The full policy
Your information.
The complete picture.
Who we are and what this policy covers
LumenDrift is operated by Lumenshore Limited, a company registered in England and Wales under company number 09607326. Our registered office is Windsor House, Troon Way Business Centre, Humberstone Lane, Leicester, England, LE4 9HA. Lumenshore Limited is the controller of the personal information we use to operate LumenDrift: we decide why that information is needed and how it is handled.
This policy covers the LumenDrift website, iPhone app, account services, sound-world delivery, Royal subscriptions, messages and reports you send us, and privacy requests. It explains information collected directly from you, information generated when you use a feature, and information received from the authentication and purchase providers you choose. Features and permissions may differ between app versions and countries.
Other Lumenshore products have their own privacy policies. Some LumenDrift services use shared Lumenshore infrastructure, but this does not make your LumenDrift information public or turn this policy into a policy for every Lumenshore product. Apple, Google, and other providers may separately act as controllers for their own account, billing, security, and legal responsibilities.
Read the sections relevant to the features you use together with the regional supplement for your location. A regional supplement applies when the relevant law covers the processing; a language setting or website visit alone does not determine jurisdiction. Mandatory privacy rights take priority over any inconsistent term in our service agreements.
The boundaries around your information
LumenDrift is designed around listening and personal choice. Local favourites, playback preferences, and listening history have a different purpose from an account record, a purchase entitlement, or a request for help. We describe these separately so that a promise about one does not obscure what happens to another.
We do not sell personal information, build third-party advertising audiences from your listening, or provide your personal content to external general-purpose AI providers for model training. The current website has no advertising pixels or session-replay integration. Essential service requests and website measurement still involve information processing, as described below.
- No automatic access to your private lifeOrdinary listening does not give us access to contacts, photos, precise GPS location, microphone recordings, calendar contents, or Apple Health records. A general privacy setting is not permission to collect all of these categories.
- No card-number collection by LumenDriftApple handles App Store payment details. LumenDrift and RevenueCat use purchase and entitlement information to recognise Royal access and restore purchases.
- No public listening profileYour favourites and listening history are not published as a public profile. Sending a message, a bug report, or something through another app is a separate action with its own recipients.
- No blanket anonymity claimAccount identifiers, hashed security identifiers, connection records, and information you submit can still be personal information. Removing a name does not automatically make a record anonymous.
The information we collect and where it comes from
The following inventory describes categories used across LumenDrift. It does not mean that every visitor provides every category. Reading a public page, playing a preview, signing in, buying Royal, and sending a report have different data requirements.
We do not buy consumer profiles from data brokers. Information received from a sign-in or payment provider is used for the relevant account or purchase relationship. We may also receive a lawful request from a regulator, an authorised representative, or a person reporting a security problem; those records are handled for that request, not as a new marketing list.
| Category | What it can include | Where it comes from |
|---|---|---|
| Account and identity | Account identifier, display name, email or Apple relay address, authentication status, and identity-provider references. | You and the sign-in provider, through Clerk. |
| App and device | Installation identifier, app and build version, operating-system version, device model, locale, time zone, notification-authorisation status, and service-access timestamps. | The app and device when connecting to account services. |
| Preferences and listening | Chosen ritual, favourites, playlists, saved settings, downloads, and listening history. Local information is distinguished from account preferences and requested media delivery below. | Your actions in the app. |
| Purchases | Product, transaction and entitlement identifiers, renewal or expiry state, purchase environment, and subscription status. | Apple, RevenueCat, and purchase/restoration requests. |
| Messages and reports | Message text, report category and severity, expected behaviour, screen and playback context, optional diagnostics, and response records. | Information you submit and the context attached to the relevant feature. |
| Website and security | Page requests, IP address and other connection signals, browser/device categories, referrer, broad location, performance measurements, and preview-access records. | Your browser and our hosting, measurement, and security providers. |
| Communications and rights | Early-access email where registration is available; privacy-request details, identity checks, correspondence, and limited records of how a request was resolved. | You, an authorised representative, and our handling of your request. |
What happens if you choose not to provide information
You can read public website pages without an account. Account-based features need an identity that we can authenticate; protected downloads need a valid access request; Royal restoration needs sufficient purchase information to check your entitlement. We cannot provide those particular functions if their necessary information is unavailable or invalid.
Sending a message, joining an available early-access list, and submitting a bug report are choices. Optional diagnostic details can help explain a technical problem, but a report still includes its text and basic feature context. You should include only information relevant to the issue and avoid passwords, payment details, medical records, or information about someone else that is not needed.
Withdrawing an optional permission or consent does not automatically close your account. It may stop the feature that depends on that permission. Similarly, refusing a preview security check can prevent that clip from playing while leaving public information pages available. We do not treat a request to exercise privacy rights as a reason to penalise you.
We may need a limited identity check before releasing account information or deleting an account. If we cannot safely verify the request, we will explain what is missing and consider another proportionate way to establish authority. Providing extra information for verification does not authorise unrelated use.
What stays on your iPhone
The app keeps local information that makes listening work: favourites, playlists, downloaded audio, playback preferences, recent listening, ritual selections, and settings. Local recommendation logic can use these choices to suggest a sound world or help you return to something familiar. This information is not automatically a cloud listening history.
Connecting to the service is separate. Account setup sends the account and device fields described in this policy, including a preferred ritual where provided. Requesting protected audio necessarily identifies the requested item to the service delivering it. A report may include the currently selected ritual or sound world. These actions mean that “stored locally” should not be read as a promise that our servers never learn which feature or audio item you requested.
An installation credential is held in the iPhone Keychain to protect access from that installation. Device backups, operating-system storage, and any information you deliberately share through Apple or another application are also subject to the controls of those systems. We do not represent an account sign-in or an iCloud-labelled setting as proof that your full library is being synchronised.
Manage downloaded worlds and other local information using the controls available in your app version. Removing the app can remove its application storage, but it does not necessarily erase Keychain items, device backups, provider records, or the account held by our service. Account deletion, local deletion, and subscription cancellation are explained separately below.
Wellbeing, sensitive information, and device permissions
A sound-world choice is not a diagnosis. We do not use a Calm Recovery selection, a listening duration, or an accessibility preference to declare that you have a medical condition, infer a treatment need, or sell a health profile. LumenDrift is a listening product, not a medical record or an emergency service.
The current app-to-service integration does not upload raw Health data, calendar entries, microphone audio, contacts, or precise location. Permission explanations or settings for possible context features do not themselves mean that those data sources are connected or collected. If a future version introduces such processing, the feature needs its own clear explanation and any required platform permission and legal consent before collection.
An operating-system permission and a lawful basis for processing are different requirements. Where sensitive personal information is involved, an additional legal condition may be necessary. For example, a future optional health-data feature could require explicit consent as well as a purpose-specific Apple permission; ordinary acceptance of this policy would not substitute for that consent.
You can choose to reveal sensitive information in free-text messages even though we do not request it. Please keep reports focused on the product issue. If a submission contains unnecessary sensitive information, you can ask us to remove it; we may restrict its use or remove it when it is not needed. Do not send someone else’s private information unless you have a proper reason and authority to do so.
Reminders and information visible to other people
Notification permission is controlled by iOS. Lock-screen previews, widgets, shared devices, audio routes, and items you share can be visible to people around you. Review those device settings if you want a more private presentation. Changing visibility on your device does not delete an account record or a report already sent to us.
Family-oriented listening does not create a child profile or authorise the collection of a child’s health, school, age, or identity information. The children’s section explains the limits of the service and the route for a parent or guardian to raise a concern.
Your account, authentication, and Sign in with Apple
Clerk provides authentication for LumenDrift. When you sign in, we use the verified account identity to associate your app session with your LumenDrift profile. Our account records can contain a display name, email address, Clerk identity reference, locale, time zone, preferred ritual, and service timestamps. Authentication records and credentials are used to confirm that requests come from the appropriate account or installation.
