Lume
Privacy Policy
Last updated and effective: August 5, 2026
Radish Retail, LLC ("Radish", "we", "us", or "our") operates the Lume mobile application, Lume public share pages, Radish-hosted Lume pages, and related services (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use and disclose it, how long we keep it, and the choices and rights available to you.
This Privacy Policy is incorporated into our Terms of Service.
1. Summary
- Lume processes selfies you choose to scan, scan-derived skin scores and insights, account and profile information, onboarding answers, routine activity, product activity, subscription status, sharing/referral activity, and app usage and diagnostic data.
- Before a scan is analyzed, Lume asks for permission to send the selfie and selected skin-profile answers to a contracted third-party cloud AI analysis provider. Lume uses the result to provide skin-wellness scores, trends, routine guidance, and product recommendations.
- Lume is not a medical device and does not diagnose, treat, cure, or prevent any condition.
- We do not sell personal information and we do not show third-party ads inside Lume.
- Lume advertises on Meta (Facebook and Instagram). To measure and optimize those campaigns, Lume shares app events such as install, subscription, and purchase with Meta, and, only if you allow tracking when iOS asks, the Apple advertising identifier (IDFA). If you decline, Meta receives no advertising identifier from Lume and attribution falls back to Apple's privacy-preserving SKAdNetwork. Face Data is never sent to Meta and is never used for advertising.
- Scan photos are private by default. If you deliberately create a public scan link and choose a share-card layout containing your photo, the rendered share image may become public. The original scan object in private storage is not made public.
- PostHog session replay is disabled. Lume sends product analytics, feature-exposure, and sanitized error events, not screen recordings or scan photos.
- You can delete individual scans and can delete your account and associated server data from inside the app.
- We do not knowingly collect personal information from children under 13.
2. Information We Collect
2.1 Account and profile information
- Authentication information. A Supabase user ID and, depending on how you sign in, a phone number, Apple or Google account identifier, and an email address or name provided by Apple or Google. We do not offer password-based login and do not receive your Apple or Google password.
- Guest accounts. Lume may create an authenticated anonymous Supabase user ID so you can complete the first-scan flow before registering. If you later create or sign into a full account, Lume may migrate eligible guest data to that account.
- Profile information. Display name, private profile photo, contact phone number, gender, date of birth, and other profile fields you choose to provide. Lume public user profiles are not a current launch feature.
2.2 Onboarding, scans, routines, and product activity
- Onboarding answers. Your selected motivation, skin type, routine level, skin concerns, and similar answers used to tailor the Service.
- Scans. Selfies captured through the camera, capture and upload timestamps, private storage paths, image-quality results, and analysis status.
- Routine data. Routine names, templates, products, morning/evening steps, schedules, completion check-ins, active plans, and routine history.
- Product activity. Product searches and filters, product and brand views, saved products, followed brands, product notes, routine-product additions, reviews you submit, retailer-link clicks, and related product-fit interactions.
- Support and text you submit. Messages you send to support and text you enter into notes, reviews, routines, profile fields, or other app fields.
2.3 Sharing, referrals, and acquisition attribution
- Share data. Public scan-share records and preview images, routine-share snapshots, public product links, weekly recap links and exported cards, invite links, share destination selections, open counts, and last-opened timestamps where supported.
- Referral data. Referral codes, share IDs, referrer and recipient account IDs, claim status, accepted-referral counts, and earned scan-credit records.
- First-party link attribution. When you open a Lume link, we may store the link ID, source, campaign, content, referring handle, landing URL, and capture time on your device and may send selected attribution fields to RevenueCat.
- Meta advertising attribution. Lume runs install and subscription campaigns on Meta (Facebook and Instagram). The app includes the Meta SDK and registers Meta's ad-network identifiers with Apple's SKAdNetwork so Apple can report campaign outcomes. Lume sends Meta app events such as app install, app open, subscription start, and purchase, along with device and app context such as device model, operating system version, app version, locale, time zone, IP address, and a Meta-assigned installation identifier. App Store purchase and subscription events are logged automatically by the Meta SDK, and Lume mirrors one conversion event. Our Meta app ID is 1586065256236445 and the associated business is Radish Retail, LLC.
