Tabulia — Privacy Policy
Applies to: Tabulia Desktop (Windows) and the Tabulia app (Android). One policy for both.
Last updated: 20 September 2026
Tabulia searches the documents that are already on your device. This policy says, in plain words, what stays on your device, what leaves it, when it leaves, who receives it and how long anyone keeps it. Where Tabulia uses a Lumineus account, the Lumineus Privacy Policy applies to that account as well; this policy covers what the app itself does.
1. Who is responsible
The data controller is Aeonloom, Copenhagen, Denmark, which also operates Lumineus.
For any privacy question, or to exercise your rights, use the contact form at https://lumineus.study/contact/. We publish no email address; the form reaches us and we can reply through it.
2. The short version
- Your documents are never uploaded by Tabulia on its own. Indexing, reading, keyword search, Meaning search and (where the model is installed) answers written on your device all happen offline, on your machine.
- There are exactly three situations in which any part of your own documents leaves your device, and each one is something you ask for at that moment: an answer you choose to have composed online, a page you choose to publish, and the filing sync, which carries encrypted names and notes the server cannot read.
- Tabulia contains no analytics SDK, no crash reporter, no advertising identifier and no third-party tracker. It does not read your contacts, your location or your accounts.
- The app can be used entirely offline and with no account at all.
3. What stays on your device
Tabulia keeps a library index in its own private application folder:
| Where | Path |
|---|---|
| Windows | %APPDATA%\Aeonloom\tabulia\tabulia-index.db |
| Android | the app's private storage (removed when you uninstall the app) |
The index holds: the text extracted from your files (including text recovered by OCR from scans and images), page images and thumbnails used for the reader, the numerical representations ("embeddings") used for Meaning search, file names and locations, your categories and tags, your notes, your search history and the items and answers you saved.
Also on your device: the AI model files you download (in a folder you choose), and — in the operating system's own secure storage (Windows Credential Manager / Android Keystore) — your Lumineus device token and your filing key, if you have created one.
Nobody but you can read any of this. It is not sent anywhere as part of ordinary use, and it is not backed up to any service of ours.
Removing it. Uninstalling the Android app removes everything above. On Windows the uninstaller removes the program and deliberately leaves your library in place; delete %APPDATA%\Aeonloom\tabulia by hand if you want the index gone too.
4. What leaves your device
Nothing in this section happens unless the relevant feature is used. The app works offline; a network failure is treated as ordinary, not as an error.
| # | When | What is sent | To |
|---|---|---|---|
| 1 | You search the Lumineus library from inside the app | Your question, the search mode, a session cookie, and your IP address as part of the connection | Lumineus (our server) |
| 2 | You choose Online for an answer about your own files | Your question, and a small number of passages — each with the file's name, its page number and the passage text | Lumineus, which passes question and passages to the AI provider |
| 3 | You sign in to a Lumineus account | Your sign-in happens in your browser on lumineus.study; the app receives a device token. The name you give the device is stored with it | Lumineus |
| 4 | The app checks your subscription (at launch, when signed in) | Your device token | Lumineus |
| 5 | You sync saved items and history (signed in) | Saved sources, saved answers and search history that came from the Lumineus library only | Lumineus |
| 6 | You sync your filing (signed in) | Encrypted category names and note bodies, file fingerprints, the structure (parents, order, tag groups) and timestamps | Lumineus, which cannot read the encrypted parts |
| 7 | You transfer your filing key to another device or to the browser | A wrapped (encrypted) copy of the key, briefly | Lumineus, which cannot open it |
| 8 | You publish an answer as a shared page (full version) | The question, the answer and the passages it quotes, including the file names — exactly as the app shows you before you confirm | Lumineus, and then anyone holding the link |
| 9 | You download an AI model | The request for the file | download.lumineus.study, served by our CDN provider |
| 10 | You press Check for updates | The request for the version manifest | Lumineus |
| 11 | Android only: you dictate a question and your phone has no offline speech model for your language | The recording of what you say — only after you agree, and you are asked again every time | Your phone's speech service (Google) |
| 12 | Android only: OCR of images and scans | Technical metrics about the library's own performance. Never your images or the recognised text | Google (ML Kit) |
Each of these is described below.
4.1 Searching the Lumineus library (1)
The app can search Lumineus's public-domain library beside your own files. Your question and the chosen mode are sent to our server; as with any web request, our server sees your IP address. A session cookie is kept for the life of the app session so that the free preview allowance is counted honestly.
