Privacy Policy
Last updated: 30 September 2026
1. Data Controller
The party responsible for data processing within the meaning of the GDPR is:
A Data Protection Officer has not been appointed, as the requirements under § 38 BDSG (fewer than 20 persons regularly involved in data processing) are not met.
2. Principle: Your Data Belongs to You
Lumen was built on the principle of "Privacy by Design". All personal data — journal entries, transgressions, resolutions, intentions, and notes — is stored on your device. There is no user account, no automatic sync between devices, and no analysis of your content by the Provider. Only if you explicitly switch on the cloud backup is a copy — already encrypted on your device — stored with us: no name, no account, and unreadable for the Provider (section 11).
3. Encryption
All personal text fields are encrypted with AES-256-GCM via the Web Crypto API. The encryption key is generated and stored locally on your device. The key is kept in the App's protected storage area on your device, separate from the database; anyone who merely copies the database files cannot read them without it. Against full access to an unlocked device or a complete device backup only the device lock protects — which is why the App additionally offers the app lock with Face ID, Touch ID, fingerprint or device passcode.
4. What Data Is Processed?
The App processes the following data exclusively on your device:
- Examen entries (gratitude, review, transgressions, resolutions)
- Confession list and transgression notes
- Spiritual intentions
- App settings (language, reminders, dark mode)
- Subscription status (stored locally; billing handled by Apple or Google)
- Mindful minutes to Apple Health (iOS only, and only if you switch it on; the App writes only the duration, reads nothing and transmits nothing)
- Suggestions from Apple's Journal app as a memory aid (iOS only, and only if you switch it on; suggestions are only shown, never stored)
- Your resolution on the lock screen widget and in the morning reminder (only if you switch it on; there it lives in the system outside the encryption)
- Live Activity during the Examen (only the name of the step, never your text)
- Approximate location (rounded to about 10 km) for the sunset mode of the reminder — stays on the device
- Technical log in the bug report (only if you attach it; without personal texts)
5. Legal Basis for Processing
Your data is processed on the following legal bases (Art. 6 GDPR):
- Art. 6(1)(b) GDPR (Contract performance): Local storage of your examen entries, intentions, and settings is necessary to provide the core functions of the App.
- Art. 6(1)(b) GDPR (Contract performance): Communication with StoreKit (Apple) or Google Play Billing (Google) to manage your MAGIS subscription.
- Art. 6(1)(f) GDPR (Legitimate interest): Fetching the daily gospel and Ignatian impulses from external sources to provide liturgical content. The legitimate interest lies in providing up-to-date spiritual content.
6. Network Requests and International Data Transfers
The App makes the following limited, read-only network requests:
- Fetching the daily gospel from bible.usccb.org (servers in the USA)
- Fetching Ignatian impulses from michaelporwol.github.io (servers potentially outside the EU)
- StoreKit communication with Apple for subscription management (processed by Apple)
- Google Play Billing communication with Google for subscription management on Android (processed by Google)
- Excerpt for spiritual direction: only when you create a link yourself, a page encrypted on your device is transmitted to lumen-note.srv1348442.hstgr.cloud (Hostinger, Frankfurt am Main) (Section 12)
- Dictation: on Android exclusively on the device, without network; in the browser, dictation uses the browser's speech recognition service (Chrome: Google), and the spoken text may be sent to its servers
None of these requests actively transmit personal data, device identifiers, or usage information. However, your IP address is technically transmitted as part of the HTTP connection to the respective servers. Fetching data from bible.usccb.org constitutes a data transfer to the USA (a third country without an adequacy decision). This transfer is based on Art. 49(1)(b) GDPR (necessary for contract performance — provision of liturgical content). You can prevent these network requests by using the App without an internet connection; core functions remain fully available.
7. Web Analytics on the Website
The website lumenexamen.com uses Umami (the App itself contains no analytics), a privacy-friendly, self-hosted web analytics tool. Umami does not collect personal data and does not use cookies. Processing is based on Art. 6(1)(f) GDPR (legitimate interest in improving the service). The following anonymous data is collected:
- Page views (which pages are visited)
- Referrer (where visitors come from)
- Approximate location (country/region, based on anonymized IP)
- Device type, browser, and operating system
Umami does not store IP addresses, does not set cookies, and does not create user profiles. Analytics data is processed on the Provider's own server in Germany and is not shared with third parties. There is no cross-site tracking. Lumen does not use any advertising networks.
7a. Email sign-ups (Lumen letter, “40 Days of Examen”)
On lumenexamen.com you can sign up for the Lumen letter or for a programme such as “40 Days of Examen”. For this we process only:
- your email address
- time and IP address of the sign-up and of the confirmation (proof of your consent and protection against abuse)
- for a programme, additionally the language of the sign-up page and, if present, a source tag from the link (for example “parish newsletter”), so we can see how people hear about it
The sign-up only takes effect once you click the link in the confirmation email (double opt-in). The legal basis is your consent (Art. 6(1)(a) GDPR). If you sign up for a programme, you only receive the emails of that programme; you join the general Lumen letter only if you explicitly choose to at the end. The data is stored with the Provider's web host, Strato in Germany, and the emails are sent via its servers; we pass nothing on to any other third party. Unconfirmed sign-ups are deleted after 72 hours. You can unsubscribe at any time via the link in every email; after that you receive nothing more, and the address is only kept marked as unsubscribed so that no email goes to it again. On request we delete it completely: michael@lumenexamen.com.
