Tabulia — Privacy Policy
Applies to: Tabulia Desktop (Windows) and the Tabulia app (Android). One policy for both.
Last updated: 3 October 2026
Tabulia searches the documents that are already on your device. This policy says, in plain words, what stays on your device, what leaves it, when it leaves, who receives it and how long anyone keeps it. Where Tabulia uses a Lumineus account, the Lumineus Privacy Policy applies to that account as well; this policy covers what the app itself does.
1. Who is responsible
The data controller is Aeonloom, Copenhagen, Denmark, which also operates Lumineus.
For any privacy question, or to exercise your rights, use the contact form at https://lumineus.study/contact/. We publish no email address; the form reaches us and we can reply through it.
2. The short version
- Your documents are never uploaded by Tabulia on its own. Indexing, reading, keyword search, Meaning search and (where the model is installed) answers written on your device all happen offline, on your machine.
- There are exactly three situations in which any part of your own documents leaves your device, and each one is something you ask for at that moment: an answer you choose to have composed online, a page you choose to publish, and the filing sync, which carries encrypted names and notes the server cannot read.
- Tabulia contains no analytics SDK, no crash reporter, no advertising identifier and no third-party tracker. It does not read your contacts, your location or your accounts.
- To count the day's allowances honestly, the app sends a randomly generated install identifier — never your question when it counts Meaning searches, never your files.
- The app can be used entirely offline and with no account at all; Meaning searches need a moment online to be collected each day (§4.1a).
3. What stays on your device
Tabulia keeps a library index in its own private application folder:
| Where | Path |
|---|---|
| Windows | %APPDATA%\Aeonloom\tabulia\tabulia-index.db |
| Android | the app's private storage (removed when you uninstall the app) |
The index holds: the text extracted from your files (including text recovered by OCR from scans and images), page images and thumbnails used for the reader, the numerical representations ("embeddings") used for Meaning search, file names and locations, your categories and tags, your notes, your search history and the items and answers you saved. It also records when you last used each category and tag, so that — if you hold more than your level allows — the most recently used ones stay active; this record never leaves the device.
Exporting it. Settings → Export notes and saved items writes your notes, saved answers, saved sources and the names of your categories and tags into one Markdown file and hands it to your device's share sheet; where it goes from there is your choice.
Also on your device: the AI model files you download (in a folder you choose), and — in the operating system's own secure storage (Windows Credential Manager / Android Keystore) — your Lumineus device token and your sync key (the key that seals your category names and notes), if you have created one.
Nobody but you can read any of this. It is not sent anywhere as part of ordinary use, and it is not backed up to any service of ours.
Removing it. Uninstalling the Android app removes everything above. On Windows the uninstaller removes the program and deliberately leaves your library in place; delete %APPDATA%\Aeonloom\tabulia by hand if you want the index gone too.
4. What leaves your device
Nothing in this section happens unless the relevant feature is used. The app works offline; a network failure is treated as ordinary, not as an error.
| # | When | What is sent | To |
|---|---|---|---|
| 1 | You search the Lumineus library from inside the app | Your question, the search mode, this install's random identifier, a session cookie, and your IP address as part of the connection | Lumineus (our server) |
| 1a | You use Meaning search without the full version, and the day's searches have to be collected | This install's random identifier, how many searches it asks for, your device token if you are signed in, and your IP address as part of the connection. Never your question, the results or anything from your files | Lumineus |
| 2 | You choose Online for an answer about your own files | Your question, and a small number of passages — each with the file's name, its page number and the passage text | Lumineus, which passes question and passages to the AI provider |
| 3 | You sign in to a Lumineus account | Your sign-in happens in your browser on lumineus.study; the app receives a device token. The name you give the device is stored with it | Lumineus |
| 4 | The app checks your subscription (at launch, when signed in) | Your device token | Lumineus |
| 5 | You sync saved items and history (signed in) | Saved sources, saved answers and search history that came from the Lumineus library only | Lumineus |
| 6 | You sync your filing (signed in) | Encrypted category names and note bodies, file fingerprints, the structure (parents, order, tag groups) and timestamps | Lumineus, which cannot read the encrypted parts |
| 7 | You transfer your sync key to another device or to the browser | A wrapped (encrypted) copy of the key, briefly | Lumineus, which cannot open it |
| 8 | You publish an answer as a shared page (full version) | The question, the answer and the passages it quotes, including the file names — exactly as the app shows you before you confirm | Lumineus, and then anyone holding the link |
| 9 | You download an AI model | The request for the file | download.lumineus.study, served by our CDN provider |
| 10 | You press Check for updates | The request for the version manifest | Lumineus |
| 11 | Android only: you dictate a question and your phone has no offline speech model for your language | The recording of what you say — only after you agree, and you are asked again every time | Your phone's speech service (Google) |
| 12 | Android only: OCR of images and scans | Technical metrics about the library's own performance. Never your images or the recognised text | Google (ML Kit) |
Each of these is described below.
