Privacy Policy

Effective: July 30, 2026

1. Overview

Luminarot is built on trust. This policy explains what data we collect, why we need it, and how we protect it. We believe privacy is a right, not a setting buried behind eight menus.

2. Data We Collect

Account data

Email address, hashed password (never stored in plaintext), and optional profile details: birth date, birth time, birth place, and preferred reflective tone.

Usage data

Daily card draws (which card, upright/reversed, mood context), journal entries, evening check-ins, card upgrade prompts, and generated AI images. We also log basic anonymized analytics: page views, feature usage counts, and session duration.

We do NOT collect

3. How We Use Your Data

4. What We Never Do

5. Data Storage & Security

Your data is stored on encrypted PostgreSQL databases with access restricted to the application server. Authentication uses bcrypt password hashing and httpOnly JWT session cookies. We follow industry best practices for server hardening, regular dependency updates, and principle of least privilege.

6. Cookies

Luminarot uses a single httpOnly session cookie for authentication. No tracking cookies, no third-party advertising cookies, no fingerprinting scripts. We do not use Google Analytics or any cross-site tracking.

7. Your Rights

8. Third-Party Services

Card upgrade images are generated via the KIE AI API. Image prompts and generated images are transmitted to and stored by the KIE service. No personal identifiers are sent with image generation requests.

9. Children's Privacy

Luminarot is not intended for children under 13. We do not knowingly collect data from children under 13. If we discover such data, we will delete it immediately.

10. Changes to This Policy

Material changes will be communicated via email or in-product notice. Continued use after changes constitutes acceptance.

Contact

Privacy questions: hello@luminarot.com