identifies the requesting client, lists its requested permissions, and prominently explains the data categories that the connection may process.

  • Data categories: Depending on the tool you request, the returned result may contain goals, habits, actions, timelines, daily or weekly reflections, and profile or personalization fields you chose to save, including emotional, spiritual, wellbeing, or health-related context.
  • Purpose and minimization: From LuminaOS to OpenAI, only the result needed for the requested tool call is shared so ChatGPT or Codex can show information or carry out the action you requested. The MCP connection does not provide OpenAI with a general copy of your LuminaOS account, database, or full conversation history.
  • Recipients: OpenAI processes the requested result to operate ChatGPT or Codex. Bright Minds and our hosting and security processors process the connection data needed to authenticate the request, execute the tool, secure the service, and return the result.
  • Oura exclusion: Imported Oura wearable data remains account-scoped in LuminaOS and is not returned through the ChatGPT or Codex MCP connection.
  • Retention and controls: The source records in LuminaOS continue to follow the retention rules in section 5. OpenAI may retain tool results within its service under your ChatGPT or Codex plan, workspace settings, data controls, and OpenAI policies; Bright Minds does not control those copies. You can disconnect or remove the LuminaOS app in ChatGPT or Codex to revoke future tool access, use LuminaOS settings to edit or delete source records or request account deletion, and use OpenAI's chat and data controls for results already shared. Revocation does not undo actions already completed or automatically erase results already included in the OpenAI service.

This optional processing is based on your explicit authorization of the connection and the performance of the service you request. Where a profile field contains data that is treated as sensitive or special-category data under applicable law, the authorization screen provides the disclosure before you choose whether to allow the connection.

i) Launch Campaign, Promotions, and Verification Emails

If you submit a LuminaOS launch campaign or promotional request, we process the data required to review and administer that request. This may include your email address, optional phone number, WhatsApp/mobile campaign group preference, confirmation statements, selected enrollment mode, source URL, referrer, UTM campaign parameters, IP address, user agent, verification status, grant status, and related admin review notes.

For automatic enrollment, we send a verification email and store only a hashed verification token with an expiry timestamp. Premium access is not activated through the public form alone; it is activated only after email verification or manual admin review, depending on the option you choose.

The legal basis is pre-contractual or contractual processing (Art. 6(1)(b) GDPR) and our legitimate interest (Art. 6(1)(f) GDPR) in fraud prevention, campaign administration, and abuse monitoring.

j) Newsletter

If you subscribe to our newsletter, we require your email address. We use a "double opt-in" procedure to verify that you are the owner of the email address and consent to receiving the newsletter. You can revoke your consent and unsubscribe from the newsletter at any time, for example, via the "unsubscribe" link in the newsletter. The data processing is based on your consent (Art. 6(1)(a) GDPR).

3. Data Recipients and Third-Party Transfers

We may share your data with trusted third parties to provide our services, including:

  • Hosting and Infrastructure Providers: To host and operate our Services, including Vercel and AWS services such as Aurora PostgreSQL, S3, CloudFront, Cognito, Lambda, EventBridge, SQS, and SES.
  • Payment and Subscription Providers: (e.g., Stripe and mobile subscription providers such as app-store billing and RevenueCat-backed entitlement handling) to process payments, subscriptions, renewals, and restores. These providers may process your billing data independently.
  • AI Service Providers: As described in section 2(g).
  • OpenAI (ChatGPT and Codex MCP Connection): If you explicitly connect LuminaOS, OpenAI receives only the result needed for the requested tool call, as described in section 2(h). Imported Oura wearable data is excluded from this connection.
  • Google Services: For Google Tasks, Google Calendar, Google Contacts / Google People, Google Docs backup, and authentication (if you choose to connect them).
  • Wearable and Health Data Providers: Oura and any other supported provider you explicitly connect, for authorization and retrieval of the health and wellness categories you approve. Imported wearable data remains account-scoped and is not shared with AI Coach, ChatGPT, community profiles, teams, or other users by the initial Oura integration.
  • Authentication Providers: For secure sign-in and account linking, including AWS Cognito and supported identity providers such as Google and Apple where you choose to use them.
  • Email Delivery Providers: For transactional emails such as account, verification, campaign, and service notifications.
  • Analytics Providers: (e.g., Google Analytics) if you have given your consent.

If we transfer data to service providers in countries outside the European Union (e.g., the USA), we ensure a legally permissible level of data protection. This is typically done through the EU-U.S. Data Privacy Framework for certified US companies or by concluding EU Standard Contractual Clauses (SCCs).