If you choose Sign in with Apple, Apple may supply your name and an email address according to your choices and its sign-in rules. If you use Hide My Email, the address available to us can be an Apple relay address. Keep that forwarding route available if it is how you receive necessary account communications. We do not receive your Apple password or the contents of your Apple account.
The identity provider may maintain its own fraud-prevention, account-security, and sign-in records. Its role is distinct from the LumenDrift profile stored by Lumenshore. Signing out stops ordinary use of the session on that device; it does not erase the account, cancel Royal, or delete a provider’s independent records.
You can manage connected applications with your identity provider. Revoking a connection can prevent future sign-in using that method, but it does not necessarily delete information we already lawfully received. Use the account-deletion or privacy-request route if you also want us to erase or restrict that information.
How Google user data is handled
Google sign-in is an optional way to authenticate through Clerk. The explanation below concerns that sign-in connection. It does not mean LumenDrift has access to all information associated with your Google account, and it is separate from any use of Google Cloud infrastructure for service backups.
Information and scope
The connection requests basic identity information used for sign-in, such as the account’s identity reference, email and verification status, and profile details that Google makes available under the requested permissions. Clerk handles the provider connection; the LumenDrift backend uses the verified Clerk account reference and available name and email. A provider profile may also contain a profile image, but this is not access to your photo library.
LumenDrift does not request Gmail messages, Google Drive files, Google Calendar events, contacts, browsing history, or an advertising profile through this sign-in flow. Review the Google permission screen before continuing. You may decline the connection; a feature requiring an authenticated account will still need a supported way to sign in.
Purpose, access, and sharing
We use the resulting identity to authenticate you, maintain the account you requested, protect sessions, recognise associated entitlements, and respond to account or privacy requests. We do not use Google user data to target advertising, sell it, or train general-purpose AI models. Access by people operating the service is limited to a justified account, security, legal, or request-handling purpose.
Clerk and the infrastructure providers that operate the account service process the information needed for their role. RevenueCat receives the stable account identifier used for subscription matching; our current integration does not deliberately set your Google name or email as RevenueCat subscriber attributes. The other limited disclosures described in this policy, including valid legal requirements, can also apply.
Retention, revocation, and deletion
Account information remains subject to the retention and deletion sections of this policy. Disconnecting LumenDrift in Google’s third-party connections controls prevents further access through that connection as Google describes, but does not by itself erase a LumenDrift account or a completed purchase record. If you request account deletion, our workflow addresses the LumenDrift profile and the associated authentication-provider profile, subject to verification and lawful retention exceptions.
Where the Google API Services User Data Policy applies, our use and transfer of information received from Google APIs must comply with that policy, including its Limited Use requirements. This is not permission to expand the scopes we request or use information for a purpose unrelated to the connection you chose.
Royal subscriptions, purchases, and restoration
Apple processes App Store purchases. LumenDrift does not receive or store your full payment-card number, card security code, or Apple payment credentials. Apple may retain payment, tax, fraud-prevention, and transaction information for its own responsibilities under its privacy notice and terms.
RevenueCat helps us manage purchase status and Royal entitlements. The integration uses a stable Clerk account identifier so that an entitlement can be associated with the correct signed-in person. It also processes product and transaction information, purchase environment, subscription state, expiry or renewal details, and events needed to recognise changes such as refunds or restoration. We do not supply your name or email as subscriber attributes in this integration.
Our backend maintains the subscription information needed to provide the correct access and reconcile provider events. A purchase identifier is still personal information when it can be connected to your account. It is not treated as anonymous merely because it differs from your email address.
Restoring purchases asks the relevant services to check an existing entitlement; it is not a new marketing registration. Deleting a LumenDrift account does not cancel an Apple subscription. Manage renewal in your Apple subscription settings, and use Apple’s refund process where applicable. Some transaction or accounting records may need to remain after account deletion for legal, fraud-prevention, or dispute purposes.
Messages, automated replies, and reports you submit
If your app version provides a messaging feature, sending a message transmits its text to the service. Conversation records can include the title, intent or category, status, source, timestamps, message order, and replies. These are service records, not information that remains exclusively on your phone. Only submit content you intend the service to receive.
The current reply implementation selects prepared responses rather than sending your conversation to an external generative-AI provider. A reply may be automated; it should not be understood as a person monitoring the conversation or as professional medical advice. The service does not provide crisis monitoring or guaranteed real-time responses.
A bug report includes your description, category, severity, expected behaviour where supplied, and the screen or entry point involved. Basic context can include the selected ritual, active world, playback state, and whether a session is active. If you include diagnostics, the report can also include app/build and operating-system versions, device class, locale, time zone, low-power mode, and broad counts of saved items or downloads.
The reporting feature filters sensitive diagnostic keys, but it cannot guarantee that private information typed into the message will be removed. Never include a password, authentication code, full payment details, private medical record, or unnecessary information about another person. We use reports to investigate the issue, improve reliability, and maintain appropriate records of its handling; submitting one does not promise a particular response time or resolution.
Information processed when you visit the website
Vercel hosts the LumenDrift website. Delivering a page involves network and request information, including your IP address, requested resource, browser information, timing, and security-related signals. These requests can be processed by hosting and network infrastructure even when you do not fill in a form or create an account.
Vercel Web Analytics provides aggregate visit information. Measurements can include page URL or path, referrer, filtered query parameters, broad location derived from the request, device and browser categories, and a timestamp. Vercel describes a request-derived visitor hash that is discarded after 24 hours. That lifespan is not a promise that aggregate statistics or separate hosting logs are deleted after 24 hours.
Vercel Speed Insights measures page performance, such as loading, responsiveness, and visual stability, together with page and device context. The website does not configure custom analytics events, advertising profiles, or session replay. It does not intentionally attach a LumenDrift account identity or your in-app listening history to these website measurements.
Website measurement currently loads during browsing. Our Cookie settings panel explains the active technologies; it does not save an acceptance or rejection choice or turn measurement off. Reading the policy, continuing to browse, and closing that panel are not recorded as consent. The Cookie Policy describes this behaviour and the available browser controls in more detail.
What happens when you press Play on a preview
A website sound preview is a separate request from reading a page. On a playback request, the player loads Cloudflare Turnstile to assess whether the request appears legitimate. Cloudflare can process browser, device, and connection signals, including an IP address. The preview service verifies the resulting token before granting access to an excerpt stored in Cloudflare R2.
The service issues a time-limited media grant and uses request limits to reduce automated downloading and abuse. Quota records use pseudonymous, keyed identifiers derived from connection information, together with information such as the requested world, grant timing, request count, and bytes delivered. These are security controls, not a public listening profile. Pseudonymous identifiers remain protected information where they can relate to a person.
The player holds the fetched excerpt and temporary playback state in browser memory. It does not create a persistent offline audio library in localStorage, sessionStorage, or a service-worker cache. An already loaded clip may remain in memory after a signed link expires. Changing the selected world or removing the player releases its audio object; merely pausing it does not necessarily do so.
Cloudflare’s security processing and our own quota records are separate. The lifetime of a token does not describe every provider log. Blocking Turnstile or refusing the information required for its check can prevent playback. You can continue to read the website without starting a preview.
Cookies, local storage, and browser caching
The current website application does not set its own account, advertising, language-preference, or consent cookie, and does not create application-owned localStorage or sessionStorage entries. Vercel Web Analytics does not use an analytics tracking cookie. These statements do not mean that network requests or provider security processing contain no personal information.
The website does not register a service worker for offline pages or audio. Browsers can still cache public images, fonts, scripts, and styles using ordinary HTTP caching. Temporary interface state, an unsubmitted form value, a Turnstile token, and a preview audio object are different from a permanent browser profile. Your browser may also independently restore form or page state.
The current preview flow does not use a Cloudflare pre-clearance cookie as its audio-access credential. Provider-managed security behaviour can differ from storage deliberately created by our application, so we do not make a blanket claim that every third-party context is cookie-free.