4.1 Searching the Lumineus library (1)
The app can search Lumineus's public-domain library beside your own files. Your question and the chosen mode are sent to our server; as with any web request, our server sees your IP address. This install's random identifier (see §4.2) and a session cookie are sent so that the daily allowance is counted honestly: one allowance per install without an account, and — with a free account — one allowance per account, shared with lumineus.study.
What we keep. We record that a search happened, with the question text, for up to 90 days, after which the text is deleted and only the counts remain. To count visitors without storing addresses we keep a keyed, daily-changing fingerprint of the IP address, which is removed on the same 90-day schedule. Standard web server logs (which do contain IP addresses) are kept for 14 days.
4.1a Counting Meaning searches (1a)
Meaning search runs entirely on your device. What is counted on our server is only how many an install or account has collected that day: the app asks for a few at a time and spends them offline, so clearing the app's data does not reset the day. The request carries the install identifier (and your device token if you are signed in) and a number — nothing about what you search for. The count is kept until the day ends at midnight Central European Time, and is then cleared. With the full version the app does not ask at all.
4.2 An answer composed online, over your own files (2)
When results from your own files are on screen you can ask for an answer. You are offered two options and the choice is the consent — it is made again for every question:
- On this device — nothing leaves your machine (requires the downloaded answer model).
- Online — the app tells you how many passages would be sent and where, before you choose.
If you choose Online, the app sends your question and up to eight passages (each up to about 4,000 characters) together with the name of the file each came from and its page number. Our server passes the question and those passages to our AI provider, Mistral AI, whose processing takes place in the EU (France), and streams the answer back.
The passages are not stored — not by us, and not as part of any corpus. The question is recorded as a search event, on the same 90-day basis as §4.1. Please bear in mind that a question can itself be revealing; if that matters for a particular document, use the on-device answer instead.
If you are not signed in, a randomly generated install identifier is sent with the request so that the daily allowance can be counted — the same allowance as Lumineus searches from this install. It is created by the app, contains nothing about you or your device, is not an advertising or hardware identifier, and changes if you clear the app's data. Hourly and daily limits per IP address also apply to unsigned-in use.
4.3 Signing in, and your subscription (3, 4)
Tabulia has no password of its own and no purchase inside the app. Signing in opens your browser at lumineus.study, where you sign in to your Lumineus account and approve this device; the app receives a device token, which is stored in the operating system's secure storage. The app never sees your password.
The device label is whatever you type (it defaults to "Tabulia") and is shown on your account page so you can recognise and revoke a device. The account's email address is stored on the device so the app can show you who is signed in.
While you are signed in, the app asks our server at launch whether the account is still entitled to the full version. A successful answer is honoured for up to 30 days offline. Signing out deletes the token, the email address, the entitlement and the sync positions from the device, and asks the server to forget this device. Nothing in your library is deleted; what is over the no-account limits is locked until you sign in again (see the Terms of Use §5).
When a subscription ends, the copies of your filing and saved items that we hold to keep your devices in step are kept for 33 days and then deleted from our servers. Your devices keep theirs.
4.4 Saved items and history (5)
Syncing your collection covers only material that came from the Lumineus library — saved sources, saved answers and the searches you ran against it. Questions you asked about your own files, and answers composed from them, are kept on the device and are never included in this sync.
4.5 Filing sync (6, 7)
If you sync your filing, your other devices can see the same categories, tags and notes. What our server receives is deliberately unreadable to it:
- Category names and note bodies are encrypted on your device with a key that is generated on your device and never sent to us. The label a note is filed under travels inside the same encrypted body.
- A file is identified only by a fingerprint — a one-way digest of its first 64 KB and its exact size. File names and file paths are never part of this sync. A fingerprint cannot be turned back into the file; someone who already holds an identical file could confirm that you also have it.
- Category and tag names travel additionally as a keyed hash, so that two devices can agree two names are the same one without us being able to read or guess them.
- The structure does travel in readable form: which category sits under which, their order, which of the three built-in tag groups a tag belongs to, a note's page and position on the page, and timestamps.
To put the key on a second device (or in your browser, to read notes there), the app can leave a wrapped copy on our server for a short time. It is encrypted, single-use and short-lived, and without the ceremony or the code you carry by hand it is meaningless to us.
If you lose the key, the names and notes that were encrypted with it cannot be recovered by anyone, including us. That is the property this design buys.
4.6 Pages you publish (8)
Sharing an answer from your own files is part of the full version. Before anything is published, the app shows you the finished page — the question, the answer and every passage, with the file names as they will appear. Only if you confirm is the page created, at an unguessable link that anyone holding it can open without an account.
- A page built from your own files is removed 60 days after it was created and does not extend when read. Pages built from the Lumineus library last 30 days (free account) or 60 days from creation or last reading (full version).
- You can end any page immediately from Your shared pages on lumineus.study; its content is then deleted from the live service at once and the link stops working for everyone.
- We keep a minimal record afterwards — which account made it, when, and a one-way fingerprint of what it held — so a later complaint can be answered.
- Anyone can report a page using the link on it. A reported page's content may be kept for up to 90 days while the report is handled.
- Routine database backups may still contain a copy for a while: up to 14 days on the server, up to 90 days offsite, and one snapshot per month for up to 12 months. Those copies are not reachable through the site.
