The short version
- LumaFlash is a flashlight utility. The torch, screen light, SOS and strobe all run entirely on your device and work offline.
- Flash alerts are optional. To blink your LED when a call or message arrives, the app needs permission to be told that an alert happened. You enable this yourself, and you can leave it off.
- When flash alerts are on, the app reacts to the fact that a notification or call arrived. It does not upload, store or transmit the content of your messages or calls.
- We do not ask for your contacts, your call log, or precise GPS location.
- The app is free and supported by ads. We use Google AdMob, Google Firebase, Adjust, and the Meta (Facebook) SDK, which process limited device and advertising identifiers.
- You can control personalized ads through the in-app consent prompt (UMP) and your Android Ads settings.
- The app has no in-app purchases or subscriptions.
1. Scope
This Privacy Policy explains how the LumaFlash application — published on Google Play as "Flashlight : Flash Alert & LED" ("the App", "we", "us", or "our") — handles information when you use it. By installing or using the App, you agree to the practices described here. If you do not agree, please do not use the App.
LumaFlash is a utility app that controls your device's LED flash and display to provide light. Its core lighting features do not require an internet connection and do not involve any account or sign-in.
2. Information we process
Your settings
Your preferences — brightness level, chosen screen-light color, strobe speed, SOS settings, and which apps may trigger a flash alert — are stored locally on your device so the App remembers them. They are not uploaded to us.
Notification and call events (only if you enable flash alerts)
If you turn on flash alerts, the App is notified by Android when an incoming call or a notification occurs, so that it can blink the LED. The App uses only what it needs to decide whether to flash — principally the identity of the app that produced the notification, so it can honour the app filter you configured. This information is processed in memory, on your device, at the moment of the alert. It is not written to our servers, not retained after the flash, and not shared with any third party. See Section 4.
Device & technical data
Through the third-party SDKs listed below, the App processes standard mobile technical data such as device model, operating-system version, language and country, app version, coarse (IP-derived) region, app-instance identifiers, and the Google Advertising ID. This supports analytics, crash reporting, attribution and advertising.
Advertising data
The free version shows ads. Our ad partners may process your Advertising ID, coarse location derived from your IP address, and ad-interaction events to deliver and measure ads. See Third-party SDKs and Your rights & choices.
Support communications
If you email us, we receive your email address and the contents of your message so we can respond.
3. Permissions we request
- Camera flash / torch control — the App controls the LED flash unit through Android's camera service to switch the torch on and off. This is used only to operate the light. The App does not open a camera preview, and does not take photos or record video.
- Notification access (optional) — required only if you enable flash alerts for messaging and other apps, so Android can tell the App that a notification arrived. Grant it in Android Settings → Notifications → Device & app notifications. You may revoke it at any time.
- Phone state (optional) — required only if you enable flash alerts for incoming calls, so the App knows when the phone is ringing. It is not used to read your call log or to place calls.
- Keep screen awake — so the screen light and strobe stay on while you are using them.
- Internet / Network state — to load ads and run analytics/attribution. All lighting features also work offline.
- Advertising ID (
com.google.android.gms.permission.AD_ID) — used by our ad and attribution SDKs to deliver and measure advertising. Required to declare on Android 13+.
- Post notifications (optional, Android 13+) — to show the App's own controls or status while a light is running.
- Vibrate — optional haptic feedback when toggling a light.
Every optional permission above is requested only at the moment you switch on the feature that needs it. Declining leaves that one feature disabled; the flashlight, screen light, SOS and strobe continue to work.
4. Flash alerts explained
Because notification access is a sensitive permission, we want to be precise about it.
- Why it is needed: Android does not let an app know that a call or message arrived unless you explicitly grant access. Without it, the LED cannot blink on alerts — there is no alternative mechanism.
- What is used: the event that a notification occurred and which app posted it, so the App can apply the per-app filter you set and blink accordingly.
- What is not used: we do not read, log, store, index or transmit the body of your messages, sender names, phone numbers, or any attachment.
- Where it happens: entirely on your device, in memory, for the duration of the alert. Nothing about the notification leaves your phone.
- Turning it off: disable flash alerts inside the App, or revoke notification access in Android Settings. Either one stops this processing immediately.
5. Third-party SDKs
The App embeds the following third-party software development kits. Each operator processes data as an independent controller or processor under its own privacy policy. None of them receives your notification or call data.
Google Firebase
Operator: Google LLC
Analytics, Crashlytics (crash reporting), Cloud Messaging (notifications) and Remote Config. Data processed: app-instance ID, device model, OS version, language, country, screen views, anonymized usage events, and crash stack traces.
Privacy: firebase.google.com/support/privacy
Google AdMob
Operator: Google LLC
Serves ads in the free version. Data processed: Google Advertising ID, coarse IP-derived location, and ad-interaction events. Personalized vs. non-personalized ads depend on the consent you give through the in-app User Messaging Platform (UMP) prompt.