Deleting browser storage affects that browser; it does not send a request to erase your LumenDrift account, provider transaction records, or an email registration already submitted. The separate Cookie Policy summarises website technologies and the current Cookie settings panel. The retention and privacy-control sections of this policy explain how those practices affect your information.
App diagnostics, operational monitoring, and analytics
Three different activities should be distinguished: local app events, operational monitoring of connected services, and website measurement. A setting about one activity does not automatically control all three. Necessary account authentication, purchase checks, and abuse prevention continue to need their relevant information when those services are used.
The current app’s analytics component keeps event records in memory and filters property names intended to exclude sensitive context and direct identifiers. It is not currently connected to an external event-upload service. Local event recording should therefore not be confused with a server-side listening history, but neither do we promise that every in-app event is disabled by every privacy-labelled setting.
The backend has operational error and performance monitoring through Sentry where configured. Error events can contain technical context, timestamps, route or job information, and diagnostic details needed to investigate a failure. Server-side scrubbing is designed to remove or mask categories such as email addresses, IP addresses, authentication tokens, and provider identifiers. Filtering reduces exposure; it does not justify putting secrets or unnecessary personal information into a report.
The LumenDrift website does not include a Sentry or PostHog browser integration, and it does not record a visual replay of your page session. Backend error monitoring is a different processing activity.
Early-access registration and communications
Where the website offers an early-access form, submitting it sends the email address you provide to our configured registration service, together with a label identifying LumenDrift as the source. Basic validation and abuse protection are used to reduce invalid or automated submissions. The form does not ask you to create a listening profile or disclose health information.
The website’s form protection can temporarily use an IP-derived request key to limit repeated submissions. A hidden form field is used to detect automated activity. The registration address is forwarded to the configured recipient service only as part of the requested registration. The form is not available when the delivery integration is not configured.
We use an early-access registration for the update or invitation described when you submit it. It is not permission to send unrelated promotions or enrol you in marketing for every Lumenshore product. Where consent is required, you can withdraw it. Use the unsubscribe option in an optional communication where provided, or the privacy-request route below.
Necessary account, purchase, security, or privacy-request messages have a different purpose from optional marketing. Withdrawing from an optional list does not prevent a message needed to address a request you made or a legal obligation. We may keep limited suppression information when needed to honour a request not to contact you again.
Our purposes and legal bases
For processing subject to UK or EU data-protection law, we identify a lawful basis for each purpose. A contract basis applies only where information is objectively needed to provide the service you request. A legitimate interest is not unlimited permission: it must be necessary for the stated interest and balanced against your rights and reasonable expectations.
Some local laws use different grounds or require consent or additional safeguards. The regional supplements explain relevant distinctions. Listing legitimate interests here does not create a legal basis under a law that does not recognise it, and a data-protection basis does not replace a separate consent requirement for device access or electronic marketing.
| Purpose | Information involved | Basis and limits |
|---|---|---|
| Provide and authenticate an account | Identity, account profile, device credential, locale, time zone, and relevant preferences. | Performance of the service contract and steps you request before entering it. |
| Deliver protected audio and Royal access | Requested audio, account/access identifier, purchase and entitlement status. | Performance of the contract; legal obligations for required transaction records. |
| Prevent abuse and protect accounts | Connection records, authentication events, preview quotas, request timing, and security diagnostics. | Legitimate interests in protecting users and infrastructure, with limited collection and retention; legal obligations where applicable. |
| Investigate faults and submitted reports | Report text and context, optional diagnostics, technical errors and performance information. | Contract where needed to provide the requested service; otherwise legitimate interests in reliable operation and resolving issues. |
| Understand website quality | Aggregate visits, device/browser categories, referrer, broad location, and page-performance measurements. | Legitimate interests in maintaining and improving the website, subject to applicable consent requirements. |
| Send optional early-access updates | Registration address and communication preference. | Consent where required. You can withdraw without affecting earlier lawful use. |
| Respond to rights requests and legal duties | Request, proportionate verification, correspondence, and completion evidence. | Legal obligation; legitimate interests in demonstrating compliance or establishing, exercising, or defending legal claims where appropriate. |
| Make optional local personalisation work | Choices and listening context held on your device. | Providing the feature you choose; consent and any additional condition where a future optional feature requires them. |
Changing a purpose or withdrawing consent
If we need to use information for a materially different purpose, we must assess whether that use is compatible with the original purpose and legally permitted. Where fresh consent or notice is necessary, we will obtain or provide it before that use. A revised policy alone does not retrospectively authorise an incompatible use.
You may object to processing based on legitimate interests and tell us about your particular circumstances. You can withdraw consent for a consent-based purpose at any time. Withdrawal does not make earlier lawful processing unlawful, and we may still need limited information for a separate legal obligation or a service you continue to request.
Service providers and their roles
Providers receive information necessary for their part of the service. A processor handles information on our behalf under the applicable arrangement; an independent controller decides its own purposes, for example Apple’s payment and account-security obligations. The same provider can perform different roles for different activities.
The register below describes the providers reflected in the current product integrations and recovery configuration. A provider being headquartered in a country does not identify every server, support location, or subprocessor it uses. Information may be handled in the United Kingdom, the European Economic Area, the United States, and other countries used by the provider’s infrastructure; see International transfers for the safeguards and how to request more detail.
| Provider | Purpose and typical information | Role and scope |
|---|---|---|
| Clerk | Authentication, identity connections, account identifiers, approved profile fields, and security/session information. | Authentication service provider; its own notice also explains independent security and business responsibilities. |
| Apple | Sign in with Apple, App Store distribution and purchases, platform permissions, and services you use on your device. | Independent platform provider for its account and payment services; receives information according to the feature used. |
| Identity information for optional Google sign-in through Clerk. | Independent identity provider; not access to Gmail, Drive, or Calendar. | |
| RevenueCat | Purchase processing integration, account identifier, products, transactions, and Royal entitlements. | Subscription infrastructure; our integration does not supply your name or email as subscriber attributes. |
| Vercel | Website delivery, connection and security information, aggregate visit statistics, and performance measurements. | Website hosting and measurement provider; distinct from the app account database. |
| Cloudflare | Turnstile, preview delivery and security quotas, object storage, and service recovery storage where configured. | Security, delivery, and storage provider. A private audio file is different from an account database backup. |
| Fly.io / Fly Managed Postgres | Backend hosting, database records, service requests, operational information, and managed database recovery. | Infrastructure for shared Lumenshore services, including product-scoped LumenDrift records. |
| Sentry | Backend errors, performance traces, and diagnostic context, subject to configured collection and scrubbing. | Operational monitoring where enabled; no LumenDrift website session replay. |
| Google Cloud Storage | Secondary recovery copies of the shared service database where that recovery layer is enabled. | Backup infrastructure, separate from optional Google sign-in and not an advertising integration. |
Access limits and changes to providers
Information is not made available to a provider simply because it appears in this list. Its access depends on its function: a media-delivery service needs the requested media and access context, while an authentication provider needs identity information. We do not intentionally send a full listening history to every provider.
Providers may use their own authorised subprocessors. You can request further information about the recipient categories and safeguards applicable to your information. We will update this notice when material changes affect these disclosures and provide additional notice or choices where required.
How information moves through the service
LumenDrift uses several distinct paths. Understanding them helps explain why removing a local file is different from deleting an account, why a website visit does not need a Clerk profile, and why a purchase can leave records with Apple even after a LumenDrift account has been removed.
Shared hosting does not automatically authorise combining your information across products for a new purpose. If a new feature needs a different data flow, such as uploading a local library or connecting sensitive context, that use must be explained and supported by the required choices and legal basis.
- BrowsingYour browser requests the site from Vercel. Website measurement and performance requests are processed separately from the app’s account and local listening information.
- PreviewingYour browser requests a Turnstile check from Cloudflare, then asks the preview service for a short-lived grant. Cloudflare delivers the excerpt and the service updates its security quota records.
- Signing inYour chosen identity provider and Clerk establish the sign-in. The LumenDrift service uses the verified identity to create or locate your product profile and authenticate subsequent requests.
