Who we are
Daylamp is operated by Jan Tabens, Constanze-Hallgarten-Str. 22, 81379 Munich, Germany. This operator is the controller of the personal data described here. For any question about your data, write to mail@tabens.com.
What this policy covers
This policy covers the Daylamp app for iPhone and Android, the Daylamp website (including the parental-consent page and the invite links), and our support channels. It does not cover the App Store, Google Play or other services you choose to use. Their own policies apply to them.
The data we use
We collect as little as we can. The table shows what the app stores, why, and where that information is visible.
| What | Examples | Why |
|---|---|---|
| Account | Email address and password (stored as a hash), or the sign-in identifier from Sign in with Apple or Google. | To sign you in and keep your account secure. |
| Profile | Username, display name, photo, bio, country and your date of birth, which is kept privately. | To run your profile and the age rules that protect young people. |
| Belief | Your belief and tradition, and who can see them. | To personalise the app. See “Religious belief” below. |
| Practice and progress | Practice days, streaks, XP and level, quests, badges, journal entries and answers to Today’s Question. | To run streaks and rewards, and to keep your private notes. |
| Community | Intentions, prayers and reactions, shared answers, friendships, circles and their messages, reports and blocks. | To run the community features and keep them safe. |
| Lumi | Your chats with Lumi, what Lumi remembers if you turn memory on, and Lumi’s bond level. | To answer you, after you agree to AI processing. |
| Play | Game results, scores, the facts you have learned, and duels or quizzes with friends. | To run the games and show your progress. |
| Notifications and devices | A push token, device type, language, time zone and your notification choices. | To send the reminders you chose, and nothing else. |
| Feedback | The message you send, and any screenshot you choose to attach. | To answer you and fix problems. |
| Contact form and deletion request form | Your name (if you give one), your e-mail address, the topic and the message you send us, and a hashed network address for spam protection. | To answer your message and keep the form safe from abuse. |
| Purchases | Whether you have Daylamp Plus, through the App Store or Google Play. We never see card details. | To unlock Plus features. |
| Analytics | Product events with a random ID made on your phone, only if you turn analytics on. | To improve the app. Off by default. |
| Crash reports | Error details with no account ID, IP address or message content. | To find and fix crashes. |
| Photos | Your profile photo, resized with metadata removed. A verification selfie only if you request verification. | To show your photo, and to verify accounts when you ask us to. |
| Parental consent | For teens who need a parent’s agreement: a hash of the parent’s email, the time, and the consent text version. | To show that the consent was given. |
| Only on your phone | Your location for prayer times and the Qibla, rounded to about one kilometre, your preferences and cached content. | To run the tools on your phone. It is never sent to us. |
Religious belief
Your belief is a special category of personal data under Article 9 of the GDPR. We ask for your explicit consent before we store it, or your parent’s consent where one is needed. Belief is private by default: only you see it, unless you choose Friends or Everyone.
We never send belief to analytics, to advertising, or to push-notification topics. We never show it on leaderboards, and we never publish statistics that combine belief with country. Lumi’s chats can reveal beliefs and other sensitive details, so they are protected in the same way. You can stop sharing your belief in Edit profile, which deletes it.
Lumi and AI providers
Lumi is an AI companion. When you chat with Lumi, we send your message and a small amount of context, so that Lumi can answer you personally: your first name, age group, faith and tradition, goals, streak and level, the local date and time, today’s holy days and Daily Light and, only if memory is on, what Lumi remembers. We do not send your email address, username, country, photos or location.
Anthropic writes Lumi’s replies. OpenAI checks messages for safety, and writes replies if Anthropic is unavailable. Posts, circle names and circle messages are also checked with AI moderation tools before they are shown. Both providers process this data in the United States under the EU’s standard contractual clauses, and under a data processing agreement with us.
You must agree before your first chat. You can withdraw that consent at any time in Settings, which deletes your chats and everything Lumi remembers. Chats are kept for 180 days, unless you delete them sooner.
