1. Who we are and what this notice covers
Lumorie is a service for private photo sharing and memories. Mosbek ApS, CVR 45899756, Ladegårdsparken 70, 8410 Rønde, Denmark, is the data controller for the personal data we process to operate the consumer service. Contact support@mosbek.com about privacy or your rights.
This notice covers our consumer apps, associated viewing devices and website. It explains both encrypted content and the account, device and operational information needed to provide Lumorie. End-to-end encryption protects content; it does not make all information anonymous or remove our data-protection responsibilities.
2. Your encrypted content
Photos, videos and private profile content are encrypted on your device before upload. We store and transmit encrypted content and encrypted key material, but do not hold the unencrypted content-decryption keys needed to read it. Content is decrypted on devices and viewers to which you grant access. Device or platform key storage may help you recover access.
We cannot normally inspect your photos, videos or private profile text. We can still associate files with account identifiers and events, operate access controls and remove stored records. Information you choose to send us in an ordinary support email is readable by us. Never send us your recovery phrase or private keys.
3. Information we process and why
- Account and device information: pseudonymous account/device identifiers, public keys, device verification records, registrations, linked viewers, accepted legal version and timestamps. We use these to create and secure accounts, verify requests and administer access.
- Event and file metadata: event identifiers, creator and participant identifiers, roles, event dates, region information derived from a chosen venue, file identifiers, types, sizes, timestamps, access and synchronization records, and backup/subscription status. These let us route, store, synchronize and manage encrypted content. Such metadata can be linked to your account even though the content is encrypted.
- Purchases: account and transaction identifiers, products, store, purchase/expiry/refund information and entitlements. We use these to provide purchases, manage subscriptions and prevent payment abuse. Apple or Google processes payment details; we do not receive your payment-card number.
- Push delivery: device push tokens and limited routing identifiers to notify devices of changes. Tokens are pseudonymous personal data. Push delivery does not require sharing photo/video content with the push provider.
- Diagnostics and security: device/app versions, crash and error information, operational logs, request timing, network/IP information and account/device/event identifiers where relevant. We use these to investigate failures, maintain performance and prevent abuse. Crash reports are anonymous unless you turn on “Share diagnostics with support” in Profile; then they carry a code derived from your account so support can find them. Our server logs at Cloudflare contain request and error lines without account identifiers.
- Support and safety reports: correspondence and information you supply, plus report categories and relevant account/event/file identifiers. We use these to answer requests, investigate reports and enforce our terms. In-app report details may be encrypted for the event host; ordinary email correspondence is not end-to-end encrypted by Lumorie.
- Product and referral measurement: first-join dates linked to account identifiers help measure whether guests later create events. Referral records can link an affiliate code, platform, account and purchase; applied affiliate codes can also be sent to RevenueCat. We use these to measure acquisition and administer referral rewards.
- Store campaign attribution: the iOS purchase integration can send Apple's advertising-attribution token to RevenueCat to measure which App Store campaigns lead to installs or purchases, subject to Apple's privacy controls. This is separate from access to your encrypted content.
We do not require an email address or phone number for ordinary account registration. If you contact us, we receive the contact details you use. We do not sell your personal data or use your encrypted content to target advertising.
4. Legal grounds
- Providing the service you request — GDPR Article 6(1)(b): account administration, storing and sharing your encrypted content, synchronization, recovery, purchases and subscription management, where necessary to perform our agreement with you.
- Legitimate interests — Article 6(1)(f): proportionate security, abuse prevention, diagnostics, support, handling reports and claims, proportionate product/referral measurement and measuring our own store campaigns. Our interests are keeping Lumorie reliable, protecting users and understanding acquisition. We must weigh those interests against your rights; you may object.
- Legal obligations — Article 6(1)(c): records and disclosures required by applicable accounting, consumer or other law.
- Consent — Article 6(1)(a): where a particular optional activity requires consent, it must be requested separately and may be withdrawn. Accepting the terms or reading this notice is not blanket consent to optional processing.
