Skip to main content
Email Us
Official Privacy Disclosure

Lumina Finance Privacy Policy

This Privacy Policy describes how VRYTIS LABS collects, protects, synchronizes, and respects your personal and financial information when you use the Lumina Finance application for Android.

Application: Lumina Finance (Android)
Developer: VRYTIS LABS
Effective Date: September 28, 2026
Canonical URL: https://vrytislabs.com/privacy/lumina

Key Privacy Guarantees at a Glance

Zero Data Selling

We never sell, rent, or trade your financial, transactional, or personal data to advertisers, aggregators, or brokers.

Biometrics Never Leave Device

Fingerprint and Face Unlock use Android's native BiometricPrompt API. Your biometric data is isolated in hardware and never accessed or transmitted.

Local Receipt Scanning

Receipts scanned via your camera are analyzed 100% locally on-device using Google ML Kit. Raw images are never sent to external servers.

AES-256 & TLS 1.3

Encrypted in transit via modern HTTPS/TLS protocols and encrypted at rest on secure Google Cloud Firestore infrastructure with per-user UID isolation.

Local Room + Cloud Sync

Offline-capable local Room SQLite database paired with secure cloud synchronization, enabling real-time backup across your personal devices.

Total Deletion Freedom

Delete transactions individually, wipe your local storage, or permanently purge your cloud account and all records anytime in app settings or by email.

Section 1

1. Introduction & Overview

Welcome to Lumina Finance. This Privacy Policy outlines the uncompromising commitment of VRYTIS LABS(“we,” “us,” or “our”) to safeguarding the confidentiality, integrity, and privacy of your personal data and financial records.

Lumina Finance is engineered to provide modern, intuitive personal expense tracking, budgeting, debt management, client invoicing, and financial insight tools for Android devices. Financial records reflect deeply personal aspects of daily life; therefore, our architecture prioritizes local-first computation, end-to-end transport security, and complete user sovereignty over data.

By downloading, installing, accessing, or using the Lumina Finance mobile application, you acknowledge that you have read, understood, and consented to the collection, synchronization, and handling of information as detailed in this policy. If you do not agree with any aspect of this Privacy Policy, please discontinue using the application.

Section 2

2. Information We Collect

We only collect data strictly necessary to fulfill the core tracking, synchronization, and operational capabilities of Lumina Finance. We do not gather extraneous background information.

A

Account & Contact Credentials

When you create an account to synchronize your financial data across devices, we collect your:

  • Email Address: Used as your unique account identifier, for authentication, password recovery, and essential transactional notices.
  • Display Name: An optional user-specified name used for personalization and client invoice sender headers.
  • Authentication Tokens: Cryptographic tokens issued via Firebase Authentication to secure your signed-in session.
B

Financial & Transactional Records

Data created, typed, or imported directly by you within the app to manage your personal finances:

  • Expense & Income Entries: Amounts, transaction dates, merchant names, payment methods, transaction tags, and user notes.
  • Account Balances & Wallets: User-defined cash, bank, or digital wallet labels and initial/current balance tallies.
  • Budgets & Goals: Spending limits per category, monthly target allocations, and savings milestone targets.
  • Debt & Loan Records: Principal amounts, creditor/debtor names, repayment terms, and interest rate notations.
  • Client Invoices: Client names, billing contacts, itemized services or product line items, hourly/unit rates, applied tax percentages, and payment status (paid/unpaid).
C

Media & Camera Permissions (Receipt Scanning)

Lumina Finance includes an optional smart receipt scanner. If you grant camera permission (android.permission.CAMERA):

  • The camera is accessed only while actively taking a photo of a receipt or invoice within the scanning interface.
  • Optical character recognition (OCR) is performed 100% on-device using Google ML Kit.
  • Zero Cloud Transmission: Raw receipt photos, thumbnails, and temporary image buffers remain isolated on your local hardware and are never uploaded to remote servers or cloud AI models.
D

App Diagnostics, Performance & Crash Telemetry

To maintain app health, catch regression bugs, and prevent crashes across thousands of Android device configurations, we collect non-identifying telemetry via Firebase Crashlytics and Google Analytics for Firebase:

  • Technical Device Specs: Device model manufacturer, Android operating system version, CPU architecture, screen resolution, and available RAM.
  • Crash Stack Traces: Code execution points and system state at the moment an unhandled exception or crash occurs.
  • Aggregated Usage Statistics: Anonymous metrics such as screen transitions, feature adoption rates, and app open frequency.
  • Strict Financial Exclusion: Crash reports and telemetry payloads never contain transaction amounts, payee names, bank balance records, or authentication passwords.
Section 3

3. Biometric Authentication & Hardware Isolation

Absolute Hardware Isolation Guarantee

VRYTIS LABS does not access, scan, collect, process, record, or transmit fingerprint, facial recognition, or iris biometric signatures. Your biometric data never leaves your device under any circumstances.

