Lumanna Privacy Policy

2026-09-28

AvonixAI LLC · support@avonixai.io

Your choices

You can read without an account. Guest records remain on this device. When you sign in to a personal Lumanna account, unclaimed guest records are assigned to that account once; test accounts are isolated. Usage, crash and performance diagnostics are optional and disabled by default. Reading this policy does not grant diagnostic consent. Manage your choice in Settings → Privacy and account.

Local and synchronized information

After sign-in, reading plans, enrollments, plan completions, reminders, notes, highlights, bookmarks and personal prayer content, steps and manual progress synchronize automatically with Lumanna. Offline changes wait locally. Reading position, general reading progress, reading and study activity, reflections, prayer execution history and reader preferences are uploaded to private cloud storage only when you create a backup; restoring is also manual. Search history, unfinished drafts, credentials, device keys, consent, synchronization queues and downloaded media are excluded from cloud backups. These records may reveal religious beliefs. Do not include unrelated sensitive information.

Accounts, purchases and essential services

Lumanna handles email/password accounts, password hashes, email verification challenges and revocable sessions. Verification email uses our configured mail provider. If you choose Google sign-in, Google verifies your identity and returns a stable identifier, name and email; Lumanna links these to your account. We do not use Firebase Authentication or create anonymous online accounts. Google Play processes payment; Lumanna processes purchase tokens, products, orders and subscription state to verify Lumanna Plus without receiving complete payment-card information. Essential requests include IP addresses, app versions, installation credentials and session identifiers. Firebase App Check verifies integrity; Remote Config provides configuration.

Optional diagnostics

With your consent, Firebase Analytics and Crashlytics process usage events, crash stacks, installation identifiers, device, system and network information. Analytics may derive approximate regions from IP addresses; the app does not request location permission. Separately enabled performance diagnostics sample a fixed 1% of installations and process timings, request paths and response information through Firebase Performance. App-supplied diagnostics restrict fields and do not attach account identifiers, notes, personal prayer text, search terms or request bodies. We do not offer advertising, sell personal information or enable advertising personalization. Withdrawal stops new app reports and clears unsent crash reports; native crash settings fully apply on the next launch. Withdrawal does not immediately erase previously sent reports.

Service providers and locations

Lumanna operates the account and synchronization service at bible.avonixai.io. Google provides optional Google sign-in; Firebase provides integrity verification, configuration and consented diagnostics. Google Play handles subscriptions. Our configured mail provider delivers verification emails. Alibaba Cloud OSS stores manual private backups and serves public content, images and audio from avonix-test.oss-us-west-1.aliyuncs.com. Private backups require account authorization and short-lived signed access. Providers may process data internationally. We disclose necessary information for the described services, security, your requests and applicable obligations. Private notes and prayers are not sent to AI services.

Retention

Local account records remain when you sign out. You can remove them through in-app deletion or device app-storage controls; other devices and exported copies need separate removal. Each account can keep at most five cloud backups, including active upload reservations. Old backups are not automatically replaced; delete a selected backup to free a slot. Before restore, a local recovery snapshot is created. Accepted account deletion disables access immediately. Cleanup waits for authorized uploads to expire, normally up to 30 minutes, and retries failures. Contact us with the receipt if still pending after 7 days. De-identified anti-recreation records remain for 30 days and deletion receipts for 90 days. Diagnostic data already sent to providers follows their retention and project settings; contact us about deletion requests. Any separately required legal or security retention must have a defined scope and period and must not reactivate a deleted account.

Delete your account

Use Settings → Privacy and account → Delete account and associated data and verify the same email/password or linked Google account. You can also use the external deletion page without reinstalling. Deletion covers account credentials and sessions, personal plans and completions, notes, highlights, bookmarks, personal prayers and reminders, synchronization metadata, subscription associations and every private cloud backup, including unfinished uploads. In-app deletion clears this account’s local data and restore points on this device. Guest deletion is local only. Other account spaces and device diagnostic consent remain separate. Deleting Lumanna does not delete your Google account or cancel Google Play renewal; cancel Lumanna Plus in Google Play. You may request deletion before expiry.

Rights and contact

You can manage app records, notifications, synchronization, backups and diagnostic consent. Contact the privacy address on this page for access, correction, deletion or other applicable requests, including concerns about a minor’s information. We may verify ownership proportionately but never request passwords, verification codes, session tokens or complete purchase tokens by email. Policy versions identify changes. Diagnostic payloads and debug logs exclude account credentials, signed backup links and private note or prayer bodies; production disables local debug logging.