4. Your Rights as a Data Subject

You have the following rights regarding your personal data under the GDPR:

  • Right of Access (Art. 15 GDPR): The right to obtain information about your personal data processed by us.
  • Right to Rectification (Art. 16 GDPR): The right to have inaccurate personal data corrected.
  • Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): The right to have your data deleted, provided there are no legal retention obligations. For practical instructions on in-app deletion and how to submit a deletion request, see section 4a below.
  • Right to Restriction of Processing (Art. 18 GDPR): The right to request a restriction on the processing of your data.
  • Right to Data Portability (Art. 20 GDPR): The right to receive your data in a structured, common, and machine-readable format.
  • Right to Withdraw Consent (Art. 7(3) GDPR): The right to withdraw your consent at any time with future effect.
  • Right to Lodge a Complaint (Art. 77 GDPR): The right to complain to a supervisory authority. The competent authority for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

Information about your Right to Object under Art. 21 GDPR

You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) (public interest) or Art. 6(1)(f) GDPR (legitimate interest).

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.

The objection can be made form-free and should be directed to legal@luminaos.app.

4a. Account and Data Deletion Requests (Art. 17 GDPR)

You can request deletion of your LuminaOS account and associated personal data at any time, subject to legal retention obligations (e.g., tax and accounting requirements for invoices).

In-App Account Deletion

You can delete your account directly in the app settings:

https://luminaos.app/settings/app

To do so, open the settings page and click the account deletion button. Once confirmed, your access is removed, active login identifiers are disabled or tombstoned, and the old account is not restored if you later sign up again with the same email. In the web app, this is currently an archive-first deletion flow. In supported mobile self-service flows, deletion may start a backend-owned permanent deletion job that deletes, anonymizes, or restricts data depending on ownership conflicts and legal retention obligations.

Deletion Request via Email

If you prefer, you can also request deletion by email.

How to submit a deletion request:

  • Send an email to: legal@luminaos.app
  • Subject line: "Request for user data deletion"
  • In the message body, include:
    1. The email address of the LuminaOS account you want to delete
    2. A short statement that you request deletion of your account and associated personal data
    3. Optional: specify whether you want (a) full account deletion or (b) deletion of specific data categories

Verification and Processing

  • We may ask for additional information to verify that the request is made by the account holder.
  • We will process deletion requests within a reasonable timeframe and confirm completion via email.
  • If certain data must be retained due to legal obligations, we will restrict processing of that data and retain it only for the required period.

Mobile App Local Storage and Offline Use

On supported mobile devices, the LuminaOS app may store certain data locally on your device to support secure sign-in, offline use, draft recovery, queued synchronization, and backup safety mechanisms.

  • Authentication or session-related credentials may be stored in secure device storage such as the iOS Keychain or Android secure storage facilities.
  • Drafts, pending operations, offline metadata, and local backup files may be stored temporarily on device and synchronized or cleared later depending on your actions and app state.
  • Where you use connected contact, journaling, or backup features, local caching may occur to support performance, recovery, and offline continuity.

5. Data Retention

We process and store your personal data only for the period necessary to achieve the purpose of storage, or as far as this is granted by European legislators or other legislators in laws or regulations to which the controller is subject.

  • Account and app data: Stored while your account is active and deleted, anonymized, or restricted after account deletion unless retention is legally required.
  • Connected wearable data: Stored while you keep the imported history in LuminaOS. You may disconnect the provider while retaining that history, or disconnect and delete the imported provider data. Provider access credentials are removed when the connection is disconnected.
  • AI Coach, journal, reflection, OBS, habit, action, contact, team, and community data: Stored to provide the Services and included in export/deletion workflows where technically and legally applicable.
  • ChatGPT and Codex MCP connection: Connecting the app does not change how long LuminaOS retains the source records. OpenAI may retain results already returned under your OpenAI plan, workspace settings, data controls, and policies. Disconnecting the app revokes future tool access but does not automatically remove prior conversation copies or undo completed actions.
  • Voice, dictation, and media processing: Uploaded or live audio and media may be processed to produce transcripts, extracted content, journal entries, AI Coach messages, or reflection drafts. Temporary processing copies are kept only as long as needed for the feature unless the feature explicitly stores the resulting content or canonical transcript.
  • Cookie consent records: Stored with the consent choices, timestamp, version, source, IP address, and user agent. Active consent records are set to expire after one year unless renewed or replaced.
  • Launch campaign records: Stored as long as needed to administer the campaign, verify requests, prevent duplicate or abusive participation, handle voucher eligibility, and document Premium grant decisions.
  • Operational, security, and deletion-job records: Some limited metadata may be retained after account deletion to complete deletion workflows, resolve ownership conflicts, prevent abuse, and document compliance actions.
  • Contractual, billing, subscription, and invoice data: Retained for the statutory periods required by German commercial and tax law, typically up to 10 years.
  • Backups and logs: May remain for limited operational periods according to backup, security, and incident-response requirements before being rotated or deleted.

6. Data Security

We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties. Our website uses SSL/TLS encryption for security and to protect the transmission of confidential content.

7. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy so that it always complies with the current legal requirements or to implement changes to our services in the privacy policy. The new privacy policy will apply to your next visit.

Last updated: August 24, 2026

For questions about this privacy policy, please contact us at legal@luminaos.app