- Using RoyalApple and RevenueCat establish purchase and entitlement status. The app and backend use the relevant identifier and status to provide access and reconcile changes.
- Sending a message or reportThe submission and relevant context enter the LumenDrift service database. Authorised handling and operational monitoring may involve the providers described above.
- Maintaining continuityService databases can have protected recovery copies. Recovery infrastructure may hold a copy of information from multiple Lumenshore products, with LumenDrift records identified within that shared system. A backup is not used as a separate marketing dataset.
International processing and transfer safeguards
Lumenshore is based in the United Kingdom. Our providers operate internationally, and using LumenDrift can involve processing outside your country of residence, including in the United States and the European Economic Area. A region selected for one storage bucket does not guarantee that all account data, support access, network processing, and backups remain in that region.
Where UK or EU law restricts a transfer, the relevant transfer must have a recognised route. Depending on the recipient and destination, that can be an adequacy decision or appropriate contractual safeguards, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, or the UK Addendum, together with required assessments and supplementary measures.
A Data Privacy Framework or UK Extension route can be relevant only when the recipient’s current certification, the transfer, and the relevant legal decision cover the processing. We do not assume that every US provider or every service is covered. A provider’s general description of its safeguards is also not a promise that all information stays in one country.
Transfers under other laws may require additional notice, consent, contracts, assessments, or restrictions. Those requirements cannot be replaced by a general statement that you accept this policy. Contact us to ask about the safeguards applicable to your information and how to obtain a copy or explanation, with confidential details redacted where justified.
How long information is kept
We retain personal information for the purpose for which it is needed, taking account of the amount and sensitivity of the information, account activity, unresolved requests, legal obligations, security needs, and applicable limitation periods. Different records have different lifecycles. A short-lived credential does not mean the underlying account or provider log has the same lifetime.
The table distinguishes fixed technical lifetimes from purpose-based retention. Where a fixed period is not stated, the relevant criteria apply; this is not a statement that we keep the information indefinitely or that another product’s retention settings apply to LumenDrift. You can ask about the retention applicable to a particular record.
| Record | Period or retention criterion | What to keep in mind |
|---|---|---|
| Local listening, preferences, and downloads | Held on your device until changed, removed, or cleared through the applicable app/device controls. | Device backups and Keychain entries can have separate lifecycles. |
| Account, device, and entitlement records | While needed to provide the account and connected services, then subject to deletion and justified legal or security exceptions. | Signing out or removing the app does not itself request backend account deletion. |
| Messages and reports | While needed for the conversation, investigation, related dispute, or legal/security obligation; also addressed by account deletion. | A message or report may need to remain while its subject is unresolved; you can ask us to assess earlier erasure. |
| Preview media grants | Grants expire at their stated expiry. Grant records at least one hour old are removed during a subsequent quota-processing request. | Cleanup is request-triggered, so storage can outlast the one-hour eligibility point. Expiry still prevents new authorised use of an expired grant. |
| Preview daily quota counters | The current and preceding day’s quota records are retained; older day records are removed on a subsequent quota-processing request. | This is separate from Cloudflare’s own operational and security retention. |
| Early-access request limits | In-memory rate-limit entries use a one-minute window and are pruned on later checks; the process has a bounded entry limit. | The submitted registration email has its own purpose-based lifecycle and is not deleted when the rate-limit window ends. |
| Website visitor identification | Vercel describes a 24-hour lifespan for its Web Analytics visitor hash. | Aggregate statistics, performance data, and hosting/security records are separate; 24 hours is not their universal deletion period. |
| Diagnostics and operational records | For investigating failures, protecting the service, and evaluating reliability, subject to provider configuration and any justified legal hold. | We do not promise another product’s Sentry retention or that all scrubbed records are anonymous. |
| Privacy and deletion-request evidence | Limited evidence needed to demonstrate the action taken, prevent unsafe account recreation, and meet applicable obligations or disputes. | Completed deletion receipts are redacted as described in the deletion section. |
| Recovery copies | Within the applicable backup lifecycle, with restricted use for recovery and integrity; retained longer only where a justified obligation requires it. | Deletion from active systems does not imply instantaneous removal from every historical recovery copy. |
Legal holds, deletion, and restored information
A valid legal obligation, dispute, security investigation, or regulatory request can justify preserving a limited record beyond its ordinary lifecycle. Such a hold should be specific to the need; it does not justify keeping unrelated data for new purposes. When that reason ends, the normal deletion or anonymisation criteria apply.
Recovery copies are not ordinary working copies. Where immediate selective removal from a backup is not practicable, retained information must remain protected and limited to the recovery purpose. A restoration should not be used to reverse a completed privacy request or reintroduce erased information into routine use. If a retained copy matters to your request, we will explain the applicable limitation.
Deleting your account and personal information
In the app, open Settings, choose Privacy, find LumenDrift account, and choose Delete LumenDrift account. Review what will be removed, then confirm. Contact Lumenshore through the privacy-request route if you cannot access the app. We need to associate the request with the correct account and verify your authority. An optional explanation can help us understand the request, but you do not need to provide a detailed reason to ask for erasure.
Submitting a request is not the same as completion. The service tracks its progress and can record a failure that needs attention. We do not describe information as erased merely because a request has been accepted. If an exception or verification issue prevents all or part of the request, we will explain the reason and the available next steps as the law requires.
What the completion workflow covers
The LumenDrift deletion workflow addresses your LumenDrift account, associated devices and access tokens, conversations and messages, and bug reports. It also deletes provider records dedicated to LumenDrift and handles linked provider-identity records. A Clerk identity or RevenueCat customer shared with another Lumenshore product is retained where needed to preserve that other account. Checks are used to avoid targeting another product or an ambiguous account.
After successful completion, the retained request receipt is redacted to remove fields such as the email, identity reference, free-text reason, and administrative note. Limited completion evidence can remain, including status, timing, product scope, record counts, and provider-deletion outcomes. Restricted security records may also be needed to stop an old credential from recreating the erased account.
What needs a separate action
- Apple subscriptionsCancel renewal through Apple’s subscription settings. Removing a LumenDrift account or RevenueCat profile does not itself cancel Apple billing or automatically request a refund.
- Information on your deviceAfter the app confirms that your deletion request has been accepted, it clears local playlists, favourites, listening history, and personalisation on that device. Downloaded recordings and other settings may remain until you remove or reset them, or delete the app. A server-side deletion request cannot remotely guarantee removal from another offline device or its backups.
- Independent provider recordsApple, Google, or another provider may keep records for its own legal and account responsibilities. You may need to exercise rights directly with that provider.
- Other Lumenshore productsA LumenDrift request concerns LumenDrift. Tell us if you also want a request considered for a separate product; we must verify the correct scope rather than deleting unrelated accounts.
Information that may remain
Erasure is subject to lawful exceptions, including required accounting information, the establishment or defence of legal claims, and proportionate evidence of handling the request. Protected backup copies may persist through their recovery lifecycle. Any remaining identifiable information should be restricted to the reason for retention, rather than reused for unrelated profiling or marketing.
If you want a copy of account information before deletion, say so when making the request. Once information has been permanently erased, we may be unable to reconstruct it. A request for access does not require you to keep an unwanted subscription active.
How information is protected
Safeguards in the service include encrypted network connections, authenticated account requests, installation credentials, product-scoped access checks, restricted media delivery, request limits, and filtering of sensitive diagnostic fields. Provider infrastructure adds its own storage, access, and operational controls. These measures serve different purposes and should not be confused with a blanket guarantee that every record is end-to-end encrypted.
An installation secret is kept in the iPhone Keychain, while the backend uses a keyed cryptographic representation for the corresponding check. Preview access uses short-lived grants rather than exposing an unrestricted private storage location. Access to account and deletion operations is checked to reduce the risk of one person or product affecting another person’s records.
Only people and service providers with an appropriate operational reason should have access to personal information. Security also depends on limiting what is collected and sent: private health details, passwords, access codes, and payment credentials do not belong in diagnostic fields or report text.
