Privacy Policy
This policy explains plainly which personal data LUME processes, why, for how long, and how you exercise your rights. It applies to the app on iOS, Android and the browser.
1. Who processes your data
The data controller is conhecendotudo.com.br.
The Data Protection Officer (LGPD, Art. 41) is conhecendotudo.com.br, reachable at contato@conhecendotudo.com.br. Use that address to exercise any right, ask a question, or complain about the processing. We answer through the same channel.
The current version of this policy is available at https://applume.site/en/privacy/ and inside the app, under Settings.
2. What we process, and why
LUME was designed to collect little. This is the complete inventory — there is no datum beyond these:
The account is optional. Without one, nothing described below as kept on our server exists: your favourites, name, language and reminder stay on this device only, and we keep no datum of yours. The app still downloads new devotionals from our server, without identifying you; the IP address of that request is handled as described in the IP address item.
- E-mail: identifies your account and lets you sign in. It lives on our own server. If you sign in with Apple, it is the e-mail you chose to share with LUME on Apple’s screen — which may be an Apple private relay address. If the account is locked by too many wrong attempts and you ask for it, we use the e-mail to send a 16-character unlock code through Cloudflare’s e-mail sending service, our processor. The code is not stored: it is computed on the spot, is valid for one hour at most, and on its own grants no access to the account.
- Password: never stored as you typed it. We store only a cryptographic derivation of it (PBKDF2 with 100,000 iterations, peppered with a server secret). An account created with Apple has no password.
- Apple identifier (only if you sign in with Apple): Apple gives us a code for your Apple account that is unique to LUME, so we recognise you on your next sign-in. We do not receive your name or your Apple password. The code is erased when you delete your account; to also remove LUME’s access to your Apple ID, use iPhone Settings › your name › Sign-In & Security › Sign in with Apple. If you remove that access, Apple tells us and we end your account’s sessions on every device; the account stays, and you can sign in with Apple again. If you delete your Apple Account, Apple tells us too and, since the account can no longer be reached, we delete it as described in section 7. Of each Apple notice we keep only a cryptographic digest, for up to 30 days, so we never act on it twice.
- Display name (optional): personalises the greeting. In the iOS and Android app it lives in the operating system’s encrypted storage and is never sent to the server. The browser has no system keychain: there it lives in browser local storage, without OS encryption — so avoid using LUME in a shared browser.
- Session token: keeps you signed in. In the iOS and Android app it lives in the OS encrypted storage (Keychain on iOS, Keystore on Android). In the browser it lives in browser local storage, without OS encryption.
- This device’s credential: after you sign in, the server gives the app a signed credential holding your account’s random code, our server’s address and an expiry, with no e-mail or name. Its only use is to let this device sign in while the account is locked by too many wrong attempts from elsewhere; on its own it grants access to nothing. It lives where the session token lives and stays on the device after you sign out (which is exactly when it is useful). It stops being valid within one year, or sooner if we rotate the server key, and the app discards it once it expires. Deleting your account from this device erases it here; on other devices it becomes useless, because the account no longer exists.
- Your account identifier: a random code that represents you on our server, containing neither your name nor your e-mail. It accompanies your favourite dates and your consent record.
- Your consent record: which document you accepted, in which version, in which language, and when — and also each time you turn name personalisation or reminders on or off while signed in. It is the evidence that the processing was authorised, which the LGPD itself requires.
- Language: an app preference, stored on your device.
- Reminder time: stored on your device. The reminder is scheduled locally by the operating system itself — no notification server receives your time or any other datum of yours.
- Favourite dates: the dates of the devotionals you marked and when you marked them. Without an account, they stay on this device only. With one, they live in it, on our server, so you can find them again on another device. We store the date, never a note or content of yours. A date you unmark is kept as removed for up to 30 days, so the removal reaches your other devices, and is then erased.
- IP address: used at the moment of each request to throttle abusive attempts. We do not store it in the clear — only a cryptographic fingerprint (hash) of it enters the attempt counters, which are purged automatically. Cloudflare, our processor, receives the address when it delivers the request to our server. For the same reason, wrong sign-in attempts on each account are counted by a cryptographic fingerprint of the e-mail, for 24 hours.
3. Legal basis for each processing activity
Performance of a contract (Art. 7, V): e-mail, password, session token and favourite dates. Without them there is no account and no sync — that is, no service.
Consent (Art. 7, I): display name, reminder time, and the processing described in item 4. The name is optional. You can withdraw the name and the reminder at any time in "My data" or by turning them off in Settings, and the change is recorded.
The item 4 consent is different: it underpins the very existence of your account in a devotional app, so there is no way to keep the account and withdraw it. You withdraw it by deleting your account, also in "My data" — and deletion erases your favourite dates for good, which is what removes the inference.
Legitimate interest (Art. 7, IX): minimal technical security records, used to throttle abusive sign-in attempts and protect your account. We do not use legitimate interest for advertising, commercial profiling or data enrichment.
4. Sensitive data: religious conviction
We need to be candid about something many apps leave unsaid. LUME is a Christian devotional. The mere fact that you hold an account here — and more so that you mark devotionals as favourites — allows your religious conviction to be inferred, which the LGPD classifies as sensitive personal data (Art. 5, II) under stricter rules (Art. 11).