Lumina Finance integrates Android's standard, secure BiometricPrompt API to enable optional app-lock protection (Fingerprint or Face Unlock).

When you authenticate using your fingerprint or face, the verification is handled entirely by your device's dedicated secure hardware — such as the Android Trusted Execution Environment (TEE) or hardware-backed Titan/Keystore security module. The operating system only returns a boolean cryptographic confirmation (authentication successful or failed) to the Lumina Finance application.

Section 4

4. Camera & Receipt Scanning (On-Device ML Kit)

Lumina Finance incorporates receipt parsing technology to save you time entering daily expenses. Here is exactly how this functionality works:

Step 1: Local Capture

You snap a photo of a physical bill or paper receipt through the app's built-in viewfinder.

Step 2: On-Device OCR

The image bitmap is processed locally using the on-device Google ML Kit Text Recognition model loaded directly on your phone.

Step 3: Local Text Extraction

Dates, total currency figures, and vendor titles are parsed via heuristic patterns entirely on your CPU/NPU.

Step 4: Memory Release

Once text fields are filled into the new expense form, the temporary camera buffer is discarded from device memory.

No images captured via the camera are ever uploaded to cloud servers, processed by remote artificial intelligence, or stored beyond your immediate receipt entry session.

Section 5

5. How We Use Your Information

We use the information collected exclusively for functional, service-delivery purposes. Specifically:

✓
Core Financial Management: Calculating category expenses, updating balance ledgers, computing budget thresholds, tracking debt amortization, and providing financial overview charts.
✓
Cross-Device Synchronization: Mirroring and securely synchronizing your transactions, accounts, and invoices between your Android phone, tablet, and subsequent signed-in devices.
✓
Account Security & Authentication: Authenticating your user identity, issuing secure session tokens, validating password resets, and shielding your data against unauthorized access.
✓
Local Invoicing & Report Generation: Compiling user-requested PDF client invoices and CSV spreadsheets directly on your local device for sharing or tax accounting.
✓
App Reliability & Bug Remediation: Investigating system stack traces, repairing crashes, evaluating app performance, and continuously improving stability across Android operating systems.

Explicit Operational Prohibitions

  • We NEVER use your financial records to target behavioral or third-party ads.
  • We NEVER build demographic or consumer purchase profiles for external resale.
  • We NEVER calculate credit scores or disclose transaction histories to lenders or financial institutions.
Section 6

6. Data Storage, Architecture & Encryption Standards

Lumina Finance is built with a defense-in-depth security model to safeguard your financial ledger both locally on your phone and in the cloud.

Local Device Storage (Android Room SQLite)

When you are offline or creating entries, your financial data is instantly stored in an Android Room database residing in sandboxed private internal storage (/data/user/0/com.vrytislabs.lumina...). Under Android's Linux-level sandbox isolation, other apps installed on your device cannot access or read Lumina Finance's database files.

Cloud Storage & Synchronization (Google Cloud Firestore)

When online, data syncs to Google Cloud Firestore database servers. Firestore security rules enforce strict user UID isolation: records can only be queried, written, or deleted if the requesting client presents a cryptographically verified Firebase Authentication token matching the document's owner ID.

Encryption in Transit

All network communications between the mobile app, Firebase Authentication, and Firestore are strictly encrypted using TLS 1.3 / TLS 1.2 with modern cipher suites over HTTPS.

Encryption at Rest

Cloud database volumes and storage systems are encrypted at rest using industry-standard AES-256 encryption managed by Google Cloud Platform infrastructure.

Section 7

7. Data Sharing, Third Parties & Zero-Sale Policy

Our Unambiguous Non-Sale Pledge

VRYTIS LABS does not sell, rent, monetize, release, disclose, disseminate, or transfer user personal data, account credentials, or financial transactions to third parties, advertising networks, or data aggregators for monetary or commercial consideration.

To deliver secure cloud sync, authentication, and application stability, Lumina Finance utilizes select infrastructure services provided by Google LLC. These services act strictly as data processors operating under rigorous enterprise security agreements:

ServiceProviderFunctional PurposePrivacy Policy
Firebase AuthenticationGoogle LLCUser login, email verification, password resets, secure JWT session management.Firebase Privacy
Cloud FirestoreGoogle LLCEncrypted cloud database for synchronizing financial transactions and invoices.Google Cloud Notice
Firebase Crashlytics & AnalyticsGoogle LLCCrash report diagnostics, crash stack traces, non-identifying performance metrics.Analytics Policies
Google Play ServicesGoogle LLCApp distribution, core system library runtime, licensing and update checks.Google Privacy
Google ML KitGoogle LLCOn-device OCR receipt parsing (runs locally; no data leaves the phone).ML Kit Terms

We may also disclose information if strictly required to do so by applicable law, court order, or valid governmental subpoena, or to protect the vital security of our users and services against severe fraudulent activity.

