The short version
Lumen Domus Schola is made for parents planning their family's homeschool year. Your lesson plans, your children's progress, and your family photos belong to you. We collect only what the app needs to work, we don't sell data, we don't show ads inside the app, and we put no advertising or analytics tracking in the app. The one piece of outside code the app does carry is a crash reporter that tells us when something breaks — it does not record your screen, and it is not used to watch how you use the app. We treat everything about your students — especially their photos — as sensitive.
Who we are
Lumen Domus Schola LLC, a Florida limited liability company ("we," "us"), publishes the Lumen Domus Schola app and operates lumendomusschola.com. Reach us anytime at hello@lumendomusschola.com, or by post at Lumen Domus Schola LLC, 3948 3rd St S #418, Jacksonville Beach, Florida.
Who the app is for
The app is designed for parents and legal guardians. The account holder must be an adult (18 or older) who is the parent or guardian of the students they add. Parents may optionally give a child a limited "student" login (see Student accounts and kid mode below); everything a child can do in the app is set up and controlled by the parent.
What we collect
- Account information. Your email address and a password (stored only in hashed form), plus a display name if you enter one. If you set a parent PIN to lock the parent view on a shared device, we store a hashed version of it.
- Planning data you create. Students' first names or nicknames, an avatar and color for each, subjects and curricula, terms, breaks, lessons and their dates, notes, supplies, completion check-offs and optional grades, extracurricular activities (including the activity's location and leader's name if you enter them) and attendance, reading plans and minutes read, memory verses and translation choice, homework and extra-credit items with points, rewards and redemptions, family calendar events, and field-trip ideas.
- Family photos (optional). Field-trip pictures, one first-day-of-school portrait per student per year, and any other pictures you choose to add. Photos are stored in a private storage area that only your signed-in account can read, are shown only in the parent view and in the Year-End report you generate, are never analyzed by any AI, and are never used by us for anything else.
- Optional profile answers. Your home city, state, and ZIP code and how far you're willing to travel (used only to suggest field trips), and which homeschool style(s) fit your family. Both are voluntary. We look at homeschool-style and state answers in aggregate — counts, never names — to decide what to build next.
- Subscription information. Which plan you're on, its status and renewal date, and the identifiers Stripe uses for your customer record. We never see or store your card number.
- Basic technical data. Standard server logs from our hosting providers (IP address, request time, browser type) needed to run and troubleshoot the service.
- Crash and error reports. When something in the app fails, an automatic report is sent to our error-monitoring service so we can find and fix it. See When something goes wrong below for exactly what it contains.
- Problems you report to us. If you use "Report a problem" on the Profile tab, we keep what you wrote, the screen you picked, your app version and platform, and your account identifier — so we can look into it and reply.
We do not collect a child's date of birth, age, gender, grade level, email address, precise device location, contacts, or advertising identifiers. Please enter no more about a child than a first name or nickname — that is all the app needs.
Student accounts and kid mode
There are two ways a child can use the app, both controlled by the parent:
- Kid mode (no separate login): from the parent's account, a "Who's learning today?" picker opens a child's simplified view on the same device. Nothing additional is collected about the child.
- Student accounts: a child may have their own login made of a username and password — no email address is collected, and the app creates an internal placeholder address that never receives mail. The parent creates that login from inside their own account — a child cannot sign themselves up — and the parent can reset its password or remove it at any time. A linked student can see their own schedule and progress and check off their own work; they cannot see photos or other students' information.
We do not knowingly collect personal information from a child beyond what a parent enters or authorizes. If you believe a child has provided information without a parent's involvement, email us and we will delete it.
Where your data lives and who processes it
- Supabase hosts our database, authentication, and file storage (United States). Row-level security means only your signed-in account can read your family's data; photos are served only through short-lived signed links.
- Anthropic provides the AI behind two features, and only receives data when you use them: curriculum scan — the pages or photos of a curriculum you upload, so the app can turn them into a lesson list; and field-trip suggestions — your home city, state and ZIP, travel preference, and your subjects, curriculum names, and upcoming lesson titles. Student names are never sent to the AI. AI results are suggestions; verify them before relying on them.
- Stripe handles checkout, card storage, billing, receipts, and cancellations. Stripe's privacy policy applies to the payment page.
- Sentry receives automatic crash and error reports from the app (United States), described in When something goes wrong below. It is configured not to record your screen and not to collect personal information by default.
- Resend delivers the email we send you about your own account — your welcome and password-reset messages, and the notes during a free trial including the warning before your card is charged. It receives your email address and the message itself, and nothing from your plan.
- Vercel hosts the web app and this website; Expo provides our build tooling.
- When you print or preview a planner, the page loads fonts from Google Fonts. When a memory verse is displayed, its text is fetched from bible-api.com (public-domain translations; no account information is sent).
- Reminders you set are scheduled locally on your device — nothing about them leaves your phone.
We do not sell or rent personal information, we do not share it with anyone for their own marketing, and we do not show third-party advertising inside the app.
The launch list (email)
If you join our launch list on this website, we keep your first name, email address, the page you signed up from, and the time you agreed to receive email. We use it to tell you when the app launches, to offer founding-member pricing, and to send occasional homeschool-planning tips — nothing else. The list is stored in our own database and in Artist Results, the service that sends our email on our behalf. Every message has an unsubscribe link, and you can ask us to remove you entirely at hello@lumendomusschola.com. The launch list is for adults; it is not connected to any student's app data.
