Privacy Policy
Version 2026-10-06-draft-legal-review · Last updated
This Privacy Policy explains how RAY APP Ltd (“DeeLumo”, “we”, “us”) collects, uses, shares and keeps personal data when you visit deelumo.com, talk to Dee by voice on the website, or use Dee in Telegram. Dee is an AI mental fitness assistant. It is software, not a person.
Questions or requests: team@deelumo.com.
1. Who we are
RAY APP Ltd, a company registered in England and Wales, company number 15352097, 63-66 5th Floor, Suite 23 Hatton Garden, London EC1N 8LE, United Kingdom. RAY APP Ltd decides how and why your personal data is used (under UK data protection law, it is the “controller”).
2. What we collect
2.1 Website voice call
- Your voice, while the call is live. It is streamed to OpenAI to run the conversation and to turn speech into text. We do not record or store the audio of the call.
- A written transcript of the call (what you said and what Dee said) and technical events of the call (for example when it started and ended, connection state, the settings it ran with).
- A random identifier created by your browser (see section 8), which links the call to the next step if you continue in Telegram or pay, and which also counts how many calls you start.
- Call-limit records: when a call starts, a hashed (not readable) form of your IP address, the browser identifier and the time. We use them only to prevent abuse and to control our costs (a limited number of calls per person per day), and delete them after 2 days.
- Your consent record: when you tick the consent box before a call, we store the version of the consent text, the time you ticked it, the browser identifier and the call identifier.
- Your email address, if you choose to leave it after the call.
2.2 Dee in Telegram
- Your Telegram account identifier and the basic profile details Telegram passes to bots, plus settings such as your language and time zone.
- Your messages and Dee’s replies. Voice notes are sent to OpenAI to be turned into text; we keep the text, not the audio.
- Memory between conversations: notes Dee keeps so it can continue where you left off (for example your name, what you are working on, the step you agreed to try, and reminders you asked for).
- If you came from a website call: a short carry-over from that call (such as your name, your request and a quote of what you said), which becomes part of your Telegram memory.
2.3 Payment
Payments are processed by Stripe. We do not receive or store your full card number. Our billing service receives your email address, the status of your subscription and payment events, and uses them to turn your access on or off.
2.4 Model traces
When Dee answers in Telegram, the system records a technical trace of that step (the input the AI model received, including recent conversation and memory, and its output). We use traces to find and fix errors.
2.5 Email correspondence
If you write to us, we keep your email and our reply in our mailbox.
3. How we use it
- To run the voice call and conversations in Telegram, and to remember context between them.
- To move you from a website call to Telegram, and to give you access after payment.
- To process your subscription, payments, cancellations and refunds.
- To send service emails, and to answer your requests and complaints.
- To keep the service safe: to detect signs of crisis and point you to human help, and to prevent abuse (including limiting the number of website calls per person per day, which also controls our costs).
- To keep a record that you gave consent before a website call.
- To find and fix errors and to improve how Dee works.
We do not sell your personal data. We do not use your conversations for advertising, and we do not show ads.
4. Who on our team can see your conversations
Your conversations are stored so that Dee can remember them. Our team opens a person’s conversation only in these cases:
- In Telegram: when review is turned on for that account (our team can turn on review for specific accounts, our own and people testing the product with us, to improve it; it is off by default); when you send
/reportto complain about a reply, until the complaint is closed; or when a message shows a sign of crisis. - Website voice calls: only when the call shows a sign of crisis.
Automatic notes to a private Telegram group of our team are sent only for Telegram conversations: for each turn when review is on for that account, and for a turn that shows a sign of crisis. When you send /report, the group receives only the complaint number. Website calls are never forwarded anywhere; the team may open a stored website call only when it shows a sign of crisis. Read access to the stored call log requires a separate access token.
5. Service providers we share data with
We share personal data only with providers that process it on our behalf to run the service, and when the law requires it.
- OpenAI (United States): AI models for chat, voice conversation and speech-to-text.
- Railway: hosting of the website and of Dee.
- Google Cloud SQL: the database where conversations, memory and call transcripts are stored.
- Stripe: payment processing and the customer portal for managing your subscription.
- Firebase and Google Cloud: our billing service, which connects Stripe payments to your access.
- Brevo: email list and service emails.
- Zoho: our team mailbox.
- Telegram: the messaging channel where you talk to Dee, and where our team receives the notes described in section 4. Telegram’s own privacy policy applies to your use of Telegram.
We may also disclose data if we must by law, to protect someone’s life or safety, or as part of a sale or reorganisation of our business (in which case this policy continues to apply to your data).
