This page lists the third-party services that process personal information on Lumi's behalf to run the Lumi Reading Diary, and — in a second table — the other third parties involved in delivering Lumi that handle information for their own purposes. It accompanies our Privacy Policy and is provided so a school can see who touches its data, what they touch, why, and where it is processed.
Every service listed here is in active use. Our cloud environment also contains services that are provisioned but technically blocked from receiving any personal information — they are not listed here because we do not use them, and we will add a service to this page, and update our Privacy Policy where the change affects what we disclose or where it is processed, before it begins handling any personal information.
The services in the first table are ones we use to run Lumi on our own and the school's instructions, under contracts that require them to protect personal information and to use it only for us. They are not independent recipients using data for their own purposes — we do not do that, and we do not sell personal information. Using these providers does not reduce our own responsibility to you under the Australian Privacy Principles.
Lumi is operated by Lumi Education Pty Ltd (ABN 45 700 349 015). Questions: support@lumi-reading.com.
Where your data primarily lives
Our main database, uploaded files and application processing are in Australia — Google Cloud's Sydney australia-southeast1 region. The first table below identifies the supporting services that operate elsewhere.
Sub-processors — services that handle personal information on our instructions
| Provider | Personal information it touches | Purpose | How we authorise it | Processing / storage countries |
|---|---|---|---|---|
| Google Cloud Firestore — cloud.google.com | School, child, adult, roster, reading and messaging records | Primary application database | Service operation, under the Google Cloud DPA | Australia (australia-southeast1, Sydney) |
| Google Cloud Storage — cloud.google.com | Optional comprehension audio, school logos, book covers | Storage for uploaded media and assets | Service operation, under the Google Cloud DPA | Australia (australia-southeast1) |
| Google Cloud Functions / Cloud Run / Eventarc / Scheduler — cloud.google.com | All record types, transiently, while server logic runs | Server-side authorisation, aggregation, notifications, deletion, media validation | Service operation, under the Google Cloud DPA | Australia (australia-southeast1) |
| Google Cloud Logging — cloud.google.com | Application and security events. Account, school, child and record identifiers are prohibited in our log payloads; an administrator identity can appear in Google's required audit logs | Operational and security logging | Service operation, under the Google Cloud DPA | Ordinary logs Australia; Google's required audit logs are global |
| Google Cloud Secret Manager — cloud.google.com | Application credentials only — no child or school content | Secure storage of service credentials | Service operation, under the Google Cloud DPA | Australia (australia-southeast1) |
| Google Cloud Vertex AI — cloud.google.com | A teacher-taken photograph of a book cover, sent to read the title and author. No student, school or account information accompanies the image. | Book-catalogue metadata (AI text recognition) | Service operation, under the Google Cloud terms | Australia (australia-southeast1) |
| Firebase Authentication — firebase.google.com | Adult account id, email or phone number, multi-factor settings, sign-in and recovery metadata | Account sign-in, MFA and recovery for parents/carers and staff | Service operation, under the Firebase Data Processing & Security Terms | United States — Google documents this as a US-only service |
| Firebase Cloud Messaging — firebase.google.com | Device push token; adult-facing notification text, which can reveal limited reading context | Delivering reminders, achievement and comment notifications, school announcements | Service operation, under the Firebase terms | Global platform service |
| Apple Push Notification service — developer.apple.com | Device push token; adult-facing notification text | Push delivery to Apple devices | Platform provider, under Apple's developer terms | Global platform service |
| Firebase App Check — firebase.google.com | App and device attestation tokens — no content data | Anti-abuse / verifying requests come from a genuine app | Service operation, under the Firebase terms | Google service; global support may apply |
| Firebase Analytics — firebase.google.com | Pseudonymous usage events — no child or account identifiers, no reading detail | Product-usage insight to improve the app | Your opt-in consent — off by default, withdrawable | May be processed outside Australia |
| Firebase Crashlytics — firebase.google.com | Crash stack traces and app/device diagnostics — no account identifier; child content prohibited | Diagnosing and fixing crashes | Your opt-in consent — off by default, withdrawable | May be processed outside Australia |
| Twilio SendGrid — twilio.com | Parent onboarding and account emails carrying the recipient's details and, for parent onboarding, the child's first name and an enrolment link code (QR image) | Onboarding, service and operational email | Service operation, under the Twilio DPA (which names the Australian Privacy Act 1988) | Infrastructure in North America and the European Union; Twilio Inc. may process in the United States |
| Google Workspace — workspace.google.com | Whatever a sender includes in an email to our support address | Receiving and actioning privacy and support requests | Service operation, under the Google Workspace Data Processing Amendment | Global (Google-managed regions) |
| Cloudflare — cloudflare.com | Network metadata inherent in delivering a request, including IP address and user-agent. We do not send Lumi account, school or student records to Cloudflare, and we do not link this metadata to Lumi records. | Serving the in-app status notice, fronting our public sites, and answering a lightweight connectivity check the app makes (an HTTP HEAD request) when it starts, when connectivity changes and periodically while it is open | Service operation, under the Cloudflare DPA | Global edge network |
| Firebase Hosting — firebase.google.com | Public website and portal delivery; standard web request logs | Serving lumi-reading.com and our web portals | Service operation, under the Firebase terms | Google global edge, with content stored in Australia |
| Google Fonts — fonts.google.com | Ordinary network information (IP address, user agent) when the app, our websites or our emails load fonts from Google. No Lumi account or student information. | Displaying text | Service operation, under Google's terms | Global |
Other third parties involved in delivering Lumi
These are not sub-processors: they do not handle personal information on our instructions, and we do not control what they do with it. We list them so the picture is complete.
| Party | What it involves | Whose terms apply |
|---|---|---|
| Apple App Store | If you install the app from the App Store, Apple handles your store account, purchase and device diagnostic information for its own purposes. | Apple's privacy policy |
| Google Play | If you install the app from Google Play, Google handles your store account, purchase and device diagnostic information for its own purposes. | Google's privacy policy |
| Google Books API | We send an ISBN or title to look up public book details and covers. No personal information is sent, and the request is not linked to a child's record. | Google public API terms |
| Open Library / Internet Archive | We send an ISBN, title or work id to look up public book details and covers. No personal information is sent. | Open Library terms |
Changes to this list
We keep this page current. Before a new sub-processor begins handling personal information, we will update this page and, where the change affects what we disclose or the countries where information is processed, our Privacy Policy. We will give schools at least 30 days' notice by email to their nominated contact before a new sub-processor starts, and a school may raise a reasonable objection during that period; if we cannot resolve it, the school may end its arrangement with us without penalty for the remainder of the term. Schools can also ask to be added to, or removed from, this notification list by emailing support@lumi-reading.com.