Website analytics and advertising measurement
This website (lumendomusschola.com) uses the Meta Pixel so that, when we advertise on Facebook and Instagram, we can tell whether an ad led someone to visit or subscribe, and show our ads to people similar to those who did. It sets a cookie and shares standard page-view data (pages visited, device type, and — if you're logged in to Facebook or Instagram — your Meta account) with Meta.
This website also uses Google Analytics to understand how visitors find and use the site — things like which pages are read and which platforms send visitors our way. Google Analytics sets cookies and collects standard usage data (pages visited, approximate location, device type) as described in Google's privacy policy; we have ads personalization (Google signals) turned off.
Both of these are website-only: neither is in the app, the app carries no advertising or analytics code at all, and no student names, planning content, or app data is ever involved with either. (The app's crash reporter is a separate thing and is described below — it is not advertising, and it is not used to measure how you use the app.) You can block either with any standard content blocker, with Google's opt-out browser add-on, or by adjusting your Meta ad preferences — the site works exactly the same either way.
When something goes wrong
An app that breaks silently stays broken, so the app tells us when it fails. There are two ways that happens, and they are deliberately narrow.
Automatic crash reports. If the app hits an error, a report goes to Sentry, our error-monitoring service. A report contains the error message and the technical trace of where in our code it happened, your device and operating system, which version of the app you were running, and a random identifier for your account. It also includes a short trail of what the app was doing beforehand — which screens were opened and which of our own web addresses were called, with the details after the "?" removed.
Just as important is what a crash report does not contain. We have deliberately turned off the features that would collect more:
- No session replay. Your screen is never recorded or reconstructed. This is on by default in the software we use; we switched it off, because on this app the screen means children's names, their work, their grades and their photographs.
- No personal information by default. We do not send your name or email address. Your account is identified only by a random identifier, which lets us tell one person hitting a problem fifty times from fifty people hitting it once.
- No student information, planning content, or photos is deliberately included, and nothing is read from your plan to build a report.
- No performance or usage tracking. We collect errors, not a record of how you move around the app.
Two things we want to be straight about. An error message is written by our software, not by us in advance, so in principle one could quote a fragment of whatever it was working on at the time — a lesson title, say. We do not seek that, we do not use it for anything other than fixing the fault, and reports are deleted on our provider's standard schedule (currently 30 days). And because a report is delivered over the internet, our provider derives an approximate location from the connection — city-level at best, never a precise position — even though we have asked it not to store the address itself.
Reporting a problem yourself. Profile has a "Report a problem" form. That sends us what you type, plus the screen you picked from a list, your app version and platform, and your account identifier — nothing else, and nothing from your plan. It goes into our own database, not to a third party, and it exists because the bugs that matter most are usually the ones where nothing crashes and a number is simply wrong. What you write is up to you; please only include a child's name if you genuinely need to.
Permissions the app may ask for
Photo library and camera access, only when you choose to add a photo or scan a curriculum; notification permission, only when you first set a reminder; and calendar access, only if you turn on device calendar sync from the Profile tab. Decline any of them and the app remains fully usable.
Device calendar sync (mobile app)
In the mobile app you can choose to put your plan on the calendar already on your phone. It is off until you turn it on, and it is the one feature that deliberately copies information out of the app.
- The app creates a separate calendar on your device for each student, named with that student's first name, and writes lesson titles, supply reminders, extracurricular activities and family events into them. It reads those same calendars back so changes you make on your phone stay in step with your plan.
- Once information is on your device's calendar it is governed by your phone, not by us. If your calendar is signed in to iCloud, Google, or another account, your device will sync those entries there under your own account, in the same way it syncs everything else on that calendar. We do not send them anywhere ourselves.
- Turning sync off from the Profile tab removes the calendars the app created, and you can switch any individual student's calendar off at any time.
Payments
Subscriptions are sold through this website and processed by Stripe. We never see or store your card details. If we later offer purchases through the App Store or Google Play, those stores' own terms and privacy practices will apply to purchases made that way.
Your choices and rights
- Edit or delete any student, plan, photo, or profile detail in the app at any time.
- Delete your entire account and all associated data from the Profile screen (Profile → Delete my account). This cancels any subscription immediately, removes your family's plans and photos, and deletes any linked student logins. You can also email hello@lumendomusschola.com and we'll do it for you — see Delete your account for exactly what is removed and what is kept.
- Change or cancel your plan at any time in the billing portal.
- Ask us what personal information we hold about you or your family, or ask us to correct it, by email.
Retention
Your data is kept while your account is active. When you delete a student, plan item, or photo, it is removed from our systems (photos may take up to 30 days to be swept from storage). If your subscription ends, your data stays in your account for 30 days so you can print or export it, and may then be deleted. When you delete your account, everything associated with it is deleted; we retain subscription and payment records as required for tax and accounting.
Crash and error reports are kept on our error-monitoring provider's standard schedule, currently 30 days, and then age out. A problem you report to us is kept until we've dealt with it, and then deleted.
Security
Data is encrypted in transit and at rest by our hosting provider, access is limited by row-level security to your own account, and passwords are stored only as hashes. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page and, for significant changes, notify you in the app or by email.
Contact
Questions about privacy? Email hello@lumendomusschola.com.