Why we use data
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the app and your account, and Daylamp Plus | Performing our contract with you (Article 6(1)(b)) |
| Your belief and the Daily Light for it | Your explicit consent (Articles 6(1)(a) and 9(2)(a)) |
| Lumi’s chats and memory | Your consent (Article 6(1)(a)). Memory is opt-in. |
| Safety, moderation and handling reports | Our legitimate interest in a safe community (Article 6(1)(f)), and legal obligations under the EU Digital Services Act (Article 6(1)(c)) |
| Analytics | Your consent (Article 6(1)(a)), which you can withdraw |
| Crash reports | Our legitimate interest in fixing crashes (Article 6(1)(f)), with no identifiers. You can switch them off. |
| Reminders and notifications you choose | Your consent: the device permission and your own switches |
| Answering a message you send us | Our legitimate interest in answering you (Article 6(1)(f) GDPR), or steps you ask us to take before a contract (Article 6(1)(b)) |
| Parental consent for a teen | Article 8 GDPR. A parent’s email is used once to send the request, and is stored only as a hash. |
Providers and locations
We use the service providers below. Our database, sign-in, storage and functions are in the EU, in Frankfurt. Some providers are in the United States or elsewhere. Where personal data leaves the EU, we rely on the EU standard contractual clauses and, where the provider is certified, the EU–US Data Privacy Framework. [confirm the transfer basis for each provider before launch]
| Provider | What it does for us | Where |
|---|---|---|
| Supabase | Database, sign-in, file storage and server functions | EU (Frankfurt) |
| Resend | Sign-in codes, parental-consent emails and emails about moderation decisions | Sent from the EU (Ireland); the provider is based in the United States |
| Google Cloud (Firebase App Hosting) | Hosts this website, with the parental-consent page and the contact and deletion forms | EU (Netherlands); requests arrive through Google’s global network |
| Firebase Cloud Messaging and Apple Push Notification service | Delivers push notifications: a short title and text, never belief or message content | Global, including the United States |
| PostHog (EU Cloud) | Product analytics, only with your consent | EU (Frankfurt) |
| Sentry (EU data region) | Crash reports, without identifiers | EU (Frankfurt) |
| Anthropic | Lumi’s replies and AI moderation checks | United States |
| OpenAI | Lumi’s safety checks, fallback replies and AI moderation | United States |
| RevenueCat | Subscription status, using your Daylamp user ID only | United States |
| Apple and Google | Sign in with Apple or Google, if you choose them. The stores handle purchases. | Global |
How long we keep data
| Data | How long |
|---|---|
| Account, profile, belief and progress | Until you delete your account |
| Lumi chats | 180 days, or until you delete them |
| Intentions and shared answers | 180 days, or until deleted; everything goes when your account is deleted |
| Circle messages | 90 days |
| Inbox notifications and the push delivery log | Inbox 90 days; delivery log 30 days |
| Verification photos | Deleted right after the decision. A request nobody reviews ends after 29 days, and its files are removed then. |
| Parental consent records | As long as the teen’s account exists |
| Teen accounts still waiting for a parent | Deleted automatically after 14 days |
| Analytics events | 12 months, and only if you turned analytics on |
| Crash reports | 90 days |
| Feedback | Until you delete your account. Support may close handled items earlier. |
| Contact messages | 12 months after we last handled them, or after they arrived while still open. The hashed network address is cleared after 30 days. |
| Reports and moderation decisions | Kept for safety, without any link to your account, after you delete it |
| Daylamp Plus store records | With your account. After deletion, store events without any link to you are kept for three years. |
Children and teens
Daylamp is for people aged 13 and over. If the age you give is under 13, we stop the sign-up and keep nothing. If you are under your country’s digital-consent age (16 by default; some countries have a lower age), a parent or guardian must agree before you can use the app. The request is sent by email, and the consent page is on this website.
Everyone aged 13 to 17 gets Teen Mode: a private profile, contact only through friends and invite-only circles, every post checked by a person before anyone sees it, no notifications between 21:00 and 08:00, and streaks only if they switch them on. We do not show ads to young people or build profiles of them. A parent can see the request, agree, or revoke consent at any time. Revoking deletes the teen’s account and its data.
Analytics and crash reports
Analytics are off until you turn them on in Settings. When they are on, the app sends a few product events, such as a completed practice, to PostHog in the EU. The events never include your belief, your messages, names or your account ID. They carry a random ID made on your phone, which is not linked to your account. Turning analytics off stops sending at once and deletes that ID.
Crash reports help us fix bugs. They contain the error, the app and device version, and no account ID, IP address or message content. You can switch them off in Settings.
This website
This website sets no cookies for visitors and uses no analytics or advertising trackers. The only cookies are two strictly necessary ones that keep our own staff signed in to the staff area, which is not open to the public. The contact form and the deletion request form store the message you send us, as the table above describes. Our hosting provider, Google Cloud EMEA Limited in Ireland (Firebase App Hosting), runs this website on servers in the Netherlands. Requests reach those servers through Google’s network, which can pass them through locations outside the EU. Google keeps standard server logs, such as IP address and time of visit, for 30 days for security, and may store them outside the EU. The parental-consent page and the invite links take a token or code from the address. They send it to our backend and do not store it. The standard logs described above can record these addresses, and with them the token or code. The parental-consent page is not indexed by search engines, and it does not pass its address on to other sites.
Security
Data travels over encrypted connections, and our providers encrypt stored data. Row-level security means each person can reach only their own data. Staff access is limited to what their role needs, requires multi-factor sign-in, and is logged. Verification photos are visible only to the person who sent them and, during a review, to one reviewer through short-lived links that are logged. We never store a password in readable form, and we remove location and other metadata from photos.
Automated checks
Automated checks flag content, and may hide a post until a person has looked at it. People make the decisions about accounts, sanctions and appeals. If we remove something, we explain why in a statement of reasons, and you can ask for a review. We do not make decisions with legal effect about you based only on automated processing.
Your rights
- A copy of your data. In the app, choose Download my data. You get a JSON file and links to your files.
- Correction. Most details can be changed in Edit profile.
- Deletion. Delete your account in the app, or request deletion on the Delete your account page. In the app, deletion is immediate.
- Objection and withdrawal. Switch off analytics, crash reports, notifications, Lumi’s memory or the AI consent in Settings. Withdrawing consent takes effect straight away.
- Complaints. You can complain to a data protection authority. The competent authority is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), lda.bayern.de.
Changes
When we change this policy in a way that matters, we tell you in the app before the change takes effect. This version is dated 10 October 2026.
Contact
For any question or request about your data, write to mail@tabens.com. We reply within one month, as the GDPR asks.