Section 8

8. Data Retention & User Control

You maintain full, sovereign ownership of your financial records at all times. Our retention practices are governed by your active usage:

  • Active Account Data: Financial records, budgets, categories, and invoices are retained in your local database and synced Firestore repository as long as your account remains active.
  • Granular In-App Edits: You can edit or delete individual expense logs, income entries, bank accounts, or invoices directly inside the app at any second. Deleted items are immediately removed from your local database and permanently removed from Firestore upon next sync.
  • Crash Diagnostic Data: Aggregated, non-identifying telemetry logged in Firebase Crashlytics is retained for up to 90 days before automated system purging by Google.
  • Local Exports (PDF & CSV):Files you generate using the export features are saved to your device storage (e.g., Downloads or Documents folder). Because these files reside outside the app's private sandbox, their retention and security are controlled by you.
Section 9 • Google Play Compliant

9. How to Delete Your Account & All Associated Data

In compliance with Google Play Developer Policies and global privacy laws, Lumina Finance gives you direct, frictionless tools to permanently delete your account, authentication records, and all stored financial entries.

1

Method 1: Direct In-App Instant Deletion (Recommended)

You can execute a complete wipe directly from the Lumina Finance Android app:

  1. Open Lumina Finance on your Android phone.
  2. Tap the Settings icon in the navigation bar.
  3. Select Security & Account.
  4. Scroll to the danger zone and tap Delete Account & Data.
  5. Confirm the prompt.
What happens immediately: Your local Room SQLite database is wiped clean, your session is revoked, and all Firestore documents tied to your user UID (expenses, incomes, wallets, budgets, debts, invoices) are permanently purged from the cloud.
2

Method 2: Email / Web Data Erasure Request

If you have uninstalled the app or cannot access your phone, you can request an account wipe via our support team:

  • Send an email to admin@vrytislabs.com.
  • Subject line: Account & Data Deletion Request - Lumina Finance.
  • Please send the message from the exact email address associated with your Lumina Finance account so we can verify ownership.
  • Or use our dedicated web portal: vrytislabs.com/delete-account
Turnaround time: Requests submitted by email are verified and completed within 48 hours. We will send a confirmation once your account and all associated cloud collections have been permanently expunged.
Section 10

10. Children's Privacy (COPPA & GDPR Compliance)

Lumina Finance is designed for personal budgeting, financial accountability, and professional client invoicing. Our service is not directed to children under 13 years of age (or under 16 years of age in the European Economic Area and United Kingdom).

We do not knowingly solicit, request, or collect personal information or financial records from children. If we discover that a user under 13 has registered an account or stored data without verified parental consent, we will take immediate operational steps to delete the account and purge all associated records from our servers.

Parents or legal guardians who become aware that their child has provided personal details to Lumina Finance may contact us at admin@vrytislabs.com for swift removal.

Section 11

11. Global Legal Rights (GDPR, CCPA/CPRA & DPDP)

Regardless of where you reside, VRYTIS LABS respects fundamental data protection principles:

European Union & UK Users (GDPR / UK GDPR)

Under the General Data Protection Regulation, our legal basis for processing your account and financial data is Contractual Necessity (to provide and sync your requested tools) and Legitimate Interests(to protect against security vulnerabilities). You enjoy rights of access, rectification, erasure (“Right to be Forgotten”), restriction of processing, data portability (via CSV export), and the right to lodge a complaint with your national supervisory authority.

California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act and CPRA, California residents have the right to know what personal categories are collected, the right to request deletion, and the right not to receive discriminatory treatment for exercising their privacy rights. We do not sell or share personal information as defined by California statutes.

India (Digital Personal Data Protection Act, 2023)

In compliance with the DPDP Act 2023, data is processed solely for user-consented financial tracking and invoicing. Data Principals have the right to access summary details, seek correction/erasure, nominate a representative, and address grievances through our Data Protection contact.

Section 12

12. Changes to This Privacy Policy

As we introduce new features to Lumina Finance (such as advanced analytics or additional export formats), we may update this Privacy Policy to reflect those enhancements or comply with amended legal standards.

When changes are enacted, we will revise the “Effective Date” at the top of this document. In the case of material alterations that affect how your financial records are processed, we will provide prominent notification through an in-app notice or by email prior to the changes taking effect.

We encourage you to review this page periodically to remain informed about how we protect your information. Your continued use of Lumina Finance after revised terms are published signifies your acceptance of the updated policy.

Section 13

13. Contact & Legal Inquiries

If you have questions, feedback, grievance redressal requests, or concerns regarding this Privacy Policy or our financial data practices, please reach out to our dedicated team:

Email Contact

Support & Inquiries:admin@vrytislabs.com

Developer & Publisher Details

VRYTIS LABS

Digital Software Development Studio

Location: Kaliyaganj, West Bengal, India

Official Portal: https://vrytislabs.com

© 2026 VRYTIS LABS. All rights reserved.