Legal
Privacy Policy
Last updated: 13 September 2026
Lumeo holds unusually personal material: the things you think about when nobody is listening. This policy describes what actually happens to that material, in the same words we would use to describe it to ourselves.
Who we are
Lumeo is published by Piotr Prus Prosurp IT & Photo, trading as Broda Labs, a sole proprietorship registered in Poland at Bernadowska 4/14, 81-553 Gdynia, NIP 8762427020. It is the data controller for the personal data described here. For anything in this policy, write to broda.labs@gmail.com.
The short version
- Your notes are stored on your device and on our server. The copy on the server is what puts your vault back if you lose your phone or reinstall the app.
- Your voice goes straight to Google to be turned into text, not through us. Your note text does pass through our servers, to be structured by Google's Gemini models. Neither the audio nor the text is retained by Google afterwards.
- The server copy is encrypted with a key of your own, which is itself kept outside the database. A stolen database, backup or replica is unreadable without it.
- We can still read your notes. The encryption above protects the database, not us: our server has to decrypt your text to transcribe, summarise, connect and answer questions about it, which is the whole product.
- Lumeo is not end-to-end encrypted. Your content is encrypted in transit and is processed in order to be useful to you. We will never claim otherwise.
- We do not sell your data, and we do not use it to train models.
What we store, and where
| Data | Where it lives | Why |
|---|---|---|
| Your thoughts: transcripts, structured note text, titles, tags, ideas | On your device, and encrypted in our database (Google Cloud, EU region) | The app reads them locally; the server copy is what survives a lost or reset phone |
| The connections between your notes | Same | So your map comes back with your notes rather than having to be rebuilt |
| Audio | Nowhere. It is streamed to Google as you speak and never written to a file, on your phone or on our server | Turning speech into text |
| Your to-dos: the text, when they are due, whether they are done | On your device, and encrypted in our database | So your list survives a lost phone, and so a reminder can find you |
| What the vault has learned about the people, places and projects in your notes — short facts, each tied to the note that said it | On your device, and encrypted in our database. The name is stored unencrypted, because it is what retrieval searches by | So Lumeo can answer questions about someone using what you have already said about them |
| Note embeddings (a list of numbers per note, with the note's id) | Our database, Google Cloud, EU region | Finding related thoughts and answering questions |
| Account: sign-in provider, the provider's stable user id, your email address | Our database | Knowing which vault is yours |
| Session tokens (stored only as a SHA-256 hash) | Our database; the token itself only on your device | Keeping you signed in |
| Subscription status and usage counters | Our database | Plan entitlements and fair-use limits |
What "encrypted" means here, precisely
Each account has its own encryption key. That key encrypts your note text in our database, and is itself locked by a second key that is not stored in the database. So a leaked database, a stolen backup or a copied replica yields nothing readable, and deleting your account can destroy your key — after which even a surviving backup of those rows cannot be opened.
It is not end-to-end encryption, and we will never call it that. Our server unlocks your key on every request because it has to read your words to transcribe them, write the summary, find the connections and answer your questions. Anyone who compromised our application could read your notes. What this protects against is the database, not the software.
Your tags, the names of people and places a note is about, and the numeric fingerprints (embeddings) are stored unencrypted, because they are the keys retrieval searches by and encrypting them would disable the feature. An embedding is a lossy list of numbers describing what a note is about; it is not encryption and research has shown text can sometimes be partially reconstructed from one.
What leaves your device, and when
- When you record. Audio is streamed over an encrypted connection to Google's Gemini transcription service. We receive the resulting text; neither we nor Google retain the audio for our purposes.
- When a note is processed. The transcript is sent to our server, which passes it to a Gemini model to produce a title, tags and a summary. The finished note is stored, encrypted, in the same request — it is not a separate step you could decline. Note text is never written to our logs.
- When a note is saved or edited. The note itself is sent to our server and stored, encrypted, so that it survives your device. If you are offline it waits on your phone and goes up when you are back — nothing is lost in the meantime.
- When a note is indexed. A distilled version of the note (title, tags, summary) is turned into an embedding for search.
- When you use Ask. Your question goes to our server, which embeds it, picks the notes most likely to answer it from the copy it already holds, and sends those notes with your question to a Gemini model. Your device sends the question and nothing else. Neither the question nor the notes are retained after the answer comes back.
Nothing is sent for any of this unless you record, save or ask. Lumeo does not read your device in the background.
Who processes data on our behalf
- Google Cloud Platform: hosting, database and logging.
- Google Gemini API: transcription, note structuring, embeddings and Ask answers. Google states that data sent through the paid Gemini API is not used to train its models.
- Google Sign-In and Sign in with Apple: authentication. We receive an identifier and your email address; we never see your password.
- RevenueCat: subscription state, if you subscribe. Payment itself is handled by Google Play or the App Store, and we never see your card details.
Some of these providers process data outside the European Economic Area. Where that happens it is covered by the European Commission's Standard Contractual Clauses.
Legal bases
- Performance of a contract (GDPR Art. 6(1)(b)): running the app you asked for: capture, processing, connections, Ask, your subscription.
- Legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing abuse, and diagnosing faults.
- Consent (Art. 6(1)(a)): microphone access, which your operating system asks you for and which you can withdraw at any time in system settings.
How long we keep things
- Notes, their connections and their embeddings: until you delete the note or your account. Deleting a note removes it from our server too, not only from your phone.
- Account record: until you delete your account.
- Sessions: until they expire or you sign out.
- Subscription and usage records: for as long as required by tax and accounting law.
- Operational logs: a short retention window. They contain request metadata (timings, error codes, account identifiers), not the content of your notes.
Deleting your account removes your account record and everything linked to it: your notes, their connections, every embedding, and your encryption key. Notes held on your device are removed when you delete the app. How to delete your account.
Your rights
Under the GDPR you may request access to your personal data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Write to broda.labs@gmail.com and we will respond within one month.
You also have the right to complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.
Children
Lumeo is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
Changes
If we change how Lumeo handles your data we will update this page and change the date at the top. Material changes will be announced in the app before they take effect.
Contact
Piotr Prus Prosurp IT & Photo (Broda Labs), Bernadowska 4/14, 81-553 Gdynia, Poland · broda.labs@gmail.com