Legal

Lumignon – Secrets & Prières

A candle that burns only on your device, an evening prayer at 8 pm, a personal prayer on request by e-mail, a directory of the «secret» tradition (Switzerland), emergency numbers and background knowledge — the app collects no data

Privacy policy

Last updated: 5 September 2026

The Lumignon app collects no data. It has no account, no login, no device identifier, no analytics, no advertising, no trackers, no third-party SDKs and no push server. The candle you light and the intention you write with it stay on your device only and are never sent. The app only loads public files (directory, content, country details) from babala.ch, without any identifier. If you want to contact us — to ask for a personal prayer, to add yourself to the directory as a «faiseur de secret», to report something or to ask for a change or deletion — you write us an e-mail yourself at info@babala.ch (to ask for a personal prayer, alternatively a WhatsApp message to our number +41 76 792 63 50): the app only opens your mail app or your WhatsApp with a prepared text, and you decide whether to send it. We treat these messages like normal correspondence (explained below). They may contain information about health and religious activities; this is sensitive personal data (Art. 5(c) Swiss FADP) — please do not write diagnoses and only what is needed. We publish directory entries only with the explicit consent of the listed person. The public files are hosted on our server at Hetzner in Germany.

1. Data controller

Company
Babala Özdemir (Einzelunternehmen)
Address
Unterer Rainweg 22
4414 Füllinsdorf
Schweiz
E-mail
info@babala.ch
Phone
076 792 63 50
Company ID
CHE-322.105.560
App identifier
iOS: ch.babala.lumignon

We have not appointed a data protection officer or an EU representative because we do not reach the relevant thresholds. Please address all requests to the contact above.

2. What data we process

Data Purpose Stored where Retention
Candles and intentions (text you write with a candle), time, history Showing your candle (visible for 24 hours) and your history. Never sent — we receive none of it. On your device only, in a file with iOS data protection, excluded from iCloud and device backups Until you delete the candle or history in the app or remove the app
Local evening notification at 8 pm (optional) Reminder “Tonight, someone prayed for you too”. Your device schedules the notification itself; there is no push token and no push server. On your device only Until you turn the notification off in the app or in the iOS settings
Settings, favourites, chosen country, “18+” and first-launch notice confirmations, offline copy of the public files Operating the app, also without an internet connection On your device only Until you choose “Delete my data” or remove the app
Download of public files (directory, countries, sources, tradition & knowledge, emergency numbers, templates, notice banner) by plain download, without an identifier; technically the web server sees the IP address, time, file and app version (user agent) Up-to-date content (texts and data only, no functions). We do not analyse the downloads and build no profiles. Our server at Hetzner (Germany); copy on your device Web server access logs at most 14 days
E-mails you send yourself to info@babala.ch (request for a personal prayer, directory sign-up, reports, change and deletion requests, support): your e-mail address, name if given, content, time Answering and handling your matter like normal correspondence; for a prayer request a volunteer of our team prays. No disclosure, no sale, no advertising. Our mailbox at our e-mail provider; accessible only to the owner of Babala Software Deleted immediately on request, otherwise at the latest 12 months after the last exchange (exception: consent records of listed people, see below)
WhatsApp messages you send yourself to our number +41 76 792 63 50 (request for a personal prayer): your phone number, your WhatsApp name, content, time Like e-mails: only answering you or the prayer you asked for; reply voluntary. No disclosure, no sale, no advertising. WhatsApp is a Meta service you use yourself; the app sends nothing. WhatsApp (Meta Platforms Ireland Ltd. / WhatsApp LLC, USA) under their terms; chat history in the WhatsApp app on our team’s phone, not forwarded Deleted immediately on request, otherwise at the latest 12 months after the last exchange (on our side; at WhatsApp according to its rules)
Directory entry (only after own sign-up and consent): name or short name, place and canton, languages, areas (kinds of secrets/prayers), phone or WhatsApp number, availability, short note, date of the telephone check Publication in the app so that people seeking help can contact the person directly by call, SMS or WhatsApp. The phone number is shown publicly for this purpose. Public file on our server (Hetzner, Germany); in the app for all users and in their offline copy Until withdrawn; deletion at any time by e-mail, usually within 2 working days
Internal review details for a sign-up: sign-up e-mail with the declarations and consent given (proof), notes on the verification call, reason for a rejection or removal Reviewing the sign-up and proving that publication is based on explicit consent; never published Our mailbox or the owner’s internal notes As long as the entry exists and at most 12 months afterwards; if rejected, at most 12 months
Contact templates (call, SMS, WhatsApp to a listed person) Preparing a message to a listed person. You start the call, SMS or WhatsApp yourself; it runs directly between you and the person, not through us — we see none of it. On your device only; when sending, via your phone carrier or WhatsApp Not stored by the app
Map view (Apple MapKit), if you open the directory map Displaying the map; when loading map tiles Apple receives the IP address and the visible map region Apple (Ireland/USA) According to Apple’s terms; nothing of it is stored by us