Privacy: policies.google.com/technologies/ads
Adjust
Operator: Adjust GmbH (an AppLovin company)
Install attribution and fraud prevention — tells us which campaign led to an install so we can measure marketing. Data processed: Advertising ID, hashed device fingerprint, install timestamp, and conversion events.
Privacy: adjust.com/terms/privacy-policy
Meta (Facebook) SDK
Operator: Meta Platforms, Inc.
Ad attribution and measurement for Meta advertising campaigns. Data processed: Advertising ID, app install/open events, and conversion events. This SDK is not used for Facebook login and does not access your Facebook profile or friends.
Privacy: facebook.com/about/privacy
Your choices regarding these SDKs
- Ad consent (UMP): in regions where it applies (e.g. EEA, UK), an in-app consent prompt lets you accept or decline personalized ads. You can reset this choice by clearing app data.
- Reset / delete your Advertising ID: Android Settings → Privacy → Ads lets you reset the Advertising ID or opt out of ad personalization entirely.
- Withdraw consent: email us (see Contact) to request that we stop processing data associated with your device where legally applicable.
6. What we do not collect
- We do not read, store or upload the content of your SMS, messages or notifications.
- We do not access your contacts or address book.
- We do not read your call log, and the App cannot place or answer calls.
- We do not collect precise GPS location.
- We do not take photos, record video, or use your microphone. Camera access is used solely to switch the LED torch on and off.
- We do not collect payment-card data — the App has no in-app purchases.
- We do not sell or rent your personal data to data brokers.
Because the App is ad-supported, the advertising and attribution partners named above necessarily receive the limited identifiers described in Section 5. We do not consider this "selling" data, but some laws (e.g. CCPA) may treat ad-related sharing as a "sale" or "sharing" — see Your rights & choices.
7. How we use information
- To operate the flashlight, screen light, colors, SOS signal and strobe.
- To blink your LED when a call or notification arrives, if you enabled flash alerts.
- To remember your settings between sessions.
- To display and measure advertising in the free version.
- To understand aggregate usage and improve features and stability.
- To diagnose crashes and fix bugs.
- To measure marketing campaign performance and prevent install fraud.
- To respond to your support requests.
- To comply with legal obligations and enforce our Terms.
8. Sharing & third parties
We share data only as described in this policy, with:
- Google — Play distribution, Firebase (analytics, crash, messaging) and AdMob (advertising).
- Adjust — install attribution and fraud prevention.
- Meta Platforms — ad attribution and measurement.
- Legal & safety — authorities where required by law, or to protect rights, safety and the integrity of the App.
Notification, call and settings data described in Sections 2 and 4 is never included in any of this sharing.
9. Data retention
- Notification / call events: not retained — processed in memory and discarded once the flash completes.
- Your settings: kept on your device until you change them, clear app data, or uninstall.
- Firebase Analytics: up to 14 months (Google default).
- Firebase Crashlytics: individual crash records up to 90 days.
- Adjust: up to 24 months.
- Meta SDK: approximately 2 years, per Meta's policies.
- AdMob: per Google's ad-platform defaults.
- Support emails: up to 24 months.
10. Your rights & choices
Depending on where you live (e.g. under the EU/UK GDPR or California's CCPA/CPRA), you may have the right to access, correct, delete or port your data, and to opt out of personalized advertising and "cross-context behavioral advertising".
- Opt out of personalized ads: decline the in-app consent prompt and/or use Android Settings → Privacy → Ads.
- Stop flash-alert processing: disable flash alerts in the App or revoke notification access in Android Settings.
- Delete on-device data: clear the App's storage or uninstall the App.
- Request access or deletion of data held by us or our partners: email devapp.aero+lumaflash@gmail.com. We aim to respond within 30 days.
We will not discriminate against you for exercising these rights.
11. Children's privacy
The App is not directed to children under 13 (or the minimum age of digital consent in your country). We do not knowingly collect personal information from children. The advertising and analytics SDKs we use are not configured for child-directed treatment. If you believe a child has provided us information, contact us and we will delete it.
12. International users
The App is operated with infrastructure and partners that may process data in the United States, the European Union and other countries. Where data is transferred internationally, our partners rely on safeguards such as the EU Standard Contractual Clauses (or equivalent mechanisms).
13. Security
We rely on Android's application sandbox and scoped storage to isolate App data, and our SDK partners use HTTPS/TLS for data in transit. Notification and call events never leave the device, which removes an entire class of transmission risk. No method of transmission or storage is 100% secure, but we take reasonable measures to protect information.
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, noted in the App or the Google Play release notes. Continued use of the App after an update constitutes acceptance of the revised policy.
Questions about this policy or your data? Reach us at devapp.aero+lumaflash@gmail.com or visit our Support page.