Privacy Policy
Overview
Lume works offline, on Mac and on iPhone. Everything you enter or import stays on your device, encrypted there too, unless you deliberately turn on sync; and if you do, it is encrypted on your device with a key only you hold before it is uploaded. We store that encrypted data. We cannot read it.
This page describes exactly what leaves your device, in which circumstances, and what we can and cannot see. It covers both apps, which work the same way; where one differs, it says so. Where something is a limitation rather than a guarantee, it says that too.
What we collect
With sync turned off - the default - the Lume app collects nothing. Specifically:
- No account or registration is required to use the app.
- No analytics or usage tracking is implemented in the app.
- No crash reporting is sent to any server.
- No advertising identifiers are used.
- No third-party SDKs that collect data are included.
This website
The app and this website are separate, and the list above describes the app. This website does use analytics: Vercel Analytics and Speed Insights, which record page views, referrer, approximate region, device type and page performance, plus a count of clicks on the App Store link. It is cookieless and we do not use it to identify or profile individual visitors.
It is mentioned here because the app's "no tracking" promise is a real one, and it would be worth less if the site quietly did the opposite.
On your device
All financial data you enter or import - income, spending, account balances, holdings, statement lines and the rules that categorise them, and settings - is stored in files inside the app's own container on your device. None of it leaves your device unless you turn on sync.
From Lume 1.5, those files are encrypted (AES-256-GCM) with a random key that the app creates on your device and keeps in that device's Keychain. The key is not sent to us and is not synced to iCloud Keychain, so nothing in the app's folder can be read without that device's Keychain - for example from a copy of the disk or a Mac backup. Earlier versions kept the same data unencrypted in the app's local storage, protected by the app sandbox and your device's own disk encryption; updating encrypts it.
The app also keeps three automatic backups on the same device - the latest, one at least a day old and one at least a week old - encrypted the same way. With sync on, your passphrase or recovery code can open them as well, so they still work if the device's Keychain is lost. If the app ever cannot open its data, it says so and offers to restore one of them or start fresh, and it does not delete what it could not open.
From Lume 1.5, statement and trade files you import are read on your device and never uploaded; Lume keeps the lines and trades it takes from them, encrypted like the rest of your data. From Lume 2.0 the same holds for a file you open in Lume from another app, such as Mail or your bank's: it is read on your device and not uploaded. What you add to a line, such as its category, is kept with the line, encrypted, and the rules that suggest categories are encrypted items of their own, synced like the rest.
Exports you make yourself (see below) are the exception: they are ordinary files, unencrypted, so you can read them anywhere. Keep them somewhere you trust.
Sync, and why we cannot read it
Sync is optional and off until you turn it on. When you do, you create an account with an email address and choose a passphrase.
Your passphrase is never sent to us. It stays on your device, where the app uses it to derive a key (Argon2id) that unlocks your data's own random encryption key. That key encrypts your data (AES-256-GCM) before anything is uploaded, so what arrives on our server is ciphertext.
From Lume 1.5, your data is uploaded as many small encrypted pieces - roughly one per month, account, scenario, rule or group of settings, and from Lume 2.0 one for each account's statement lines in each month - so a change sends only what changed. Each piece is filed under a code the app computes from its name with a key we do not have, so we cannot tell a month from a setting, or one month from another. Each is padded to a whole number of kilobytes before it is encrypted. Because a month's lines are one piece, its size gives a rough idea of how many lines that account had that month, though not what any of them say. Earlier versions uploaded your whole encrypted copy as a single block.
A separate value is derived from the same passphrase and used as your account password, so that you can sign in. It is derived along a different path and cannot be worked backwards into your encryption key. We store only a hash of it, as any service does.
What we can see is therefore limited to: your email address, that authentication value, the encrypted data itself, how many encrypted pieces there are, their size to the nearest kilobyte, and when each was written or deleted. What we cannot see is anything inside them, or what any piece is - no balances, no accounts, no holdings, no notes, no dates you entered.
