1.Who receives data, and what
This is every service Lumen’s own code sends your data to. Everything marked Lumen reaches one address, api.lumenapp.news. Story images load directly from the news organisations that published them, described in section 2. Everything below happens without you doing anything, except reader polls, problem reports and email, which happen only when you choose to.
| Who | What they receive | When | Why |
|---|---|---|---|
| Lumen’s own server | Your IP address, and the version, build, operating system and device model your app reports, as part of the connection itself. Which stories you open. | Whenever the app loads the feed or a story | To send you the news, and to limit how often one address can post votes and reports. Unavoidable for any app that talks to a server. |
| Lumen - usage data | The random identifier described in section 3, which screens you open, which stories you open, and how far you read them | While you use the app, unless you turn off Share usage data | To see which parts of the app are used and which are not |
| Lumen - reader polls | A random identifier generated on your device, and the option you chose | Only when you vote in a reader poll | To count each installation once. |
| Lumen - problem reports | The reason you selected, whatever you write in the box, and the same random identifier described in section 3. Reports sent from a story or from the About screen also carry an email address if you choose to give one. | Only when you report a problem - from a context card, from the foot of a story, or from the About screen | To fix what you reported, and to reply if you left an address |
The greeting and weather lineicanhazip.com ipwho.is geojs.io open-meteo.com |
Your IP address, to the first three. Lumen sends Open-Meteo no IP address - only approximate coordinates. Like any server it hosts, Open-Meteo still sees the address your request arrives from. | When the app starts, and at most once an hour while you use it. The temperature at most every fifteen minutes. | To work out roughly which town you are in and show its temperature, for the greeting at the top of the feed. Two services are asked the same question so that a disagreement drops the answer rather than showing you a wrong city. |
| Namecheap - email forwarding | Whatever you put in an email to our support address, including your own address | Only when you email us | To forward the support address to a person. |
Lumen’s own server
- Sent
- Your IP address, and the version, build, operating system and device model your app reports, as part of the connection itself. Which stories you open.
- When
- Whenever the app loads the feed or a story
- Why
- To send you the news, and to limit how often one address can post votes and reports. Unavoidable for any app that talks to a server.
Lumen - usage data
- Sent
- The random identifier described in section 3, which screens you open, which stories you open, and how far you read them
- When
- While you use the app, unless you turn off Share usage data
- Why
- To see which parts of the app are used and which are not
Lumen - reader polls
- Sent
- A random identifier generated on your device, and the option you chose
- When
- Only when you vote in a reader poll
- Why
- To count each installation once.
Lumen - problem reports
- Sent
- The reason you selected, whatever you write in the box, and the same random identifier described in section 3. Reports sent from a story or from the About screen also carry an email address if you choose to give one.
- When
- Only when you report a problem - from a context card, from the foot of a story, or from the About screen
- Why
- To fix what you reported, and to reply if you left an address
The greeting and weather lineicanhazip.com ipwho.is geojs.io open-meteo.com
- Sent
- Your IP address, to the first three. Lumen sends Open-Meteo no IP address - only approximate coordinates. Like any server it hosts, Open-Meteo still sees the address your request arrives from.
- When
- When the app starts, and at most once an hour while you use it. The temperature at most every fifteen minutes.
- Why
- To work out roughly which town you are in and show its temperature, for the greeting at the top of the feed. Two services are asked the same question so that a disagreement drops the answer rather than showing you a wrong city.
Namecheap - email forwarding
- Sent
- Whatever you put in an email to our support address, including your own address
- When
- Only when you email us
- Why
- To forward the support address to a person.
Everyone above, and the hosting provider whose machines the server runs on, is held to the standard UK data protection law requires of us, is sent only the minimum needed, and may not use your data for their own advertising, profiling or resale. Where one operates outside the United Kingdom we rely on the UK’s approved transfer safeguards.
2.Story images
Story images load directly from the news organisation that published them - Lumen does not copy them onto its own servers. The publisher’s servers see your IP address and the general type of device you are using, in the same way they would if you visited their website. Lumen sends no referrer and no identifier with the request, though the image address belongs to one specific article, so a publisher who looked could work out which story you were shown. Tapping “read the original” opens the article on the publisher’s own site, under their privacy policy.
3.What stays on your device
Lumen stores the following on your phone. None of it is sent anywhere except where section 1 says so.
- A random identifier, created when you first open the app. Not linked to your name or to any account, it is sent with poll votes, problem reports and usage data so that one installation is not counted twice.
- Which polls you have voted in, and which option you chose, so the app can show you your own answer.
- Small settings - whether you have seen the opening screen, and whether Share usage data is on.
- The town you are in and the latest weather reading, worked out from your IP address as section 1 describes, so the greeting and the weather line are there the moment you open the app. The town is re-checked at most once an hour, the reading at most every fifteen minutes. Lumen’s own server never receives either.
All of it is erased when you delete the app.
On Android, the system’s own backup can copy app data to your Google account. Lumen turns that off, so none of it is backed up or copied to a new phone.
4.Our lawful basis
Under the UK GDPR we need a lawful basis for each purpose. Delivering the app and its content, keeping it working, limiting abuse of the endpoints that accept votes and reports, and measuring how the app is used all rest on legitimate interests. We have weighed that against your privacy: the data is limited, it is not sold, and you can turn usage data off in the app.
5.How long we keep things
- Server logs and usage data are kept for one month and then deleted. Server logs include IP addresses.
- Poll votes are kept with the random identifier for 12 months. After that the totals are kept and the identifiers are deleted.
- Problem reports are kept for 12 months after we have dealt with them, and in no case longer than 24 months. Any email address you give is deleted within 90 days.
- The town you are in and the latest weather reading stay on your phone until they are replaced by newer ones, or until you delete the app.
6.Deleting your data
On your phone. Delete the app. That erases the random identifier and everything else Lumen stored on your phone.
On our server. Poll votes, problem reports and usage data are stored under the random identifier your app holds, not under your name, so unless you give us that identifier we usually cannot tell which rows are yours. Turning off Share usage data on the About screen stops new usage data; Erase usage data, on the same screen, deletes what we already hold for your installation.
By email. Write to us with the story and roughly the date, and we will remove a specific vote or report if we can identify it with confidence. You do not need to give a reason.
7.Your rights
By law you can ask us for a copy of the personal data we hold about you, or to correct it, erase it, restrict or object to our use of it, or send it to you in a portable form. There is no charge. We answer within one month - three if the request is complex, and we will tell you why.
To complain, email us or use Report a problem in the app and choose Privacy or data; we will acknowledge within 30 days and tell you the outcome. You can also complain to the ICO at ico.org.uk/make-a-complaint.
8.Security
Everything the app sends travels over HTTPS, and it refuses to talk to anything unencrypted. Servers are kept patched, and shell access needs a cryptographic key, not a password. The database is backed up daily and backups are kept about a week. If a breach puts anyone at risk we will tell the ICO within 72 hours, as the law requires, and say so on this page.
9.Cookies
This website sets no cookies and contains no analytics, no tracking pixels, no embedded videos and no third-party fonts. Nothing on it needs your consent.
The app does not use cookies either.
10.Children
Lumen is not designed for or directed at children, and we do not knowingly collect anything from a child. If you believe a child has sent us something, email us and we will delete it.
11.Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects what happens to your data, we will say so at the top of this page.
12.Contact
Lumen is made by Tigin Ltd, a company registered in England and Wales, company number 11034539, and the data controller for everything this page describes. For anything about your data, email support@lumenapp.news.