Privacy Policy
Your data, plainly.
Last updated · August 24, 2026
Luminelle is operated by HushThrive SRL. This policy explains what we collect, why we collect it, who we share it with, and the rights you have. It applies to the Luminelle mobile app, the website at luminelle.ai, and our backend services.
1. Who we are
HushThrive SRL is the data controller for the personal data described in this policy.
HushThrive SRL
Strada Verzișori, Nr. 6, Bl. D, Ap. B118
Sectorul 4, București, 040301, Romania
CUI 53282190 · Nr. Reg. Com. J2026002531005 · EUID ROONRC.J2026002531005
For any privacy question or data-rights request, email info@luminelle.ai.
2. What we collect
Account data
- Email address, username, and display name.
- Date of birth - used to enforce the 13+ minimum age and to tailor age-appropriate features.
- Biological sex (female, male, nonbinary, or prefer-not-to-say) - used by cycle and nutrition features.
- A profile picture, if your sign-in provider supplies one. Otherwise we generate a placeholder avatar from your account details.
- A sign-in identifier from your chosen sign-in method (Apple or Google).
Health and wellness data
- Menstrual cycle data: period start dates, cycle length, period length, and current phase.
- Daily journal entries: redness, breakouts, and stress on 0-100 scales, plus free-text notes you choose to write.
- Nutrition: daily calorie target, nutrition goal, and the meals you log.
- Skincare concerns you select during onboarding.
This is special-category personal data under EU law, and we process it on the basis of your explicit consent. You can withdraw that consent at any time by deleting the relevant entries or your account.
Once a week, if you have allowed AI analysis, the free-text notes from your journal entries of the last seven days are sent to Microsoft Azure OpenAI so it can draft the qualitative observations in your weekly summary. Your cycle dates, symptom scores, and the rest of your health data are not sent - those patterns are computed statistically on our own servers. Turning AI analysis off in Settings → Privacy & data stops your notes being sent.
Face data
The daily selfie is optional. When you choose to take one, the face data we collect is the photograph of your face that you capture, together with up to five close-up crops of that same photograph - forehead, nose, left cheek, right cheek, and jaw - which your phone cuts from it. We collect no other face data.
We do not create, derive, or store a face template, faceprint, face embedding, or any other biometric identifier. We never use face data to identify or authenticate you, to recognise you across photographs, for advertising, or to train AI models, and we never sell it. Your phone runs its own built-in, on-device face detection - Apple's Vision framework on iPhone, Google's ML Kit on Android - to locate your eyes, nose, and mouth so it knows where to cut the five crops; those measurements stay on your device, are used only to compute the crop rectangles, and are never transmitted to us or to anyone else.
The photograph and its crops are sent, over an encrypted connection, to Microsoft Azure OpenAI - reached through Cloudflare's AI Gateway - which analyses them for visible skin characteristics and returns a written result. Microsoft and Cloudflare act as our processors and are not permitted to use your face data for their own purposes or to train their models. They are the only third parties that ever receive it. We ask for your permission inside the app, and name Microsoft there, before any selfie is sent; you can withdraw that permission at any time in Settings → Privacy & data, and no selfie is sent after you do.
We do not store the photograph or its crops on our servers. They exist in memory only for as long as the analysis request takes, typically a few seconds, and are discarded when it completes. What we retain is the written result - observations, recommendations, and numeric skin scores - stored with your account for as long as your account exists, so the app can show you change over time. You can delete a day's result from the app at any time, and deleting your account deletes all of them.
The original selfie is saved on your own phone, inside the Luminelle app's private storage, so you can see your history. It is never uploaded to us. It is removed when you retake that day's selfie, when you delete it, or when you delete your account.
Selfies
Alongside the analysis result, we record the date and time you took a selfie so the app can count streaks and award badges. That record contains nothing derived from the image itself, and it is deleted with your account.