When you turn on sync you are shown a recovery code, once. It is the second way into your data: if you forget your passphrase, the code proves to us that the account is yours so we can let you set a new one, and separately unwraps your data on your device. We never see the code itself - only a value derived from it that proves possession and opens nothing.
To be clear about what that code is: it does not expire, and using it does not spend it. Recovering with it replaces your passphrase, not the code - the same code keeps working afterwards. From Lume 2.0 you can replace it yourself, in Settings: the app issues a new code and retires the old one, without re-encrypting your data or changing your passphrase. Until then, deleting the account and setting sync up again is the only way to retire a code you think someone else has seen.
Losing both is final. Without your passphrase and without your recovery code, nobody can open your encrypted copy, including us. That is the direct consequence of not being able to read it, and there is no reset that restores your history. Keep the recovery code somewhere separate from your passphrase, and keep exporting backups.
If you ask Lume to stay unlocked on a Mac or an iPhone, what it needs to sign in and decrypt without asking - your data key and the authentication value derived from your passphrase - is stored in that device's Keychain, so the app can unlock without asking again. Anyone who could read that Keychain entry could open your encrypted copy, so treat it like your passphrase. Turning that off deletes it.
App lock on iPhone
On iPhone you can require Face ID, Touch ID or your passcode to open Lume. The check is made by iOS on your device; Lume only learns whether it succeeded, and nothing about it - no biometric data, no record of unlocking - is sent to us. The setting belongs to that iPhone alone and is not synced.
Market prices and ticker checks
If you track stocks or crypto, the app talks to our own endpoints rather than contacting a market-data provider directly, in two ways:
- Prices. When you fetch month-end prices while closing a month (the monthly review, before Lume 2.0), a request carries a ticker symbol (for example "VWCE.DE") and the month being priced. For an account in a currency other than your main one, the same kind of request carries the currency pair instead (for example "USDEUR=X"), to fetch that month's exchange rate.
- Ticker checks. When you type a ticker into a trade, or import trades, the app checks that Yahoo Finance lists it, so its prices can be fetched later. The request carries the ticker as typed, or, from Lume 1.5, for a fund a broker's file names only by its ISIN, that ISIN. Our server passes it on to Yahoo Finance to look it up and to suggest the symbol you probably meant; a ticker already confirmed is remembered on your device and not sent again.
To be precise about the limitation: like any web request, these reach our server with your IP address attached, so this path is not anonymous in the way your encrypted copy is. Yahoo Finance receives the ticker from our server, not from you, and never sees your IP address. We do not link those requests to your account, and answers are cached and shared across all users rather than stored per person - a ticker is usually looked up once for everybody. But we would rather state the caveat than imply a guarantee we are not making. Both are optional: without prices, an investment's balance is left where it was until they can be fetched (before Lume 2.0 you could also type it by hand), and without a connection the app keeps a ticker as typed.
Where data is processed
Encrypted copies are stored in London, in the United Kingdom, and the price and ticker endpoints run there too. We use Supabase for database and authentication, and Vercel for hosting this website and those endpoints. Neither can read your financial data, for the same reason we cannot: it is encrypted before it reaches them.
Data export and deletion
On Mac and iPhone you can export everything as CSV or JSON at any time. Exports are saved where you choose, or shared from the iPhone's share sheet, and are not transmitted by the app otherwise. Before Lume 1.5 the iPhone app had no export; with sync on, the same data can be exported from Lume on a Mac.
Forgetting a device in sync settings removes the stored key from that device. You can delete your account and the encrypted data held for it from inside either app, under Settings, and it is removed immediately - because we cannot read that data, deletion is the only operation we can meaningfully perform on it. Deleting your account does not touch the copy on your devices: Lume keeps working offline with your history intact, and only syncing stops. Settings → Delete all data removes that local copy as well.
Children's privacy
Lume is not directed at children under 13, and collects nothing from anyone who does not turn on sync.
Changes to this policy
If this policy changes, the updated version will be posted at this URL, with the date above amended.
Contact
Questions? Reach out at henriquejcpacheco@gmail.com.