Privacy Policy

Last updated: July 22, 2026

1. Introduction

OpenLumin (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Bible learning platform at openlumin.com (the “Service”).

2. Information We Collect

We collect the following types of information:

  • Account Information: When you create an account, we collect your name, email address, and password (stored securely as a hash).
  • Learning Data: Courses you create, lessons completed, flashcard review history, daily verse interactions, and learning preferences (mode, level, translation).
  • Organization Data: If you join or create an organization through the Church Plan, we collect the organization name, denomination, optional public profile (location, tagline, logo), member list (names and emails of invited members), group and pathway assignments, shared course selections, and announcements posted by administrators.
  • Engagement Data:To power learning features and, for Church Plan organizations, pastoral-care insights, we record activity events such as lessons opened and completed, flashcards reviewed, courses shared or exported, and announcements opened, along with your last-active time and current course. Within an organization, this activity is visible to your leaders (see “Data Sharing” below).
  • Question Topics:For every account, the topic and intent of your AskLumin questions (e.g. “grief”, “asking for an explanation”) are classified from conversation titles only — never the question or answer text — and stored per conversation for our own internal product analysis. Separately, for Church Plan organizations, the topics of members' questions are also grouped into anonymized themes so leaders can see what their congregation is exploring; that org-facing feature stores only masked aggregates, and you can opt out of contributing to your organization's anonymized trends at any time in Settings. That opt-out applies to the organization trends only — it does not affect our internal per-conversation topic analysis.
  • Notifications: We store in-app notifications (such as a course being ready, an announcement, or a pathway unlocking) so that we can display them to you.
  • Payment Data: If you subscribe to a paid plan, payment is processed by Polar.sh. We receive your email and subscription status but do not store credit card numbers or payment details.
  • Referral Data:If you sign up via a referral link, we store the referral source (e.g. “church” or “twitter”) to understand how users find us. This is stored in our own database and is never attached to your account in any third-party analytics service.
  • Usage Data: Pages visited, features used, and general interaction patterns to improve the Service. On our public pages this is collected through Google Analytics and Umami; see sections 5 and 8 for exactly what each one receives and where each one runs.

3. How We Use Your Information

  • To provide and personalize the Service, including generating courses tailored to your level and preferences.
  • To track your learning progress and power spaced repetition scheduling.
  • To cache and serve courses efficiently: When you generate a course, it may be cached and served to other users who ask a similar question at the same learner level. Cached courses contain no personal information — only the topic, scholarly content, and lesson structure. Your name, email, and learning progress are never shared through caching.
  • To facilitate organization features (Church Plan), including sharing courses, groups, pathways, and announcements within your organization.
  • To provide Church Plan pastoral-care insights — including congregational engagement summaries, named follow-up (“care”) lists for organization leaders, and anonymized study and question trends — and to send periodic digest emails to organization leaders.
  • To understand what our users ask about in aggregate, so we can decide which study material to build and where the Service falls short. We classify each conversation using only its title — never the text of your questions — and store the resulting topic category, the kind of help sought, and any Bible passage the title refers to. We use this internally to guide what we build; we do not sell it or publish it. The classification itself is performed by our AI provider — see “AI Model Providers” below.
  • To process payments and manage subscriptions through our payment provider (Polar.sh).
  • To send transactional emails (account verification, password reset, organization invites, and important Service updates) through our email provider (Resend).
  • To improve the Service based on usage patterns.

4. Data Storage and Security

Your data is stored securely using Turso (libSQL) with encrypted connections. Passwords are hashed using bcrypt and are never stored in plain text. Session tokens are stored in HTTP-only cookies. We implement industry-standard security measures to protect your data, but no method of transmission over the Internet is 100% secure.

5. Third-Party Services

We use the following third-party services:

  • Bible MCP API: To retrieve Bible text, commentaries, cross-references, and scholarly data. No personally identifiable information is sent to this service.
  • AI Model Providers (OpenRouter/Google/Anthropic): To generate course structures and lesson content. Your personal data is not included in these prompts — only the topic, passage, learning mode, and learner level you selected. Your denomination and statement of faith may be included to personalize content but are not stored by the AI provider. The titles (not the contents) of AskLumin questions are sent to this provider so they can be grouped into anonymized themes: for Church Plan organizations approximately once per week for congregation trends, and across all accounts approximately once per day so we can see which topics to build study material for. The questions and their answers are not retained by the provider.
  • Polar.sh: To process subscription payments for the Church Plan and supporter tiers. Polar receives your email address for payment processing. We do not store credit card information.
  • Resend: To send transactional emails (verification, password reset, organization invites) and, for Church Plan leaders, periodic digest emails. Digest emails may include member names and organizational engagement summaries needed to compose the message. We share only what is necessary to deliver the email and do not use this service for marketing or advertising.
  • Voyage AI: To generate text embeddings for semantic search of scholarly sources. No personal data is sent — only Bible topics and terms.
  • Amazon Web Services (S3): To store course cover images. Images contain no personal data.
  • Google Analytics: To measure traffic on our public pages only — the home page, company and legal pages, the blog, the learn articles, and the course catalog. Google receives standard web analytics data (pages viewed, approximate location derived from IP address, device and browser type, and the site or search that referred you). We do not send Google your name, email address, or anything you write, ask, or study in the app, and Google Analytics does not run on signed-in app pages at all.
  • Umami: To measure traffic across the whole Service. Umami is a privacy-focused analytics service that sets no cookies and does not build cross-site profiles of visitors.

6. Data Sharing

We do not sell, trade, or rent your personal information to third parties. We will disclose information if required by law or to protect our rights.

Course Caching: Generated courses may be cached and served to other users who request the same topic at the same learner level. Cached content includes only the course topic, lesson text, and scholarly citations — never your name, email, study progress, or any personal data.

Organization Sharing: If you are a member of a Church Plan organization, courses, groups, pathways, and announcements shared or assigned by your administrators are visible to their intended audience within your organization. The detailed content of your study — your quiz answers, flashcard state, and personal notes — remains private to you.

Pastoral-Care Visibility:Your engagement activity — such as when you were last active, lessons you have completed, your group and pathway assignments and progress, and whether you have opened an announcement — is visible to your organization's owners and administrators so they can shepherd their congregation. This information stays within your organization's leadership for pastoral-care purposes; we never sell it and never share it outside your organization. Trends about the topics your congregation studies and asks about are shown to leaders only in aggregated, anonymized form, and individual questions are never revealed.

7. Your Rights

You have the right to:

  • Access, update, or delete your account information at any time through Settings.
  • Export your learning data.
  • Opt out of contributing your question topics to your organization's anonymized trends, at any time in Settings.
  • Leave a Church Plan organization at any time from your settings or by contacting us.
  • Request deletion of your account and all associated data by contacting us.

8. Cookies

We use a single essential session cookie to keep you signed in. We do not use advertising cookies, and we never sell or share cookie data with advertisers.

Our public pages — the home page, our company and legal pages, the blog, the learn articles, and the course catalog — load Google Analytics, which sets first-party analytics cookies to measure how people find and move through the site. These pages are the only place it runs: once you sign in, the app itself (AskLumin, your dashboard, courses, notes, and review) loads no Google Analytics and sets no analytics cookies. We also use Umami, a privacy-focused analytics service that sets no cookies at all.

9. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the Service. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy, please contact us at kalib@openlumin.com.