Product and meal scans
When you scan a product label or a meal, the image is sent to our servers and on to Microsoft Azure OpenAI for analysis. We use the result - ingredients, category, calorie estimate, safety status - and don’t keep the image. Scanning a barcode alone sends no photograph anywhere and works whether or not you allow AI analysis. For meals and food products, a copy of the photo is also saved on your phone so you can see it in your in-app history. Ingredient-label scans are processed in memory and the photo is not stored anywhere.
We store a record of your scans - product, brand, ingredients, the computed status - so your history is available across your devices.
Products you submit
If you submit a product that is missing from our catalog, the photos you take of its packaging are uploaded and kept, along with a reference to your account, so we can review the submission and add the product. This is the one photo flow where we retain the image. They are also sent to our AI provider, which reads the name, brand, and ingredient list off the packaging. An approved product photo becomes part of the public catalog and is served to anyone who scans that product; your identity is never shown alongside it.
Subscription and billing
Apple App Store and Google Play handle your payment. We do not collect or store payment card details. We receive your subscription state (active or lapsed, tier, expiry) from our subscription provider.
Device and usage data
- A push-notification token and your notification preferences.
- In-app product analytics: which features you use and when - for example signing in, finishing onboarding, completing a scan, logging a meal, opening the paywall, subscribing. These events carry your account id and email address so we can measure retention, and a few onboarding events also carry the choices you made there (the wellness areas you picked and your nutrition goal). Your journal entries, cycle dates, selfies, and selfie analyses are never sent to analytics.
- Session replay: a periodic screenshot of the app, roughly once a second, so we can see where a flow confuses people. Every text field is masked before the screenshot leaves your phone, and so is every photo of you or taken by you - your selfies, your meal and label photos, your profile picture. What stays visible is the app’s own artwork and the product images from our catalog. Recording is switched off completely whenever the front camera, a selfie, a label or meal photo, or a photo analysis is on screen - so your face, your labels, and your meals are never recorded. The one camera view we do record is the barcode scanner. Replay is stored in the EU.
- Device and app context that the analytics and push SDKs collect by default: device model, OS version, app version, and locale.
- Basic web analytics on luminelle.ai (page views, referrer, approximate region).
3. Why we use your data
- To provide the Service - scanning, scoring, syncing, and any notifications you opted into.
- To process your cycle, journal, and selfie data - based on your explicit consent.
- To send transactional messages such as subscription receipts and account notices.
- To send optional marketing emails or push messages, if you’ve consented.
- To understand how the app is used, in aggregate, so we can fix what is broken and improve what is not - never for advertising.
- To prevent abuse, fraud, and security incidents.
- To keep tax records for paid subscriptions, as required by law.
4. Where your data lives
Your account, history, and synced data are stored on servers in the EU. Data is encrypted in transit and at rest.
5. Providers we work with
The third parties that process Luminelle data on our behalf:
- Supabase - database and authentication.
- Cloudflare - backend hosting, request routing, and storage for the product photos you submit.
- Microsoft Azure OpenAI - the AI analysis of your selfies, product and meal photos, the photos you submit to the catalog, ingredient text read from labels, and your journal notes. We reach it through Cloudflare's AI Gateway. We ask for your permission in the app, naming Microsoft, before anything is sent, and you can withdraw it in Settings → Privacy & data.
- PostHog (EU region) - in-app product analytics and session replay. Replay records how you move through the app, with all text you type and all images masked out, and it is switched off entirely on the selfie and photo-capture screens.
- RevenueCat - subscription state.
- OneSignal - push notifications.
- Apple - sign-in (if you choose it) and App Store subscription billing.
- Google - sign-in (if you choose it), Google Play subscription billing on Android, and website analytics. On Android, push notifications are delivered through Google's Firebase Cloud Messaging.
We also query public product databases when you scan a barcode. These requests include the scanned barcode but no user identifiers.
6. International data transfers
Some of our providers are headquartered outside the EU, including in the United States. Where personal data is transferred outside the EEA, we rely on the European Commission’s standard contractual clauses and applicable safeguards. Encryption in transit and at rest applies in all cases.
