Last updated June 4, 2026
Lumi (“Lumi,” “we,” “us”) is operated by Om Society Press, a family imprint based in Calgary, Alberta, Canada. We take privacy seriously — especially children’s privacy — and we’ve tried to write this in plain language. We follow Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the U.S. Children’s Online Privacy Protection Act (COPPA).
The short version
- Only adults create accounts. Children never log in and never have an account.
- For a child, we store only a first name and an age range — nothing more.
- We never run behavioral advertising, and we never sell or rent your data.
- Your data lives on Canadian infrastructure, and you can delete it at any time.
Who this applies to
This policy covers the Lumi website, the subscription product, and the marketing waitlist. The person who creates an account must be a parent or legal guardian, 18 or older.
What we collect
From you, the parent
- Account details: your email address and a password (stored hashed, never in plain text).
- Billing details: handled by Stripe, our payment processor. We never see or store your full card number. We retain a Stripe customer reference and your subscription status.
- Consent records: the date and policy version you agreed to, so we can prove consent was given.
- Support correspondence: if you email us, we keep that thread.
About your child (a “kid profile”)
We practice strict data minimization for children. For each kid profile we store only:
- A first name (a nickname is fine), used to label the profile.
- An age, used to pick age-appropriate stories.
- Basic listening activity (which stories were played and whether they finished), used to choose tonight’s story and surface favorites.
We do not collect a child’s full date of birth, email, address, phone number, photos, location, or any contact information. We do not knowingly let children provide personal information directly.
How we use it
- To run the service: authenticate your account, choose nightly stories, and play them.
- To process your subscription and the 30-day free trial.
- To send essential service emails (receipts, account notices) and, if you opt in, occasional updates.
- To keep the product safe and working (basic, first-party diagnostics).
We do not use children’s information to advertise to them or to anyone. Listening activity is used only to make the story selection better and stays first-party.
Who we share it with
We don’t sell, rent, or trade your information. We use a small set of trusted processors who handle data on our behalf under their own data-processing agreements:
- Supabase — database and authentication (Canadian region).
- Stripe — payments. Stripe receives the parent’s billing information only; it never receives children’s data.
- Resend — transactional and lifecycle email.
- Cloudflare R2 — storage and delivery of audio and illustrations.
- Vercel — application hosting.
We may disclose information if required by law, or to protect the rights and safety of our users.
Where your data lives
We store personal data on Canadian infrastructure (Supabase ca-central-1) wherever possible. Some processors operate globally; we choose vendors with appropriate safeguards.
Verifiable parental consent (COPPA)
Because Lumi is used by children but operated through a parent’s account, we obtain consent from the parent. Creating an account and entering payment establishes that an adult is in control, and we record consent with a timestamp and policy version. Adding each kid profile reaffirms your consent for that child. You can review, change, or withdraw consent at any time from your account.
Your rights and choices
- Access & correction: view and edit your account and kid profiles anytime in settings.
- Deletion: delete an individual kid profile (and its listening history) or your entire family account, which removes the associated personal data.
- Export: request a copy of your family’s data.
- Email preferences: every non-essential email has a one-click unsubscribe.
To exercise any of these, use your account settings or email hello@goodnightlumi.com. We respond promptly.
Data retention
We keep personal data only as long as your account is active, plus a short window for backups and legal obligations. Listening history is retained while the account is active and deleted on account closure. When you delete a profile or account, we remove the associated data on our normal deletion schedule.
Cookies & tracking
We use only the cookies needed to keep you logged in and to run the site. We do not use third-party advertising or cross-site behavioral tracking, and we never profile children for marketing.
Security
We use industry-standard measures: encrypted connections, hashed passwords, row-level database security so each family can access only its own data, and least-privilege access for our processors. No system is perfect; if a breach ever affects you, we will notify you as required by law.
Changes to this policy
If we make a meaningful change, we’ll update the date above and, where appropriate, notify account holders by email.
Contact
Questions or requests? Email hello@goodnightlumi.com. We’re a small team and a real person will read it.