LumiJar Privacy Policy
Effective date: July 27, 2026
LumiJar is a product of Lumiti, LLC ("Lumiti," "we," "us"), a California limited liability company. Lumiti, LLC is the operator of LumiJar and the data controller for the information described here.
Contact: privacy@lumijar.com
Lumiti, LLC · 22287 Mulholland Hwy #149, Calabasas, CA 91302
The short version. LumiJar is a family app built around the tooth-fairy ritual that helps children learn money habits and healthy-teeth habits. It uses virtual money only — we never hold, move, or touch real money. The parent creates and owns the account, consents before any child information is collected, and can review, correct, export, or delete it at any time. We show no ads, we never sell personal information, and we do not disclose children's personal information to third parties. We use it only to run LumiJar for your family — nothing else. Children under 13 use LumiJar only under a parent-managed account with verifiable parental consent (COPPA).
1. Who uses LumiJar
LumiJar is designed for families with children roughly ages 5–12. The service is directed to children, so we treat every child profile as a child under 13 and apply COPPA's protections to all of them. The account holder must be a parent or legal guardian, 18 or older. One account serves the whole family; parents and guardians share the account login.
2. Information we collect
From parents (the account holder)
- Account: email address and password (the password is stored only as a salted hash by our authentication provider — we never see it).
- Family setup: a family display name you choose (for example, "The Johnsons"), a parent app-PIN (a convenience screen lock), currency and app settings.
- Content you create: deposits and notes you record, messages and letters you write for your child (including any you write in the fairy's voice), chores and allowance settings, and dentist notes and a next-checkup date if you choose to enter them.
- Feedback: if you use "Send Feedback," we collect your message, an optional category, and basic context (app version, the screen you were on, browser type, language and currency). Feedback is parent-only — child devices are technically blocked from submitting it — and we ask you not to include your child's personal details in it.
- Technical: IP address and basic request data when you sign in or sign up (used for security and rate limiting), and standard server logs. If the app crashes, we also receive a diagnostic crash report: the error message and technical stack trace, the app version, and which screen it happened on. Crash reports never include a child's name, fairy name, goals, balances, tooth chart, or any other child information.
About children (collected only after parental consent)
All child information lives inside the parent-owned account:
- Profile: a first name or nickname (never a legal full name), an age band the parent selects (broad ranges such as 5–7, 8–11, and 12+ — we never collect a birthdate or exact age), an optional birth month (month only, used solely for in-app birthday celebrations and reminders), and a chosen avatar.
- The child's own inputs on their linked device: the name they invent for their tooth fairy, sorting virtual money into jars, marking chores done, goals and wishlist items, and logging a lost or wiggly tooth.
- Activity: virtual jar balances and virtual transaction history, badges and progress, and baby-tooth chart entries (which tooth, what date).
- Device link: when you link a child's device, we create a device record and an anonymous session for that device so it can access only that child's profile. Child devices sign in anonymously — no child email, phone number, or password exists.
What we do not collect
No real-money or payment information from anyone (LumiJar is currently free and holds no payment features). From children: no birthdate or exact age, no email, phone number, or contact information, no precise location, no photos, audio, or video, no biometric identifiers, no government identifiers, and no advertising identifiers. We do not use third-party advertising or tracking SDKs anywhere in the app.
3. How we use information
We use personal information only for the internal operation of LumiJar — running the service for your family — and for no other purpose. Concretely, we use it to run the accounts and child profiles, sync your family's data across your devices, deliver the in-app experience (jars, chores, tooth chart, fairy visits), send the transactional emails the service requires (signup confirmation, password and PIN reset, parental confirmation), respond to feedback, keep the service secure (bot prevention, rate limiting, abuse prevention), and comply with law.
We do not use personal information for advertising, do not sell it, do not build profiles for marketing, and do not use it for any purpose beyond operating LumiJar for your family. The only outside parties that ever touch it are the service providers that run the app on our behalf (Section 5), and they are contractually limited to that role.
We may create and use de-identified or aggregated information — data that does not identify, and cannot reasonably be linked back to, any individual child or family — to understand how LumiJar is used, to improve and develop the service, and to produce or publish general, non-identifying statistics and insights. Because this information is not personal information, we may retain and use it, including after personal information has been deleted. We do not attempt to re-identify it.
4. Verifiable parental consent (children under 13)
Before any child profile is created or any child information is collected:
- The parent creates a parent account and confirms it by email.
- The parent is shown a direct notice on screen stating what LumiJar collects about children, how it is used, who it is shared with, how long it is kept, and how to consent — together with a link to this full policy.
- The parent gives affirmative consent by checking an unchecked consent box. Consent is recorded for each individual child, with a timestamp and the version of the notice shown. A separate consent is required each time an additional child is added.
