Legal

Cookie Policy

Last updated: 3 September 2026

1. About this policy

This Cookie Policy explains how Moritz Affolter, the operator of Lumora ("Lumora," "we," "us," or "our"), uses cookies, browser local storage, pixels, and similar technologies on asklumora.com.

For information about personal-data processing and your rights, see our Privacy Policy.

2. What are cookies and similar technologies?

A cookie is a small text file stored by a website or service in your browser. Session cookies expire when the browser session ends; persistent cookies remain until their expiry or deletion. Local storage is a browser feature that can retain preferences and identifiers without using a traditional cookie. Pixels and software development kits can record that a page was viewed or an action completed.

First-party technologies are set by Lumora. Third-party technologies are provided by services such as Stripe, PostHog, or an advertising-measurement provider.

3. Categories we use

Strictly necessary

These technologies provide authentication, security, checkout, consent storage, load balancing, and other functions requested by you. Lumora cannot operate reliably without them. They do not require consent where applicable law exempts strictly necessary storage.

Preferences and referrals

These remember settings, first-touch campaign information, referral codes, or an experiment assignment so that the service remains consistent. Where the law requires consent for a particular preference or attribution technology, we ask before using it.

Analytics and experiments

With your consent, PostHog and Lumora measure how visitors use the product, whether features work, and how variants perform. We configure analytics not to receive selfies, skin-analysis results, email addresses, or full payment details.

Advertising measurement

With your consent, Lumora's advertising-measurement technology records limited conversion events, such as completed registration or subscription creation, to evaluate campaigns. Lumora does not send selfies, analysis results, or email addresses with those events.

Lumora does not send scan completion, analysis mode, skin observations, scores, concerns, routines, image-quality failures, or other consumer health data to advertising providers. Consent to advertising cookies is separate from consent to process a photo for a requested scan.

Payments and fraud prevention

When you open checkout or billing management, Stripe may use cookies and device signals to authenticate the session, remember payment preferences, and detect fraud. Some of these technologies are necessary to provide secure checkout.

4. Technologies used by Lumora

The following table reflects the intended production configuration:

TechnologyProviderCategoryPurposeTypical duration
lumora:cookie-consentLumoraStrictly necessaryStores whether you accepted, declined, or customized optional technologiesUntil changed or browser storage is cleared; choice renewed after no more than 12 months
Supabase authentication storage, commonly named sb-…-auth-tokenSupabase/LumoraStrictly necessaryMaintains a signed-in or guest session and protects account accessSession-dependent; refreshed while the session is active
Temporary scan and result state in session storageLumoraStrictly necessaryCarries a selected image and result between scan screensBrowser session
lumora_exp_landing_hero_v1LumoraAnalytics/experimentKeeps the same landing-page variantUp to 180 days, and only after consent where required
lumora_exp_price_v1LumoraAnalytics/experimentKeeps the same monthly-price variantUp to 180 days, and only after consent where required
lumora_attr and lumora:attributionLumoraAttributionRemembers first-touch UTM and campaign informationUp to 180 days, subject to consent where required
lumora_friend_ref and lumora:friend_refLumoraPreference/referralApplies a referral code requested by the visitorUp to 180 days
PostHog storage, commonly including ph_*_posthogPostHogAnalytics/experimentMeasures consented product usage and experiment outcomesNo more than 12 months
OpenAI advertising-measurement pixel/storageOpenAIAdvertising measurementRecords consented campaign-conversion eventsProvider-controlled, no more than 13 months unless law or configuration requires a shorter period
Stripe cookies and identifiers, which may include m, __stripe_mid, __stripe_sid, and Link or Checkout session identifiersStripeStrictly necessary/payment and fraud preventionProvides checkout, remembers payment preferences where selected, authenticates sessions, and helps prevent fraudSession-based or persistent as determined by Stripe and applicable settings

Exact provider-controlled names may vary by browser, service configuration, and provider updates. Stripe describes its payment and fraud technologies in its Privacy Center and Cookie Policy.

5. Your choices

On your first visit, you can accept or decline optional analytics and advertising technologies. Declining optional technologies does not prevent basic scans, account access, or purchases.

You can later reopen Cookie choices from the site footer or Settings → Privacy, change categories, or withdraw consent. Withdrawal applies going forward. Lumora will stop optional tracking and clear its optional first-party identifiers where technically possible; you may also clear cookies and local storage through your browser.

Blocking all browser storage may prevent login, referral attribution, checkout, or other requested features from working correctly.

Lumora does not permit analytics or advertising providers to use their technologies on Lumora to collect consumer health data over time across unrelated websites or services. Optional tools are configured with automatic page-content and form capture disabled.

6. Do Not Track and Global Privacy Control

Browser signals are not uniformly interpreted. Where legally required and technically supported, Lumora treats recognized opt-out signals such as Global Privacy Control as a request to disable optional advertising technologies. You may always use Lumora's own Cookie choices control.

7. Changes to this policy

We may update this policy when our technologies or providers change. We will post the revised version with a new update date and request consent again where required.

8. Contact

Questions about cookies or privacy may be sent to moritz@moritscls.com.