No storage or transmission method removes every risk. Protect your device, use the security controls offered by your identity provider, and avoid sharing account sessions. If you suspect unauthorised access or an information disclosure, use the privacy-request route and provide enough detail to identify the issue without sending further sensitive information unnecessarily.
Personal-data breaches and notification
A personal-data breach can involve loss, alteration, destruction, or unauthorised access or disclosure. If we become aware of a suspected breach affecting LumenDrift information, the response is to investigate the facts, limit the impact, assess the risk to people, and document the decisions and remedial steps. A technical fault does not automatically amount to a reportable personal-data breach.
Where UK or EU notification duties apply, a reportable breach must be notified to the relevant supervisory authority without undue delay and, where feasible, within 72 hours after awareness. A breach likely to create a high risk to people’s rights and freedoms may also require notice to affected people without undue delay. Other jurisdictions can impose different thresholds or timing; the applicable rule governs.
A notice, when required, should explain the nature of the incident, likely consequences, protective steps taken or proposed, practical steps you can take, and a contact route. We may provide information in stages if the investigation is continuing. We will not require you to provide your password or a payment to receive a breach notice.
Please report a suspected exposure promptly and avoid forwarding another person’s private data more widely than necessary. Keeping account contact details current can help necessary communications reach you. A promise to notify where required is not a claim that no incident can occur.
Recommendations, profiling, and automated decisions
The app can use locally stored choices and listening context to suggest a ritual or sound world. Those suggestions are intended to help you choose audio. They do not determine eligibility for employment, credit, insurance, healthcare, or another similarly significant service, and they are not a clinical assessment of mood or health.
Some service decisions are automated for practical reasons: a purchase check determines whether a Royal entitlement is active, a security rule limits repeated preview requests, and a session check may reject an invalid credential. If you believe a result is wrong, you can ask us to review the relevant account or privacy issue. Correcting a purchase may also require the provider that holds the transaction.
Current messaging replies select prepared content and do not send your conversation to an external general-purpose AI model. We do not use personal messages, sign-in data, or listening history to train such models. Introducing a materially different AI feature would require its own assessment, clear explanation, and any required choices before the new use.
We do not currently make solely automated decisions about you that produce legal or similarly significant effects of the kind subject to special protections under applicable privacy law. If that changes, the required information about the logic, significance, consequences, and safeguards—including human review where required—must be provided. You retain the rights available under the law that applies to you.
Aggregate statistics and de-identification
Aggregate statistics can help us understand whether a page is slow, a feature is failing, or a sound-world preview is being requested. Where information has been irreversibly anonymised so that a person cannot reasonably be identified, it is no longer treated as personal information under laws that recognise that distinction.
Pseudonymisation is different. A hashed request key, account reference, device identifier, or transaction reference may still be linkable to a person. We continue to treat such information as protected where the applicable law requires it. A dashboard displaying totals does not mean that every underlying request or service log was anonymous at collection.
We do not use aggregation as a reason to re-identify people or assemble advertising profiles from private listening choices. When de-identified information is shared, the intended purpose and restrictions must be appropriate to its form and the applicable law. Access and erasure requests may not be technically meaningful for information that can no longer be linked to you; we will not collect new identifying information solely to reconnect a genuinely anonymous statistic.
Legal requests, professional advisers, and business changes
In addition to the providers listed above, a limited disclosure may be necessary to comply with a valid legal requirement, respond to a regulator, establish or defend a legal claim, investigate fraud or a security incident, or protect someone’s vital interests where the law permits. The request, recipient, authority, and scope matter; a general interest in the information is not by itself a reason to release an account’s contents.
Where appropriate, we assess the validity and proportionality of a government or law-enforcement request and seek clarification or challenge an overbroad request. We disclose only the information legally required or otherwise lawfully justified for that purpose. We may notify the affected person where permitted and appropriate, but cannot promise notice where the law prohibits it or doing so would compromise a lawful investigation.
Professional advisers, such as lawyers or accountants, may need relevant information for confidential advice, compliance, or a dispute. If Lumenshore is involved in a merger, acquisition, financing, or transfer of a business, relevant information may be disclosed under appropriate confidentiality and data-protection restrictions. Any successor’s use must remain subject to applicable law, and material changes to the controller or purposes require the appropriate notice.
Links to Apple, Google, regulators, or other websites take you to services with their own notices. Their independent processing is not controlled solely by this policy. Following a link does not authorise LumenDrift to send unrelated private information to that service.
The rights you can exercise
Your rights depend on the law applicable to the information and processing. You do not need to know a statute name or use legal terminology to make a request. Describe what you want to access, correct, delete, restrict, or challenge, and we will consider the applicable right and explain the outcome.
The following rights commonly apply under UK or EU law; regional supplements explain additional or different rights. They are subject to conditions and exceptions, such as another person’s privacy, legal privilege, required records, or a justified legal claim. An exception should be explained rather than used as a blanket refusal.
- Information and accessAsk whether we process your personal information, obtain a copy where the right applies, and understand purposes, categories, sources, recipients, transfers, retention, and relevant automated processing.
- CorrectionAsk us to correct inaccurate information or complete information that is incomplete for its purpose. Some identity or purchase details also need to be corrected with the provider that supplies them.
- ErasureAsk us to delete information where the legal grounds for erasure apply. Account deletion and local-device cleanup are separate; limited lawful retention exceptions are explained above.
- RestrictionAsk us to limit use in circumstances such as a dispute about accuracy or a pending objection. Restricted information may still be retained while the issue is resolved.
- PortabilityWhere the conditions apply, receive information you provided in a structured, commonly used, machine-readable format and ask for transfer to another controller where technically feasible. This does not require disclosure of another person’s data or proprietary materials.
- ObjectionObject to processing based on legitimate interests for reasons relating to your situation. You can object to direct marketing at any time without having to justify that objection.
- Withdrawal of consentWithdraw consent for an optional purpose without affecting processing that was lawful before withdrawal. We will explain any consequence for the feature involved.
- Review and complaintAsk for review of an applicable automated decision, challenge a refused request, and complain to a supervisory authority or seek a judicial remedy. You do not have to waive these rights to use LumenDrift.
Privacy requests, verification, and response times
You can use the relevant privacy or account control available in the app. If that route is unavailable, you cannot sign in, or your request concerns the website, write to Lumenshore at the address below, marked “LumenDrift — Privacy request”. This postal route does not require an active account or subscription. The privacy contact is Lumenshore Limited; this policy does not designate a separate statutory Data Protection Officer.
Tell us the product, the account email or other information reasonably needed to find the record, what you want us to do, and how to reply. An approximate date or description can help identify a message or website interaction. Do not send a password, one-time sign-in code, full payment-card details, or an identity document unless a specific, proportionate verification step has been explained.
Verification and authorised representatives
We verify authority before disclosing or erasing information. We will normally seek to use information already associated with the account or request before asking for more. The level of verification should match the risk: receiving a copy of private messages needs a stronger check than asking a general question about this policy. We use additional verification information for that check and related security or compliance needs.
An authorised agent, parent, guardian, or other lawful representative can contact us. We may need evidence of the authorisation and, where appropriate, direct confirmation from the person concerned. A family relationship or access to a shared device does not automatically give someone a right to another person’s complete records.
Timeframes, fees, and extensions
For requests governed by UK or EU GDPR rules, the normal response period is one month. Where legally permitted because of complexity or the number of requests, it may be extended by up to two further months; we will notify you within the initial period and explain why. Necessary identity verification or clarification affects timing only as the applicable law allows.
Under the California rules, covered access, correction, and deletion requests generally have a 45-calendar-day response period, with a further 45 days where permitted and explained. Canadian access requests commonly have a 30-day period, and New Zealand generally requires a decision on access or correction within 20 working days. The regional law and the particular right govern; these are not universal deadlines for every message.
Requests are generally free. Where the law permits a fee or refusal for a manifestly unfounded or excessive request, or for additional copies, we will explain the basis before charging. We do not charge merely because you used a privacy right or require you to purchase Royal to exercise it.