4.7 Downloads and update checks (9, 10)
Model files are served from download.lumineus.study by our CDN provider, whose request logs (including your IP address) are kept by the provider for a short time; from them we count downloads per file, per day and per country and keep no IP address. The update manifest is fetched from lumineus.study only when you press Check for updates; the app does not check by itself. Downloads are refused on a connection your device reports as metered until you say otherwise.
4.8 Speech (11) and reading aloud
Reading aloud uses your system's own voice and is entirely local on both platforms; Tabulia does not ask for network voices.
Dictation exists on Android only. The app asks for your phone's offline recogniser first; if your phone has one for your language, nothing leaves the phone. Only where there is no offline model are you asked — in those words, for that one use — whether the recording of your question may be sent to the system's speech service (Google on Android). You are asked again every time, and only what you say into the search box would be sent. Tabulia Desktop draws no microphone at all.
4.9 Text recognition (12)
Scans and images are read on your device: with Google's ML Kit on Android, and with Tesseract (running locally on your machine) on Windows. ML Kit does its recognition on the device; according to Google it may send Google technical data about the library's own performance and use, and Google states that the input — your images and the resulting text — is not sent to Google servers.
5. Why we may use this, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the online features you use — library search, online answers, sync, sharing | Performance of a contract |
| Keeping your account and your devices in order, and honouring your subscription | Performance of a contract |
| Preventing abuse, enforcing the free allowance, keeping the service available | Legitimate interest |
| Understanding usage in aggregate and improving the product | Legitimate interest |
| Counting daily allowances with an install identifier or your account | Legitimate interest (enforcing the free allowance fairly) |
| Sending you a newsletter | Your consent, given separately at sign-up or on your account page, and withdrawable with one click |
| Sending a recording to your phone's speech service when no offline model exists | Your consent, asked per use |
| Sending passages from your own documents to be composed into an answer, or publishing a page | Your consent, given per answer and per page |
| Acting on a report about a published page | Legitimate interest, and our legal obligation as a host |
You can withdraw consent simply by not choosing those options again; the app never remembers a consent for future use.
6. Who else is involved
| Provider | Purpose | Region |
|---|---|---|
| netcup | Hosting of the Lumineus service | EU (Germany) |
| Scaleway | Backups and transactional email | EU (France) |
| Bunny (BunnyWay d.o.o.) | Delivery of app and model downloads | EU (Slovenia; files served from Germany) |
| Mistral AI | Writing answers from the question and passages sent to it | EU (France) |
| Android only: the system speech service, per use and only if you agree; ML Kit technical metrics | Outside the EU/EEA, under Google's own terms |
Tabulia itself takes no payment. A Lumineus subscription is bought on lumineus.study; when that becomes possible, the payment provider will be named in the Lumineus Privacy Policy and here.
We do not sell your data and we use no advertising trackers.
7. How long things are kept
| What | How long |
|---|---|
| Everything in your device's index | Until you delete it or uninstall the app — it is not on our servers at all |
| The question text of a search or an online answer | Up to 90 days, then deleted; counts remain |
| Daily keyed IP fingerprint (counting visitors) | Up to 90 days, then deleted |
| Passages sent for an online answer | Not stored |
| Daily allowance counters (install identifier or account, and a count) | Until the day ends at midnight Central European Time; then cleared |
| Newsletter consent (the sentence you agreed to, and when) | While the account exists — it is the record that the consent was given |
| Account data, device tokens and labels | Until you sign the device out or close the account |
| Synced saved items, history, categories, tags and encrypted notes | Until you delete them or close the account — or 33 days after a subscription ends |
| A wrapped sync key left for another device | Short-lived and single-use |
| Published pages | 30 or 60 days — see §4.6 |
| A reported page's content | Up to 90 days after removal |
| Web server logs (contain IP addresses) | 14 days |
| Download counts | Per file, day and country; no IP address kept |
| Database backups | Up to 14 days on the server, 90 days offsite, one monthly snapshot for up to 12 months |
8. Your rights
You have the right to access, correct, erase, restrict or object to the processing of your personal data, and the right to data portability. In practice:
- Data held on your device is yours directly: delete notes, categories, history and saved items in the app, or remove the index folder.
- For data held by us — your account, synced items, published pages — use the contact form at https://lumineus.study/contact/, or your account pages on lumineus.study where the controls exist (revoking a device, ending a shared page).
- You may lodge a complaint with your local data-protection supervisory authority. In Denmark this is Datatilsynet.
9. Security
Connections to our servers use HTTPS. Device tokens and your sync key are held in the operating system's secure storage. Category names and note bodies are encrypted on your device before they are sent, with a key we never receive. Published pages sit behind unguessable links and expire on their own.
No system is perfect: an index on a device that other people can use is readable by them, so protect your device the way you would protect the documents themselves.
10. Changes to this policy
We may update this policy. Material changes will be announced in the app or on lumineus.study, and the date at the top will change. Questions: https://lumineus.study/contact/.
Tabulia download page · Tabulia Terms of Use · Lumineus Privacy Policy · Lumineus Terms · Contact