- App Tracking Transparency and the advertising identifier. Before any advertising identifier is used, iOS asks whether Lume may track you across other companies' apps and websites. If you allow it, Lume sends Meta the Apple advertising identifier (IDFA) so Meta can attribute an install or subscription to the ad you saw. If you decline or later turn tracking off, Lume sends Meta no advertising identifier and attribution relies on Apple's privacy-preserving SKAdNetwork, which reports aggregated campaign outcomes without identifying you. Scan photos and scan-derived Face Data are never included in any of this, regardless of your tracking choice.
- Deferred referral matching. If iOS does not preserve an invite through App Store installation, Lume may temporarily match one recent invite click to first app open using a keyed hash of the request IP address, coarse locale and time-zone hints, a random installation ID, and the referral code. The raw IP address is not stored in the referral table. Invite-click rows expire after two hours and are pruned after expiration.
2.4 Subscription information
Apple and RevenueCat provide app-user identifiers, product identifiers, purchase and restore results, entitlement status, offer eligibility, purchase and expiration dates, renewal status, and related transaction and diagnostic metadata. Lume may also send RevenueCat first-party campaign and referral attribution described above. We do not receive your full payment-card number.
2.5 Information generated or collected automatically
- Scan-derived information. Skin score, Clarity, Hydration, Smoothness, apparent Skin Age, facial-zone findings, quality warnings, trend summaries, and AI-generated observations. Internal analysis may also evaluate visible breakout control, evenness, and under-eye appearance. These are appearance-based wellness signals, not diagnoses.
- Product-fit information. Recommendation scores and reasons, relevant categories, ingredients, skin concerns, retailer availability, and catalog-ranking signals.
- Usage analytics. App launches, screen views, taps, scan-funnel events, paywall and purchase events, feature-flag exposure, sharing and referral events, routine and product events, notification-preference events, and conversion-funnel timing.
- Device and diagnostic data. Device model, operating system, app version, platform, locale, time zone, performance data, sanitized error messages and stack traces, and technical request context.
- Server logs. IP address, request path, timestamp, response status, and security, rate-limit, or debugging metadata may appear in infrastructure logs.
2.6 Information we do not collect or use
- We do not collect precise GPS location.
- We do not access your contacts or Apple Health/HealthKit data.
- We do not record microphone audio.
- We do not show third-party ads inside Lume, and we do not use scans, scores, or any Face Data for advertising. Lume does measure the ads we run on Meta; Section 2.3 describes exactly what Meta receives, Section 7.1 lists it in the provider table, and Section 8 explains how to decline tracking.
- We do not perform face recognition, identify you from facial geometry, or compare your face with another person.
- We access the photo library only when you choose a profile photo or ask Lume to save/export a share image.
3. Face Data: Collection, Use, Sharing, Retention, and Deletion
This section describes Lume's practices for face data specifically. In this policy, "Face Data" means the two-dimensional selfie you choose to capture for a Scan; image metadata and quality information associated with that selfie; temporary facial-zone crops; scan-derived facial-zone placement information, scores, and written observations; and, on supported devices, the transient ARKit or TrueDepth face-position and alignment information used on the device during capture.
3.1 Face Data we collect and do not collect
Lume collects a two-dimensional selfie only when you choose to take a Scan. Lume also creates image-quality results and appearance-based skin information from the selfie, including Skin score, Clarity, Hydration, Smoothness, apparent Skin Age, facial-zone findings, and related observations.
On supported iPhones, Apple ARKit or TrueDepth face tracking may process face position and geometry on the device to guide alignment and trigger capture. That tracking information exists only during the live capture session. Lume does not store or transmit a TrueDepth facial-geometry map, Face ID enrollment, faceprint, or other reusable biometric template. Lume does not use Face Data to recognize or identify a person, verify identity, match faces, or authenticate an account.
