Lume

Privacy Policy

Last updated and effective: August 5, 2026

Radish Retail, LLC ("Radish", "we", "us", or "our") operates the Lume mobile application, Lume public share pages, Radish-hosted Lume pages, and related services (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use and disclose it, how long we keep it, and the choices and rights available to you.

This Privacy Policy is incorporated into our Terms of Service.

1. Summary

2. Information We Collect

2.1 Account and profile information

2.2 Onboarding, scans, routines, and product activity

2.3 Sharing, referrals, and acquisition attribution

2.4 Subscription information

Apple and RevenueCat provide app-user identifiers, product identifiers, purchase and restore results, entitlement status, offer eligibility, purchase and expiration dates, renewal status, and related transaction and diagnostic metadata. Lume may also send RevenueCat first-party campaign and referral attribution described above. We do not receive your full payment-card number.

2.5 Information generated or collected automatically

2.6 Information we do not collect or use

3. Face Data: Collection, Use, Sharing, Retention, and Deletion

This section describes Lume's practices for face data specifically. In this policy, "Face Data" means the two-dimensional selfie you choose to capture for a Scan; image metadata and quality information associated with that selfie; temporary facial-zone crops; scan-derived facial-zone placement information, scores, and written observations; and, on supported devices, the transient ARKit or TrueDepth face-position and alignment information used on the device during capture.

3.1 Face Data we collect and do not collect

Lume collects a two-dimensional selfie only when you choose to take a Scan. Lume also creates image-quality results and appearance-based skin information from the selfie, including Skin score, Clarity, Hydration, Smoothness, apparent Skin Age, facial-zone findings, and related observations.

On supported iPhones, Apple ARKit or TrueDepth face tracking may process face position and geometry on the device to guide alignment and trigger capture. That tracking information exists only during the live capture session. Lume does not store or transmit a TrueDepth facial-geometry map, Face ID enrollment, faceprint, or other reusable biometric template. Lume does not use Face Data to recognize or identify a person, verify identity, match faces, or authenticate an account.

3.2 Intended uses of Face Data

Lume uses Face Data only to:

We do not sell, rent, or license Face Data. We do not use Face Data for advertising, cross-app tracking, identity recognition, biometric authentication, or training a publicly released Radish or third-party AI model. This is unchanged by Lume's advertising measurement: no scan photo, facial-zone crop, skin score, or other scan-derived facial information is ever sent to Meta or to any other advertising, ad-network, or ad-measurement service, whether or not you allow tracking. What those services receive is described in Section 2.3 and Section 7.1 and is limited to app events and device or advertising identifiers.

3.3 Face Data sharing and third-party protection

Lume shares Face Data only as follows:

Face Data is not sent to Meta, PostHog, RevenueCat, Typesense, retailers, affiliate programs, or any advertising or ad-measurement service. We require every service provider that receives Face Data, including Supabase and our cloud AI analysis provider, to process it only to provide the contracted service, follow our instructions, maintain appropriate security, delete or return it as required, and provide the same or equivalent protection for Face Data that this Privacy Policy provides.

3.4 Face Data retention

Limited copies may remain temporarily in encrypted or access-restricted backups, security records, or records that must be retained for law, fraud prevention, or dispute handling. Those copies are isolated from ordinary product use and are deleted under the applicable provider retention schedule.

3.5 Consent, revocation, and Face Data deletion

Before analysis, Lume asks for permission to collect the selfie and send it with selected skin-profile answers to a contracted third-party cloud AI analysis provider. You may decline by not taking a Scan. You may revoke permission for future collection at any time by not taking further Scans or by disabling Lume's camera access in iOS Settings. Disabling camera access or deleting the app does not by itself delete Face Data already collected.

You can delete Face Data already collected in any of these ways:

Deleting an individual Scan removes its private scan image, derived scan result, and associated owned storage objects. Deleting your account removes the Face Data associated with the account, including owned scan images, derived results, and public scan-share records and preview images where supported. We also direct service providers to delete Face Data they retain on our behalf, subject only to the limited backup, security, fraud-prevention, legal, and dispute-retention exceptions described above.

4. Product Search, Retailer Links, and Affiliate Commerce

Lume's product catalog supports product search, category and brand browsing, recommendations, saved products, retailer comparisons, and external retailer links. Search terms and filters may be sent to Typesense Cloud; when that service is unavailable, Lume may use a Supabase database search fallback. Search services receive catalog queries and technical request information, not your scan photos.

Product names, ingredients, prices, images, availability, retailer names, ratings, reviews, and claims may come from retailer feeds, affiliate feeds, manufacturers, or other catalog sources. This information may be incomplete, delayed, or inaccurate. Verify product details, price, availability, ingredients, allergens, suitability, shipping, returns, and safety with the retailer or manufacturer.

Retailer links leave Lume and open the external browser or retailer app. Lume may record the product, retailer, source surface, and affiliate redirect result. The retailer then processes your visit and purchase under its own privacy policy. Some links are affiliate links; Radish may earn a commission from qualifying purchases at no additional cost to you. As an Amazon Associate, Radish earns from qualifying purchases.

5. Public Sharing and Referrals

Sharing is optional. Depending on the surface and destination, Lume may export an image, create a public URL, or do both.

Public URLs and preview images can be accessed by anyone with the link, including recipients, social platforms, messaging services, search or link-preview crawlers, and other viewers. Do not share a layout or content you do not want others to see. Account deletion removes public share records and preview objects owned by the account where supported.

6. How We Use Information

We do not use personal information to make automated decisions that produce legal or similarly significant effects.

7. How We Disclose Information

We disclose information only as described in this policy. We do not sell personal information. We require service providers that receive personal information to process it only for authorized services, security, support, or legal compliance and to provide the same or equivalent protections described in this policy and required by applicable law.