Decisions, appeals, and complaints
If we cannot fulfil a request in full, we will explain the applicable reason, any information or part of the request that can still be provided, and the available review or complaint route. To ask us to reconsider, use the same contact route, identify the decision, and mark your request as a privacy appeal. Where a local law provides a specific appeal process or deadline, that process applies.
You can complain to the UK Information Commissioner’s Office or the authority competent for your location, as described in the regional sections. You may contact the authority without first exhausting an informal conversation with us where the law permits. Rights to a court remedy or compensation are not removed by our Terms, EULA, or this policy.
Children’s privacy and family use
LumenDrift is not directed to children under 13, and we do not knowingly collect their personal information through an account without the authorisation required by applicable law. Older children can also receive special protection. Thirteen is not a universal age for independent consent or contractual capacity; the relevant country and type of processing matter.
A parent playing audio for a child does not require a child account, school record, named child profile, or health history. Family-oriented content is not a request to upload information about children. We do not ask for child names or ages as analytics properties, and we do not use children’s information for behavioural advertising.
The current product does not offer a school administration service or a process for a school to authorise a child’s account on behalf of a parent. We do not claim that a general family feature is a FERPA arrangement, a COPPA parental-consent mechanism, or an age-verification system. If a future feature requires those safeguards, they must be established before the relevant processing begins.
Consent ages and requests from guardians
For consent-based online services under EU rules, the age at which a child may consent independently varies by country between 13 and 16; the UK threshold is 13. This threshold addresses that specific form of consent, not every rule affecting children. Other laws use different ages and conditions, such as under-14 protections in South Korea and China and the staged Indian framework’s child provisions.
If you believe a child has provided information that should not have been collected, contact us through the privacy-request route. Tell us enough to locate the record and explain your relationship to the child. We will assess the concern, restrict or remove information where required, and verify authority in a way appropriate to the situation. We will not ask a child to send sensitive information merely to obtain a general explanation of their rights.
If a service is likely to be accessed by children, applicable design and safety obligations can extend beyond a minimum-age statement. These can include privacy-protective defaults, clear explanations, limits on profiling and location use, and proportionate assessment of risks. These requirements must be considered for the actual feature and its likely audience.
Global Privacy Control, Do Not Track, and your choices
We do not sell personal information or share it for cross-context behavioural advertising, and the current website has no targeted-advertising integration. Where a law requires recognition of an applicable opt-out preference signal, that right remains available. You do not need to turn on a signal to obtain our stated no-sale and no-advertising-sharing practices.
The current website does not have a custom Global Privacy Control or Do Not Track handler that disables Vercel measurement. Sending one of these browser signals, opening Cookie settings, or closing that panel does not currently switch off the measurement scripts. We do not represent those actions as a stored acceptance, rejection, or withdrawal of consent.
You can control website access and storage through your browser and privacy tools, avoid starting an optional preview, manage permissions in iOS, disconnect an identity-provider connection, and use the relevant account or deletion controls. Blocking scripts may affect previews or other functionality. Browser-level choices do not automatically remove information already received by a provider.
Where consent is required for a processing activity, an appropriate affirmative choice is necessary; a no-cookie design or a legitimate-interest statement does not automatically settle that requirement. If we introduce advertising, sale, or other consent-dependent processing, the notice and controls must reflect the new practice before it begins. You can also use the request route to object or ask how a choice affects your information.
Policy changes and version history
We may update this policy when features, providers, data flows, or legal requirements change. The version and date identify this notice. For a material change, we will provide additional notice appropriate to the change and required by law, such as a prominent website or in-app notice. Where new consent is required, a notice alone is not sufficient.
A policy update does not remove rights that already apply, authorise an incompatible use of information retroactively, or change an independent provider’s legal obligations. The Terms of Service and EULA describe the service relationship; this policy explains personal-information handling. Mandatory privacy and consumer protections continue to apply.
Version 1.0 — 17 September 2026: expanded LumenDrift-specific notice covering local and connected app information, identity providers, Royal, website measurement and previews, the provider register, retention and deletion, request handling, children, and regional supplements.
You can print or save this page using the control at the top. If you need clarification about a previous notice or how a change affects information you already provided, contact Lumenshore through the privacy-request route.
United Kingdom and European Economic Area
These supplements explain regional rights in addition to the main policy. They apply where the relevant law covers our processing, taking account of its territorial scope, exemptions, and commencement dates. The same request route is available regardless of whether your country appears below. We do not infer your legal residence or age from your interface language.
For UK processing, the relevant framework includes the UK GDPR and Data Protection Act 2018, as amended. For processing covered by EU/EEA law, the GDPR and applicable national legislation apply. Lumenshore Limited is the controller identified at the start of this policy. Our UK address is our company contact; it should not be read as an address for an EU representative.
The purposes and lawful-bases table, provider register, retention criteria, and international-transfer section explain the corresponding information for LumenDrift. You can ask for further detail about a legitimate-interest assessment or the safeguard applicable to a transfer. Where we rely on consent, it must be specific to the processing and capable of withdrawal.
Rights and independent oversight
You may have rights of access, correction, erasure, restriction, portability, objection, and protections concerning significant automated decisions, subject to the statutory conditions. The request-handling section explains the usual one-month response period, verification, and permitted extensions. An objection to direct marketing does not need a reason.
In the UK, you can raise a concern with the Information Commissioner’s Office. In the EEA, you can complain to a supervisory authority, particularly in the country of your habitual residence, place of work, or alleged infringement. A UK company address does not remove your right to contact an EEA authority or seek a remedy in the competent court.
Electronic communications and device access
Rules governing electronic marketing and access to information on a device can apply separately from the GDPR, including UK PECR and national ePrivacy rules. The website’s current measurement and information-only Cookie settings panel are described openly above. Continued browsing is not recorded as consent. Where a particular use requires consent, the applicable requirement must be met before that use.
A local supplement below may add country-specific information, such as a child-consent threshold or post-death directions. It does not reduce the GDPR rights described in the main policy.
California notice and other United States privacy rights
Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies, this section supplements the collection and use disclosures above. State privacy laws have coverage thresholds and exceptions; we do not suggest that every law applies to every visitor solely because the website can be reached there.
The categories below reflect the LumenDrift processing described in this notice. Sources are you, your browser or device, authentication and purchase providers, and people submitting authorised requests. Business purposes are providing accounts and media access, managing Royal, protecting and measuring the service, handling submissions, and meeting legal obligations. Retention follows the category-specific criteria in the main policy.
| Category | Examples and collection | Business-purpose recipients |
|---|---|---|
| Identifiers and account records | Name, email, account and installation identifiers, IP address and connection identifiers when the relevant feature is used. | Authentication, hosting, security, and account-service providers. |
| Commercial information | Royal product, transaction, renewal, expiry, and entitlement information; not your full payment-card details. | Apple, RevenueCat, and backend infrastructure. |
| Internet or electronic activity | Page and preview requests, performance measurements, technical diagnostics, and relevant service events. | Website measurement, delivery, security, and operational-monitoring providers. |
| Approximate location | Broad location derived from website connection information; not a request for precise GPS coordinates. | Website infrastructure and measurement providers. |
| Preferences and submitted content | Account preferences, messages, reports, and information you choose to include. Local listening information is described separately. | Relevant service infrastructure and authorised people handling the submission. |
| Sensitive information, where involved | Credentials used to secure account access and sensitive details you may voluntarily put in a message. Ordinary listening does not require medical records, biometrics, or precise location. | Providers and authorised people necessary for that limited purpose; no sensitive-information advertising profile. |
Sale, sharing, and sensitive information
We do not sell personal information or share it for cross-context behavioural advertising. We do not knowingly sell or share information about people under 16. There is no paid privacy incentive or different Royal price in exchange for permission to sell your information. Our no-sale and no-advertising-sharing practice applies whether or not you send an opt-out signal.
Sensitive information is not used to infer characteristics for targeted advertising. Where a statutory right to limit sensitive-information use applies, you can exercise it through the privacy-request route. Necessary authentication and the specific service you request can still require the relevant information.
