Lumida
Privacy policy
This policy explains how Lumida handles personal data when you create an account, connect Google Health or use the service.
Last updated on August 17, 2026
Data controller
The controller for personal data processed by Lumida is Eddy Nicolle, sole trader.
Our core principle
Your health data remains yours. Lumida retrieves it only to display the features you request and does not build a permanent copy of your health measurements in its database.
Data we process
Depending on how you use Lumida, the following categories may be processed:
- Account data: first name, email address, profile image when supplied by Google, verification state, role and account dates.
- Authentication and security data: password hash, provider account identifier and, where required, tokens used for social sign-in, session token, session expiry, IP address, user agent, verification records and rate-limit counters.
- Beta-access administration data: the Google account email you submit, request language, request date and approval date.
- Service preferences and administration data: language selected through the URL, appearance stored on the device, temperature unit, latest coarse activity date and any account restriction information.
- Google Health connection data: stable Google identifier, granted permissions, connection status and dates, and the encrypted refresh token needed to maintain the connection.
- Health and fitness data requested on demand: activity and exercise, sleep, heart rate, oxygen saturation, recovery measurements, weight, nutrition, hydration and, when authorized, workout location routes.
- Product-feedback and communications data: feedback messages, account linkage, app language, time zone, normalized source page, viewport size, user agent and deployment version, plus email content and technical metadata when you contact Lumida or receive a transactional message.
- Waiting list data: the email address you submit when early access is full, the language of the request, its confirmation state and the related dates. No IP address is stored.
- Bot protection: the public waiting-list form is protected by Cloudflare Turnstile, which checks that the request comes from a real browser. Cloudflare receives your IP address and technical browser signals for that check alone; Turnstile collects no data for advertising retargeting. It runs on the public home page only, never on signed-in pages.
Purposes and legal bases
- Providing the account, authentication, preferences and requested service features: performance of the contract formed by these terms.
- Protecting accounts, preventing abuse, administering beta access and maintaining the service: Lumida’s legitimate interests in security and reliable operation.
- Retrieving and displaying Google Health data: your explicit consent under Articles 6(1)(a) and 9(2)(a) of the GDPR.
- Reviewing product feedback, responding to requests and sending account, security and access messages: performance of the service and Lumida’s legitimate interests in improving Lumida and answering users.
- Complying with legal obligations and establishing or defending legal claims: legal obligation or legitimate interest, as applicable.
Consent for health data
Connecting Google Health is optional. The connection flow explains that access is used to display your data in Lumida, then Google presents the requested read-only categories and asks you to approve them. Lumida does not use acceptance of the terms as consent for health-data processing.
You may withdraw consent at any time by disconnecting Google Health in Lumida. Lumida then revokes the Google grant where possible and deletes the local connection record. Withdrawal does not affect processing lawfully carried out beforehand.
Google Health Limited Use
Lumida’s use of information received from the Google Health API adheres to the Google Health API Developer and User Data Policy, including its Limited Use requirements.
How health data is handled
Health measurements pass through Lumida’s server only for the time needed to answer your request and are never written to the database. To make the interface faster, summaries you have already viewed are kept in a local cache on your device (browser memory and IndexedDB browser storage). This cache never leaves your device, expires automatically after 30 days at the latest, is deleted when you sign out, and can be disabled at any time in the app settings — for example on a shared computer. Workout GPS routes are never written to browser storage and remain in memory only.
Google Health refresh tokens are encrypted at rest using AES-256-GCM. Access tokens remain server-side and are kept only in short-lived process memory. OAuth tokens are never exposed to the browser; the only health data on your device is the local cache described above, under your control.
Recipients and service providers
Personal data is disclosed only as needed to operate Lumida, to the following categories of providers:
- Hetzner: application hosting and server execution (Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (Nuremberg NBG1 data center)).
- Neon / Databricks: PostgreSQL account database (Neon (Databricks), AWS eu-central-1, Frankfurt, Germany). Health measurements are not stored there.
- Resend: transactional email delivery (Resend, AWS eu-west-1, Ireland).
- Google: social sign-in, OAuth authorization and the Google Health API, when chosen by the user.
- Cloudflare: content delivery network placed in front of the application: DNS, attack protection and TLS termination, so all traffic including health data in transit passes through its network; also routes messages sent to Lumida contact addresses (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, United States).
- OpenStreetMap: map-tile delivery for a visible workout area; the complete route line is not uploaded to OpenStreetMap.
International transfers
The application is hosted in Germany, the primary database region is Frankfurt and transactional email data is processed in Ireland. Some providers are established in the United States or may provide support from outside the European Economic Area. Where required, transfers rely on an adequacy mechanism such as the EU–US Data Privacy Framework, standard contractual clauses or another safeguard made available by the relevant provider.
Retention periods
- Account data is kept while the account remains active, then deleted following a verified deletion request, except where retention is legally required.
- Health measurements are not retained in the database; the temporary server-side handling and the on-device cache under your control are described above.
- Google Health connection data is retained until you disconnect Google Health or the account is deleted.
- A Google Health OAuth transaction expires after 10 minutes, an email-verification link after one hour and a password-reset link after 15 minutes.
- Account-linked product feedback is kept while useful for improving Lumida and is deleted with the account, unless retention is needed for a legal claim. Other correspondence is kept for the time needed to answer and manage follow-up.
- A waiting-list address is kept until you unsubscribe with the link carried by every message.
- Technical security and hosting logs are retained for limited periods according to provider settings and legitimate security needs. Provider backups may remain until their normal rotation completes.
Your rights
Subject to the conditions of the GDPR, you may exercise the following rights:
- access and correct your personal data;
- request erasure of your account data;
- object to or request restriction of certain processing;
- receive data you provided in a portable format where applicable;
- withdraw consent at any time, without affecting prior lawful processing.
You may also lodge a complaint with the French data-protection authority, the CNIL.
Security
Lumida applies measures designed to protect personal data, including server-side OAuth handling, encryption of Google Health refresh tokens, secure cookies, access controls, input validation and rate limiting. No online service can guarantee absolute security; users should also protect their credentials and devices.
Adults only
Lumida is reserved for people aged 18 or over and does not knowingly provide accounts to minors. If a minor’s data is identified, it may be deleted after appropriate verification.
Changes to this policy
This policy may be updated when Lumida’s features, providers or legal obligations change. The effective date appears at the top of the page, and material changes will be communicated by an appropriate means.
Privacy contact
To exercise your rights or ask a privacy question, contact Lumida using the dedicated address below. Identity verification may be requested when reasonably necessary to protect the account.
Hidden until requested to limit automated collection.