7.1 Service providers

ProviderPurposeData received
SupabaseAuthentication, database, Edge Functions, private scan/avatar storage, and public share-preview storageUser and provider IDs, phone/email where supplied, profile data, scans, scores, routines, saved products, reviews, shares, referrals, subscription state, and technical logs
GoogleGoogle sign-inGoogle OAuth identifiers where used
Contracted cloud AI analysis providerStructured Scan analysisScan images, temporary facial-zone crops where used, selected skin-profile context, and limited technical or safety data needed for analysis
AppleSign in with Apple, App Store subscriptions, app distribution, and Apple platform servicesApple account identifiers and optional name/email, subscription transactions, offer eligibility, renewal/cancellation status, and diagnostics managed by Apple
BirdPhone verification and account phone-change SMS deliveryPhone number, one-time verification code, delivery status, and technical message metadata
RevenueCatSubscription entitlement, offerings, purchase/restore, and first-party acquisition attributionAnonymous or Supabase-linked app user ID, product and transaction identifiers, entitlement and offer status, campaign/referral attribution, and diagnostics
PostHogProduct analytics, feature flags, conversion measurement, and sanitized error trackingPseudonymous or Supabase-linked user ID, device/app metadata, event properties, feature exposure, and sanitized error messages and stack traces; session replay and scan-image capture are disabled
Meta PlatformsMeasurement, attribution, and optimization of Lume advertising campaigns on Facebook and Instagram (Meta app ID 1586065256236445, Radish Retail, LLC)App events such as install, app open, subscription start, and purchase; device and app metadata such as model, OS version, app version, locale and time zone; IP address; a Meta-assigned installation identifier; and the Apple advertising identifier (IDFA) only when you allow tracking in the iOS prompt; never scan photos or scan-derived Face Data
Typesense CloudProduct catalog search and filteringSearch terms, filters, catalog queries, and technical request data; not scan photos
Retailers and affiliate programsExternal product destinations, price comparison, affiliate attribution, and purchase routingProduct, retailer, referring Lume surface, redirect metadata, and information the retailer collects after you leave Lume
Cloudflare, Vercel, Expo/EAS, and infrastructure providersHosting, share pages, domains, networking, security, builds, and app deliveryIP addresses, request logs, app/build metadata, device/platform data, and content needed to host public pages or deliver the Service
Social, messaging, and link-preview servicesDelivering a share you chooseThe exported image, public URL, message text, or public preview information you choose to send

Meta receives the advertising data listed above to measure and optimize the campaigns we run, and also processes it for its own purposes under the Meta Privacy Policy. Apple's SKAdNetwork reports install and conversion outcomes to Meta in aggregated form that does not identify you. Meta does not receive scan photos or scan-derived Face Data.

7.2 Public sharing chosen by you

Public share pages, public product pages, invite links, social share targets, messaging services, and link-preview services receive the information needed to render or deliver the share you choose.

7.3 Business transfers

If Radish is acquired, merged, reorganized, financed, or sells assets, information may be transferred as part of that transaction, subject to applicable law.

7.4 Legal and safety

We may disclose information to comply with law or valid legal process, protect rights and safety, prevent fraud or abuse, or enforce our Terms.

7.5 With your consent

We may disclose information for another purpose that we explain when requesting your consent.

8. Your Rights and Choices

California residents and residents of other U.S. states with privacy laws may have rights to know, access, correct, delete, and obtain a copy of personal information; to limit certain uses of sensitive personal information; to opt out of sale or sharing; and to receive equal service. We do not sell personal information. We do disclose the app events described in Section 2.3 to Meta, and the Apple advertising identifier when you allow tracking, so Meta can measure and optimize the ads we run for Lume. California and similar state laws generally treat that disclosure as "sharing" for cross-context behavioral advertising even though no sale occurs, so we describe it as sharing here. To opt out, decline the iOS tracking prompt or turn Lume off in iOS Settings > Privacy & Security > Tracking, which stops the advertising identifier from reaching Meta; to also stop the app events, email privacy@radish.software and we will act on the request. We never share Face Data, scan photos, or scan-derived scores for advertising under any setting, and we do not use sensitive personal information to infer characteristics about you.

Where GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict, object, portability, withdraw consent, and complain to a supervisory authority. Depending on the processing, our legal bases may include performance of a contract, consent, legitimate interests, and legal obligations. Advertising measurement described in Section 2.3 relies on your consent where consent is required, and you can withdraw it through the iOS tracking setting above.

9. Retention

Account deletion removes associated server records and owned storage objects where technically supported. Limited copies may remain in backups or records we must retain for law, fraud prevention, security, accounting, or dispute handling and are isolated from ordinary product use until deleted under the applicable retention schedule.

10. Security

We use HTTPS, Supabase authentication, private storage buckets, row-level security, short-lived signed URLs, server-side authorization, service-role isolation, input validation, and access controls. No transmission or storage method is perfectly secure, and we cannot guarantee absolute security.

11. Children

Lume is not directed to children under 13, and users under 13 are not permitted to use the Service. We may collect date of birth as an optional profile field. Users from 13 to the age of majority may use Lume only with permission from a parent or legal guardian. If you believe a child under 13 provided personal information, contact privacy@radish.software.

12. International Transfers

Radish is based in the United States. We and our providers may process information in the United States and other countries. Where required, we use appropriate transfer mechanisms and service-provider commitments.

13. Changes to This Policy

We may update this Privacy Policy. If a change is material, we will provide notice by email, in-app notice, app update notes, or another reasonable method where required. The effective date above identifies the current version.

14. Contact

Privacy: privacy@radish.software

Legal: legal@radish.software

Support: support@radish.software