Providing account and device identifiers is not a legal requirement, but without them we cannot create your account or deliver the service. You choose what content to upload and who may access it. Other people may provide information about you through shared content or reports. We assess their rights and yours in context; a private event host is not automatically responsible for all of Lumorie's processing. A private person who hosts an event and shares photos with invited guests normally acts for purely personal or household purposes, which the GDPR does not cover (Article 2(2)(c)). That exemption does not apply to us: we provide the means and remain the controller for the processing we carry out to operate Lumorie. A company or professional organizer cannot rely on it.
5. Providers and other recipients
Authorized participants and viewers receive the content and information you share with them. We also use providers for the following purposes:
- Cloudflare: hosting, encrypted storage, databases, network delivery, transfer/push performance metrics and security. Data-processing terms.
- RevenueCat: purchase/subscription administration and supported store attribution, using purchase records and pseudonymous identifiers. Data-processing terms.
- Apple and Google: app-store purchases, device/app verification and platform services. iOS push uses Apple Push Notification service; Android registers Firebase Cloud Messaging tokens. Their own policies apply to processing they control: Apple and Google.
- Sentry: crash/error reporting and selected performance diagnostics, anonymous by default; a pseudonymous account code is added only while you have turned on sharing diagnostics with support. Data-processing terms.
- Email providers: services used to handle support and safety correspondence. They receive the correspondence data described above, not access to the keys that decrypt your event content.
We may also disclose necessary information to professional advisers or competent authorities where legally required or justified to protect rights and address abuse. We cannot supply decrypted event content that we do not possess.
Providers may process information outside the EU/EEA, including in the United States. Transfers require an applicable legal basis: an adequacy decision, such as the EU–US Data Privacy Framework for a covered, certified recipient, or EU Standard Contractual Clauses with any necessary supplementary measures. The linked processing terms describe provider safeguards. Contact us for information about the safeguards applicable to your data or a copy of relevant clauses.
6. How long information is kept
- Ordinary events: cloud access normally ends 30 days after the later of the event end date and creation date, rounded up to the end of that UTC day. A further 30-day operational buffer allows cleanup. After that, encrypted content and per-event synchronization state are removed if no participant backs the event through the Bright Memories subscription (“Memories” below). Limited event-index metadata can remain with the records described below. Actual cleanup may take additional time for processing and retries.
- Events kept in Memories: an event can remain in the cloud while one or more participants back it through Memories. After ordinary cloud access ends, only eligible backers retain cloud access. Another person's backing can therefore keep shared content after you stop backing it or delete your account.
- Cancelled Memories subscriptions: ordinary cancellation keeps paid access until the paid period ends, followed by a 31-day read-only period. When expiry is reported without that cancellation schedule, the 31-day period starts when we process the expiry. After the read-only period, the personal Memories vault's encrypted content is deleted, necessary metadata can remain, and its backing of other events is released. Other participants' backing can keep their shared events available.
- Account data: account registration and personal recovery/profile data are kept while needed to provide your account, then removed through account deletion. Shared event records have their own retention described here. We do not promise automatic account deletion solely because a fixed inactivity period has passed.
- Other records: crash reports are kept by Sentry for 90 days and Cloudflare's worker logs for 7 days; support and report records for handling the request and necessary follow-up; purchase and refund records for five years after the end of the financial year under Danish bookkeeping law; event-index, deletion and acquisition/referral records for service administration, attribution and relevant claims. These records do not all expire automatically when an account or event is deleted. You may request erasure; any continued retention needs a lawful, necessary purpose. A specific legal preservation requirement or dispute can justify longer retention of the necessary records.
Retention concerns our cloud systems. Copies exported to a participant's device or another service are controlled by that participant or service. A refunded event follows the 30-day refund reserve explained in section 8 below and in the terms.
7. Deleting content or your account
The ordinary “delete photo/video” action marks content as deleted so it disappears from the active gallery. It is recoverable where the app permits restoration: encrypted files and records remain until the event's applicable retention ends. Archived events backed by other participants restrict ordinary deletion. This action is therefore different from a request for permanent erasure of personal data.
