Legal
Privacy Policy
1. Who We Are
Lumiritz is a learning system for homeschoolers, built today for children aged 4–8 and currently in early access.
Email: care@lumiritz.com
We offer our service to families around the world including in the United States, the European Union, and India.
2. Who This Policy Covers
This policy applies to:
- Parents and guardians who create accounts and manage their child's profile.
- Children who use Lumiritz under a parent or guardian's supervision.
- Visitors to our website and anyone who contacts us.
Children do not create accounts independently. All accounts are created and managed by a parent or guardian. We define a "child" as a person under 13 in a US context (COPPA), under 18 in an Indian context (DPDP Act, 2023), and under 16 where EU/UK GDPR principles apply — whichever threshold is higher for the user's jurisdiction.
3. Information We Collect
From parents and guardians
| What | Why we collect it |
|---|---|
| Name and email address | To create and manage your account, send important notices, and provide support. |
| Country / region | To apply the correct privacy protections and localise content. |
| Payment information (where paid plans are active) | Paid plans may be introduced gradually. When billing is live, payments are processed by a third-party payment provider. We do not store full card details on our servers. |
From children (on behalf of the parent account)
| What | Why we collect it |
|---|---|
| Child's first name or nickname | To personalise the learning experience. |
| Age or year of birth | To serve age-appropriate content and apply the right safeguards. |
| Learning activity data (session responses, reading progress, session duration, topics explored) | To adapt lessons, track progress, and generate the parent progress report. |
| Device type and operating system | To ensure the app works correctly on the child's device. |
We do not collect:
- The child's full name, home address, phone number, or school name.
- Photos, videos, or precise location data.
- Social network information.
- Behavioural data for advertising purposes.
4. How We Use This Information
We use the information we collect to:
- Deliver and personalise the learning experience for each child.
- Generate progress reports visible only to the parent or guardian.
- Improve the quality and safety of Lumiritz (using aggregated, de-identified data only).
- Send parents transactional messages such as account notices, security alerts, and policy updates.
- Respond to support requests.
- Comply with our legal obligations.
We do not use children's data to serve targeted or behavioural advertising, build marketing profiles, or sell data to third parties.
5. Our Approach to Privacy Law
India — Digital Personal Data Protection Act, 2023 (DPDP)
For children's data we seek to process only with the consent of a parent or guardian, consistent with Section 9 of the DPDP Act. We do not process a child's data until a parent has created an account and provided consent. Parents may withdraw consent at any time by contacting us.
US — Children's Online Privacy Protection Act (COPPA)
We do not knowingly collect personal information from children under 13 without parental involvement. The account creation flow requires a parent or guardian to complete sign-up before a child profile is created. If we discover we have inadvertently collected data from a child under 13 without appropriate consent, we will delete it promptly.
General GDPR principles (for EEA/UK users)
Where GDPR principles apply, we aim to process personal data only where there is a lawful basis to do so — including to perform the service you signed up for, to meet legal obligations, or where you have given consent for specific optional features.
6. Sharing Your Information
We share data only where necessary and only with parties bound by confidentiality obligations:
- AI model provider — Learning interactions are processed by an AI service. Session data is used only to generate the response and is not retained by the provider for model training without a separate agreement.
- Cloud infrastructure — We host on reputable cloud infrastructure. Data is encrypted in transit and at rest using industry-standard measures.
- Payment processor (where applicable) — When billing is active, payment details are handled by a third-party payment processor and are never stored on our servers.
- Analytics (aggregated only) — We may use anonymised, aggregated usage statistics to understand how features are used. No individual child's data is shared.
- Legal requirements — We may disclose information if required by law or in response to a valid legal process.
We do not sell personal data. Ever.
7. Data Retention
We keep data only for as long as it is needed:
- Active accounts: Learning data is retained while the account is active to support the progress experience.
- Deleted accounts: When you delete your account, we will permanently erase personal data (parent and child) within a reasonable time, except where we are required by law to retain certain records (for example, transaction records for tax compliance).
8. Your Rights as a Parent or Guardian
You are in control. At any time, you can:
- Access the personal data we hold about you and your child.
- Correct inaccurate information.
- Delete your account and all associated data.
- Withdraw consent for data processing.
- Request a copy of your child's learning data where this is technically available.
- Object to or restrict certain processing activities.
To exercise any of these rights, email us at care@lumiritz.com. We will acknowledge your request promptly and aim to fulfil it within 30 days.
9. Security
We apply reasonable administrative, technical, and organisational safeguards to protect personal data. These include:
- Encrypted connections (TLS) for all data in transit.
- Strong encryption for data stored at rest.
- Role-based access controls — access to personal data is restricted to authorised team members and logged.
- Regular internal security reviews.
- No third-party advertising SDKs in the app.
No system is perfectly secure. In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.
10. International Data Transfers
Lumiritz is based in India. If you are located in the EEA, UK, or another jurisdiction with data transfer restrictions, we take reasonable steps to ensure that any transfer of your data is protected by appropriate safeguards recognised under applicable law.
11. Cookies and Tracking
We use only strictly necessary cookies to keep you logged in and maintain your session. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics that profile individual users.
You can manage cookie settings through your browser. Disabling strictly necessary cookies may prevent the app from functioning correctly.
12. Children's Safety by Design
Everything in Lumiritz is built with children's wellbeing in mind:
- No social features, public profiles, or ability for children to communicate with strangers.
- No in-app purchases accessible directly to children.
- Age-appropriate AI guardrails on all generated responses.
- Notifications go to parents only — not to the child.
13. Changes to This Policy
We may update this policy from time to time. If we make a material change — particularly one that affects how we handle children's data — we will notify you by email at least 14 days before the change takes effect, and we will ask for fresh consent where required. The "last updated" date at the top of this page will always reflect the most recent version.
14. Privacy Grievances (India — DPDP Act)
If you have a privacy concern or grievance relating to how we handle personal data, please contact us directly. We will acknowledge your concern and work to resolve it promptly.
Email: care@lumiritz.com
Subject line: Privacy Grievance
We aim to respond to all privacy grievances within 48 hours of receipt.
15. Contact Us
Questions, concerns, or requests about this policy are always welcome:
- Email: care@lumiritz.com
If you are in the EEA and feel we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection authority.