What we explicitly do not collect

3. Permissions on your device

The app requests only the following permissions. Each of them can be revoked at any time in your device settings; the app remains usable afterwards, with reduced functionality.

4. Legal bases

We process personal data under the Swiss Federal Act on Data Protection (revFADP). Where the GDPR applies, we rely on:

The app itself does not process any personal data on our side. What you do in the app (candles, intentions, favourites, settings) stays on your device. We only receive personal data if you write us an e-mail yourself and — for listed people — for the directory entry. E-mails and sensitive data. A request for a personal prayer or a directory sign-up may contain information about health and religious activities (Art. 5(c) Swiss FADP). Before opening the mail app, the app tells you that your e-mail address becomes visible to us and that you should not write diagnoses. By sending the e-mail yourself, you explicitly consent to the processing of the information in it for the purpose of answering (Art. 6(7) FADP). The same applies to a prayer request by WhatsApp to +41 76 792 63 50 (the app tells you that your phone number becomes visible to us). We use e-mails and WhatsApp messages only to handle your matter, do not pass them on to third parties and delete them immediately on request, otherwise at the latest after 12 months. Please do not include full names or health information of other people. Directory entries are published only with the explicit consent of the listed person, given in their sign-up e-mail and confirmed in the verification call (name or short name, place, canton, languages, areas, phone or WhatsApp number, availability, note, date of check); consent can be withdrawn at any time by e-mail, and the entry is then deleted. Children and young people: requesting a personal prayer and signing up to the directory are intended for people aged 18 or over (confirmation in the app, stored locally only); the app is not directed at children and is not designed for the Kids category or COPPA. Who prays: a volunteer of the Babala Software team; we do not publish who that is. Call, SMS, WhatsApp: contacts with listed people run directly from your phone to theirs; we see none of it. With WhatsApp you act yourself as a WhatsApp user; the data goes to WhatsApp/Meta under their own privacy terms — to us only if you write to us yourself. Abroad: the public files are hosted in Germany, which offers adequate data protection under Annex 1 of the Swiss Data Protection Ordinance; depending on the mail provider, e-mails may also be processed outside Switzerland (providers with adequate protection or under the Data Privacy Framework). WhatsApp messages to us run via Meta (Ireland/USA; Swiss-U.S. and EU-U.S. Data Privacy Framework); you choose this channel yourself and can write an e-mail instead. Legal bases under the GDPR (for people in the EU/EEA, Art. 3(2) GDPR): e-mails and WhatsApp messages containing health-related information on the basis of your explicit consent given by sending (Art. 9(2)(a) GDPR); answering your request and maintaining your directory entry in order to carry out your request (Art. 6(1)(b) GDPR); publication of the entry on the basis of explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR); web server access logs, the handling of reports and keeping consent records on the basis of our legitimate interest in a secure, lawful service and in being able to demonstrate consent (Art. 6(1)(f) and Art. 7(1) GDPR). Your rights (Art. 25 ff. Swiss FADP; Art. 15–22 GDPR): access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time with effect for the future. As the app sends no data to us, we can only provide information about e-mails, WhatsApp messages and directory entries; you delete data on your device yourself (More › Delete my data). Write to info@babala.ch; we reply within 30 days. Complaints: you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch) and, in the EU/EEA, to the data protection supervisory authority of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR). There is no automated individual decision-making and no profiling; entries are always decided by a human. Consumer Health Data Privacy Policy (Washington, Nevada and other US states) — applies to users in the USA (including the Washington My Health My Data Act, RCW 19.373, and Nevada SB 370). Collection by the app: the app collects no consumer health data; candles and intentions stay on your device. E-mails and WhatsApp: if you voluntarily write us an e-mail or WhatsApp message (e.g. a request for a personal prayer), it may contain health information. Source: only you. Purpose: only answering you or the prayer you asked for. Consent: by sending. Sharing: we never sell such data and do not share it with third parties; it is kept only in our mailbox or in the WhatsApp chat on our team’s phone (WhatsApp/Meta carries it under its own terms, as a service you use yourself). No geofencing, no advertising, no tracking. Your rights: access, deletion and withdrawal of consent by e-mail to info@babala.ch; reply within 45 days. Appeal: e-mail with the subject “Appeal” to info@babala.ch; reply within 45 days; if we uphold the refusal you may complain to your state Attorney General (Washington: www.atg.wa.gov/file-complaint). Deletion at the latest 12 months after the last exchange.