Requests, agents, and state-law appeals
Covered California rights include knowing and accessing information, correcting inaccuracies, requesting deletion, opting out of sale or sharing, limiting certain sensitive-information uses, and freedom from unlawful discrimination for exercising those rights. You may appoint an authorised agent; we may verify both the agent’s authority and your identity as allowed by law. Covered access, correction, and deletion requests generally receive a response within 45 calendar days, with a permitted extension explained to you.
Other state laws may provide access, correction, deletion, portability, opt-outs from targeted advertising, sale, or qualifying profiling, and a right to appeal a refusal. Use the contact route below and identify the decision you want reconsidered. We will apply any required state-specific appeal deadline and explain the relevant regulator complaint route if an appeal is denied. We do not currently conduct the targeted-advertising or significant profiling activities described above.
Universal opt-out mechanisms such as Global Privacy Control have a legally defined scope. Our website does not currently use that signal to disable ordinary Vercel measurement; this limitation does not change the no-sale and no-advertising-sharing practices or remove a statutory opt-out right.
Canada, including Québec
Where PIPEDA or applicable provincial private-sector privacy law governs, you can ask about the existence, use, and disclosure of your personal information, request access, and challenge its accuracy or completeness. Consent must be meaningful for the purpose and sensitivity involved. Withdrawal may be subject to lawful or contractual limits, which should be explained.
PIPEDA access requests generally require a response within 30 days; limited extensions require an explanation and notice of the complaint right. Québec also generally requires a response to an access or correction request within 30 days. Provincial requirements may apply instead of, or alongside, federal rules.
Québec choices and overseas processing
Québec law can provide additional rights concerning portability of certain computerised information, consent, and information used for exclusively automated decisions. The current LumenDrift data flows and recommendation limits are described above. Requests about these matters can be addressed to Lumenshore through the privacy contact; an account is not required to raise a concern.
Service providers may process information outside Canada or Québec. The transfer section explains the international service model; your request can ask for the recipient, purpose, and relevant safeguards. You can complain to the Office of the Privacy Commissioner of Canada or the appropriate provincial authority, including Québec’s Commission d’accès à l’information.
Brazil — Lei Geral de Proteção de Dados
Where Brazil’s LGPD applies, you can request confirmation of processing, access, correction, information about shared use, and anonymisation, blocking, or deletion of unnecessary, excessive, or unlawfully processed data. You may also have rights to portability, withdrawal of consent, and deletion of consent-based information, subject to statutory retention exceptions.
You can ask about the consequences of refusing consent and the entities with which information is shared. The purposes, sources, recipient categories, and retention criteria in this policy describe the relevant LumenDrift activities. A lawful basis must fit the actual purpose; optional consent cannot be assumed from ordinary browsing.
If you challenge a decision made solely through automated processing that affects your interests, we will consider the review and explanation rights provided by the LGPD. LumenDrift’s current local suggestions and prepared message replies are described above; they are not a medical or credit assessment.
International transfers must meet the applicable LGPD requirements and ANPD rules. Contact Lumenshore through the privacy-request route for rights or transfer questions. You can petition or complain to the Autoridade Nacional de Proteção de Dados where its procedures apply.
Japan — Act on the Protection of Personal Information
Where Japan’s APPI applies, the stated purposes of use are the account, listening-service, subscription, security, website, request-handling, and legal purposes described in this policy. We should not use personal information beyond a permitted purpose without the authorisation required by law.
You may request disclosure of retained personal data and relevant third-party provision records, correction of inaccurate information, and cessation of use, deletion, or cessation of third-party provision where the statutory conditions apply. The scope and exceptions differ from GDPR terminology; we will assess the request under the applicable Japanese requirements.
Foreign transfers may require consent and specified information or another recognised APPI route, together with continuing safeguards where required. Our provider register and international-transfer section identify the service roles; you can request details of the relevant overseas recipient and protection measures. A provider’s country of incorporation alone does not establish the transfer’s lawfulness.
Use the privacy-request route to exercise a right or raise a concern. You can also seek guidance from Japan’s Personal Information Protection Commission. Verification should be proportionate and should not require unrelated sensitive information.
Mainland China — Personal Information Protection Law
Where the PIPL applies, you may have rights to know and decide about processing, restrict or refuse it, access and copy information, correct it, request deletion in the specified circumstances, and request an explanation of processing rules. Withdrawal of consent applies where consent is the basis.
The PIPL does not provide a general legitimate-interests basis equivalent to the GDPR. Processing must fit a ground recognised by the PIPL, and separate consent may be required for matters such as sensitive information or overseas provision. Children under 14 receive specific protection; LumenDrift does not provide a child-information collection flow that substitutes a general policy acceptance for guardian consent.
An overseas transfer may require additional information about the recipient, a permitted transfer mechanism, an impact assessment, and other conditions depending on the circumstances. This notice does not assert that a security assessment, certification, or filing has been completed merely because a global provider is listed.
You can use the privacy-request route for information, correction, deletion, consent withdrawal, or an explanation. Where mandatory local conditions cannot be met for a feature, that feature must not process the information in a way that disregards those conditions.
South Korea — Personal Information Protection Act
Where South Korea’s PIPA applies, you can request access, correction, deletion, and suspension of processing, subject to the law’s conditions and exceptions. Applicable rights relating to automated decisions and transmission of personal information must also be considered. You may exercise rights through a duly authorised representative.
Overseas processing requires a lawful route and the information or choices required for that route, including recipient and purpose details where applicable. The provider register and transfer section explain LumenDrift’s service model; contact us for the details relevant to your information. We do not treat broad agreement to this policy as permission for every overseas disclosure.
The law provides particular safeguards for children under 14, including legal-guardian consent where required. A family listening feature is not a child-account consent process. If you believe a child’s information has been collected improperly, use the privacy-request route so we can assess and address it.
The Personal Information Protection Commission provides guidance and oversight. Its rules can apply to overseas businesses where the relevant criteria are met. The identity of an overseas provider does not remove your applicable rights or the obligations associated with a reportable breach.
Australia and New Zealand
Australia
Where the Australian Privacy Act and Australian Privacy Principles apply, you may request access to personal information and correction of information that is inaccurate, out of date, incomplete, irrelevant, or misleading for its purpose. A refusal must have a permitted basis, and the available complaint route should be explained.
Overseas disclosures and eligible data breaches have specific requirements under the applicable Australian framework. Our transfer and breach sections describe the general approach; they do not remove those obligations. You can first raise a concern with Lumenshore and may then complain to the Office of the Australian Information Commissioner in accordance with its process. Coverage and exemptions are assessed under the law, rather than assumed solely from a website visit.
New Zealand
Where New Zealand’s Privacy Act 2020 applies, you can ask for access to your personal information and request a correction. If a correction is not made, you can ask for a statement of the correction sought to be attached where the law provides. A decision on an access or correction request is generally required within 20 working days, subject to permitted extensions.
Overseas disclosure and notifiable-breach requirements apply according to their legal conditions. You can contact Lumenshore through the privacy-request route or raise a concern with the Office of the Privacy Commissioner. The fact that our controller is based in the UK does not itself remove rights that apply under New Zealand law.
India — the developing DPDP framework
India’s Digital Personal Data Protection Act 2023 and the Digital Personal Data Protection Rules 2025 have a staged commencement. This notice does not present every provision as already in force. The applicable obligations and rights depend on the provision’s commencement, the processing involved, and any relevant exemption.
As the relevant provisions become applicable, the framework includes rights concerning information about processing, correction and erasure, grievance redressal, and nomination of another person to exercise rights in specified circumstances. Consent must satisfy the applicable notice and choice requirements, and it must be possible to withdraw it as the law provides.
The framework contains specific requirements for children’s information, including a statutory under-18 definition subject to the applicable provisions and exemptions. We do not treat the general under-13 statement in this policy as replacing an Indian child-protection requirement or claim to operate a verified parental-consent system that the app does not provide.
