Lumina Sanctuary

Legal

Privacy policy

Applies to the Lumina Sanctuary desktop application and this website · Version 1.8.0 · Last updated 31 August 2026

Lumina Sanctuary is desktop software. It has no user accounts, no sign-in and no cloud service behind it. There is no server that holds your congregation's data, because the software was built so that one would not be needed.

1. What the software stores, and where

Everything you create in the app is written to a local database and local files inside your own Windows user profile, under %APPDATA% on the machine where it is installed. That includes:

  • Saved services and orders of service, including planned times and item notes
  • Songs you add, arrangements, and your CCLI licence number
  • Operator notes, overlay presets, ticker and notice text
  • Settings: church name, logo, giving URL, display arrangement, remote port and access code
  • References to your media files, and the trim, volume and loop choices saved against them
  • Any recording of a service you ask the app to keep, written to the folder you choose

None of this is transmitted to the publisher. There is no account to attach it to and no sync service to send it through. If you uninstall the app or the machine fails, that data is gone unless you have made a backup from Settings → Maintenance.

2. When the software uses the network

The app can run an entire service with no internet connection. It reaches the network only in these situations, all of which you initiate:

Streaming

When you go live, audio and video are sent to the destinations you configured — YouTube, Facebook, or an RTMP address you entered. What you broadcast is then governed by that platform's own privacy policy and terms, not this one.

YouTube features you connect

Playing a YouTube video, or using features that read details of your broadcast, contacts YouTube's services. If you authorise the app against a YouTube account, the credential that permits it is stored locally on your machine and used only to talk to YouTube on your behalf.

Update checks

The app checks whether a newer version exists and downloads it in the background. As with any download, the server involved may record ordinary technical information such as an IP address and the version being requested. This is not used to identify you or your church, and it is not combined with anything from inside the app.

Phone remotes

Remotes work over your own local network. The phone talks directly to the church computer; the traffic does not leave the building and does not pass through any service of ours. The app records paired devices and their permissions locally so it can remember them.

Outside these cases, the software does not phone home. It does not send your services, songs, notes, media or settings anywhere.

3. Analytics and tracking

The application does not include advertising, third-party tracking, or behavioural analytics that profile how you use it. Nothing you type into it is collected for study.

4. Diagnostic information you choose to send

Error details and log files stay on your machine. If you email a log or a screenshot as part of a support request, you are sending it deliberately, and it is used only to answer that request. Logs can contain the names of your services, songs, media files and church, so read what you are sending if any of it is sensitive.

5. Children

The software is an operator tool for church volunteers and is not directed at children. It collects nothing about anybody, of any age. Note that if you broadcast a service, children present in the room may appear in it — deciding whether that is appropriate, and obtaining any consent required where you are, is your church's responsibility.

6. Your responsibilities as the church

Because the data lives on your computer, your church is the party that controls it. Physical access to the media machine, who is allowed to pair a phone, where backups are stored, and how long recordings are kept are all decisions you make. Under data protection law in your country, the obligations of a data controller are likely to fall on your church rather than on the publisher.

7. This website

This site exists to describe the software and offer the installer. It sets no cookies, runs no analytics, and carries no advertising or tracking script. There is nothing here to sign in to and no form to fill in. Its typefaces are served from this site rather than from Google, so reading a page does not announce you to a third party.

Two companies necessarily see a request. The site is hosted on Cloudflare Pages, which keeps ordinary server logs — an IP address, a page, a time, a browser string — to serve and protect the site, under Cloudflare's own privacy terms. The installer itself is served from GitHub, and the pages ask GitHub which version is current, so your browser contacts github.com when a page loads and again if you download. GitHub counts downloads and keeps its own logs, under its own policy. Neither of those records reaches the publisher as anything but a total.

No profile of any visitor is built, here or anywhere else.

8. Changes and contact

If this policy changes, the date at the top changes with it, and material changes will be noted in the release notes. Questions about privacy go to the address on the contact page.