Lumeo

Legal

Privacy Policy

Last updated: 13 September 2026

Lumeo holds unusually personal material: the things you think about when nobody is listening. This policy describes what actually happens to that material, in the same words we would use to describe it to ourselves.

Who we are

Lumeo is published by Piotr Prus Prosurp IT & Photo, trading as Broda Labs, a sole proprietorship registered in Poland at Bernadowska 4/14, 81-553 Gdynia, NIP 8762427020. It is the data controller for the personal data described here. For anything in this policy, write to broda.labs@gmail.com.

The short version

What we store, and where

DataWhere it livesWhy
Your thoughts: transcripts, structured note text, titles, tags, ideas On your device, and encrypted in our database (Google Cloud, EU region) The app reads them locally; the server copy is what survives a lost or reset phone
The connections between your notes Same So your map comes back with your notes rather than having to be rebuilt
Audio Nowhere. It is streamed to Google as you speak and never written to a file, on your phone or on our server Turning speech into text
Your to-dos: the text, when they are due, whether they are done On your device, and encrypted in our database So your list survives a lost phone, and so a reminder can find you
What the vault has learned about the people, places and projects in your notes — short facts, each tied to the note that said it On your device, and encrypted in our database. The name is stored unencrypted, because it is what retrieval searches by So Lumeo can answer questions about someone using what you have already said about them
Note embeddings (a list of numbers per note, with the note's id) Our database, Google Cloud, EU region Finding related thoughts and answering questions
Account: sign-in provider, the provider's stable user id, your email address Our database Knowing which vault is yours
Session tokens (stored only as a SHA-256 hash) Our database; the token itself only on your device Keeping you signed in
Subscription status and usage counters Our database Plan entitlements and fair-use limits

What "encrypted" means here, precisely

Each account has its own encryption key. That key encrypts your note text in our database, and is itself locked by a second key that is not stored in the database. So a leaked database, a stolen backup or a copied replica yields nothing readable, and deleting your account can destroy your key — after which even a surviving backup of those rows cannot be opened.

It is not end-to-end encryption, and we will never call it that. Our server unlocks your key on every request because it has to read your words to transcribe them, write the summary, find the connections and answer your questions. Anyone who compromised our application could read your notes. What this protects against is the database, not the software.

Your tags, the names of people and places a note is about, and the numeric fingerprints (embeddings) are stored unencrypted, because they are the keys retrieval searches by and encrypting them would disable the feature. An embedding is a lossy list of numbers describing what a note is about; it is not encryption and research has shown text can sometimes be partially reconstructed from one.

What leaves your device, and when

Nothing is sent for any of this unless you record, save or ask. Lumeo does not read your device in the background.

Who processes data on our behalf

Some of these providers process data outside the European Economic Area. Where that happens it is covered by the European Commission's Standard Contractual Clauses.

Legal bases

How long we keep things

Deleting your account removes your account record and everything linked to it: your notes, their connections, every embedding, and your encryption key. Notes held on your device are removed when you delete the app. How to delete your account.

Your rights

Under the GDPR you may request access to your personal data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Write to broda.labs@gmail.com and we will respond within one month.

You also have the right to complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.

Children

Lumeo is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.

Changes

If we change how Lumeo handles your data we will update this page and change the date at the top. Material changes will be announced in the app before they take effect.

Contact

Piotr Prus Prosurp IT & Photo (Broda Labs), Bernadowska 4/14, 81-553 Gdynia, Poland · broda.labs@gmail.com