Privacy policy
About FlorLume
Updated 9 October 2026. FlorLume is operated by THE COGITOLAB TECHNOLOGY LIMITED. Contact theemansunder764@gmail.com about privacy or your data.
Accounts and bouquets
You can arrange and save free bouquets without signing in. Guest drafts are stored on your device. Signing in through Apple or Google connects your bouquets and purchases to an account. We receive the sign-in identifier and the name or email that the provider shares. We store account-linked bouquets, flower positions, your message or signature, saved images and purchase entitlements to provide syncing and recovery. Your sign-in email is never shown on shared bouquets.
Optional AI suggestions
AI suggestions are optional. Before you ask for a suggestion, we explain the sharing and ask you to agree by submitting the request. Create from feeling sends your words to TypeSafe AI’s Jev model through Vercel AI Gateway. A requested change also sends relevant flower names, positions and which stems should stay in place. We do not send your sign-in email, account name, payment details or saved image to the model. Please leave out private information about yourself or other people. We request zero-data-retention routing for these AI calls. We keep bounded request hashes, usage counts and suggestion results for limits and retry recovery; service error logs do not include your full words. You can arrange by hand without using AI.
Links, photos and sharing
Creating a link makes a frozen image and the message or signature you included available to anyone who has that link. It does not give editing access. You can disable links in your account. Saving an image asks for the platform access needed to add that image or lets you choose a file destination; FlorLume does not read your photo library. The system share sheet sends the image to the destination you choose. Downloaded copies and copies saved by other people are outside our control. Temporary sharing files are cleaned up after 24 hours.
Payments and service providers
Apple and Google process in-app payments. We receive transaction references and purchase or refund status to verify payment, deliver flower styles and recover purchases. We do not receive your full payment-card number or biometric data. Supabase provides account, database and image storage services; Vercel hosts the service and AI gateway. Apple and Google also provide sign-in. These providers process the information necessary for their role and may process it outside your country. FlorLume does not sell your personal information or use it for advertising tracking.
Optional analytics, diagnostics and notifications
With your choice, Google Firebase Analytics helps us understand which features work well, and Firebase Crashlytics helps us diagnose crashes. These services receive app interactions, device and app information, and pseudonymous installation or hashed account identifiers. We do not include your feeling, search words, bouquet title, message, signature, images, sign-in credentials or payment receipts in these reports. Usage and diagnostics are off until you choose, and you can change each in Account. Disabling collection stops new reports; it does not recall reports already sent. Notification permission is separate. If you enable notifications, Firebase Cloud Messaging and Apple or Google use a device token to deliver them; that token is not included in our analytics events. You can change notification permission in system settings. Firebase processes this information under Google’s privacy policy; contact us about access or deletion of existing reports.
Retention and deletion
Account-linked data is kept while you use the service. Deleted bouquets remain in Recently Deleted for 30 days unless you delete them permanently sooner. You can delete your account in Account → Delete account. Account access and shared links stop immediately; your personal information, bouquets and stored images are deleted within 7 days. Known local account copies are removed when deletion is requested. We retain only the payment and refund records necessary for accounting, legal obligations and dispute handling, with personal bouquet text and images removed. Required accounting records may need to be retained for at least seven years. Account deletion cannot recall images you already downloaded or shared.
Your choices and support
You can edit your bouquets, disable a shared link, sign out, revoke Apple or Google access through that provider, or request account deletion. Revoking a sign-in is separate from deleting your FlorLume account. To request access, correction or deletion without the app, contact theemansunder764@gmail.com from your sign-in email and identify FlorLume. We may ask you to verify account ownership; never send a password, payment-card details or a sign-in code by email. Rights and mandatory retention requirements depend on the laws that apply to you.