LUME

Privacy Policy

Last updated 11 June 2026

This Privacy Policy explains how Kyle McQueen, trading as Spiel Labs ("we", "us", or "our"), handles your information when you use the Lume mobile application ("Lume" or the "App"). Lume is a voice-first health and nutrition logging app. We have written this policy to describe, in plain terms, exactly what the App does with your data.

The short version. Almost everything you log stays on your device. When you use a voice feature, the spoken audio is transcribed and only the resulting text is sent to our AI parsing service to turn it into a structured entry. We do not run advertising, we do not sell your data, and we do not track you across apps or websites. The App collects a small amount of anonymised usage analytics — never the contents of your logs — described in section 5. Health data read from Apple Health is used on your device and, with one narrow exception described below, is never transmitted off it.
Contents
  1. What information the App handles
  2. Voice input and speech transcription
  3. Apple Health (HealthKit) data
  4. AI parsing service
  5. Usage analytics
  6. How we use information
  7. When information is shared
  8. Subscriptions and payments
  9. Data retention and deletion
  10. International processing
  11. Security
  12. Children
  13. Your privacy rights
  14. Australian privacy rights
  15. Changes to this policy
  16. Contact us

1. What information the App handles

The personal information involved in Lume falls into a small number of categories:

We do not collect your name, email address, contacts, photos, or location, and the App contains no advertising and no third-party tracking software. The App does include a single privacy-preserving analytics service, described in section 5, which never receives the contents of your entries.

2. Voice input and speech transcription

When you tap to log by voice, the App records audio through your device microphone and passes it to Apple's Speech framework to produce a text transcript.

How audio is handled. The audio is processed by Apple's speech recognition service to generate a transcript. Depending on your device and language, Apple may perform this recognition entirely on your device or may process the audio on Apple's servers, in line with Apple's Privacy Policy. Lume itself does not store your voice recordings and does not transmit the audio to us or to any third party. Only the resulting text transcript leaves the App, and only to our AI parsing service described in section 4.

You can revoke microphone and speech recognition permissions at any time in your device Settings. Doing so disables voice logging but does not affect manual entry.

3. Apple Health (HealthKit) data

If you grant permission, Lume integrates with Apple Health to read certain metrics and to write entries you log. This integration is optional; the App functions without it.

Data Lume reads from Apple Health

Used to display your daily activity and, where you choose, to pre-fill your profile:

Data Lume writes to Apple Health

When you log entries in the App, Lume writes the corresponding samples back to Apple Health so your data stays consistent across apps:

Editing or deleting an entry in Lume updates or removes the matching sample in Apple Health.

How Health data is used and protected. Health data is used solely to provide the App's features on your device. We never use Apple Health data for advertising or marketing, we never sell it, and we never share it with third parties for their own purposes. With the single, limited exception below, all Apple Health data read by Lume, including steps, active energy, height, body fat percentage, biological sex, and date of birth, remains on your device and is never transmitted off it.

The one Health value that may be transmitted

When you log by voice or text, the App includes your current body weight with the request it sends to our AI parsing service (see section 4), so that if the entry is a workout, the service can estimate the calories you burned. Because the parser works out what kind of entry you logged from your words, your weight is included with parsing requests generally, even though it is only ever used for workout calorie estimation. If you previously set your weight using the "Import from Health" option, that figure originated from Apple Health; if you entered it manually, it did not. In either case, the value sent is a single number (your weight in kilograms); no other Apple Health data is included. No height, body fat, sex, date of birth, step, or energy data is ever sent.

4. AI parsing service

Lume's core feature turns a free-text description into a structured entry using an artificial intelligence model. To do this, the App sends the relevant text to a parsing service we operate, which forwards it to our AI provider, Anthropic, for processing. Requests are routed through a proxy we run on Cloudflare's global edge network, which lets us keep our provider credentials secure and apply rate limits.

What is sent in a parsing request:

No name, email, account identifier, location, or other profile or Health data is included in these requests. Your input and the AI output are processed by Anthropic to provide this feature. You can review Anthropic's practices in their privacy policy. You must not use the AI features in any way that violates the terms or policies of our AI provider.

5. Usage analytics

To understand how Lume is used and to improve it, the App collects a small set of anonymised usage events — such as which screens are visited, which logging methods are used (voice, typed, or saved meals), when the subscription screen is shown, and when the daily AI limit is reached. This data is processed by TelemetryDeck (TelemetryDeck GmbH, Germany), a privacy-focused analytics service.

6. How we use information

We process this information because it is necessary to provide the service you have requested, to pursue our legitimate interest in operating and securing the App, and, where required, with your consent (for example, microphone and Apple Health permissions, which you grant explicitly and can withdraw at any time).

7. When information is shared

We do not sell your personal information and we do not share it for advertising. We rely on a small number of service providers strictly to operate the App:

ProviderPurposeWhat it receives
AnthropicAI parsing of your entriesThe entry text, saved meal names, and your body weight (used only for workout calorie estimation)
CloudflareEdge proxy and rate limiting for parsing requestsRequest traffic, including the data above and the device identifier
AppleSpeech transcription; subscription billing; Apple HealthVoice audio for transcription; payment details (which we never see); Health data on your device
TelemetryDeckAnonymised usage analyticsAnonymised usage events (screen and feature names, coarse device context) and a hashed device identifier; never the contents of your entries, transcripts, or Health data

We may also disclose information if required by law, or in connection with a sale or transfer of our business, in which case we will continue to protect it under this policy.

8. Subscriptions and payments

Lume offers an optional auto-renewable subscription, Lume+. All purchases, billing, and renewals are handled by Apple through the App Store. We do not collect or store your payment instrument; we receive only your subscription entitlement status so the App can unlock paid features. Subscription terms, pricing, and cancellation are managed in your Apple account settings and are governed by Apple's Standard End User License Agreement.

9. Data retention and deletion

To delete the data Lume holds on your device, delete entries within the App or uninstall it. To remove samples written to Apple Health, use the Apple Health app.

10. International processing

We are based in Australia. Our service providers, including Anthropic, Cloudflare, and Apple, may process data on infrastructure located in the United States and other countries. TelemetryDeck processes usage analytics on infrastructure in the European Union (Germany). Where data is transferred internationally, we rely on the safeguards offered by these providers, including standard contractual clauses where applicable, to protect your information consistent with this policy.

11. Security

We use reasonable technical and organisational measures to protect your information, including transport encryption for network requests, signed and rate-limited API requests, and storing the device identifier in the device keychain. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and limit what is collected in the first place.

12. Children

Lume is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, please contact us and we will delete it.

13. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. Because most of your information is stored only on your device, you can exercise many of these rights directly: by editing or deleting entries, by managing permissions in your device Settings, and by uninstalling the App. For anything else, or to make a formal request, contact us using the details in section 16. We will respond in accordance with applicable law and will not discriminate against you for exercising your rights.

14. Australian privacy rights

We handle personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles. You may request access to or correction of your personal information by contacting us. If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with the Office of the Australian Information Commissioner.

15. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above. If we make material changes, we will provide a more prominent notice. We encourage you to review this policy periodically.

16. Contact us

If you have questions about this policy or your information, contact:

Kyle McQueen, trading as Spiel Labs
Email: privacy@lume.fitness