Privacy policy

Last updated: October 4, 2026

This policy explains how Lumen Guide processes information when you use the Lumen Guide mobile app and related services. Lumen Guide provides Zi Wei chart calculation, daily reflection tools, optional AI conversations, personalized discovery content and related account features.

Information processed for the chart

When you create a chart, the app sends the information needed for calculation to our Java API and Zi Wei calculation service. This can include your birth date, birth time, gender, selected birth city, calendar type, leap-month choice, true-solar-time setting, longitude, target date and language. The services return chart facts and reflection content; the app does not use this information for advertising.

Without an account, chart profiles, profile names, reflections, moods, reminders, learning progress, report progress, avatar choices and discovery preferences are stored on your device. The app currently does not use advertising SDKs, push notifications, contacts, photos, precise location or an advertising identifier.

Accounts and email verification

An account is optional for the local chart experience. An account is required for cloud-saved AI conversations and account-linked personalization. If you register, we process your email address, display name, password-derived authentication data, account identifier and login-session data. Passwords and session tokens are stored in derived or hashed form rather than as raw passwords or raw session tokens.

To protect registration, the email-verification service stores a short-lived verification-code hash, expiration and attempt counters. It also stores a hash of the requesting IP address for rate limiting; the raw IP address is not stored for this purpose. Verification codes expire after 10 minutes, and login sessions expire after 30 days unless replaced or deleted earlier. Verification emails are sent through the configured email-delivery provider.

AI conversations

If you use AI chat, we process your questions, AI answers, chat-session information, bounded chart context and a limited recent conversation history. These records are stored with your account so that you can revisit conversations across sessions. AI requests may also be recorded in an account-linked audit record containing the question and the request context sent to the configured AI provider. The configured AI provider and its infrastructure process the request to generate an answer.

The app may extract limited structured focus labels from a chat question, such as a topic, goal, palace or star. It does not need to store the original question as a focus label. Do not enter passwords, payment credentials, government identifiers, emergency information or other sensitive information that is not needed for your question.

Focus and discovery personalization

When you are signed in, Lumen Guide can maintain a small focus profile containing structured labels you add, save, open, mark helpful, or that are extracted from chat. Focus entries are limited to a topic, goal, palace or star, with a label, source, weight and expiry. Explicitly added or pinned entries remain until you remove or clear them; other focus signals are designed to expire or decay over time.

The discovery service receives a random app identifier, locale, target date, bounded chart facts such as palace and star keys, reflection areas and daily suggestions, and the structured focus profile when available. It does not need your birth date, birth time, gender or profile name to rank discovery content. The random app identifier is hashed before discovery events are stored. Stored events are limited to controlled actions such as impression, open, save, helpful, unhelpful and topic visibility choices. Generated discovery batches are cached for a limited period to reduce repetition and provider calls.

Local reflection text remains on your device by default. If you explicitly enable the reflection-personalization setting, a saved reflection of up to the app’s displayed limit may be sent once to extract structured focus labels. The raw reflection and raw extraction response are not stored as focus data. You can turn this setting off, remove individual focus entries, or clear the focus profile in the app.

Purchases

Paid features are feature-gated and may be unavailable in some deployments. When enabled, purchases are handled by Google Play on Android and the applicable Apple store flow on iOS. To verify access, restore purchases, prevent duplicate grants and process refunds or revocations, the service may receive purchase product identifiers, purchase tokens and a pseudonymous app-user identifier. Purchase tokens and app-user identifiers are stored as hashes where the service ledger permits; they are not used for advertising or recommendations.

Store subscriptions and purchases are managed through the applicable store. Deleting a Lumen Guide account does not cancel a store subscription.

Analytics and technical diagnostics

Remote analytics is consent-gated in the app and server-gated in each deployment. When both controls allow it, Lumen Guide sends only a controlled set of aggregate product events, such as language, screen or journey state, safe counters and controlled purchase outcomes. It does not send raw birth details, profile names, reflection text, chat content, passwords, email verification codes or purchase tokens as analytics properties. The server stores aggregate event counts rather than raw event rows.

Request diagnostics and AI audit previews may be kept locally on the device only when the relevant diagnostics or development setting is enabled. They are intended for troubleshooting and can be cleared from the app’s diagnostic controls. They are not used for advertising.

Retention and deletion

Local information remains on your device until you clear it in the app, use the reset-data action, or remove the app’s local data. Account-linked records are retained while your account is active and are deleted when you permanently delete the account, subject to the limited exceptions below. Generated discovery batches are temporary caches, and non-explicit focus signals have bounded expiry or decay. Verification records and rate-limit records are retained only for security operations and cleanup.

Registered users can permanently delete their account in Settings. Account deletion removes the account, login sessions, saved charts, chat sessions and messages, AI request audits, focus profiles, generated-content caches, chat quota and purchase bindings linked to the account, plus matching pseudonymous discovery records when the app identifier is supplied. It also clears local profiles, reflections, reminders and cached content on that device. You can also use the account deletion page for instructions.

We may retain limited transaction, security or accounting records when required by law, to prevent fraud, resolve disputes or establish and defend legal claims. Such records are not used to personalize discovery content.

Your choices and rights

Third-party services

Lumen Guide may use infrastructure providers for hosting, database operation, email delivery, AI generation and store purchase verification. Those providers process only the information needed for their services and under their applicable terms and privacy policies. Lumen Guide does not sell personal information and does not use personal information for behavioral advertising.

Children and safety

Lumen Guide is intended for general audiences and is not directed to children. The service is for entertainment and self-reflection. It is not medical, legal, financial, mental-health, emergency or other professional advice, and it does not guarantee future outcomes.

Contact

For privacy questions or account-data requests, contact genieai.toolbox@proton.me. You can also request permanent account and cloud-data deletion online.

The app is available in English, Simplified Chinese, Traditional Chinese, Japanese and Korean. This English policy is the authoritative version until localized legal review is completed.