LUMEN · LIGHTING REPORTS

Privacy policy

Effective September 13, 2026. This policy describes the Lumen — Lighting Reports app and its hosted report services, operated by Julian Cousineau. Contact: Lumen support.

Community connection and shared inspections

You enter an administrator-issued community code to connect a work device. The server validates the code and issues a separate revocable credential for that device. We store its hash, assigned community, a generated account/device identifier, status, and security audit records. The credential stays in app/browser storage so you do not need to sign in on every patrol. Enrollment requests use a hashed network address and time bucket to limit abusive attempts. There is no individual public account registration.

Once connected, inspector names, report dates, observations, fixture coordinates, notes, drafts, completed inspection history, and attached photos or videos synchronize with Lumen's Cloudflare service. Other authorized devices in that community can continue the shared draft and view its history. Changes save locally first. Offline changes become available to other devices only after successfully synchronizing. The welcome screen's last inspection uses the community's last synchronized completed record.

Unlink community at the bottom of Settings removes the device's saved community connection and returns to setup. Local recovery copies of reports may remain on the device for recovery in that community. Unlinking does not delete shared community records or exported copies. Administrators can revoke future server access, but cannot remotely erase copies already downloaded or exported.

Report submission and email

Submitting a report uploads its saved snapshot and three report files to Cloudflare and sends them through Resend to administrator-configured community recipients. The report can include inspector names, exact fixture coordinates, notes, and photos. Recipient email addresses, delivery status, and report identifiers are retained for delivery and administration. The app does not read your email inbox or address book. Preparing or manually exporting files does not itself send an email, although a connected inspection's contents synchronize as described above.

Emailed report files and snapshots expire from Cloudflare KV after 90 days. The private map link grants access to that report to anyone possessing the link, expires after 90 days, and can be revoked. Recipient copies do not expire with the link. Shared inspection history and its attachments are separate and remain until administratively removed. Delivery metadata, recipient settings, access records, and audit records are retained for administration. Contact support for access, correction, or deletion requests. Resend and recipient email providers process messages under their own retention policies. See Resend's privacy policy.

Shared inventory is public

The app includes and downloads community lighting reference information, including fixture identifiers, coordinates, descriptions, and reference photos. The current Fiddler's Creek reference inventory is distributed with the app and through public reference services. Community codes protect shared inspection records, not the confidentiality of this bundled reference inventory.

If you connect an authorized inventory setup key and edit a shared location, its coordinates, descriptions, fixture layout, reference media, and associated file metadata are uploaded to the inventory service and made available to other users. Pending setup changes retry when the device reconnects. Do not put private incident information, access codes, or unnecessary personal information in public reference fields or photos. A reference photo or description may identify a person if you include them.

Location, camera, and selected media

Location access is optional and is used while the app is open to show nearby lights or place a fixture on the map. The app does not record a continuous patrol track on its server. A location used to create a shared inventory asset becomes part of that public asset when an authorized setup device uploads it.

You control camera, microphone, and photo access through your device permissions and file picker. Community-connected devices upload incident attachments through inspection sync as described above. Reference media added through connected inventory setup is uploaded as described above. Media may contain identifying details and embedded metadata; avoid including information you do not want the intended recipients to receive.

Paired Apple Watch

The paired Apple Watch companion receives the assigned lighting inventory and active inspection context from its paired iPhone. It uses foreground location and compass readings for approximate nearby-light guidance. Watch outage entries are queued locally and transferred to the paired phone for saving in its inspection; community-connected phones then synchronize them as described above. The Watch does not receive community connection credentials or incident photos.

Network services

Cloudflare hosts the website and shared inventory service. The patrol map requests detailed map tiles from OpenStreetMap when available, with saved community geometry as a fallback when connectivity or tile loading fails. Public map reference data may be requested from ArcGIS services. Network providers receive information needed to handle requests, such as an IP address, requested resource, and request timing. A map tile request reveals the map area being viewed; that can correspond to your location when following your position.

See Cloudflare’s privacy policy, OpenStreetMap Foundation’s privacy policy, and Esri’s privacy information for their practices. The app has no advertising or third-party behavioral analytics SDK and does not use your data for cross-app advertising tracking.

Optional product analytics

If you enable Share usage and diagnostics in App information, the app sends fixed feature-use events, error counts, timing ranges, GPS accuracy ranges, platform, screen-size class, appearance, and app version to our Cloudflare service. These measurements help us understand feature use, reliability and performance. They do not include exact coordinates, search text, report content, photos, names or credentials. Operational location and media data described above are separate from these measurements.

Events are aggregated by day. The owner dashboard shows a 90-day window; older aggregate rows are removed when the next batch is received. Random batch identifiers become eligible for cleanup after 24 hours and are not device identifiers. An hourly keyed network-address digest limits abusive requests and becomes eligible for cleanup after the hour. Expired batch and rate-limit records are removed on the next received batch; the analytics tables do not store raw IP addresses. Cloudflare still processes network requests as described above. No analytics are sent until you enable this setting. Turning it off clears unsent events and stops new collection; a request already sent may finish. Aggregated measurements cannot be attributed back to a specific worker for individual deletion. The owner dashboard requires a separate private credential. Counts are event totals, not verified unique users or complete business records.

Storage, retention, and deletion

Local reports remain until you remove them, clear the app’s storage, or delete the app. Browser storage can also be removed by the browser or operating system. Exported files, backups, and copies you send to recipients remain wherever you save or send them. Removing the app does not delete those copies or public shared inventory.

Shared inventory is kept to support future inspections; it has no automatic expiry. Contact the support email above to request correction or removal of shared content you provided. Provider logs follow the relevant provider’s retention practices. Disconnecting inventory setup stops future synchronization from that connection; an upload already sent may still finish.

Support and your choices

If you email support, we receive your email address and what you send so we can respond. You can deny or revoke device permissions, use the map without following your location, choose what to attach, unlink the community, and decide when to submit report emails. There is no individual account to delete in this release. Contact us about data access, correction, or deletion requests.

Policy updates

We will update this policy when the app’s practices change and show the effective date here.