Privacy Policy

Last updated: May 21, 2026

This policy applies to the Lumon personal life planning application (“the App”, “we”, “us”). It complies with the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL) and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Data Controller

The App is operated by Lumon AI FZE LLC, based in Ajman, UAE. Contact: askar@mylumon.ai

2. Data We Collect and Why

Data Purpose Lawful basis
Name & email addressAccount creation, sign-in, password reset emailsContract performance
Profile details (age, country, profession, etc.)Personalise the dashboard and AI responsesContract performance
Goals, tasks, milestonesCore planning functionalityContract performance
Financial transactionsBudget tracking and spending analysisContract performance
WHOOP health metrics (recovery, HRV, sleep, strain, resting HR)Display health dashboard widgetConsent (opt-in integration)
Google account profile & emailSign-in with GoogleConsent
Google Calendar access (events you ask us to create)Push tasks and rituals to your calendarConsent (opt-in integration)
AI conversation historyContext for the Lumon Agent; session continuityContract performance
Password hashSecure authentication for email/password accountsContract performance
Password reset tokens (hashed)One-time use reset links; auto-expire after 1 hourContract performance

We do not use your data for advertising, profiling for third parties, or any purpose beyond what is listed above.

3. Third-Party Processors

We share data with the following processors solely to operate the App:

  • ·AWS (Amazon Web Services) — Database and file hosting (us-east-1 region). aws.amazon.com/privacy
  • ·Google OAuth / Calendar API — Sign-in and calendar sync, only when you connect. policies.google.com/privacy
  • ·WHOOP API — Health data sync, only when you connect. whoop.com/privacy-policy
  • ·OpenRouter / Anthropic — Powers the Lumon Agent AI responses; only the messages you type into the chat are sent to process your request. Data obtained from Google APIs (account identity and Calendar) is never shared with this processor. openrouter.ai/privacy
  • ·Resend — Transactional email delivery (password reset, notifications). resend.com/legal/privacy-policy

No other third parties receive your personal data.

4. Google User Data — Limited Use

Lumon’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, when you connect Google Calendar (using the calendar.events scope):

  • ·We use the access only to create calendar events for the tasks and rituals you choose to push to your calendar.
  • ·We do not read, sell, or share your Google Calendar data, and we do not transfer it to third parties except as needed to provide this feature.
  • ·We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalised AI/ML models.
  • ·No humans read your Google data except where required for security, to comply with the law, or with your explicit consent.
  • ·Your Google Calendar access token is deleted immediately when you disconnect the integration in the App.

Regardless of the scope granted, no data obtained from Google APIs is ever sent to our AI provider (OpenRouter/Anthropic) or any other third-party AI service. Your Google account identity (name, email, profile picture) is used only to sign you in and display your account, and your Google Calendar access is used only to create the events described above. The Lumon Agent processes only the content you type into the App.

5. International Data Transfers

Your data is stored on AWS servers in the US (us-east-1). AI processing via OpenRouter/Anthropic may involve servers outside the UAE and EEA. By using the App, you consent to these transfers. We ensure each processor maintains appropriate security standards.

6. Data Retention

  • ·Account data: Retained until you delete your account.
  • ·Password reset tokens: Expire automatically after 1 hour; cannot be used after expiry.
  • ·Google Calendar tokens: Deleted immediately when you disconnect the integration.
  • ·WHOOP tokens: Deleted immediately when you disconnect the integration.
  • ·AI conversation history: Retained while your account is active; deleted with your account.

7. Your Rights

Under the UAE PDPL and GDPR (where applicable), you have the following rights:

  • ·Right of access: Request a copy of all personal data we hold about you.
  • ·Right to rectification: Correct inaccurate or incomplete data.
  • ·Right to erasure: Delete your account and all associated data instantly from Account settings.
  • ·Right to data portability: Receive your data in a machine-readable format.
  • ·Right to restrict processing: Ask us to pause processing pending a complaint or correction.
  • ·Right to object: Object to processing based on legitimate interests.
  • ·Right to withdraw consent: Disconnect WHOOP or Google Calendar at any time from Integrations settings.

To exercise any right, use the Account settings page in the App or email askar@mylumon.ai. We will respond within 30 days.

8. Cookies and Session Storage

The App uses a single session cookie (managed by NextAuth.js) to keep you signed in. No advertising, analytics, or tracking cookies are used. No third-party scripts with access to cookies are loaded.

9. Security

Passwords are stored as bcrypt hashes (cost factor 12) — the plain-text password is never stored. Integration access tokens are encrypted at rest. Database access is restricted by security group rules. All connections use TLS in transit.

10. Children

The App is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us for immediate deletion.

11. Changes to This Policy

Material changes will be communicated by updating the “Last updated” date at the top of this page. Continued use of the App after changes constitutes acceptance of the revised policy.

12. Contact & Complaints

For any privacy questions or to exercise your rights: askar@mylumon.ai

If you are an EU resident and believe your GDPR rights have been violated, you may lodge a complaint with your local supervisory authority.

If you are a UAE resident and wish to escalate a complaint, you may contact the UAE Data Office at uaedataoffice.ae.