← Back

Privacy Policy

Last updated: June 8, 2026

This privacy policy explains how we process personal data when you visit this website and use the Lume app. It is based on the services and data flows currently implemented in this project. It takes into account in particular the GDPR, the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), and other applicable European and national data protection laws. It does not replace individual legal advice.

1. Controller

The controller responsible for data processing is Nicklas Matthias Wehling, c/o IP-Management #9523, Ludwig-Erhard-Strasse 18, 20459 Hamburg, Germany.

For privacy-related questions, you can contact us at support@vital-stat.com.

Based on the current scope and nature of the processing, we believe that the appointment of a data protection officer is not legally required. You can direct privacy-related questions to the contact details above.

2. Scope and principles

This privacy policy applies to the Vitalstat/Lume website and to the Lume iOS app.

We process personal data in accordance with the GDPR, the German Federal Data Protection Act (BDSG), the German Telecommunications Digital Services Data Protection Act (TDDDG), and other applicable data protection laws. Relevant legal bases are in particular Art. 6(1)(b) GDPR (contract or pre-contractual steps), Art. 6(1)(c) GDPR (legal obligations), Art. 6(1)(f) GDPR (legitimate interests), and, where required, Art. 6(1)(a) GDPR (consent).

We follow a data minimisation approach. Based on the current product implementation, we do not store plain names or gender information in Firestore; that information remains local on the respective device.

Where content used in the app permits conclusions about a person's intimate life, sex life, sexual preferences, or sexual orientation, that content may qualify as special category personal data within the meaning of Art. 9 GDPR. We process such content only to the extent required for the storage, sync, and sharing functions that you expressly use and only where you yourself enter, create, or share that content within the app.

3. Overview of legal bases

We process website delivery and technically necessary server logs on the basis of Art. 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and abuse-resistant provision of our online offering.

We process the provision of the app, the user account, authentication, synchronisation, the couple space, in-app purchase unlocking, and account deletion on the basis of Art. 6(1)(b) GDPR to the extent necessary for the performance of the user relationship.

We process optional permissions and features, in particular local notifications, on the basis of Art. 6(1)(a) GDPR where consent or device-level permission is required.

To the extent that content voluntarily entered or synchronised by you within the app contains information about intimate life, sex life, or highly personal relationship boundaries and preferences, we additionally process that content on the basis of Art. 9(2)(a) GDPR, meaning your explicit consent given through the voluntary entry, storage, and synchronisation of that content within the app features you choose to use.

Where statutory retention or proof obligations apply, processing also takes place on the basis of Art. 6(1)(c) GDPR.

4. Processing when you visit the website

The website is provided through Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. This includes the processing of technically required access data, in particular IP address, date and time of access, requested URL, referrer, browser type and operating system, and other connection and log data.

This processing is carried out to provide a secure, stable, and efficient website and to defend against abuse and technical faults. The legal basis is Art. 6(1)(f) GDPR.

Based on the current setup, we do not use our own analytics, marketing, advertising cookies, or third-party tracking tools on this website. Where Vercel or the browser uses technically necessary storage, access, or logging functions, this is done solely for the technical provision of the site.

If non-essential cookies or comparable technologies are introduced in the future, we will obtain any consent required under the TDDDG and the GDPR before using them.

5. App download via Apple

The app is distributed through the Apple App Store. Apple processes personal data under its own responsibility when you download the app or use the store, including Apple ID data, device information, usage data, payment information, and purchase history.

The legal basis for our making the app available through the App Store is Art. 6(1)(b) GDPR; Apple remains independently responsible for its own processing operations within the App Store.

6. Account, authentication, and app use

We use Firebase Authentication and Cloud Firestore from Google for central cloud-based app functions. On first launch, an anonymous Firebase account may be created so that a protected app space can be provided. You may optionally link that account to an email address and password or sign in with an existing email account.

In this context, we process in particular an internal user identifier (Firebase UID), the status of the anonymous or linked account, any email address you choose to add, and technical metadata required for authentication and session management.

The legal basis is Art. 6(1)(b) GDPR to the extent the processing is necessary to provide the user account and synchronisation features.

7. Couple space, invite links, and synchronised content

If you create a shared couple space in the app or join an invite, we process a couple-space ID, the Firebase UIDs of the participating devices, timestamps such as creation and last-activity dates, and the system-derived role allocation within the couple space.

Based on the current implementation, invite links do not contain plain names; they contain only a technical room identifier. When a second device joins, its UID is added to the couple space.

