Effective date: 28 June 2026
Service: myLumita
Data Controller: Erdős Tímea EV, registered sole proprietor
Contact: info@mylumita.com
Registration number: 59772051
Tax number: 90543412-1-33
This Privacy Policy explains how myLumita collects, uses, stores and shares personal data, what rights you have, and how you can contact us.
For the purposes of this Privacy Policy, the data controller is Erdős Tímea EV, registered sole proprietor, operating the myLumita service.
This Privacy Policy applies to:
We may process:
When you create or join a family space, we may process:
Depending on how you use myLumita, we may process content such as:
If you enable the family map or location sharing, we may process:
Location sharing is optional. It only works if the user enables it in myLumita and grants location permission on the device.
myLumita may include personal record-keeping features where you can enter health-related or sensitive information, such as:
These types of data may be sensitive and may, depending on the content, qualify as special category personal data under the GDPR.
You should only enter health-related data if you choose to use that feature and understand that myLumita is for personal record keeping only.
myLumita is not a medical device and does not provide medical advice.
If you subscribe or make a purchase, we may process:
RevenueCat states that it acts as a processor when handling end-user personal data for app developers, and its documentation also refers to purchase history in the context of Google Play Data Safety disclosures.
We may process technical information such as:
If you contact us, we may process:
We may process personal data for the following purposes:
| Purpose | Example | Legal basis |
|---|---|---|
| Account creation and login | account access, authentication | performance of contract |
| Providing family organization features | calendars, tasks, lists, notes, chat | performance of contract |
| Managing family spaces | invitations, roles, permissions | performance of contract / legitimate interest |
| Optional location sharing | family map display | consent |
| Personal and health-related journals | cycle records, blood sugar records, wellness notes | explicit consent, where required |
| Subscription management | entitlements, renewals, access control | performance of contract |
| Payment processing | Apple, Google Play, Stripe, RevenueCat | performance of contract / legal obligation |
| Security and fraud prevention | detecting unauthorized access | legitimate interest |
| Customer support | answering messages and complaints | performance of contract / legitimate interest |
| Accounting and legal compliance | invoices, tax records | legal obligation |
| Marketing communication | newsletters, offers | consent, where required |
myLumita is designed for shared family use.
Content added to a family space may be visible to other members of that family space, depending on permissions and feature settings. This may include calendar events, lists, tasks, notes, messages, reminders, family information and, if enabled, location data.
Please only invite people you trust and only add information that is appropriate for the members of the family space.
The location sharing feature is optional.
Location data is processed only when:
Shared location may be visible to authorized members of the family space.
The purpose of location sharing is everyday family coordination. It is not an emergency service, safety monitoring tool or rescue system.
You can turn off location sharing:
Location data may be inaccurate, delayed, outdated or unavailable.
Baby care notes, cycle tracking, blood sugar records, wellness notes and similar personal journals are voluntary.
You decide whether to use these features and what information to enter.
Because this information may be sensitive:
myLumita is for personal record keeping only. It is not a medical device and does not provide diagnosis, treatment or medical recommendations.
We may use third-party providers to operate myLumita.
| Provider | Purpose | Notes |
|---|---|---|
| Google Firebase / Firestore / Google Cloud | backend infrastructure, database, synchronization, possible authentication and storage | Firebase states that Google is generally a data processor under GDPR when customers use Firebase. |
| Mapbox | map display and location-related map features | Mapbox states that it receives location data in certain app SDK cases when the end user has authorized device location access. |
| RevenueCat | subscription and entitlement management | RevenueCat states that it acts as a processor when handling end-user personal data for app developers. |
| Stripe | web / desktop payments | Stripe provides privacy information for payment-related personal data through its Privacy Center. |
| Apple App Store | iOS app distribution, in-app purchases and subscriptions | Apple handles App Store subscription and payment processes. |
| Google Play | Android app distribution, in-app purchases and subscriptions | Google handles Google Play subscription and payment processes. |
This provider list may change as myLumita develops. We will update this Privacy Policy when necessary.
Some of our providers may process data outside the European Economic Area, including in the United States.
This may include providers such as Google/Firebase, Mapbox, RevenueCat or Stripe.
Where international transfers take place, we aim to rely on appropriate safeguards, such as data processing agreements, standard contractual clauses, technical and organizational security measures, or other lawful transfer mechanisms.
RevenueCat’s DPA describes processing of customer personal data, sub-processors, security measures and international transfer-related terms.
We keep personal data only for as long as needed for the relevant purpose or as required by law.
General retention principles:
Deletion may not be immediate in all backup or log systems, but data will be removed according to our technical deletion cycles unless retention is legally required.
We use technical and organizational measures designed to protect personal data, such as:
No online service can be guaranteed to be completely risk-free. Please use a strong password, protect your devices and invite only trusted people to your family space.
The myLumita website and web payment pages may use cookies or similar technologies.
These may be used for:
Strictly necessary cookies are used to provide the website and payment flow. Non-essential analytics or marketing cookies are used only where required consent has been obtained.
We may send marketing e-mails, newsletters or promotional messages only if you have consented or if applicable law otherwise allows it.
You can unsubscribe at any time by using the unsubscribe link in the message or contacting info@mylumita.com.
We may still send important service messages, such as security, payment, account, legal or technical notices, even if you unsubscribe from marketing.
myLumita is a family app, so information about children may be recorded by parents or legal guardians.
This may include routines, school events, care notes, family calendar entries or reminders.
Parents and legal guardians are responsible for entering children’s data and supervising children’s use of the Service.
The GDPR includes specific rules for children’s consent in relation to information society services, including parental authorization below the relevant age threshold.
Please only record child-related data that is necessary, proportionate and appropriate for family organization.
Depending on your location and applicable law, you may have the right to:
NAIH provides guidance on GDPR data subject rights, including access, rectification, erasure, restriction, portability and objection rights.
To exercise your rights, contact us at info@mylumita.com.
We may need to verify your identity before responding, especially where the request relates to an account or family space.
If processing is based on consent, you may withdraw your consent at any time.
For example:
Withdrawing consent does not affect processing that took place before consent was withdrawn.
You may request account deletion through the app, if available, or by contacting info@mylumita.com.
You may also request an export of your data where the right to data portability applies and where the data can technically be provided.
Some shared family content may remain available to other family members if it is part of a shared family space and is not deleted by an authorized user, unless deletion is required by law.
If you believe your personal data has not been handled properly, please contact us first at info@mylumita.com.
You may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.
Hungarian National Authority for Data Protection and Freedom of Information — NAIH
Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
Phone: +36 (1) 391 1400
E-mail: ugyfelszolgalat@naih.hu
NAIH publishes these contact details on its official website.
If you are a consumer and have a consumer dispute with us, you may be able to contact a Hungarian conciliation board.
The Budapest Conciliation Board states that it helps consumers and businesses settle consumer disputes out of court.
The European Commission’s Online Dispute Resolution platform has been discontinued as of 20 July 2025, so myLumita should not publish the old ODR platform link as an active dispute resolution route.
We may update this Privacy Policy from time to time, for example when we add new features, change providers, update our data practices or need to reflect legal changes.
The updated version will be published on the website or in the app. If the change is significant, we will try to notify you separately.
For privacy questions, requests or complaints, contact:
myLumita / Erdős Tímea EV
E-mail: info@mylumita.com
Website: www.mylumita.com