What we keep. We record that a search happened, with the question text, for up to 90 days, after which the text is deleted and only the counts remain. To count visitors without storing addresses we keep a keyed, daily-changing fingerprint of the IP address, which is removed on the same 90-day schedule. Standard web server logs (which do contain IP addresses) are kept for 14 days.
4.2 An answer composed online, over your own files (2)
When results from your own files are on screen you can ask for an answer. You are offered two options and the choice is the consent — it is made again for every question:
- On this device — nothing leaves your machine (requires the downloaded answer model).
- Online — the app tells you how many passages would be sent and where, before you choose.
If you choose Online, the app sends your question and up to eight passages (each up to about 4,000 characters) together with the name of the file each came from and its page number. Our server passes the question and those passages to our AI provider, Mistral AI, whose processing takes place in the EU (France), and streams the answer back.
The passages are not stored — not by us, and not as part of any corpus. The question is recorded as a search event, on the same 90-day basis as §4.1. Please bear in mind that a question can itself be revealing; if that matters for a particular document, use the on-device answer instead.
If you are not signed in, a randomly generated install identifier is sent with the request so that the free daily allowance can be counted. It is created by the app, contains nothing about you or your device, is not an advertising or hardware identifier, and changes if you clear the app's data. Hourly and daily limits per IP address also apply to unsigned-in use.
4.3 Signing in, and your subscription (3, 4)
Tabulia has no password of its own and no purchase inside the app. Signing in opens your browser at lumineus.study, where you sign in to your Lumineus account and approve this device; the app receives a device token, which is stored in the operating system's secure storage. The app never sees your password.
The device label is whatever you type (it defaults to "Tabulia") and is shown on your account page so you can recognise and revoke a device. The account's email address is stored on the device so the app can show you who is signed in.
While you are signed in, the app asks our server at launch whether the account is still entitled to the full version. A successful answer is honoured for up to 30 days offline. Signing out deletes the token, the email address, the entitlement and the sync positions from the device, and asks the server to forget this device.
4.4 Saved items and history (5)
Syncing your collection covers only material that came from the Lumineus library — saved sources, saved answers and the searches you ran against it. Questions you asked about your own files, and answers composed from them, are kept on the device and are never included in this sync.
4.5 Filing sync (6, 7)
If you sync your filing, your other devices can see the same categories, tags and notes. What our server receives is deliberately unreadable to it:
- Category names and note bodies are encrypted on your device with a key that is generated on your device and never sent to us. The label a note is filed under travels inside the same encrypted body.
- A file is identified only by a fingerprint — a one-way digest of its first 64 KB and its exact size. File names and file paths are never part of this sync. A fingerprint cannot be turned back into the file; someone who already holds an identical file could confirm that you also have it.
- Category and tag names travel additionally as a keyed hash, so that two devices can agree two names are the same one without us being able to read or guess them.
- The structure does travel in readable form: which category sits under which, their order, which of the three built-in tag groups a tag belongs to, a note's page and position on the page, and timestamps.
To put the key on a second device (or in your browser, to read notes there), the app can leave a wrapped copy on our server for a short time. It is encrypted, single-use and short-lived, and without the ceremony or the code you carry by hand it is meaningless to us.
If you lose the key, the names and notes that were encrypted with it cannot be recovered by anyone, including us. That is the property this design buys.
4.6 Pages you publish (8)
Sharing an answer from your own files is part of the full version. Before anything is published, the app shows you the finished page — the question, the answer and every passage, with the file names as they will appear. Only if you confirm is the page created, at an unguessable link that anyone holding it can open without an account.
- A page built from your own files is removed 60 days after it was created and does not extend when read. Pages built from the Lumineus library last 30 days (free account) or 60 days from creation or last reading (full version).
- You can end any page immediately from Your shared pages on lumineus.study; its content is then deleted from the live service at once and the link stops working for everyone.
- We keep a minimal record afterwards — which account made it, when, and a one-way fingerprint of what it held — so a later complaint can be answered.
- Anyone can report a page using the link on it. A reported page's content may be kept for up to 90 days while the report is handled.
- Routine database backups may still contain a copy for a while: up to 14 days on the server, up to 90 days offsite, and one snapshot per month for up to 12 months. Those copies are not reachable through the site.