7. How long we keep your data
- Account data - while your account is active, and for up to 30 days after a deletion request to complete the purge.
- Cycle, journal, scan, and selfie analysis records - deleted with your account, or earlier if you remove individual entries.
- Face data - the selfie photograph and its close-up crops are not retained. They exist only in memory for the few seconds the analysis request takes, and are discarded when it completes. No face template or biometric identifier is ever created, so none is retained. The written analysis result is kept for the life of your account and can be deleted per day from the app. The original selfie stays on your own phone until you retake it, delete it, or delete your account.
- Photos from product submissions - the submission record, including the link to your account, is deleted with your account. The photo itself is stored separately, and an approved one stays in the public product catalog detached from your account. To have a photo you submitted removed, email us.
- Analytics events - retained by our analytics provider under its retention settings, and deleted on request.
- Backups - rolling deletion within 30 days.
- Subscription invoices and tax records - retained as required by Romanian tax law.
8. Your rights
You have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased.
- Restrict processing of your data.
- Receive your data in a portable, machine-readable format.
- Object to processing based on our legitimate interest.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with your local supervisory authority. In Romania this is ANSPDCP.
To exercise any of these rights, email info@luminelle.ai. We respond within 30 days.
9. California residents
The categories of personal information we collect are listed in section 2 above. In the last 12 months, we have not sold personal information, and we have not shared personal information for cross-context behavioral advertising. You have the right to know, delete, correct, and limit the use of sensitive personal information (your cycle and journal data qualify). To exercise these rights, email info@luminelle.ai.
10. Children
Luminelle is intended for users 13 and older. If you are under the digital consent age in your country (for example, 16 in Romania), you need consent from a parent or guardian. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, email info@luminelle.ai and we will delete it.
11. Automated analysis
We use AI to analyze your daily selfie, your product and meal photos, the photos you submit to the catalog, ingredient text read from labels, and your journal notes when we build your weekly summary. This processing is carried out by Microsoft Azure OpenAI on our behalf, and we ask for your permission in the app - naming the provider and listing what is sent - before anything leaves your device.
The output - observations, recommendations, scores - is informational. It does not constitute a medical diagnosis or any decision with legal or similarly significant effect on you. You can decline, or withdraw your permission later in Settings → Privacy & data; the rest of the app - barcode scanning, your routine, cycle tracking, and your journal - continues to work without it.
12. Security
Our security practices are described on our Security page.
13. Cookies
luminelle.ai uses cookies in two categories. The Luminelle mobile app does not use browser cookies.
Strictly necessary
These cookies are required for the site to work and cannot be disabled. They are first-party and not shared with anyone.
- Supabase auth cookies (
sb-*) - keep you signed in across pages. Expire when your session ends.
Analytics (opt-in)
These cookies are only set if you accept the analytics category in the cookie banner. We use Google Analytics 4 to understand site traffic in aggregate - we do not use the data for advertising and we do not sell it.
- _ga, _ga_* - Google Analytics. Distinguish visitors. First-party, expires after 2 years.
- _gid - Google Analytics. Distinguish visitors. First-party, expires after 24 hours.
Until you accept, Google Analytics runs in cookieless mode using Google Consent Mode v2 - no analytics cookies are set and no identifiers are sent. If you withdraw consent later, any analytics cookies already set on your device are deleted.
Managing your choice
You can change your preferences at any time. The same option is available from the “Cookie settings” link in the footer of every page.
14. No ads, no data sold
We do not show advertising in Luminelle. We do not sell your personal data and we do not share it with third parties for their own marketing.
15. Changes to this policy
We will update the “Last updated” date when we revise this policy. For material changes we will notify you in the app or by email.
16. Contact
For privacy questions or to exercise any of the rights above, email info@luminelle.ai, or write to HushThrive SRL at the address in section 1.