Back to home
Privacy

Privacy Policy

Last updated: January 2026

Aura Devs operates the LumenChat application ("LumenChat", the "App", the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have over it. By using LumenChat you agree to the practices described here.

1 Who We Are

LumenChat is built and operated by Aura Devs, an independent development team based in Guatemala. We are the data controller for the personal information described in this policy.

If you have any privacy-related questions or want to exercise your rights, you can reach us at any time at soporte@lumenchat.app.

2 Our Privacy Principles

We do not sell, rent, or trade your personal information. Ever.

LumenChat is built around anonymity. Three principles guide everything we do with your data:

  • Minimum data: We only collect what is strictly necessary to make the service work.
  • No commercial use: Your data is never used for advertising, profiling, or resale.
  • Private by default: Your conversations are private. No engineer, moderator, or employee of Aura Devs can read them unless you or another user files a report involving that specific chat (see Section 6).

3 Information We Collect

3.1 Information you provide

You can use LumenChat fully anonymously. Any data below is provided by you and can be edited or removed from the app at any time.

Data Purpose Required
Display name Identification in chats Optional
Age Search filters and 18+ enforcement Optional
Gender Search filters Optional
Profile pictures Personalization (scanned by an automated NSFW filter) Optional
Google account Authentication so you don't lose your data when switching devices Optional

If you choose to sign in with Google, we receive your Google account ID and email. We use this only to recognize your account on a new device. We do not import your contacts, profile photo, or any other information from Google, and we do not share your data with Google beyond what is required to complete authentication.

3.2 Information collected automatically

  • Anonymous user ID: A random identifier we generate so the service can recognize your account. It is not tied to your real-world identity unless you choose to sign in with Google.
  • Device identifier & push token: Used to deliver push notifications for new messages and matches.
  • Technical logs: App version, operating system, crash reports, and error traces, used to diagnose bugs and keep the service stable.

3.3 Content you create

  • Text messages, images, and audio messages (voice notes) sent in chats.
  • Reports you file against other users, including any context you add.

Chat content (text, images, voice notes) is stored only as long as needed to deliver it to the other participant and keep your chat history accessible to you across devices. We do not analyze, train AI models on, or otherwise process the content of your private conversations.

4 How We Use Your Information

  • Run the service: Match you with other users in Discoverable mode and deliver text, image, and voice messages between you.
  • Sync across devices: Restore your chats and profile when you sign in on a new device.
  • Notifications: Alert you about new messages and matches.
  • Safety & moderation: Detect spam and abuse, run the automated NSFW filter on profile pictures, and review reports against users.
  • Legal compliance: Respond to lawful requests and enforce our Terms.
  • Bug fixes: Diagnose crashes and improve stability.

We do not use your data for advertising, profiling, behavioral targeting, or training third-party AI models.

5 Profile Pictures & the NSFW Filter

To keep LumenChat safe and compliant with the Google Play store policies, every profile picture you upload is automatically scanned by an NSFW (Not Safe For Work) detection model before it becomes visible to other users.

  • If the image is flagged as containing nudity, sexually explicit content, or other policy violations, it will be rejected and not shown to anyone.
  • The scan happens automatically. No human reviewer looks at your profile picture during this process.
  • Repeated attempts to upload prohibited content may result in your account being suspended.

Note about chat content: The automated NSFW filter is applied to profile pictures only. Images and voice notes shared inside private conversations are not analyzed, since chats are end-to-end private to the participants. You remain responsible for the content you send (see our Terms & Conditions).

6 Access to Private Conversations

Aura Devs employees, contractors, and moderators cannot read your private chats by default.

Chats live on our servers in encrypted form so we can deliver them and keep your history. Access is gated behind two specific situations:

  • You file a report against another user. By submitting the report you authorize our moderation team to read the conversation between you and the reported user, strictly to investigate the report.
  • A legal authority issues a binding request that we are obligated to comply with under applicable law.

We log every moderator access so we can audit it internally. Access is limited to the specific conversation involved in the report, and only for the time needed to make a decision.