3.2 Intended uses of Face Data
Lume uses Face Data only to:
- guide framing and determine whether a submitted image is suitable for analysis;
- generate the private skin-wellness scores, facial-zone findings, and written observations shown to you;
- provide your scan history, progress comparisons, trends, routine guidance, and product-fit recommendations; and
- create an exported or public share image containing your selfie only when you deliberately select a photo-containing share layout.
We do not sell, rent, or license Face Data. We do not use Face Data for advertising, cross-app tracking, identity recognition, biometric authentication, or training a publicly released Radish or third-party AI model. This is unchanged by Lume's advertising measurement: no scan photo, facial-zone crop, skin score, or other scan-derived facial information is ever sent to Meta or to any other advertising, ad-network, or ad-measurement service, whether or not you allow tracking. What those services receive is described in Section 2.3 and Section 7.1 and is limited to app events and device or advertising identifiers.
3.3 Face Data sharing and third-party protection
Lume shares Face Data only as follows:
- Supabase. The two-dimensional selfie is uploaded over HTTPS to a private Supabase Storage bucket scoped to the authenticated user ID. Supabase also hosts the associated private database records and server functions. Lume uses row-level access controls and short-lived signed URLs to restrict access.
- Contracted cloud AI analysis provider. After the server validates your session and ownership of the Scan, Lume sends its contracted third-party AI processor the two-dimensional selfie, temporary facial-zone crops where used, and selected skin-profile context for structured analysis. The processor returns scores and observations to Lume. The processor is not authorized by Radish to use Lume Face Data for advertising, face recognition, or training publicly released AI models.
- Sharing chosen by you. If you deliberately create a public scan link and select a photo-containing layout, the rendered share image containing your selfie may be disclosed to the recipients, social or messaging services, and link-preview services involved in that share. The original private scan object and full private report are not made public.
Face Data is not sent to Meta, PostHog, RevenueCat, Typesense, retailers, affiliate programs, or any advertising or ad-measurement service. We require every service provider that receives Face Data, including Supabase and our cloud AI analysis provider, to process it only to provide the contracted service, follow our instructions, maintain appropriate security, delete or return it as required, and provide the same or equivalent protection for Face Data that this Privacy Policy provides.
3.4 Face Data retention
- On-device alignment data. ARKit or TrueDepth face-position and alignment information is used only during the live capture session and is discarded when that session ends. Lume does not retain it.
- Temporary crops and failed attempts. Temporary facial-zone crops are deleted after the analysis attempt. The scan pipeline removes failed or invalid uploads when no result is created where technically supported.
- Successful Scans stored by Lume. Lume retains the successful two-dimensional selfie and its derived result in private Supabase storage and database records until you delete that Scan, delete your account, or ask us to delete it.
- Cloud AI processing. Our contracted AI processor handles the submitted Face Data to return the requested analysis. It may retain limited request, security, or abuse-prevention data only as permitted by its contracted service terms and applicable law; it may not retain or use Lume Face Data for an independent advertising, recognition, or public-model-training purpose.
- Public share images. A public share image containing your selfie remains available until the share is deleted, the associated account is deleted, the share expires where supported, or you ask us to remove it.
Limited copies may remain temporarily in encrypted or access-restricted backups, security records, or records that must be retained for law, fraud prevention, or dispute handling. Those copies are isolated from ordinary product use and are deleted under the applicable provider retention schedule.
3.5 Consent, revocation, and Face Data deletion
Before analysis, Lume asks for permission to collect the selfie and send it with selected skin-profile answers to a contracted third-party cloud AI analysis provider. You may decline by not taking a Scan. You may revoke permission for future collection at any time by not taking further Scans or by disabling Lume's camera access in iOS Settings. Disabling camera access or deleting the app does not by itself delete Face Data already collected.