To provide the core features, we also process the content and status data created by you in the app, in particular swipes and card choices, wishes, responses to wishes, consent proposals, daily answers, planned evenings, custom decks, custom evenings, shared to-do or match lists, tonight picks, unlocked decks, progress states, subscription states, and related timestamps.

We process this data solely to provide the synchronisation and shared-use features you requested between the connected devices. The legal basis is Art. 6(1)(b) GDPR.

To the extent that this content contains information about intimate life, sex life, sexual preferences, or consensual boundaries, it may qualify as special category personal data. Such content is processed only within the app use initiated by you and additionally on the basis of Art. 9(2)(a) GDPR.

8. Local storage on your device

In addition to cloud data, the app stores certain settings and content locally on your device, including onboarding status, app settings, language choice, app-lock state, local progress and favourites, selected content for offline or convenience use, and other usage-related settings.

If you enable app protection with Face ID, Touch ID, or the device passcode, biometric verification is performed locally through your device's operating system. We do not receive any raw biometric data.

This local processing is carried out to provide app functionality and on the basis of Art. 6(1)(b) and Art. 6(1)(f) GDPR.

9. Notifications

Based on the current implementation, the app uses local iOS notifications, for example for reminders or in-app events. The app therefore requests the notification permission provided by Apple.

These notifications are currently scheduled locally on the device. A server-side push infrastructure that processes push tokens is not active in the current implementation.

The legal basis for optional notifications is Art. 6(1)(a) GDPR where permission is requested and granted.

10. Payments, premium, and in-app purchases

If you use paid features or in-app purchases, payment processing is handled by Apple. Based on the current implementation, we do not receive full payment details such as credit card numbers, only billing-related status information where required to unlock or restore purchased features.

Where a lifetime or subscription status is stored within the couple space, this is done solely to unlock the booked features within the app. The legal basis is Art. 6(1)(b) GDPR.

11. Recipients, processors, and international transfers

Recipients of personal data are only those service providers and bodies that we need for technical operation, the provision of individual functions, payment processing, or compliance with legal obligations. These include in particular Vercel for website hosting, Google/Firebase for authentication, the database, and server-side app logic, and Apple for App Store and in-app purchase processes. Where these providers act on our behalf, they are engaged as processors under Art. 28 GDPR.

Depending on the technical process, personal data may therefore be processed in third countries, in particular the United States. Where a provider is certified under the EU-U.S. Data Privacy Framework, transfers may be based on that certification. Otherwise, we rely on appropriate safeguards, in particular standard contractual clauses and supplementary protective measures where required.

Further information is available in the privacy notices and contractual documentation of the respective providers, in particular Google/Firebase, Vercel, and Apple.

12. Retention and deletion

We store personal data only for as long as necessary for the purposes described above or as required by law.

Data stored locally on your device generally remains on that device until you delete it yourself, remove your account, or uninstall the app, unless the data is overwritten or removed earlier within the app.

You can delete your account within the app. Based on the current implementation, this removes the related Firebase Auth account, the shared couple space including synchronised sub-data, and local app mappings, unless statutory retention obligations require otherwise.

Billing-related or transaction-related information that we may exceptionally need for verification or support purposes is stored only for as long as required for that purpose or by law.

13. No obligation to provide data; consequences of not providing it

You are generally not obliged to provide personal data. However, without certain technical data such as the user identifier, couple-space ID, or content required for synchronisation, central app features cannot be provided.

Providing an email address is currently optional and is only necessary if you want to link your anonymous account permanently to an email address and password or sign in with an existing email account.

14. Data security

We implement appropriate technical and organisational measures to protect personal data against loss, unauthorised access, manipulation, or disclosure. These measures include in particular role-based access controls, transport encryption, security mechanisms provided by the platforms we use, and data restrictions limited to what is necessary for operation.

However, despite all appropriate measures, complete security of electronic data transmission and storage cannot be guaranteed.

15. Your rights

Subject to the statutory requirements, you have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR).

Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

Where we process personal data on the basis of legitimate interests, you have the right to object to that processing on grounds relating to your particular situation.

To exercise your rights, simply email support@vital-stat.com.

16. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement.

The supervisory authority with local responsibility at our registered seat is in particular the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Strasse 22, 20459 Hamburg, Germany.

17. No automated decision-making

Based on the current implementation, we do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

18. Changes to this privacy policy

We will update this privacy policy if legal requirements, service providers, or the actual processing activities change. The version published on this website is the authoritative version.

Where changes materially affect your rights or the scope of processing, we will separately inform you in an appropriate manner where legally required.