Lumi is operated by Lumi Education Pty Ltd (ABN 45 700 349 015) ("Lumi", "we", "us" or "our"). This Privacy Policy explains how we collect, use, disclose and protect personal information when you use the Lumi Reading Diary app and related services (together, the "Service").
Lumi is a children's reading-tracking tool provided to schools. We handle most information about students on behalf of, and at the direction of, the school that enrols them. We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. The kinds of personal information we collect
Account information
When a teacher, school administrator or parent/carer creates an account, we collect:
- name and the role you hold (parent/carer, teacher or school administrator);
- a mobile phone number (required for parent/carer accounts, and used for sign-in and reminders) and, optionally, an email address;
- for parents/carers, the relationship to the child (e.g. Mum, Dad, Guardian);
- the school and class you are associated with, and the link or school code used to join;
- a chosen in-app character;
- a record that you accepted our Terms of Use and this Privacy Policy — the acceptance itself, the date and time, the version you accepted, and whether you accepted in the app or in a web portal.
Account passwords are managed by our authentication provider (Google Firebase Authentication). We do not see or store your raw password.
Student information
Schools and the parents/carers and teachers they authorise enter information about students so reading can be tracked. This may include:
- the student's name, class and year level;
- reading level and the history of reading-level changes;
- reading activity — dates, minutes read, books read, how the child felt about the session, and any notes;
- optional short voice recordings of the child recapping what they read (the "comprehension recording" feature), where an authorised school administrator has turned this feature on, confirmed the school will notify families and selected a 30, 90 or 365-day deletion period;
- messages exchanged between a teacher and a parent/carer about a reading log;
- a photograph of a book's cover, taken by a teacher to add that book to the school's book catalogue. The photograph is stored as that book's cover, and the image is sent to Google's Vertex AI service in Australia (Sydney) to read the book's title and author; no student information accompanies the image, and the photograph is of the book, not of any person.
Device and technical information
- a push-notification token, so we can deliver reminders and updates to your device;
- app version and device type where needed to operate the Service;
- optional crash reports and limited product-usage analytics, only where an adult account holder has enabled the relevant control on that device;
- information you provide when you contact support or send feedback.
To display text and to check connectivity, your device also contacts Google's fonts service and Cloudflare — a lightweight connectivity check when the app starts, when your connection changes and periodically while the app is open, alongside fetching our in-app service status notice; these requests carry ordinary network information such as your IP address, but no Lumi account or student information.
We do not collect information for advertising, and we do not track you across other companies' apps or websites.
2. How we collect and hold personal information
How we collect it
We collect information directly from the adults who use the Service — when a school provisions staff, when a teacher or parent/carer creates an account and enters reading activity, and when you contact support. A school, and the teachers and parents/carers it authorises, enters student information.
A school may also import a class or roster list that it has exported from its own student information system (for example CASES21), by uploading a spreadsheet or pasting the data. We use that file only to create and update the student, class and staff records for that school.
We also receive a small amount of technical information from your device (for example, a push-notification token) and — only if you opt in — diagnostic information.
How we hold it
Information is stored using Google Cloud / Firebase infrastructure, with our primary database and file storage hosted in Australia (the Sydney australia-southeast1 region). We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Information is encrypted in transit and at rest using our cloud providers' standard encryption. Access is designed to be role-, class- and family-scoped, with roles determined by our servers rather than asserted by the app, and is enforced by authentication and server-side security rules. No online service can be completely secure, and we do not warrant that our safeguards will never be circumvented. The database has point-in-time recovery and deletion protection. Some supporting provider systems operate overseas — see sections 6 and 7.
3. The purposes for which we collect, hold, use and disclose it
We use personal information to:
- provide the Service — record and display reading activity, progress and achievements;
- enable communication between teachers and parents/carers about a child's reading;
- send reading reminders, achievement and comment notifications, and school announcements;
- operate and secure the Service, and—where an adult has opted in—troubleshoot and improve the app using pseudonymous crash reports or product-usage analytics;
- verify school enrolment and manage access entitlements;
- record and evidence your acceptance of our Terms of Use and this policy; and
- respond to support requests and meet legal obligations.
We disclose personal information only as needed to run the Service:
- Within the school community: a child's reading information is visible to that child's teachers and school administrators, and to the parents/carers linked to the child.
- Service providers: we use Google Firebase / Google Cloud (authentication, database, file storage, messaging and, where you opt in, crash reporting and analytics), Twilio SendGrid for transactional email, Google Workspace for our support mailbox, Cloudflare to deliver the in-app service status notice, and, where a teacher photographs a book cover, Google's Vertex AI service in Australia to read the book's title and author. These providers handle personal information only to deliver services to us, on our instructions and under contractual data-protection terms. Using them does not reduce our responsibility to you under the Australian Privacy Principles. Our Sub-Processors page lists each of these providers, what they touch, why, and the countries where they process it.
- Book look-ups: to fetch book titles and cover images, we send a book's ISBN or title to public book databases (such as Google Books and the Open Library). We do not send any student, account or school identifier with these look-ups, and the request is not linked to a child's record.
- Legal reasons: where required by law, or to protect the rights, safety and security of users, the public or Lumi.
We do not sell personal information, and we do not use it for third-party advertising.
Children's information
Lumi is designed to be used about children by the adults responsible for them — schools, teachers and parents/carers — rather than by young children independently. The school is responsible for ensuring it has the appropriate authority and parental consent to enter student information into the Service and to enable optional features such as voice recordings. Parents/carers can see the reading information for the child or children linked to their account. If you believe a child's information has been provided to us without proper authority, contact us and we will work with the school to address it.
