Privacy Policy
Updated 12 September 2026
Your cycle, symptoms and documents are sensitive. This page explains what Luma stores on your device and what happens when you choose an online feature.
At a glance
- Your health records are saved in this browser or app on this device.
- Signing in uses Supabase. Signing in alone does not upload your health records.
- Cloud backup is a separate, manual action. Automatic sync is a separate opt-in on each device. Cloud OCR asks for permission before sending a document.
- Device storage is not end-to-end encrypted or protected by an app biometric lock. Protect access to your device.
- Luma has no advertising, sells no personal data, and does not use your records to train AI models.
Who operates Luma
Luma PCOS Tracker is operated by Dawood Togoo, Qatar. Address: Building I 4, Street 1149, Floor 3, Apartment 308, Al Barbasati, Doha, Qatar.
For privacy requests, contact privacy@luma-pcos.com. Account support: support@luma-pcos.com.
Records on your device
Luma stores the details you choose to enter: profile and cycle context, period dates, symptom ratings, lab results and extracted report text, food and medication logs, measurements, journal entries, attachments, voice recordings, preferences and a local activity history. Optional Apple Health imports become local records after you grant permission. Health Connect is not currently supported.
Health records are separated by the saved account on this device. This separation is not encryption. Someone with access to your unlocked browser profile or device may be able to access its storage. Local account passwords are hashed; cloud passwords are handled by Supabase.
Browser storage can be lost when you clear browsing data, change devices, uninstall, or when the operating system removes site data. Settings lets you download a device backup, including saved files and recordings, and restore a backup after reviewing it. Downloaded backups contain private health information and are not encrypted by Luma. Store them securely. Cloud backups contain text and record details only. Backup restoration adds missing records and preserves existing edits. Separately, optional automatic device sync uploads tracking records and document text to your account and merges changes while Luma is open. Deletions propagate to other enabled devices. Conflicting edits are kept for your review. Original files, photos and voice audio are not automatically synced.
Optional reminders
Installed apps can schedule local device notifications without sending reminder content to a push server. Browser push requires permission and stores a subscription endpoint, encryption keys, reminder schedule and time zone in your Supabase account. Apple, Google or Mozilla delivers browser notifications, depending on your browser. Browser notification text is generic. Installed-app notification names are hidden by default and can be enabled in settings. Browser subscriptions expire after 90 days without an update. Disabling browser delivery unsubscribes that browser; deleting your cloud account removes its subscriptions and synced records. Device settings can delay or silence delivery.
Sign-in and optional cloud backup
Supabase processes your email, account identifier, authentication credentials or provider identity, sign-in activity and acceptance of our terms. If you choose Google, Apple or another offered identity provider, that provider authenticates you under its own privacy policy.
Choosing to save a cloud snapshot sends your entered health information and text, including notes and journals, to Supabase associated with your account. Original document files, profile photos, attachment binaries and voice recording audio are excluded from that snapshot. This is not end-to-end encryption: the service operator and authorised infrastructure providers can have technical access.
You can stop uploading at any time. Clearing the cloud copy in Settings removes the supported snapshot rows after the service confirms deletion. It does not delete your sign-in account or copies you previously exported.
Document scanning and OCR
PDF, image, text and supported Word-document extraction starts on your device. Reading software and English/Arabic OCR models are served by Luma. Local reading does not send the selected document to an OCR provider.
If local extraction is poor and cloud OCR is available, Luma asks before sending the document to our server and Microsoft Azure Document Intelligence. A document may contain names, identifiers and health information. You may allow one scan, remember permission, or decline. Change remembered permission in Settings. Files are processed for extraction; the application does not intentionally save original uploads to its server storage. Azure processing and retention also depend on the provider service.
OCR can misread text, numbers and units. Review the extracted text and every lab result before saving or using it.
Service providers and technical data
Supabase provides authentication and optional cloud storage. Luma’s current Supabase database is hosted in Tokyo, Japan. Vercel hosts the web application; Cloudflare provides domain and traffic services. Zoho is configured to deliver sign-in emails. Microsoft Azure is used only for authorised cloud OCR. These services may process connection information such as IP addresses and request times, and may process data outside your country. The database location does not establish the processing location of every provider or authentication service.
When error reporting is configured, Sentry receives restricted technical error information, such as application version and code stack locations. Luma omits application error messages, form content, user identity, request bodies and interaction breadcrumbs from those reports. Performance tracing and session replay are disabled. Network providers can still receive connection metadata.
We use browser storage for account sessions, preferences and records. Cloud session tokens are held in local storage and are sent to the authentication or authorised cloud service when needed. We do not use advertising cookies or tracking pixels.
Purposes, choices and your rights
We process information to provide the features you request, keep your account secure, store a backup when you choose it, and resolve technical failures. Where consent is required for health information or an optional feature, you may decline or withdraw it. Withdrawing permission stops future use of that feature; previously saved cloud copies must be cleared separately.
Depending on the law that applies to you, you may have rights to access, correct, export or delete personal information, restrict or object to processing, and complain to your local privacy authority. Contact us to make a request. We may need to verify your identity and will respond within the applicable legal timeframe.
Luma displays descriptive patterns and estimates. It does not make decisions with legal effects, diagnose PCOS, confirm ovulation, or provide contraception advice.
Retention and deletion
Local records remain until you delete them or the device removes them. Manual cloud backups and the automatic cloud copy can be cleared separately in Settings, or together through account deletion. Clearing the automatic cloud copy pauses sync when other devices next connect; local records are retained. Deleted record identifiers are retained as deletion markers in the automatic cloud copy to prevent older devices from silently restoring deleted entries. The application includes a scheduled process to remove snapshots that have not been updated for about 24 months; its operation on the live service is being verified, so we do not currently guarantee that deadline. This process does not delete the sign-in account.
Use Settings to request account deletion. A cloud account must be signed in, and the server must confirm removal before Luma reports success and clears this device. If deletion is unavailable or fails, your local records are retained and you can retry or contact us. Account deletion covers the account and its associated supported cloud rows; copies on other devices and exported files need separate deletion.
Infrastructure logs and provider backups follow the providers’ configured retention and deletion processes. Their exact periods and processing locations are being verified; we do not promise immediate removal from all backups. Contact us for the information available for your request.
Age, security and updates
This version is intended for adults aged 18 or older. PCOS can also affect adolescents, but adolescent assessment and tracking require different clinical considerations. Contact us if a child has submitted personal information.
Luma uses HTTPS for online services and account-based access controls for supported cloud records. No system is completely secure. Report suspected security issues to security@luma-pcos.com. We assess incidents and meet applicable notification obligations.
We update this policy when practices change and request renewed acceptance where appropriate. This page does not certify compliance with every jurisdiction. Provider locations, retention, transfer safeguards and applicable legal bases require verification before expanding availability.