6. How long we keep data
| Data | How long |
|---|---|
| Audio of website calls and Telegram voice notes | Not stored by us |
| Website call transcripts and call events (including an email left after the call) | 30 days, then deleted automatically |
| Call-limit records (hashed IP address, browser identifier, time a call started) | 2 days, then deleted automatically |
| Consent records (consent text version, time, browser and call identifiers) | As long as we may need to prove that you gave consent |
| Model traces | 30 days, then deleted automatically |
| Telegram conversation history, memory and settings | While your account is active, or until you ask us to delete them |
| Email address linked to your access, and your contact in Brevo | While your account is active, or until you ask us to delete it or unsubscribe |
| Notes delivered to our team’s Telegram group (section 4) | Until deleted by the team, or on your deletion request |
| Payment and invoice records | As long as tax and accounting law requires (in the UK, usually six years) |
Browser identifier deelumo_sid | On your device until you clear your browser’s site data |
7. Deleting your data and your other choices
To delete your data, email team@deelumo.com from the address you used with us, or tell us your Telegram username. We delete your Telegram conversation history and memory, your website call transcripts, your reminders, and your contact in Brevo. We keep only what the law requires us to keep (such as payment records). We reply within 30 days.
You can also ask for a copy of your data, ask us to correct it, or unsubscribe from emails using the link in any email.
8. Cookies and browser storage
The website stores one random identifier, deelumo_sid, in your browser’s local storage. It is used only to run the voice call, to count calls for the daily call limit, to link your consent record to the call, and to carry you over to Telegram or to your access after payment. It does not contain your name or email. We do not use analytics or advertising cookies. Stripe sets its own cookies on its checkout and portal pages, under Stripe’s privacy policy.
9. Consumer Health Data
Our Consumer Health Data Policy (Washington My Health My Data Act, Nevada SB 370, Connecticut and similar laws) is a separate page: Consumer Health Data Policy. It describes what health-related data we collect, why, who we share it with, how you consent, and how to use your rights.
10. Privacy rights in US states
Depending on where you live, state law (for example California, Colorado, Connecticut, Virginia, Texas, Oregon and others) may give you the right to know what personal data we hold, get a copy, correct it, delete it, and opt out of its sale, targeted advertising or profiling with significant effects. We do not sell personal data, we do not use it for targeted advertising, and we do not make decisions about you that have legal or similarly significant effects by automated means. We honour these requests for every user, wherever they live. Send them to team@deelumo.com; the appeal process described in the Consumer Health Data Policy applies. We will not treat you differently for using your rights.
11. If UK or EU data protection law applies to you
RAY APP Ltd is the controller. We rely on these legal bases:
- Contract (Article 6(1)(b) UK GDPR): to provide the calls and conversations, your access and your subscription.
- Explicit consent (Article 6(1)(a) and Article 9(2)(a)): for information about your health and well-being that you share with Dee. On the website you give it with a separate checkbox before the call, and we keep a record of it. You can withdraw consent at any time; this does not affect what we did before.
- Legitimate interests (Article 6(1)(f)): security, preventing abuse, fixing errors and improving the service.
- Vital interests (Article 6(1)(d) and Article 9(2)(c)): in a crisis, where needed to protect your life.
- Legal obligation (Article 6(1)(c)): payment records and answers to authorities.
You have the right to access, correct, delete, restrict, and port your data, to object to processing based on legitimate interests, and to withdraw consent. Contact team@deelumo.com; we reply within one month. You can also complain to the UK Information Commissioner’s Office (ico.org.uk, 0303 123 1113) or to the data protection authority where you live.
12. International transfers
We are based in the United Kingdom and our service providers process data in the United States, the European Union and other countries. For example, conversations are processed by OpenAI in the United States. Where UK or EU law applies, we rely on adequacy regulations (such as the UK-US data bridge for certified companies) or on standard contractual clauses with the UK Addendum.
13. Security
Data travels over encrypted connections (HTTPS). The database is hosted on Google Cloud SQL. Access to production data is limited to our team and follows the rules in section 4. No system is completely secure; if a breach affects your data, we will tell you and the authorities as the law requires.
14. Children
DeeLumo is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has used the service, write to team@deelumo.com and we will delete their data.
15. Changes to this policy
We may update this policy. The date at the top shows the latest version. If a change is material, we will tell you in Telegram or by email before it takes effect. We will ask for your consent again where the law requires it.
16. Contact
RAY APP Ltd, 63-66 5th Floor, Suite 23 Hatton Garden, London EC1N 8LE, United Kingdom. Company number 15352097. Email: team@deelumo.com.