4. How you can access and correct your personal information
You may request access to, or correction of, the personal information we hold about you. Parents/carers can view and update much of their own and their child's information in the app, and schools can manage student records directly. A parent/carer or teacher can permanently delete their own Lumi account from Settings → Account. This removes the login, memberships, authored messages and voice recordings. Deleting an adult account also removes that adult's identity from the reading sessions they logged: we replace their name and account link with "Former guardian" or "Former staff member" and delete the notes and voice recordings attached to those sessions. The underlying reading event — the date, book and minutes — remains part of the child's school reading record, which the school holds and controls, so that deleting an adult's login does not erase a child's educational history. To have a child's record removed, contact the school (see the next paragraph). A minimal completion receipt is retained for security and audit purposes for 90 days and then deleted.
Authorised school staff can permanently delete a student record and its linked reading history, messages, recordings, notifications and roster references. Deleting a student does not delete the accounts of their parents/carers. Because Lumi holds student information on behalf of schools, a parent/carer who wants a child's school record accessed, corrected or deleted should contact the school or email support@lumi-reading.com. We verify a requester's authority through their existing account or the school contact before acting; legal or school record-keeping requirements may apply.
5. How to complain, and how we handle complaints
If you have a question about this policy, or wish to make a privacy complaint, contact our Privacy Officer at support@lumi-reading.com.
We will acknowledge your complaint within 5 business days and give you a substantive response within 30 days. If we need longer, we will tell you why and when to expect a decision. When handling a complaint we record the requester's identity, their authority to make the request, the scope of the request, our decision and its completion, and we verify authority before making any change.
If we become aware of a data breach likely to cause you serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
6. Whether we disclose personal information overseas
Yes — some information is handled overseas. Our primary database, file storage and application processing are in Australia (Sydney), but some supporting provider systems operate outside Australia:
- Account authentication (Google Firebase Authentication) is processed in the United States.
- Push notifications are delivered through Apple and Google's global messaging services.
- Transactional email is sent through our email provider, whose infrastructure is in North America and the European Union, and which may process in the United States.
- Our support mailbox (Google Workspace) and the delivery of our in-app service status notice (Cloudflare) are global provider services.
- Optional crash reporting and product-usage analytics — only if you opt in — may be processed outside Australia.
Where information is handled overseas, we take reasonable steps to ensure it is handled consistently with the APPs, minimise what is sent, and keep child names and content out of the flows that leave Australia wherever possible.
7. The countries in which recipients are likely to be located
- Australia — primary: the Sydney
australia-southeast1region hosts the main database, user-content storage, application compute and, going forward, ordinary logs. - United States — Firebase Authentication (account identity); our email provider, Twilio SendGrid (Twilio Inc.), may process there; some global platform services and Google's required audit logs.
- North America and the European Union — the infrastructure sub-processors of our email provider, Twilio SendGrid (Twilio Inc.).
- Global / other — Apple and Google push-notification delivery, our Google Workspace support mailbox, Cloudflare's edge network, and (only if you opt in) Analytics and Crashlytics may be processed in other countries where those providers or their sub-processors operate.
Our Sub-Processors page identifies each provider and the countries where it processes information, and is kept current.
8. How long we keep information
We keep personal information for as long as the related account or school relationship is active, and as needed to provide the Service. Access to a student's data is tied to the school's enrolment and annual renewal. When information is no longer required, or on a valid deletion request, we delete it or de-identify it, unless we are required to retain it by law.
Comprehension voice recordings are kept only for the deletion period selected by the school when the feature is enabled: 30, 90 or 365 days. Legacy 7-day settings continue to be honoured for deletion but cannot authorise new recordings. Unconfirmed uploads are removed after 24 hours. A school can delete a recording earlier, and account or student deletion also removes applicable recordings.
9. Push notifications and analytics
You can turn off push notifications at any time in your device settings. Product-usage analytics and crash reporting are separate, optional controls that are off by default. An adult parent/carer or staff account holder may enable or withdraw either choice at any time in Settings → Account → Privacy & diagnostics. Choices are stored on that device.
Lumi does not attach a Firebase account UID, child identity, school, book title, recording, note or detailed reading result to Analytics. Feature events omit reading duration and count, feelings, badge types and streak values. If enabled, Analytics uses a pseudonymous app-instance identifier. If enabled, a crash report may contain a stack trace plus app, operating-system and device diagnostics, but Lumi does not attach the account UID. These services are provided by Google Firebase, may be processed outside Australia, and are used only to improve reliability and usability—not for advertising or tracking across other companies' services. Turning a control off stops future collection; Lumi also clears legacy identifiers and locally queued reports where the SDK supports that action.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last revised" date above. Where the change is significant, we will ask you to review and accept the current version before you continue to use the Service — both in the app and in our web portals. We keep a record of which version you accepted and when.
Our "Version" identifies the release you accepted; where we make editorial or clarifying revisions without changing what we do with your information, we update the revision date shown at the top of this page without asking you to re-accept. Where a change is significant — for example, a new purpose, a new category of information, a new recipient country, or a change to how long we keep information — we issue a new version and ask you to review and accept it before you continue to use the Service. Earlier versions are available on request from support@lumi-reading.com.
11. Contact us
Lumi Education Pty Ltd (ABN 45 700 349 015) — Privacy Officer, support@lumi-reading.com.
