Luminaria ("we", "us", "our") is operated as a personal project by an individual based in the United Kingdom. This policy explains what data we collect, how we use it, and your rights.
When you register for a sync token, we collect your email address. This is the only personal data we hold about you.
When you sync highlights from your KOReader device, or upload a highlights file while signed in with a token, we store the content of your highlights (the text you marked in your books) on Cloudflare's infrastructure. This data is associated with your token and is only accessible to you. If you use Luminaria without a token, your highlights stay entirely in your browser and are never sent to our servers.
We store a content hash (a short numerical fingerprint of your highlights) alongside your highlights. This is used to detect whether your highlights have changed since the last sync, avoiding unnecessary uploads. The hash cannot be used to reconstruct your highlights.
For free accounts, we store a weekly sync count against your token to enforce the sync limit. This count resets automatically and is not linked to any personal data beyond your token.
If you subscribe to Luminaria Premium, payment is handled entirely by Stripe. We do not see or store your card details. We receive confirmation of payment status from Stripe and store a Stripe customer reference against your token.
If you connect Notion, we store a Notion access token against your Luminaria token. This token is used only to export your highlights to your Notion workspace on your request.
Your data is stored on Cloudflare's infrastructure (Cloudflare KV) which is hosted in data centres across the EU and UK. Cloudflare is GDPR compliant. Highlights are stored encrypted at rest.
We take reasonable precautions to protect your data but no internet service can guarantee absolute security.
We retain your email address and highlights for as long as you have an active token. You can request deletion of your account and all associated data at any time by emailing [email protected].
As a UK resident or EU citizen you have the right to:
To exercise any of these rights, email [email protected]. We will respond within 30 days.
Luminaria is not directed at children under 13. We do not knowingly collect data from children.
We may update this policy from time to time. We will notify registered users of significant changes by email. The current version is always available at luminaria.uk/privacy.html.
For any privacy-related questions, email [email protected].