7 Moderation, Bans, and Appeals

If our moderation team determines that a user has violated our Terms (harassment, illegal content, sharing CSAM, threats, etc.), we may:

  • Issue a warning.
  • Temporarily suspend the account.
  • Permanently ban the account from LumenChat.

Moderation decisions are based on the reported conversation, the reporter's context, and our policies. If you believe a ban was issued in error, you can appeal by emailing soporte@lumenchat.app from the email associated with your account. We will review the case and respond within a reasonable time. Decisions on appeals are final.

For audit and safety reasons, we may keep records of banned accounts (including the conversation that triggered the ban) for up to 12 months after the decision, even if the account itself is deleted.

8 How We Share Information

We only share data in the following narrow cases:

  • With other users: Your display name and profile pictures are visible to users you chat with or are matched with. Messages you send are visible to the recipient.
  • Service providers: Trusted vendors that operate the infrastructure behind the app:
    • Supabase (database, authentication, file storage).
    • Amazon Web Services (AWS) as the underlying cloud provider for Supabase.
    • Expo for push notifications.
    • Google when you choose to sign in with a Google account.
    These providers are contractually bound to process your data only on our instructions and to protect it appropriately.
  • Legal compliance: When required by valid legal process or to protect the rights, safety, and property of users, third parties, or Aura Devs.

We never sell your data. We never share your data for advertising or marketing purposes.

9 Data Storage & Security

Your data is stored on secure servers operated by Supabase on top of AWS infrastructure. We apply industry-standard safeguards, including:

  • Encryption in transit (HTTPS/TLS) for all communication between the app and our servers.
  • Encryption at rest for sensitive data.
  • Role-based access controls and Row Level Security (RLS) policies in the database.
  • Audit logs of administrative actions.
  • Restricted physical and network access at the cloud provider level.

No system is 100% secure. While we work hard to protect your data, we cannot guarantee absolute security. If a breach occurs that affects your personal information, we will notify you and the relevant authorities as required by law.

10 Data Retention

  • Active account: We keep your data for as long as your account is active.
  • Messages: Deleted from our servers when both participants delete the chat, or when an account is deleted.
  • Account deletion: When you request account deletion, your data is permanently erased within 30 days. See our Account Deletion page for the process.
  • Reports & bans: Reports and the conversations involved in them may be retained for up to 12 months for safety and audit purposes, even after an account is deleted.
  • Backups: Encrypted backups may persist for up to 30 days after deletion before being overwritten.
  • Anonymized logs: Technical logs that do not identify you personally may be kept longer for analytics and abuse prevention.

11 Your Rights

Depending on where you live, you may have the following rights over your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete information in your profile.
  • Deletion: Delete your account and the data associated with it.
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection / Restriction: Object to or restrict certain processing activities.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time.
  • Lodge a complaint: File a complaint with your local data protection authority.

To exercise any of these rights, email us at soporte@lumenchat.app. We will respond within 30 days.

12 Children & Minors

LumenChat is strictly for users 18 years of age or older. We do not knowingly collect data from minors.

If we discover that an account belongs to someone under 18, we will delete it and any associated data immediately. If you believe a minor is using LumenChat, please contact us at soporte@lumenchat.app so we can take action.

13 Cookies & Local Storage

LumenChat is a mobile application and does not use browser cookies. The app uses local device storage to:

  • Keep your session signed in.
  • Cache messages and media for offline access and faster loading.
  • Save app preferences (language, notifications, filters, etc.).

You can clear this data at any time from your device settings or by uninstalling the app.

14 International Data Transfers

Our service providers may process your data on servers located outside your country, including in the United States. When we transfer data internationally, we rely on the safeguards offered by these providers (such as Standard Contractual Clauses) to ensure your data continues to be protected to a standard comparable to your local law.

15 Third-Party Services

LumenChat integrates with third-party services that have their own privacy policies. We encourage you to review them:

16 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the service, or applicable law. When we make material changes, we will notify you through the app and update the "Last updated" date at the top of this page. Continued use of LumenChat after changes take effect means you accept the updated policy.

17 Contact

For privacy questions, requests, or to exercise your rights:

Email: soporte@lumenchat.app

Data controller: Aura Devs

Country: Guatemala