You can delete Face Data already collected in any of these ways:
- delete an individual Scan from its Scan detail screen in Lume;
- delete your account from Profile > Settings > Delete account, which is available to guest and registered users; or
- request deletion by emailing privacy@radish.software.
Deleting an individual Scan removes its private scan image, derived scan result, and associated owned storage objects. Deleting your account removes the Face Data associated with the account, including owned scan images, derived results, and public scan-share records and preview images where supported. We also direct service providers to delete Face Data they retain on our behalf, subject only to the limited backup, security, fraud-prevention, legal, and dispute-retention exceptions described above.
4. Product Search, Retailer Links, and Affiliate Commerce
Lume's product catalog supports product search, category and brand browsing, recommendations, saved products, retailer comparisons, and external retailer links. Search terms and filters may be sent to Typesense Cloud; when that service is unavailable, Lume may use a Supabase database search fallback. Search services receive catalog queries and technical request information, not your scan photos.
Product names, ingredients, prices, images, availability, retailer names, ratings, reviews, and claims may come from retailer feeds, affiliate feeds, manufacturers, or other catalog sources. This information may be incomplete, delayed, or inaccurate. Verify product details, price, availability, ingredients, allergens, suitability, shipping, returns, and safety with the retailer or manufacturer.
Retailer links leave Lume and open the external browser or retailer app. Lume may record the product, retailer, source surface, and affiliate redirect result. The retailer then processes your visit and purchase under its own privacy policy. Some links are affiliate links; Radish may earn a commission from qualifying purchases at no additional cost to you. As an Amazon Associate, Radish earns from qualifying purchases.
5. Public Sharing and Referrals
Sharing is optional. Depending on the surface and destination, Lume may export an image, create a public URL, or do both.
- Scan shares. A public record may contain the score, result headline, scan date, creation date, preview image, and open metadata. If you select a photo-containing card for a link-backed share, the rendered card may include your scan photo. The original private scan object and full private report remain private.
- Metric shares. Individual metric cards are exported as images and do not create a public Lume URL.
- Routine shares. A public routine snapshot may include its name, description, cover art, creator label, and displayed products or steps. A snapshot may remain unchanged after you edit the original routine.
- Product shares. Public links contain catalog product information and route recipients to the relevant product page.
- Weekly recap shares. Exported recap images may contain scan and routine summary statistics. A recap URL identifies the week being shared and routes to the Lume experience.
- Invite links. Invite URLs contain a referral code. When an eligible friend joins and accepts the referral, both the referrer and recipient currently receive one additional scan credit. Credits are subject to eligibility, fraud controls, and program changes.
Public URLs and preview images can be accessed by anyone with the link, including recipients, social platforms, messaging services, search or link-preview crawlers, and other viewers. Do not share a layout or content you do not want others to see. Account deletion removes public share records and preview objects owned by the account where supported.
6. How We Use Information
- provide authentication, scans, scores, history, trends, facial-zone findings, routines, product matching, saved products, sharing, referrals, and subscriptions;
- migrate eligible guest data to a registered account;
- personalize routines, product recommendations, scan guidance, and app surfaces based on scans and answers you provide;
- process purchases, restores, entitlements, offer eligibility, and earned referral scan credits;
- attribute first-party Lume campaigns, public links, and referrals;
- measure, attribute, and optimize the advertising campaigns Radish runs for Lume on Meta, including install and subscription conversion measurement;
- schedule local reminder notifications if you enable them;
- debug, secure, rate-limit, monitor, and improve the Service;
- measure aggregate product performance and conversion funnels;
- comply with law, enforce our Terms, and defend legal claims.
We do not use personal information to make automated decisions that produce legal or similarly significant effects.
7. How We Disclose Information
We disclose information only as described in this policy. We do not sell personal information. We require service providers that receive personal information to process it only for authorized services, security, support, or legal compliance and to provide the same or equivalent protections described in this policy and required by applicable law.