- Shortly afterward, we send a confirmation email to the parent's address. It repeats the substance of the notice, explains how to review and delete the information, and includes a one-click link to stop the collection and delete the children's data if the recipient did not set up the account.
This process is available to us because children's personal information stays internal to Lumiti and is not disclosed to third parties. You may refuse consent, in which case no child profile is created, and you may withdraw consent at any time — see Section 8.
5. Service providers (processors)
We share information only with the vendors that host and run LumiJar, under agreements limiting use to providing the service. They are not permitted to use it for their own purposes:
| Provider | Role | What it touches |
|---|---|---|
| Supabase | Database, authentication, hosting | All account and family data (encrypted in transit and at rest) |
| Vercel | Web hosting and delivery of the app | Standard web-request data |
| Resend | Transactional email delivery | Parent email address and the emails we send |
| Cloudflare (Turnstile) | Bot prevention at parent signup only | The signup interaction and related technical data. Never runs on child devices or in the child experience |
| Google Workspace | Our business email | Correspondence you send us |
| GoatCounter | Cookieless, aggregate page analytics on our marketing pages only (for example, the tooth-fairy calculator) | Aggregate page counts. Not present inside the app |
We do not disclose children's personal information to any third party for that party's own use. If a future feature ever required sharing a child's information with a new third party, we would first obtain separate parental consent for it.
6. Data retention
We keep personal information only as long as needed to provide LumiJar to your family, and then delete it.
- Setup codes. Device-link setup codes expire after 15 minutes and are then purged.
- Deletion you control. From your parent dashboard you can delete an individual child's profile or all of your family's data at any time. Doing so removes that information from our servers — child profiles, virtual balances and history, tooth-chart entries, goals, badges, and family settings. Your parent login record (your email address and hashed password) is not removed by these in-app deletions; to delete the login record itself, email privacy@lumijar.com and we will remove it.
- Inactive accounts. If an account goes unused for 24 months, we delete the children's data associated with it so that it is not kept indefinitely. Before we do, we send the parent up to three email notices, each with a one-tap option to keep the account (which resets the clock) and a link to export the family's data. The parent login record remains unless you ask us to delete it.
- Feedback and logs. Feedback submissions and server and security logs are kept only as long as needed for support, security, and abuse prevention, and are then deleted or de-identified on a routine schedule.
- Diagnostic crash reports. Kept for 90 days and then deleted. They contain no child information. Deleting your family's data also deletes your crash reports.
- Backups. Deleted data may persist briefly in routine encrypted backups before those backups cycle out on their normal schedule.
This section is the public summary. We maintain a full written retention and deletion schedule internally.
7. Security
We protect your family's information with encryption in transit (TLS) and at rest; deny-by-default row-level security that isolates every family and every child at the database layer; anonymous, single-child-scoped sessions on child devices that cannot write to the database directly; least-privilege server functions for privileged actions; single-use, short-lived, hash-stored device setup codes; passwords stored only as salted hashes; bot protection and per-IP rate limiting on signup; and strict security headers on the web app.
Parent and child app-PINs are convenience screen locks, not the security boundary — the server-side controls are. No system is perfectly secure, but we designed LumiJar so that the database itself enforces who can see what.
8. Parental rights and controls
From the parent dashboard you can:
- Review and correct everything on a child's profile.
- Delete an individual child's profile, or all of your family's data — this removes it from our servers.
- Export your family's data at any time, as a transaction ledger (CSV) or a full backup (JSON).
- Link and disconnect your child's devices at any time, including a one-tap "disconnect all devices" action for a lost or stolen device.
- Withdraw consent to further collection. Withdrawing consent means deleting the child profile, which removes that child's data.
In-app deletion removes your family's data but not your parent login record (your email address and password). To delete the login record itself, email privacy@lumijar.com.
You can also contact privacy@lumijar.com to exercise any of these rights, ask what we hold, or request an export. We will verify that a request comes from the account holder before acting on it.
9. Where data is processed
LumiJar is operated from the United States, and all data is processed on U.S. infrastructure. LumiJar launched for families in the U.S. and is designed for a U.S. audience. If you access it from elsewhere, you are responsible for complying with your local laws, and your information will be processed in the United States as described here.
10. Changes to this policy
If we make material changes, we will notify the parent account email and post the updated policy at lumijar.com with a new effective date. Material changes affecting children's information will be notified before they take effect, and where required we will obtain fresh consent.
11. Contact
Lumiti, LLC
22287 Mulholland Hwy #149, Calabasas, CA 91302
Privacy: privacy@lumijar.com
General support: support@lumijar.com