The short version

Lumen Domus Schola is made for parents planning their family's homeschool year. Your lesson plans, your children's progress, and your family photos belong to you. We collect only what the app needs to work, we don't sell data, we don't show ads inside the app, and we put no advertising or analytics tracking in the app. The one piece of outside code the app does carry is a crash reporter that tells us when something breaks — it does not record your screen, and it is not used to watch how you use the app. We treat everything about your students — especially their photos — as sensitive.

Who we are

Lumen Domus Schola LLC, a Florida limited liability company ("we," "us"), publishes the Lumen Domus Schola app and operates lumendomusschola.com. Reach us anytime at hello@lumendomusschola.com, or by post at Lumen Domus Schola LLC, 3948 3rd St S #418, Jacksonville Beach, Florida.

Who the app is for

The app is designed for parents and legal guardians. The account holder must be an adult (18 or older) who is the parent or guardian of the students they add. Parents may optionally give a child a limited "student" login (see Student accounts and kid mode below); everything a child can do in the app is set up and controlled by the parent.

What we collect

We do not collect a child's date of birth, age, gender, grade level, email address, precise device location, contacts, or advertising identifiers. Please enter no more about a child than a first name or nickname — that is all the app needs.

Student accounts and kid mode

There are two ways a child can use the app, both controlled by the parent:

We do not knowingly collect personal information from a child beyond what a parent enters or authorizes. If you believe a child has provided information without a parent's involvement, email us and we will delete it.

Where your data lives and who processes it

We do not sell or rent personal information, we do not share it with anyone for their own marketing, and we do not show third-party advertising inside the app.

The launch list (email)

If you join our launch list on this website, we keep your first name, email address, the page you signed up from, and the time you agreed to receive email. We use it to tell you when the app launches, to offer founding-member pricing, and to send occasional homeschool-planning tips — nothing else. The list is stored in our own database and in Artist Results, the service that sends our email on our behalf. Every message has an unsubscribe link, and you can ask us to remove you entirely at hello@lumendomusschola.com. The launch list is for adults; it is not connected to any student's app data.

Website analytics and advertising measurement

This website (lumendomusschola.com) uses the Meta Pixel so that, when we advertise on Facebook and Instagram, we can tell whether an ad led someone to visit or subscribe, and show our ads to people similar to those who did. It sets a cookie and shares standard page-view data (pages visited, device type, and — if you're logged in to Facebook or Instagram — your Meta account) with Meta.

This website also uses Google Analytics to understand how visitors find and use the site — things like which pages are read and which platforms send visitors our way. Google Analytics sets cookies and collects standard usage data (pages visited, approximate location, device type) as described in Google's privacy policy; we have ads personalization (Google signals) turned off.

Both of these are website-only: neither is in the app, the app carries no advertising or analytics code at all, and no student names, planning content, or app data is ever involved with either. (The app's crash reporter is a separate thing and is described below — it is not advertising, and it is not used to measure how you use the app.) You can block either with any standard content blocker, with Google's opt-out browser add-on, or by adjusting your Meta ad preferences — the site works exactly the same either way.

When something goes wrong

An app that breaks silently stays broken, so the app tells us when it fails. There are two ways that happens, and they are deliberately narrow.

Automatic crash reports. If the app hits an error, a report goes to Sentry, our error-monitoring service. A report contains the error message and the technical trace of where in our code it happened, your device and operating system, which version of the app you were running, and a random identifier for your account. It also includes a short trail of what the app was doing beforehand — which screens were opened and which of our own web addresses were called, with the details after the "?" removed.

Just as important is what a crash report does not contain. We have deliberately turned off the features that would collect more:

Two things we want to be straight about. An error message is written by our software, not by us in advance, so in principle one could quote a fragment of whatever it was working on at the time — a lesson title, say. We do not seek that, we do not use it for anything other than fixing the fault, and reports are deleted on our provider's standard schedule (currently 30 days). And because a report is delivered over the internet, our provider derives an approximate location from the connection — city-level at best, never a precise position — even though we have asked it not to store the address itself.

Reporting a problem yourself. Profile has a "Report a problem" form. That sends us what you type, plus the screen you picked from a list, your app version and platform, and your account identifier — nothing else, and nothing from your plan. It goes into our own database, not to a third party, and it exists because the bugs that matter most are usually the ones where nothing crashes and a number is simply wrong. What you write is up to you; please only include a child's name if you genuinely need to.

Permissions the app may ask for

Photo library and camera access, only when you choose to add a photo or scan a curriculum; notification permission, only when you first set a reminder; and calendar access, only if you turn on device calendar sync from the Profile tab. Decline any of them and the app remains fully usable.

Device calendar sync (mobile app)

In the mobile app you can choose to put your plan on the calendar already on your phone. It is off until you turn it on, and it is the one feature that deliberately copies information out of the app.

Payments

Subscriptions are sold through this website and processed by Stripe. We never see or store your card details. If we later offer purchases through the App Store or Google Play, those stores' own terms and privacy practices will apply to purchases made that way.

Your choices and rights

Retention

Your data is kept while your account is active. When you delete a student, plan item, or photo, it is removed from our systems (photos may take up to 30 days to be swept from storage). If your subscription ends, your data stays in your account for 30 days so you can print or export it, and may then be deleted. When you delete your account, everything associated with it is deleted; we retain subscription and payment records as required for tax and accounting.

Crash and error reports are kept on our error-monitoring provider's standard schedule, currently 30 days, and then age out. A problem you report to us is kept until we've dealt with it, and then deleted.

Security

Data is encrypted in transit and at rest by our hosting provider, access is limited by row-level security to your own account, and passwords are stored only as hashes. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.

Changes to this policy

If this policy changes in a meaningful way, we'll update the date at the top of this page and, for significant changes, notify you in the app or by email.

Contact

Questions about privacy? Email hello@lumendomusschola.com.