That is why signup asks for a specific, highlighted consent for this alone, separate from the general acceptance of this policy. It is recorded with date, time and the accepted document version.
In practice: we share this with nobody, never use it for segmentation, advertising or recommendation outside the app itself, and when you delete your account we erase your favourite dates for good rather than merely hiding them — keeping them archived would keep the inference alive.
5. Who we share with
We do not sell, rent or trade your data. There is no ad network, data broker, behavioural analytics tool, tracker or advertising identifier in the app.
There is a single processor: Cloudflare, which provides the infrastructure our authentication server and your account database run on. It processes data under our instructions so that we can operate the service.
If you use Sign in with Apple, Apple knows you use LUME, under its own privacy policy; we send it no datum of yours.
The app stores (Apple and Google) receive the data of your transaction with them, not with us — installation and, on the App Store, buying the app and billing are your relationship with the store, governed by its own privacy policy.
6. Where your data sits, and international transfer
The authentication server and your account database run on Cloudflare infrastructure, a globally distributed network. That means processing may occur outside Brazil.
Where an international transfer happens, the LGPD (Art. 33) requires a specific basis. The basis we adopt is: art. 33, I, da LGPD (União Europeia reconhecida como adequada pela Resolução CD/ANPD nº 32/2026) para o banco da conta, mantido na jurisdição UE da Cloudflare; art. 33, IX, combinado com o art. 7º, V, para identificadores pseudônimos, metadados técnicos de curta duração e o envio do código de desbloqueio por e-mail.
Display name, language and reminder time never leave your device and are therefore not transferred anywhere.
7. How long we keep it
Account data (e-mail, password derivation, favourite dates): while your account exists. A date you unmarked is kept as removed for up to 30 days and then erased automatically.
On account deletion: e-mail, password derivation and Apple identifier are irreversibly overwritten or erased and your favourite dates are erased. Only technical records remain, with no e-mail, name or password: the deleted account row, with the random code that identified it and its creation and deletion dates, to evidence that the deletion happened; a marker with that same code, kept outside the main database, that stops a database restore from reactivating the account; and, until they expire (30 days at most), the records of ended sessions. That code does not reveal who you are; it could only re-link you to these records for someone already holding an old token or export of your account.
An honest caveat: deletion erases the database’s live state at once, but the database provider retains, for a limited period, the ability to restore the whole database to an earlier moment for disaster recovery. We do not use that facility to undo deletions, and a restore requires re-applying the deletions requested after the restored point.
Consent records: kept while your account exists, as evidence that the processing was authorised. When you delete your account they are erased along with the rest — keeping them tied to your account identifier would allow you to be re-linked to the erased data, which would defeat the erasure.
Technical security records (attempt counters): valid for 10 minutes to 24 hours, then purged automatically by the server, which runs that cleanup every six hours.
Your account’s data on your device: erased when you sign out, delete your account, or remove the app. Favourites saved on this device without an account (and not moved into one) stay on it until you remove them or delete the app. The exception is this device’s credential, which stays after you sign out, is erased from this device when you delete your account from it, and is discarded when it expires, within one year.
8. Your rights, and where to tap
The LGPD (Art. 18) grants concrete rights, and here they do not live only on paper — they are in the app, under Settings › Privacy and data:
- Confirmation and access: the "My data" screen shows what we hold about you.
- Portability: "Export my data" produces a machine-readable file with your account, your consents, your favourite dates and the removed dates still retained.
- Correction: you edit or clear your display name in Settings. To correct your e-mail, contact the DPO.
- Erasure: "Delete my account" erases your data as described in item 7. The action asks for your password — or, for an account created with Apple, a fresh Apple confirmation — because a deletion must not happen by accident or at the hands of whoever picked up your unlocked phone.
- Withdrawal of consent: you can turn off name personalisation and reminders, and the withdrawal is recorded.
- Information about sharing, and objection: through the DPO channel.
9. How we protect it
All traffic with the server is HTTPS by force — the app refuses to speak in plaintext, as a matter of code policy.
Passwords go through PBKDF2 with 100,000 iterations plus an additional server secret, so a database leak alone does not reveal passwords.
In the iOS and Android app, the session token and display name live in the operating system’s encrypted storage, not in an ordinary app file. In the browser that protection does not exist: local storage is not OS-encrypted and is exposed to anyone with access to the same browser profile.
You can end every session on your account at once, including on devices you do not have with you, from Settings.
Sign-in attempts are rate limited to contain brute force. After 100 wrong attempts in 24 hours, from anywhere, the account accepts sign-in only from a device you have signed in with before, or one unlocked with a code sent to your e-mail.
10. Children and adolescents
LUME is not directed to children. At signup you declare that you are at least 18 years old or hold the consent of your legal guardian.
If we learn that an account belongs to a child without the specific consent of one parent or legal guardian required by LGPD Art. 14, we will delete the account and its data.
Guardians may request the deletion of a minor’s account through the DPO channel.
11. Changes to this policy
This policy is versioned and the current version appears on this screen, with its date. Your consent record points to the exact version you accepted, not to "the current policy".
If a material change requires new consent, we will ask for it before that change starts to apply to you. Until then, the version you accepted is the one that governs.
Version 1.8.0, dated 2026-09-24.