Lume Society Pty Ltd
Privacy Policy
How we handle personal information for Lume House members aged 18 and over in Australia and Singapore.
Effective
Information we handle
We may collect and handle:
- account and contact information, including your email address and internal account identifier;
- application and profile information, including your name, age, city, occupation, education, photos, prompts, biography, relationship intent, and optional cultural background;
- sensitive dating information you choose to provide, including gender, attraction, preferences, and the people you would like to meet;
- activity and communications, including introduction decisions, matches, in-app messages, read state, availability, feedback, and matching signals;
- trust and safety information, including blocks, reports, report details, evidence, case decisions, and restricted moderation records; and
- limited technical and operational records needed to secure, operate, troubleshoot, and delete data from the service.
We collect this information from you, from your activity in Lume House, and from restricted staff actions taken to operate admissions, matching, account support, and trust and safety. We do not use advertising SDKs, sell personal information, or track members across other companies' apps or websites.
Why we handle it
We use personal information to:
- create and secure accounts, assess applications, and manage membership;
- build profiles and preferences, make and explain introductions, and support matches and messages;
- personalise the service using the preferences and feedback you provide;
- prevent abuse, receive reports, investigate safety concerns, enforce the House Rules, and keep a bounded record of those decisions;
- respond to access, correction, deletion, support, and privacy requests;
- operate, secure, diagnose, and improve the service; and
- comply with applicable law and establish, exercise, or defend legal claims.
Where consent is required for sensitive information, you provide it by choosing to submit that information for these stated purposes. You may withdraw it by removing optional information or deleting your account, subject to the restricted safety and legal records described below.
Who receives information
We disclose information only as needed to operate the service, respond to you, protect members, or comply with law. Recipients may include:
- Supabase, our hosted database, authentication, private object-storage, function, backup, and operational-log processor;
- infrastructure, delivery, security, and support subprocessors used by that processor;
- authorised Lume Society staff and contractors with a role-based operational need; and
- regulators, courts, law enforcement, advisers, or another party where disclosure is required or permitted by law or necessary to protect rights and safety.
We do not disclose member data to advertisers or data brokers. Other members receive only the profile, introduction, match, and message information the product authorises them to see.
Location and overseas handling
The primary Lume House Supabase project and object-storage region is Tokyo, Japan (ap-northeast-1). People in Australia and Singapore should therefore expect their information to be stored in Japan. Supabase and its subprocessors may also process limited information in other countries to provide network, security, support, and service operations. Lume Society remains responsible for taking reasonable steps to protect personal information disclosed overseas.
Retention and account deletion
We keep information only for as long as it serves the purposes above.
| Information | Retention rule |
|---|---|
| Account and product data | Account, application, profile, preferences, photos, introductions, matches, messages, feedback, and matching signals are deleted from primary systems when account deletion is executed. No member-level feedback or matching aggregate is retained. |
| Safety records | Direct account links are removed on account deletion. Restricted, case-pseudonymous reports, evidence, and moderation audit are deleted 365 days after case resolution. |
| Abuse-prevention standing | Relationship rows are deleted. Where necessary, a keyed, non-readable standing tombstone is retained for 365 days after account deletion. |
| Operational logs | No more than 7 days. We do not configure an external log drain. |
| Database backups | 7 days. Deletion replay markers are kept separately for that window and must be applied before a restored service reopens. Point-in-time recovery and manual backup exports are not used. |
A specific safety case may be kept beyond its normal expiry only under a recorded legal hold that identifies its authority and has an expiry. General, indefinite, or convenience holds are not permitted. A backup may contain data deleted from the primary database until that backup expires. Restore controls must prevent the deleted account from returning to service.
You can request deletion from Settings in the app. We remove the account and associated user-generated content unless a restricted record must be kept for the bounded safety or legal reason above. If a safety case needs review before direct links can be removed safely, the account is frozen while that reviewed process is completed. We do not require you to keep an active account to make or complete a deletion request.
Security
We use access controls, private storage, transport encryption, restricted service credentials, pseudonymous safety-case identifiers, deletion ledgers, and operational monitoring designed to protect personal information. No system is completely secure. If an eligible data breach occurs, we will assess, contain, and notify affected people and regulators as required by applicable law.
Access, correction, complaints, and questions
You may ask to access or correct your personal information, delete your account, withdraw consent where applicable, or complain about our handling of your information.
Lume Society Pty Ltdadmin@lume-society.comPlease describe your request and the email address associated with your account. We may need to verify your identity before acting. We will investigate privacy complaints and respond within a reasonable time. If you are not satisfied, you may contact the Office of the Australian Information Commissioner or Singapore's Personal Data Protection Commission, as applicable.
Changes
We may update this policy when the product, providers, or legal requirements change. We will post the updated policy at the in-app policy link, change its effective date, and provide additional notice where a change is material or consent is required.