7.1 Service providers
| Provider | Purpose | Data received |
|---|---|---|
| Supabase | Authentication, database, Edge Functions, private scan/avatar storage, and public share-preview storage | User and provider IDs, phone/email where supplied, profile data, scans, scores, routines, saved products, reviews, shares, referrals, subscription state, and technical logs |
| Google sign-in | Google OAuth identifiers where used | |
| Contracted cloud AI analysis provider | Structured Scan analysis | Scan images, temporary facial-zone crops where used, selected skin-profile context, and limited technical or safety data needed for analysis |
| Apple | Sign in with Apple, App Store subscriptions, app distribution, and Apple platform services | Apple account identifiers and optional name/email, subscription transactions, offer eligibility, renewal/cancellation status, and diagnostics managed by Apple |
| Bird | Phone verification and account phone-change SMS delivery | Phone number, one-time verification code, delivery status, and technical message metadata |
| RevenueCat | Subscription entitlement, offerings, purchase/restore, and first-party acquisition attribution | Anonymous or Supabase-linked app user ID, product and transaction identifiers, entitlement and offer status, campaign/referral attribution, and diagnostics |
| PostHog | Product analytics, feature flags, conversion measurement, and sanitized error tracking | Pseudonymous or Supabase-linked user ID, device/app metadata, event properties, feature exposure, and sanitized error messages and stack traces; session replay and scan-image capture are disabled |
| Meta Platforms | Measurement, attribution, and optimization of Lume advertising campaigns on Facebook and Instagram (Meta app ID 1586065256236445, Radish Retail, LLC) | App events such as install, app open, subscription start, and purchase; device and app metadata such as model, OS version, app version, locale and time zone; IP address; a Meta-assigned installation identifier; and the Apple advertising identifier (IDFA) only when you allow tracking in the iOS prompt; never scan photos or scan-derived Face Data |
| Typesense Cloud | Product catalog search and filtering | Search terms, filters, catalog queries, and technical request data; not scan photos |
| Retailers and affiliate programs | External product destinations, price comparison, affiliate attribution, and purchase routing | Product, retailer, referring Lume surface, redirect metadata, and information the retailer collects after you leave Lume |
| Cloudflare, Vercel, Expo/EAS, and infrastructure providers | Hosting, share pages, domains, networking, security, builds, and app delivery | IP addresses, request logs, app/build metadata, device/platform data, and content needed to host public pages or deliver the Service |
| Social, messaging, and link-preview services | Delivering a share you choose | The exported image, public URL, message text, or public preview information you choose to send |
Meta receives the advertising data listed above to measure and optimize the campaigns we run, and also processes it for its own purposes under the Meta Privacy Policy. Apple's SKAdNetwork reports install and conversion outcomes to Meta in aggregated form that does not identify you. Meta does not receive scan photos or scan-derived Face Data.
7.2 Public sharing chosen by you
Public share pages, public product pages, invite links, social share targets, messaging services, and link-preview services receive the information needed to render or deliver the share you choose.
7.3 Business transfers
If Radish is acquired, merged, reorganized, financed, or sells assets, information may be transferred as part of that transaction, subject to applicable law.
7.4 Legal and safety
We may disclose information to comply with law or valid legal process, protect rights and safety, prevent fraud or abuse, or enforce our Terms.
7.5 With your consent
We may disclose information for another purpose that we explain when requesting your consent.
8. Your Rights and Choices
- Access, correction, export, and deletion. You may request access to, correction of, export of, or deletion of your personal information by contacting us.
- Scan deletion. You can delete supported scans from scan detail or ask us to delete them.
- Account deletion. Registered and guest users can initiate account deletion in app settings. You may also email privacy@radish.software.
- AI and camera choice. You may decline a scan, revoke camera permission in iOS Settings, and delete prior scans or your account. Lume cannot provide scan analysis without sending the scan to the disclosed AI provider.