Use Lumenshore’s privacy-request route for a request or grievance about LumenDrift information. Any statutory escalation to the Data Protection Board follows the provisions and procedures in force. The official commencement materials linked below govern the rollout; a future commencement does not prevent you from raising a present concern with us.
Switzerland — Federal Act on Data Protection
Where the Swiss FADP applies, you can ask whether personal data about you is processed and obtain the information needed to understand that processing, including purposes, recipients, retention, and relevant overseas disclosure. Access information is generally provided free of charge within 30 days, subject to the applicable exceptions.
You may seek correction of inaccurate data and the available remedies to stop unlawful processing or obtain deletion. The conditions for portability and protections concerning automated individual decisions apply where their statutory requirements are met. LumenDrift’s current recommendation and automation practices are described in the main policy.
Overseas disclosure requires the protection recognised by Swiss law, such as a recognised adequate destination or appropriate safeguards. An EU or UK mechanism does not automatically answer every Swiss requirement. You can request information about the destination and safeguard relevant to your data.
Contact Lumenshore through the privacy-request route. You can also consult the Federal Data Protection and Information Commissioner or seek the remedy available before the competent court. This notice does not claim a local representative exemption or designate an unverified Swiss representative.
Germany — GDPR, BDSG, and device privacy
For processing covered by German law, the GDPR operates alongside the Federal Data Protection Act and other applicable rules. The rights, purposes, provider information, and request process in the main policy apply. You may complain to a competent German data-protection authority; a local authority can help determine the appropriate jurisdiction.
Section 25 of the Telecommunications-Digital-Services Data Protection Act (TDDDG) separately governs storing information on, or accessing information from, terminal equipment. Consent is generally required unless a statutory exception applies, including qualifying strictly necessary activity. A technology’s not using a traditional cookie does not itself remove this requirement.
The current website’s measurement loads without a saved optional-analytics choice, and Cookie settings is informational. The Cookie Policy describes that behaviour. We do not label continued browsing as consent or assume that all measurement is exempt simply because its reports are aggregate.
For consent-based information-society services offered directly to children, the GDPR age threshold in Germany is 16. This specific consent rule does not determine every aspect of a minor’s legal capacity or replace the protections described in the children’s section.
France — Informatique et Libertés
Where French law applies, the GDPR and the French Data Protection Act provide the rights described in the main policy, with national provisions that may add protections. You can exercise rights through Lumenshore’s privacy-request route and complain to the Commission nationale de l’informatique et des libertés (CNIL).
French law allows directions concerning the retention, erasure, and communication of personal data after death, within the applicable legal conditions. A person entitled to act may contact us about such directions or a deceased person’s account. We will verify their authority and consider other people’s privacy; being a relative does not automatically grant unrestricted access to every message.
For consent-based online services, France uses a threshold of 15 for a child’s independent consent. Below that age, the applicable joint consent requirements involving the child and a holder of parental authority must be met. This is not a general permission to collect children’s information.
Cookies and similar technologies remain subject to the relevant French rules and CNIL guidance. Our current browser storage and measurement disclosures appear in the Cookie Policy; reading this page or closing an information panel is not recorded as consent.
Poland — RODO and national protections
Where Polish law applies, the GDPR (RODO) and applicable national rules govern the processing. You may request access, correction, deletion, restriction, portability, and objection where the conditions for each right are met. Consent can be withdrawn for a consent-based purpose without making earlier lawful processing unlawful.
The right to erasure is not absolute. For example, a specific legal duty or a justified claim may require limited retention. We should explain the reason and restrict remaining information to that purpose. Our account-deletion section describes the difference between active service records, completion evidence, local device data, and backup copies.
You can complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych). You do not need to send your request in legal language, and a complaint or request does not require a Royal subscription. The UK location of Lumenshore does not remove rights that apply to our processing under Polish or EU law.
National rules on electronic communications and device access can apply in addition to the GDPR. A Polish language or locale setting is not evidence that a user has consented to tracking, disclosed an age, or authorised a new purpose.
Ukraine — protection of personal data
Where Ukraine’s Law on Personal Data Protection applies, you can ask about the sources and location of your data, the purpose of processing, the controller and recipients, and the conditions of access. Applicable rights include access, a reasoned objection, correction or destruction of unlawfully processed or inaccurate information, and withdrawal of consent where relevant.
The main policy describes the LumenDrift categories, purposes, recipients, retention criteria, and international service model. Transferring information abroad must satisfy the legal conditions that apply to the transfer. Merely listing an international provider is not a substitute for those conditions.
Use Lumenshore’s privacy-request route to exercise a right or explain a concern. The Ukrainian Parliament Commissioner for Human Rights provides information and oversight concerning personal-data protection, and judicial remedies may also be available. We will assess the request under the applicable law rather than assuming that an interface language determines your rights.
The current app does not require medical records, school information, or precise location for ordinary listening. Please avoid including such information in a report unless it is necessary to explain the specific issue you want us to address.
Spain and selected Latin American jurisdictions
A shared language does not create a single privacy regime. The following points apply under the relevant local law; the general contact route remains available in each case. Brazil has its own supplement above.
Spain
The GDPR and Spain’s Organic Law 3/2018 provide rights including access, correction, deletion, objection, restriction, and portability where applicable. Spain generally uses 14 as the age for a child’s own data-protection consent, subject to other legal rules. You can raise a complaint with the Agencia Española de Protección de Datos (AEPD). The main policy explains our actual data uses and request process.
Argentina
Where Law 25,326 applies, you may ask about and access personal data and request correction, updating, or deletion in the circumstances provided by law. Information about the purpose, recipients, controller, and consequences of providing data should be clear. The Agencia de Acceso a la Información Pública (AAIP) provides guidance and accepts complaints under its procedures.
Mexico
Where Mexico’s private-sector personal-data law applies, you can exercise access, rectification, cancellation, and opposition rights (ARCO), and withdraw consent where permitted. Identify the information and right involved when contacting us. Necessary service purposes and optional communications are distinguished in this policy. The federal framework was replaced in 2025; the current statute and competent authority govern, rather than an assumption that the former INAI procedure remains unchanged.
Colombia
Where Colombia’s data-protection regime applies, you may know, update, and correct your information, request information about its use and proof of authorisation where required, and seek revocation or deletion subject to lawful exceptions. You can use the required consultation or complaint process and, where applicable, raise the matter with the Superintendencia de Industria y Comercio (SIC).
United Arab Emirates, Saudi Arabia, and Bahrain
These countries have distinct privacy frameworks. This supplement does not assume a single regional consent rule, a universal data-localisation requirement, or that a website visit alone establishes the application of every local law.
United Arab Emirates
Where the UAE federal personal-data framework applies, rights can include information, access, correction, erasure, and objections or restrictions concerning particular processing, subject to the law’s conditions. Cross-border transfers require an applicable legal route. Separate regimes can apply in jurisdictions such as the DIFC and ADGM; the relevant establishment and processing determine the framework, rather than a generic reference to the UAE.
Saudi Arabia
Where the Saudi Personal Data Protection Law applies, you may have rights to be informed of the legal basis and purpose, access your data, obtain a readable copy, request correction or completion, seek destruction where the conditions apply, and withdraw consent. Overseas transfers must meet the applicable law and regulations. The Saudi Data and AI Authority (SDAIA) provides the relevant regulatory materials and complaint information.
Bahrain
Where Bahrain’s Personal Data Protection Law applies, the processing must have an appropriate basis and respect applicable rights of information, access, correction, and objection or erasure. Overseas transfer conditions are assessed separately from a provider’s ordinary service terms. The Personal Data Protection Authority provides the applicable guidance and procedures.
Making a regional request
Contact Lumenshore using the privacy-request route and identify your concern and the information involved. You can ask about the relevant recipient, transfer route, purpose, or retention criterion. We do not require you to identify the exact statutory article before considering the request, and any mandatory local protection takes priority over an inconsistent service term.
Clarity is part of the calm.
Back to top ↑