4.7 Downloads and update checks (9, 10)
Model files are served from download.lumineus.study by our CDN provider, whose request logs (including your IP address) are kept by the provider for a short time; from them we count downloads per file, per day and per country and keep no IP address. The update manifest is fetched from lumineus.study only when you press Check for updates; the app does not check by itself. Downloads are refused on a connection your device reports as metered until you say otherwise.
4.8 Speech (11) and reading aloud
Reading aloud uses your system's own voice and is entirely local on both platforms; Tabulia does not ask for network voices.
Dictation exists on Android only. The app asks for your phone's offline recogniser first; if your phone has one for your language, nothing leaves the phone. Only where there is no offline model are you asked — in those words, for that one use — whether the recording of your question may be sent to the system's speech service (Google on Android). You are asked again every time, and only what you say into the search box would be sent. Tabulia Desktop draws no microphone at all.
4.9 Text recognition (12)
Scans and images are read on your device: with Google's ML Kit on Android, and with Tesseract (running locally on your machine) on Windows. ML Kit does its recognition on the device; according to Google it may send Google technical data about the library's own performance and use, and Google states that the input — your images and the resulting text — is not sent to Google servers.
5. Why we may use this, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the online features you use — library search, online answers, sync, sharing | Performance of a contract |
| Keeping your account and your devices in order, and honouring your subscription | Performance of a contract |
| Preventing abuse, enforcing the free allowance, keeping the service available | Legitimate interest |
| Understanding usage in aggregate and improving the product | Legitimate interest |
| Sending a recording to your phone's speech service when no offline model exists | Your consent, asked per use |
| Sending passages from your own documents to be composed into an answer, or publishing a page | Your consent, given per answer and per page |
| Acting on a report about a published page | Legitimate interest, and our legal obligation as a host |
You can withdraw consent simply by not choosing those options again; the app never remembers a consent for future use.
6. Who else is involved
| Provider | Purpose | Region |
|---|---|---|
| netcup | Hosting of the Lumineus service | EU (Germany) |
| Scaleway | Backups and transactional email | EU (France) |
| Bunny (BunnyWay d.o.o.) | Delivery of app and model downloads | EU (Slovenia; files served from Germany) |
| Mistral AI | Writing answers from the question and passages sent to it | EU (France) |
| Android only: the system speech service, per use and only if you agree; ML Kit technical metrics | Outside the EU/EEA, under Google's own terms |
Tabulia itself takes no payment. A Lumineus subscription is bought on lumineus.study; when that becomes possible, the payment provider will be named in the Lumineus Privacy Policy and here.
We do not sell your data and we use no advertising trackers.
7. How long things are kept
| What | How long |
|---|---|
| Everything in your device's index | Until you delete it or uninstall the app — it is not on our servers at all |
| The question text of a search or an online answer | Up to 90 days, then deleted; counts remain |
| Daily keyed IP fingerprint (counting visitors) | Up to 90 days, then deleted |
| Passages sent for an online answer | Not stored |
| Account data, device tokens and labels | Until you sign the device out or close the account |
| Synced saved items, history, categories, tags and encrypted notes | Until you delete them or close the account |
| A wrapped filing key left for another device | Short-lived and single-use |
| Published pages | 30 or 60 days — see §4.6 |
| A reported page's content | Up to 90 days after removal |
| Web server logs (contain IP addresses) | 14 days |
| Download counts | Per file, day and country; no IP address kept |
| Database backups | Up to 14 days on the server, 90 days offsite, one monthly snapshot for up to 12 months |
8. Your rights
You have the right to access, correct, erase, restrict or object to the processing of your personal data, and the right to data portability. In practice:
- Data held on your device is yours directly: delete notes, categories, history and saved items in the app, or remove the index folder.
- For data held by us — your account, synced items, published pages — use the contact form at https://lumineus.study/contact/, or your account pages on lumineus.study where the controls exist (revoking a device, ending a shared page).
- You may lodge a complaint with your local data-protection supervisory authority. In Denmark this is Datatilsynet.
9. Security
Connections to our servers use HTTPS. Device tokens and your filing key are held in the operating system's secure storage. Category names and note bodies are encrypted on your device before they are sent, with a key we never receive. Published pages sit behind unguessable links and expire on their own.
No system is perfect: an index on a device that other people can use is readable by them, so protect your device the way you would protect the documents themselves.
10. Changes to this policy
We may update this policy. Material changes will be announced in the app or on lumineus.study, and the date at the top will change. Questions: https://lumineus.study/contact/.
Tabulia download page · Tabulia Terms of Use · Lumineus Privacy Policy · Lumineus Terms · Contact