8. Recipients and Third Parties
The App does not transmit personal data to the Provider or third parties. As part of the connections described in Sections 6 and 7, technical connections exist to:
- United States Conference of Catholic Bishops (USCCB) – bible.usccb.org – fetching liturgical content
- GitHub Inc. / Microsoft Corp. – michaelporwol.github.io – fetching Ignatian impulses
- Apple Inc. – StoreKit communication for subscription management (Apple's privacy policies apply to payment processing)
- Google Ireland Limited / Google LLC – Google Play Billing for subscription management on Android (Google's privacy policy applies to payment processing; Google is independently responsible for Google Play as a distribution channel)
- Provider's own server – web analytics with Umami (no personal data, no cookies, self-hosted in Germany)
- Provider's own server – lumen-note – storage of encrypted excerpts for spiritual direction (Section 12)
9. In-App Purchases via Apple and Google
When you subscribe to MAGIS, payment is processed on iOS by Apple through your Apple ID account and on Android by Google through your Google account (Google Play Billing). The Provider does not receive any payment data, credit card information, or other financial data. Apple's or Google's privacy policies, respectively, apply to payment processing.
10. Data Retention
All data stored in the App remains on your device until you delete it yourself. You alone determine the retention period. Data is deleted when you manually delete it in the App (Settings > Reset Data), uninstall the App, or delete the exported backup file.
11. Data Backup
You can export your data as an encrypted file using the export function and import it on a new device if needed. This backup file only leaves your device if you share it yourself (e.g., via AirDrop or the Files app). The Provider has no access to it. In addition, MAGIS subscribers can switch on the cloud backup. A copy of your entries is then encrypted on your device with AES-256-GCM and stored under a random identifier derived from your backup key on a server in Frankfurt am Main (Hostinger, EU). Only that random identifier, the hash of an access token and the encrypted block are stored there — no name, no email address, no user account and no access logs with IP addresses. The key never leaves your device; the Provider cannot technically decrypt the contents. The legal basis is your explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR), given by switching the feature on and revocable at any time by deleting the backup in the app. The backup is deleted as soon as you delete it in the app, and at the latest after 800 days without access. If you lose your backup key, the Provider cannot restore the data either.
12. Excerpt for Spiritual Direction
If you share an excerpt from your Examen for a conversation with a spiritual director, you can pass it on as a PDF file or create a short-lived link. For the link, the page is encrypted on your device with AES-256-GCM and a fresh random key; only the ciphertext is stored on a server in Frankfurt am Main (Hostinger, EU). The key exists solely in the fragment of the address after the hash sign, which browsers never send to a server; the Provider cannot read the excerpt. Stored are only a random identifier, the hash of a deletion token, the ciphertext and the expiry date — no name, no account, no access logs with IP address. Sins are never part of an excerpt. The excerpt deletes itself after the period you choose, one to thirty days, and can be withdrawn in the App at any time. The legal basis is your explicit consent (Art. 6(1)(a), Art. 9(2)(a) GDPR), which you give by creating the link and revoke by withdrawing it. You decide who receives the link; sending it by email gives it to both email providers.
13. Data of Minors
The App is not specifically directed at persons under 16. Without the optional cloud backup, no personal data leaves device storage; with it, the data rests with the Provider only in a form he cannot decrypt. The Provider therefore does not collect or process data of minors in plain text.
14. Your Rights Under the GDPR
Since no readable personal data is transmitted to the Provider, the Provider cannot technically fulfill the usual data subject rights with respect to locally stored data — however, you have full control yourself. The same applies to the cloud backup: the Provider cannot link the encrypted block to any person and, under Art. 11 GDPR, is not obliged to obtain additional information for that purpose. You can delete or retrieve that backup yourself in the app at any time. Regardless, we inform you of your rights under the GDPR:
- Right of access (Art. 15 GDPR): You can view all data directly in the App (Journal, Confession List, Patterns).
- Right to rectification (Art. 16 GDPR): You can edit all entries directly in the App.
- Right to erasure (Art. 17 GDPR): You can delete all data under Settings > Reset Data or by uninstalling the App.
- Right to restriction of processing (Art. 18 GDPR): You can stop using the App at any time; data remains stored locally.
- Right to data portability (Art. 20 GDPR): You can export your data via Settings > Backup as a file.
- Right to object (Art. 21 GDPR): Since the Provider receives no readable data, objection is not applicable in practice. You can uninstall the App at any time.
15. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). The competent authority is the one at the place of your habitual residence, your place of work, or the place of the alleged infringement.
16. Automated Decision-Making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place in the App.
17. Changes to This Privacy Policy
The Provider reserves the right to update this Privacy Policy as needed. Users will be notified within the App of any significant changes.
18. Contact
For questions about data privacy, please contact: michael@lumenexamen.com