Privacy Policy
Last updated: May 21, 2026
This policy applies to the Lumon personal life planning application (“the App”, “we”, “us”). It complies with the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Data Controller
The App is operated by Lumon AI FZE LLC, based in Ajman, UAE. Contact: askar@mylumon.ai
2. Data We Collect and Why
| Data | Purpose | Lawful basis |
|---|---|---|
| Name & email address | Account creation, sign-in, password reset emails | Contract performance |
| Profile details (age, country, profession, etc.) | Personalise the dashboard and AI responses | Contract performance |
| Goals, tasks, milestones | Core planning functionality | Contract performance |
| Financial transactions | Budget tracking and spending analysis | Contract performance |
| WHOOP health metrics (recovery, HRV, sleep, strain, resting HR) | Display health dashboard widget | Consent (opt-in integration) |
| Google account profile & email | Sign-in with Google | Consent |
| Google Calendar access (events you ask us to create) | Push tasks and rituals to your calendar | Consent (opt-in integration) |
| AI conversation history | Context for the Lumon Agent; session continuity | Contract performance |
| Password hash | Secure authentication for email/password accounts | Contract performance |
| Password reset tokens (hashed) | One-time use reset links; auto-expire after 1 hour | Contract performance |
We do not use your data for advertising, profiling for third parties, or any purpose beyond what is listed above.
3. Third-Party Processors
We share data with the following processors solely to operate the App:
- ·AWS (Amazon Web Services) — Database and file hosting (us-east-1 region). aws.amazon.com/privacy
- ·Google OAuth / Calendar API — Sign-in and calendar sync, only when you connect. policies.google.com/privacy
- ·WHOOP API — Health data sync, only when you connect. whoop.com/privacy-policy
- ·OpenRouter / Anthropic — Powers the Lumon Agent AI responses; only the messages you type into the chat are sent to process your request. Data obtained from Google APIs (account identity and Calendar) is never shared with this processor. openrouter.ai/privacy
- ·Resend — Transactional email delivery (password reset, notifications). resend.com/legal/privacy-policy
No other third parties receive your personal data.
4. Google User Data — Limited Use
Lumon’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, when you connect Google Calendar (using the calendar.events scope):
- ·We use the access only to create calendar events for the tasks and rituals you choose to push to your calendar.
- ·We do not read, sell, or share your Google Calendar data, and we do not transfer it to third parties except as needed to provide this feature.
- ·We do not use Google user data for advertising, and we do not use it to develop, improve, or train generalised AI/ML models.
- ·No humans read your Google data except where required for security, to comply with the law, or with your explicit consent.
- ·Your Google Calendar access token is deleted immediately when you disconnect the integration in the App.
Regardless of the scope granted, no data obtained from Google APIs is ever sent to our AI provider (OpenRouter/Anthropic) or any other third-party AI service. Your Google account identity (name, email, profile picture) is used only to sign you in and display your account, and your Google Calendar access is used only to create the events described above. The Lumon Agent processes only the content you type into the App.
5. International Data Transfers
Your data is stored on AWS servers in the US (us-east-1). AI processing via OpenRouter/Anthropic may involve servers outside the UAE and EEA. By using the App, you consent to these transfers. We ensure each processor maintains appropriate security standards.
6. Data Retention
- ·Account data: Retained until you delete your account.
- ·Password reset tokens: Expire automatically after 1 hour; cannot be used after expiry.
- ·Google Calendar tokens: Deleted immediately when you disconnect the integration.
- ·WHOOP tokens: Deleted immediately when you disconnect the integration.
- ·AI conversation history: Retained while your account is active; deleted with your account.
7. Your Rights
Under the UAE PDPL and GDPR (where applicable), you have the following rights:
- ·Right of access: Request a copy of all personal data we hold about you.
- ·Right to rectification: Correct inaccurate or incomplete data.
- ·Right to erasure: Delete your account and all associated data instantly from Account settings.
- ·Right to data portability: Receive your data in a machine-readable format.
- ·Right to restrict processing: Ask us to pause processing pending a complaint or correction.
- ·Right to object: Object to processing based on legitimate interests.
- ·Right to withdraw consent: Disconnect WHOOP or Google Calendar at any time from Integrations settings.
To exercise any right, use the Account settings page in the App or email askar@mylumon.ai. We will respond within 30 days.
8. Cookies and Session Storage
The App uses a single session cookie (managed by NextAuth.js) to keep you signed in. No advertising, analytics, or tracking cookies are used. No third-party scripts with access to cookies are loaded.
9. Security
Passwords are stored as bcrypt hashes (cost factor 12) — the plain-text password is never stored. Integration access tokens are encrypted at rest. Database access is restricted by security group rules. All connections use TLS in transit.
10. Children
The App is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us for immediate deletion.
11. Changes to This Policy
Material changes will be communicated by updating the “Last updated” date at the top of this page. Continued use of the App after changes constitutes acceptance of the revised policy.
12. Contact & Complaints
For any privacy questions or to exercise your rights: askar@mylumon.ai
If you are an EU resident and believe your GDPR rights have been violated, you may lodge a complaint with your local supervisory authority.
If you are a UAE resident and wish to escalate a complaint, you may contact the UAE Data Office at uaedataoffice.ae.