Privacy Policy
Last updated: July 21, 2026
This policy explains what data Lumday uses, why it is needed, and how you can control it.
1. Who is responsible for the app
Lumday is an app for birthdays, reminders, widgets, and personal greeting suggestions. Privacy questions can be sent to support@lumday.app.
2. Data you add
Lumday stores information you voluntarily add, including names, birthdays, groups, notes, avatar emoji, and selected photos. This information is used for your people list, search, profiles, reminders, backups, and widgets.
3. Storage and iCloud
Data is stored on your device using Apple system technologies. If iCloud is enabled, Lumday uploads saved records to your private Apple CloudKit database so they can synchronize between devices connected to your Apple Account and support reminders and widgets. Apple processes CloudKit data under Apple’s terms and privacy policy. Lumday does not use CloudKit records for advertising, analytics, or marketing.
4. Contacts and Photos
Lumday requests Contacts access only when you choose to import people. Before access is granted, the native iOS permission alert explains that, if iCloud is enabled, the names, birthdays, and photos of people you select are uploaded to your private iCloud database for synchronization, reminders, and widgets. You can deny access and continue using Lumday without contact import.
Lumday reads contact information on your device only to show import candidates and saves only the people you explicitly select. Lumday does not upload your full address book. Unselected contacts, phone numbers, email addresses, and Contacts identifiers are not saved or uploaded.
Photos access is requested only when you choose a photo for a person. The selected image is stored with that person’s Lumday record.
5. AI greetings
AI greeting generation is available only with Lumday PRO and is optional. Immediately before the first generation, Lumday asks for explicit consent to send the person’s full saved name, birthday and calculated age, group, note, selected tone, length, and language through the Lumday Cloudflare Worker to Cloudflare Workers AI using Google’s Gemma 4 model (@cf/google/gemma-4-26b-a4b-it).
The request is processed only to create the greeting. The Worker does not persist request or response content, connect AI content to an account or analytics identifier, or include names, birthdays, notes, prompts, or generated text in logs. Each request is stateless and sets store=false. Cloudflare states that it does not use Customer Content to train or improve models without explicit consent and does not store that content unless the customer explicitly uses a storage service. Lumday has not connected such a storage service for AI content.
You can reset this permission from the menu in the AI greeting generator. After a reset, Lumday asks again before the next AI request.
For each AI request, the Worker writes one aggregate operational metric to Cloudflare Analytics Engine: outcome, status class, language, tone and length category, model, normalized error code, duration, attempt count, and response character count. It uses a random request identifier unrelated to a person or account. The metric never contains the payload, IP address, prompt, name, birthday, notes, or generated greeting. Cloudflare retains these metrics for three months. The IP address is used momentarily only for rate limiting.
6. Apple analytics and diagnostics
Lumday does not include Firebase Analytics, Firebase Crashlytics, advertising analytics SDKs, session replay, or custom event tracking.
Apple may provide Lumday with privacy-preserving App Store Connect Analytics and Xcode Organizer diagnostics, such as downloads, sessions, retention, crashes, hangs, and performance metrics. Usage and quality metrics are based on users who choose in Apple system settings to share diagnostics and usage information with app developers. Apple applies privacy protections and minimum reporting thresholds, so some metrics may be unavailable when there is not enough data.
These Apple reports do not give Lumday access to names, contacts, birthdays, notes, photos, greeting text, advertising identifiers, or a history of actions connected to a particular person.
7. Website data
If you join the waitlist on lumday.app, we store the email address you submit, the signup date, the signup source, and the applicable consent version in Cloudflare D1. We use this information only to manage the Lumday launch waitlist and related product updates.
You can ask us to remove your waitlist email at any time by contacting support@lumday.app.
The website may use Cloudflare Web Analytics to understand aggregate page traffic without advertising profiles or cross-site tracking. Cloudflare may process limited technical data such as page, referrer, browser or device category, and approximate country under its own privacy terms. Legal pages do not set Lumday advertising cookies.
8. Notifications and widgets
Lumday schedules reminders locally through iOS system services. Notification permissions are controlled in iOS Settings.
Widgets receive a limited snapshot through an Apple App Group. When PRO access is inactive, widgets display a locked state without personal birthday data.
9. Purchases
Purchases are processed by Apple through StoreKit. Lumday receives transaction and entitlement status needed to unlock PRO features. Lumday does not receive your payment card details.
10. Backups, retention, and deletion
A backup file is created only when you request an export and is stored wherever you choose in Files or iCloud Drive.
App records are retained until you edit or delete them, clear the people list, remove synchronized data through Apple or iCloud settings, or uninstall the app where no synchronized copy remains. Waitlist records are retained until they are no longer needed for the stated purpose or you request deletion.
11. Advertising and tracking
Lumday does not use third-party advertising SDKs, does not sell personal data, and does not track users across other companies’ apps or websites.
12. Security
We use reasonable technical and organizational safeguards, including Apple system storage, private CloudKit, request validation, rate controls, and controlled backend error messages. No electronic storage method can guarantee absolute security.
13. Children
Lumday is not intended for independent use by children below the age at which they may legally consent to personal data processing in their country.
14. Policy changes
This policy may be updated as Lumday evolves or legal requirements change. The current version is always published on this page with its update date.
15. Contact
Questions or access and deletion requests can be sent to support@lumday.app.