5. Recipients and third parties

We do not sell data and do not disclose it for advertising purposes. Data is disclosed only to the following parties, and only where required for operation:

Recipient Location Purpose
Hetzner Online GmbH Gunzenhausen (Germany), data centre inside the EU Operation of our servers. Hetzner processes data solely on our behalf and is contractually bound to confidentiality.
Apple MapKit Cork (Ireland) / USA Map rendering. When loading map tiles Apple receives the IP address and the visible map region.
Apple Inc. / Apple Distribution International Ltd. Cupertino (USA) / Cork (Ireland) App Store distribution, processing of in-app purchases and subscriptions, and crash reports if you have enabled them with Apple.

Authorities and courts receive data only where we are legally obliged to provide it.

Transfers abroad

Some of the recipients listed above process data outside Switzerland and the EEA, in particular in the United States. We base such transfers on the European Commission’s Standard Contractual Clauses with the Swiss adaptations recognised by the FDPIC and, where applicable, on the EU-US Data Privacy Framework. We will provide information on the safeguards in place on request.

6. Retention and deletion

In the app: candles, intentions, history, favourites and settings stay on your device only until you delete them (More › Delete my data) or remove the app. E-mails to info@babala.ch (prayer requests, sign-ups, reports, change and deletion requests, support) and WhatsApp messages to +41 76 792 63 50 are deleted immediately on request, otherwise at the latest 12 months after the last exchange. Directory: entries remain published until the listed person withdraws them by e-mail (deletion usually within 2 working days) or we remove them. We keep the sign-up e-mail with consent and declarations as proof as long as the entry exists and at most 12 months afterwards; review notes and sign-ups that are not published at most 12 months after rejection. Web server access logs (IP address, time, file) at most 14 days. Our server is backed up daily (7 generations); deleted entries therefore also disappear from the backups at the latest 7 days after deletion. Users who loaded the directory earlier keep an offline copy until their app next refreshes.

Step-by-step instructions are available at Delete data.

7. Children and young people

This app is not directed at children. We do not knowingly collect personal data from children under 16. If we learn that such data has been submitted without parental consent, we delete it without delay.

8. Data security

Wherever the app transmits data at all, connections are encrypted via HTTPS/TLS. On the server side we use access restrictions, tenant separation and regular backups. Nobody can, however, guarantee absolute security for data transmission over the internet.

The app stores candles and intentions in a file with iOS data protection (encrypted while the device is locked) that is excluded from iCloud and device backups; they are never transmitted. The app only loads public files over HTTPS and sends no identifier and no content when doing so. On our server there is no database with user data for Lumignon, only public files. The mailbox info@babala.ch is password-protected and accessible only to the owner; WhatsApp messages are kept only in the WhatsApp app on our team’s locked phone. E-mails and WhatsApp messages relating to health are not passed on to third parties and are deleted once handled. Should a data security breach nevertheless occur that is likely to result in a high risk for you, we report it as quickly as possible to the Swiss Federal Data Protection and Information Commissioner (FDPIC, Art. 24 FADP) and inform you where necessary and possible.

9. Your rights

An informal message to info@babala.ch or a call to 076 792 63 50. We normally respond within 30 days. To verify your identity we may request suitable proof. You may also lodge a complaint with a supervisory authority (Switzerland: FDPIC; EU: your competent authority).

10. Changes to this policy

We may adapt this policy when the app or the legal framework changes. The version published on this page, with the date shown above, is the applicable one. We announce material changes inside the app.

← Back to the app overview