What stays local today.
Lumina is still a prelaunch preview. This page says only what the current build can prove, and names the controls that must exist before launch.
The free chart
Birth date, local time when provided, the explicit unknown-time choice when selected, place, optional traditional cycle-rule category (including an explicit not-provided state), and optional name are processed in your browser tab. Merely opening, completing, or calculating the free chart does not send those values to Lumina, save them to browser storage, or write them to an account database.
Only after you actively start optional account saving may the same browser place the validated original form values—including the selected frozen GeoNames place record—a random draft ID, and creation time in local storage for a 30-minute use window so a magic-link sign-in can return to the chart. It stores no calculated chart, summary, email, or user ID. Cancellation or successful saving asks the browser to remove it; after the use window, or when the value is corrupt or unsupported, Lumina refuses it and attempts removal the next time it is read. The draft is still not uploaded until you return, review the named account and data scope, select an unchecked consent box, and submit.
Your browser still downloads the application code needed to calculate. Hosting and security infrastructure may record ordinary request metadata such as an IP address, user agent, time, and requested path; the birth-form values are not part of that code request.
Accounts and cookies
Before you choose a language, Lumina uses the browser's standard language request for that visit and does not write the inferred choice to a preference cookie or account record. The language control stores an explicit first-party preference cookie for up to one year. It contains only the selected interface locale and no birth-form values.
Public account enrollment and account saving are currently off. In an explicitly allowlisted, isolated development/test Supabase project, magic-link sign-in submits an email address through Lumina's server to that authentication project and the resulting session uses authentication cookies. Calculating a chart, signing in, or returning from the link never uploads birth details automatically.
After the final consent submission, the server verifies the current non-anonymous email account and compares it with the account securely bound to that confirmation page; an account switch requires a new review. It then rejects stale calculation references, validates the original input, recomputes the canonical chart, and atomically saves one owner-bound birth-input/chart pair. The browser does not choose the owner or supply a trusted chart result. Repeated submission of the same random draft creates no duplicate; the saved fields are the disclosed birth details or explicit unknown-time status, the optional traditional cycle-rule category or explicit not-provided state, optional name, consent version/time, calculation version/reference year, adjusted local time only when calculable, and language-neutral full or partial chart facts. When that category is not provided, no category-directed decade or annual cycle array is created. For a newly saved chart, the disclosed place record also includes its GeoNames source and dataset version, stable place ID, frozen multilingual city/region/country names and canonical label, city-reference coordinates, IANA timezone, identity confidence, and coordinate precision. Older development rows are not silently backfilled with that evidence.
An authenticated development account can download a JSON copy of the account identity, synchronized birth inputs—including the frozen place record when one was saved—derived charts, reports and their publication provenance, safe report-fulfillment status, and Lumina application order records currently stored for it. The export is bound to the verified session and also includes retained reports hidden by current entitlement state. It excludes private queue metadata, lease capabilities, worker identifiers, and frozen Stripe Price IDs.
In an explicitly allowlisted, isolated Supabase development/test project, a signed-in account can request a fresh email verification link and then permanently delete its Auth identity and current owner-bound Lumina application rows. The server derives the deletion target only from the verified session and requires that recent sign-in; public preview and production keep the action disabled. An anonymous result in another open tab and an unconfirmed temporary browser draft are not server account data; the result remains until close/reload, while Lumina refuses the draft after its 30-minute use window and attempts removal when it is next read.
The production retention map, future provider cleanup, backup/log handling, end-to-end deletion exercise, and a verified support contact are not complete. Public account enrollment remains blocked until those controls are approved and tested.
Payments, reports, and providers
Public accounts, saved-chart purchasing, Checkout, paid report generation, publication, and delivery are disabled. An explicitly enabled isolated development Sandbox can create owner-scoped test orders and send only minimized order identifiers and the frozen product contract to Stripe test mode; it must never receive real payment data. The free chart does not send birth details to Stripe or a report model provider.
The four public Simple/Deep English/Simplified-Chinese format samples are human-authored, editorially frozen around a fictional chart, and make no model call. They carry aiGenerated: false and are not user reports, purchased artifacts, published successor artifacts, or evidence of model quality. Opening or downloading one does not create an account, order, entitlement, generation job, or paid artifact.
Before these features open, the production notice will name each processor, what it receives, why it receives it, where it operates, and the applicable retention and deletion behavior.
What this notice is not
This is a factual description of the current preview, not a final legal privacy notice or a claim of GDPR, CCPA, or other regulatory compliance.
The operating legal entity, launch regions, age policy, lawful bases, retention periods, data-rights process, and privacy contact still require owner and legal review before production data collection.