- Photo access. You control photo-library permission in iOS Settings. Existing profile photos can be removed in Lume.
- Reminders. Reminders are local and optional. You can disable them in Lume or in device settings.
- Subscriptions. Manage or cancel an App Store subscription in Apple account settings. Deleting your Lume account does not cancel an Apple subscription or stop renewal.
- Advertising tracking. When iOS asks whether Lume may track you across other companies' apps and websites, declining means Meta receives no advertising identifier from Lume and attribution falls back to Apple's SKAdNetwork. You can change the choice at any time in iOS Settings > Privacy & Security > Tracking, or turn tracking off for every app there. To also stop Lume from sending Meta app events for advertising measurement, email privacy@radish.software.
- Analytics rights. Contact us to exercise an opt-out or objection right for non-essential analytics where applicable.
California residents and residents of other U.S. states with privacy laws may have rights to know, access, correct, delete, and obtain a copy of personal information; to limit certain uses of sensitive personal information; to opt out of sale or sharing; and to receive equal service. We do not sell personal information. We do disclose the app events described in Section 2.3 to Meta, and the Apple advertising identifier when you allow tracking, so Meta can measure and optimize the ads we run for Lume. California and similar state laws generally treat that disclosure as "sharing" for cross-context behavioral advertising even though no sale occurs, so we describe it as sharing here. To opt out, decline the iOS tracking prompt or turn Lume off in iOS Settings > Privacy & Security > Tracking, which stops the advertising identifier from reaching Meta; to also stop the app events, email privacy@radish.software and we will act on the request. We never share Face Data, scan photos, or scan-derived scores for advertising under any setting, and we do not use sensitive personal information to infer characteristics about you.
Where GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict, object, portability, withdraw consent, and complain to a supervisory authority. Depending on the processing, our legal bases may include performance of a contract, consent, legitimate interests, and legal obligations. Advertising measurement described in Section 2.3 relies on your consent where consent is required, and you can withdraw it through the iOS tracking setting above.
9. Retention
- Successful scan photos and results remain until you delete the scan or account, subject to limited legal, security, backup, and dispute retention.
- Account, routine, profile, saved-product, review, referral, and share records remain while your account or the feature requires them and are removed on account deletion where supported.
- Deferred referral-click records expire after two hours and are periodically pruned. Rate-limit, security, and infrastructure logs may be retained longer when reasonably necessary.
- Advertising measurement events sent to Meta, and any advertising identifier shared while you allowed tracking, are retained by Meta under its own policies and schedules. Deleting your Lume account or turning tracking off does not by itself delete events Meta has already received, but it stops further advertising-identifier sharing.
- RevenueCat, Apple, Meta, retailers, and other independent providers retain transaction, advertising, or account records under their own legal obligations and policies.
Account deletion removes associated server records and owned storage objects where technically supported. Limited copies may remain in backups or records we must retain for law, fraud prevention, security, accounting, or dispute handling and are isolated from ordinary product use until deleted under the applicable retention schedule.
10. Security
We use HTTPS, Supabase authentication, private storage buckets, row-level security, short-lived signed URLs, server-side authorization, service-role isolation, input validation, and access controls. No transmission or storage method is perfectly secure, and we cannot guarantee absolute security.
11. Children
Lume is not directed to children under 13, and users under 13 are not permitted to use the Service. We may collect date of birth as an optional profile field. Users from 13 to the age of majority may use Lume only with permission from a parent or legal guardian. If you believe a child under 13 provided personal information, contact privacy@radish.software.
12. International Transfers
Radish is based in the United States. We and our providers may process information in the United States and other countries. Where required, we use appropriate transfer mechanisms and service-provider commitments.
13. Changes to This Policy
We may update this Privacy Policy. If a change is material, we will provide notice by email, in-app notice, app update notes, or another reasonable method where required. The effective date above identifies the current version.
14. Contact
Privacy: privacy@radish.software
Legal: legal@radish.software
Support: support@radish.software