Privacy policy.
Lumen is built around one promise: what you read and ask stays on your phone. There is no server to send it to, no account to sign in with, and no analytics. This document spells out what that looks like in practice, both for the iOS app and for this website.
The iOS app
No accounts, no cloud
Lumen does not require a sign-in, an email, or any identifier. There is no cloud sync, no backup to our servers, and no server to speak of. We do not have your reading, your questions, your answers, or your browsing activity, because none of it is ever sent to us.
What gets stored on your device
Lumen stores the following inside the app’s sandboxed container:
- The text of pages you spend time reading, in a SQLite database with a full-text index
- The topic and site each page is filed under
- Summaries the model writes for each page, and an overview for each site
- Sentence embeddings used to find related pages
- Your highlights
Questions you ask in the Ask panel, and the answers to them, are held in memory and never saved. The library is excluded from iCloud and device backups. You can wipe it at any time from Settings → Delete All Knowledge.
Browsing activity
Lumen’s web engine is Apple’s WKWebView, configured with hardened defaults:
- Trackers on the Disconnect list blocked by default, through WebKit content rules
- Third-party cookies blocked while Block Trackers is on
- Images and scripts on a page upgraded from HTTP to HTTPS
- Canvas, WebGL, and audio features switched off for the rest of a page when one script reads them three times in ten seconds, a common sign of fingerprinting
The site menu counts the trackers Lumen blocked on the current page. The count is a floor, because requests a page makes from its own scripts are blocked without being counted.
On-device AI
The language model is mlx-community/Llama-3.2-1B-Instruct-4bit, run through MLX Swift. The model weights, roughly 700 MB, are downloaded from Hugging Face the first time the model is needed and cached on your phone. After that, the model runs offline. Questions and answers never leave your phone.
The only network call related to the AI feature is the one-time weight download from Hugging Face. Hugging Face’s privacy policy applies to that single transaction.
Third-party services
Lumen does not include analytics SDKs, crash reporters, A/B testing tools, or marketing pixels. Apart from the pages you visit, it makes three kinds of request:
- The one-time model download from Hugging Face
- Search suggestions: as you type in the address bar, the text is sent to your chosen search engine. Turn this off with
Search Suggestionsin Settings. Incognito tabs never ask for suggestions. - Site icons, fetched from each site’s own
/favicon.icowithout cookies
When you browse the web inside Lumen, websites you visit may still set their own cookies, use their own trackers, and record their own logs, as with any browser. Lumen blocks the trackers it knows about, but it cannot prevent a site from collecting data you submit to it directly.
Your controls
- Turn off
Collect Knowledgeto stop saving pages from any site - Delete a topic, a site, or a single page from the Library, or everything with
Delete All Knowledge - Turn
Block Trackerson or off for one site or for all of them - Turn off
Search Suggestions, or turn onClear History on Close - Clear history and website data with
Clear Browsing Data - Delete the app, which removes everything Lumen stored on your device
This website
The marketing site you are reading is a static Next.js app served by Vercel. It does not set tracking cookies, embed third-party analytics, or collect personal information. There is no newsletter, login, or form that asks for your data.
Vercel’s edge may record basic request logs (IP, timestamp, path) for operational purposes, as described in Vercel’s privacy policy.
Your rights
Because we do not collect or store personal data on our servers, there is nothing on our end to export, correct, or delete on your behalf. Your reading, your questions, and your answers live on your phone. The app itself is the only place to exercise control over that data.
If you are in a jurisdiction that grants rights under GDPR, CCPA, or similar frameworks, those rights apply only to data a controller actually holds. In Lumen’s case, that is nothing.
Changes
If this policy changes, the effective date above will change and the updated version will be pushed with the app’s next release and on this page. We do not have your contact details, so we cannot email you about changes. Check back occasionally.
Contact
Lumen is made by Lux Softworks, an independent team. For privacy questions, open an issue on the GitHub repository or reach out via the channels listed in the README.