Privacy Policy

Lumora — A Global Learning Village
App
Lumora
Effective date
15 April 2026
Contact
amigoraj888@gmail.com
Jurisdiction
Malaysia (global compliance)
Contents
  1. Who this applies to
  2. What we collect
  3. How we use it
  4. Legal bases
  5. Who we share with
  6. Children's privacy
  7. Your rights
  8. Retention
  9. Security
  10. International transfers
  11. Payments
  12. Cookies
  13. Changes
  14. Contact

Lumora ("we", "our", "us") is an educational app that helps students learn, teachers teach, and parents support their children. Because many of our users are children, we take privacy very seriously and comply with the U.S. Children's Online Privacy Protection Act (COPPA), the EU General Data Protection Regulation (GDPR) including the children's protections under Article 8 GDPR-K, and the Malaysian Personal Data Protection Act 2010.

1. Who this policy applies to

Lumora has four types of accounts:

Children under 13 (or under 16 in the EU) can only use Lumora with verified parent or school-administrator consent. Safety features (Safe Shield, Mirror Room, Toxic Pattern Detector) are never paywalled — every child has access regardless of plan.

2. What we collect

2.1 You give us directly

2.2 Collected automatically

2.3 We do NOT collect

3. How we use your information

PurposeExamples
Provide the serviceShow lessons, save answers, sync across devices
Educational personalisationRecommend practice at your level, match study buddies by subject
SafetyDetect toxic language, age-gate features, enforce parent controls
Teacher & parent dashboardsShow parents activity trends, show teachers pass/fail statistics
Account securitySign-in, prevent unauthorised access, detect abuse
CommunicationService announcements, trial expiry reminders
Improve LumoraFix bugs, prioritise features, measure changes

We do not use your information for behavioural advertising, profile-building for third parties, or training third-party AI models.

For children, consent is obtained from a parent or school administrator, not the child.

5. Who we share with

We share only what is strictly necessary, and never sell personal data.

5.1 Service providers

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageEU / US
Firebase Cloud Messaging (Google)Push notificationsGlobal
Apple App Store / Google Play / StripeSubscription paymentsGlobal

Each is bound by a Data Processing Agreement and processes data only on our instructions.

5.2 Within the app

5.3 We will NOT share

6. Children's privacy (COPPA / GDPR-K)

Lumora is designed for children. The protections below are enhanced over our general policy.

If you believe a child created an account without parental consent, email amigoraj888@gmail.com and we will delete the account within 30 days.

7. Your rights

Wherever you live, you have these rights:

Email amigoraj888@gmail.com with subject "Privacy request". We respond within 30 days, free of charge.

8. Data retention

9. Security

If we discover a breach affecting you, we will notify you and the relevant regulator within 72 hours (GDPR requirement).

10. International transfers

Your data may be processed in Malaysia, the EU, or the US. Transfers out of the EU are protected by Standard Contractual Clauses approved by the European Commission.

11. Payments and subscriptions

Subscriptions are processed by Apple, Google, or Stripe. We receive only your subscription status — never your card number, bank details, or billing address. Refunds are handled by the platform that processed your payment.

The 30-day free trial does not require a card.

12. Cookies and tracking

Lumora uses essential storage only for:

We do not use advertising cookies, tracking pixels, or analytics cookies that identify you personally.

13. Changes to this policy

If we make material changes we will:

14. Contact us

In the EU, you may also contact your national data-protection authority. In Malaysia, you may contact the Jabatan Perlindungan Data Peribadi (PDP).