Privacy Policy
Last updated: August 2026. This policy explains what personal data lumen ("we") collects when you use this private festival companion, why we hold it, and the choices you have. lumen is an invite-only tool for a single festival community; it is not a public service.
Who we are
The data controller is the festival organiser operating lumen. For any privacy request, contact the administrator at the address given to you with your invitation.
What we collect
Account data: your email address, display name, chosen username, and the role assigned to your account. Application data: the name, email, and motivation you submit when you request access, together with the consent choices recorded at that time.
Planning data: the sessions you mark as interesting or book, private notes you attach to sessions, custom time blocks you add, and the companion connections you form. Optional preference profile: if you choose to complete it, a small set of preferences you provide, including sensitive ("special category") free text such as boundaries. This is encrypted at rest and is visible only to you.
Technical data: minimal security and audit logs (for example, hashed identifiers and timestamps) needed to keep the service safe.
Why we use it and our legal basis
We process account and planning data to provide the service you asked for (performance of a contract / legitimate interest in running the community tool). We process the optional preference profile only with your explicit consent, which you may withdraw at any time. We keep security logs on the basis of our legitimate interest in protecting the service and its members.
Sharing
We do not sell your data or use it for advertising. Companions you connect with can see only what you explicitly share with them (for example, that you invited them to a session). Your private notes and preference profile are never shown to other members. We use Supabase and Cloudflare as processors to host the service; email delivery uses a transactional email provider. These providers act on our instructions.
Analytics
We measure how the app is used in two privacy-preserving ways, and we never use third-party advertising or tracking SDKs. For traffic figures we use Cloudflare Web Analytics, which is cookieless and does not profile or fingerprint you. For product analytics (understanding which features are used, so we can improve them) we record pseudonymised events: your account identifier is replaced with a keyed one-way hash (HMAC) before the event is stored, so these records are not directly linked to you and are not used to build a profile about you.
Retention
We keep your data while your account is active. When you delete your account, your profile and planning data are removed and related rows are cascaded; some minimal, anonymised security logs may be retained where required.
Your rights
You can access and export your data at any time from Settings → Privacy, edit or delete your preference profile, withdraw consent, and delete your account. Depending on your location you may also have rights to rectification, restriction, and to complain to a supervisory authority.
International transfers and security
Data may be processed in the EU/EEA and other regions where our processors operate, under appropriate safeguards. Sensitive free text is encrypted before storage and access is restricted by row-level security so members cannot read each other's private data.