Deleting your account removes its registration, device keys, personal encrypted recovery/profile storage and personal Memories vault, and releases its backing of shared events. Cleanup may need retries. It does not automatically remove all contributions or account references in shared events, event-index, purchase or acquisition/referral records, diagnostic logs or necessary legal records. Those follow their respective retention and applicable erasure requirements.
Leaving an event you do not host removes your participation, your name and picture in that event, your Memories backing of it and the recovery copy of its keys stored for your account. If you leave before the event starts, we also delete the photos, videos and reactions you added, including the stored files; this cannot be undone. If you leave after it has started, what you shared stays available to the other participants for the event's retention period. Our legal basis is the legitimate interest of the host and the other participants in keeping the event's shared photos (Article 6(1)(f)), in line with the terms you accepted. You can still ask for erasure of your own photos, videos or reactions under Article 17 by writing to support@mosbek.com. We erase them unless there are overriding legitimate grounds to keep them, which we weigh against the other participants' rights; the host can also remove photos and videos in the app.
You can contact us about permanent erasure, including information about you in someone else's event. We assess what we can identify, our role, applicable legal grounds and other people's rights. We do not treat prior sharing as an automatic exception to erasure. We cannot remotely erase copies people have already exported. See account and data deletion for practical steps.
8. Export and refunds
While you retain access and the necessary keys, the app can export available content by decrypting it on your device. Account or subscription deletion and expiry can remove that access. Store cancellation at period end is different from a refund.
When a store confirms an event refund, the event closes and ordinary cloud access to it ends for every participant. On your device the app keeps your own photos and videos and the keys needed to use them, and removes content contributed by others. We keep the event's encrypted cloud content for 30 days from the refund so that you can retrieve your own contributions that are not on your device; once the app confirms that every original of yours is on the device, we delete the cloud copies that no one else keeps, and at the end of the 30 days the remaining cloud content is deleted. A copy kept by another participant through a valid Memories subscription stays for as long as that backing lasts. Limited event-index and purchase/refund records can remain. This describes current behavior and does not waive statutory content-retrieval or data-protection rights; contact us to exercise those rights.
9. Your rights
Subject to the conditions in applicable law, you may request access and a copy, correction, erasure, restriction, and portability of your personal data. You may withdraw any consent for future processing. We do not use solely automated decisions producing legal or similarly significant effects on you; automated technical security checks can be raised with support for review.
Your right to object. You can object at any time to processing we base on legitimate interests: security and abuse prevention, diagnostics, support, handling reports, product/referral measurement and store-campaign measurement. Email support@mosbek.com; we then stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
Email support@mosbek.com. Rights also apply to information about people who do not hold a Lumorie account. We normally respond within one month. If a lawful extension is needed for complexity or volume, we explain it within that month. Requests are normally free.
We may need proportionate information to verify a request and locate the relevant data, such as an account or event identifier and proof of account control. Do not send private keys. We provide readable data we hold in readable form; encrypted content remains encrypted unless your device can decrypt it. If we cannot identify the relevant data or verify the request, we explain the limitation and consider any additional information you supply.
You may complain to Datatilsynet in Denmark or another competent supervisory authority, including where you live or work. You can contact a regulator without contacting us first.
10. Device storage, age and updates
The app stores keys, settings and content on your devices as needed for its features. The website remembers choices such as language and theme using local storage. Its font files are served from the same website through our hosting provider; loading the fonts does not connect your browser to Google Fonts. Optional tracking requiring consent must be distinguished from necessary storage; this notice is not a cookie-consent mechanism.
Lumorie accounts are intended for people aged 16 or over. This is our service requirement and does not limit the rights a younger person has over information about them. Photos may include younger people; the people sharing them must respect their privacy and rights. Contact us about a child's information or an account used below the minimum age.
We update this notice when processing changes and make the current version available in the app and on our website. Material changes receive appropriate notice; a new purpose requiring consent does not become authorized merely by publishing an update. Mandatory rights under applicable law remain unaffected.