lumi. Legitimate Interests Assessment — three-part balancing test for service operation and safety monitoring processing under UK GDPR Article 6(1)(f).

lumi.
Legitimate interests assessment
Prepared: May 2026  ·  Controller: lumi. (Sarah-Jane Barton trading as lumi.)  ·  ICO: C1942494
This document records the legitimate interests assessment (LIA) conducted by the data controller for lumi. It covers the two areas where legitimate interests is relied upon as the legal basis for processing under UK GDPR Article 6(1)(f). It is an internal governance document, not a user-facing policy.
Overview — processing activities covered

lumi.'s Privacy Policy relies on legitimate interests as the legal basis for two distinct processing activities:

  • LI-1 — Service operation and improvement: processing journal entry transcripts, AI-generated content, and usage patterns to operate, maintain, and improve the lumi. service
  • LI-2 — Safety monitoring: running automated keyword analysis on entry transcripts to detect signs of distress and surface crisis support resources

Each is assessed separately below using the ICO's three-part balancing test: purpose, necessity, and balance.


LI-1 — Service operation and improvement
Part 1 — Purpose test
Passes
What is the legitimate interest?

To operate a functional personal journalling service: processing voice entry transcripts through AI systems to generate summaries, identify patterns, tag life areas, and maintain a longitudinal record — which is the core value proposition of lumi.

Is the interest genuine?

Yes. Without processing journal content through AI, lumi. cannot function. The service exists to provide AI-assisted reflection — this processing is not incidental, it is the product.

Is the interest legitimate?

Yes. Processing personal data to deliver a service a user has signed up for and actively uses is a well-established legitimate interest recognised by the ICO. It is proportionate, lawful, and not in conflict with data protection principles.

Part 2 — Necessity test
Passes
Is processing necessary to achieve the purpose?

Yes. The AI analysis that produces summaries, tags, intentions, voice profiles, and pattern alerts cannot be performed without access to the transcript content. There is no less privacy-intrusive way to deliver these features.

Could the purpose be achieved without processing, or with less data?

No. A journalling tool that does not process journal content cannot generate meaningful reflections. The data processed is the minimum necessary — transcripts are processed but audio is deleted immediately. Sensitive fields are encrypted at rest. No content appears in application logs.

Part 3 — Balancing test
Passes
Nature of the data

Journal entry transcripts are personal and potentially sensitive — they may contain health information, relationship details, financial circumstances, or emotional content. This is a significant factor that weighs toward the individual's interests.

Reasonable expectations

Users sign up for lumi. explicitly to have their journal entries processed by AI. The AI-powered nature of the service is disclosed prominently in the beta disclaimer, Terms of Service, and AI Disclosure Notice — all of which must be acknowledged before use. There is no reasonable expectation that the service would function without processing their content.

Impact on individuals

The processing is used solely to provide the service back to the same user. Content is not shared, sold, or used for any other purpose. No third party other than the necessary sub-processors (Anthropic, OpenAI, Railway) accesses content. The impact is low beyond what the user has actively chosen by using the service.

Safeguards in place

AES-256-CBC encryption at rest for all sensitive fields. Audio deleted immediately after transcription. No content in application logs. User can delete all data at any time via Settings. Full disclosure of AI processing before first use.

Conclusion

The controller's interest in operating a functional AI journalling service is genuine, necessary, and proportionate. Users have clear reasonable expectations that their content will be processed. Safeguards meaningfully mitigate the privacy impact. The balance falls in favour of the controller's legitimate interest.

Assessment outcome — LI-1

Legitimate interests is an appropriate legal basis for service operation and improvement processing. The three-part test is satisfied. Processing should continue with the safeguards documented above maintained.


LI-2 — Safety monitoring
Part 1 — Purpose test
Passes
What is the legitimate interest?

To protect user wellbeing by running an automated keyword check on entry transcripts before AI processing, and surfacing crisis support resources if signals of significant distress are detected.

Is the interest genuine?

Yes. lumi. handles emotionally sensitive material in a private, often unsupervised context. Users may record entries during periods of significant distress. The safety monitoring system exists specifically to ensure users are not left without signposting to support in those moments.

Is the interest legitimate?

Yes — and unusually, this legitimate interest aligns directly with the interests of the individual being protected. The processing exists to benefit the user, not to extract value from them. The ICO recognises protecting individuals from harm as a legitimate interest even where it involves processing sensitive content.

Part 2 — Necessity test
Passes
Is processing necessary to achieve the purpose?

Yes. Detecting distress signals in journal entries requires reading those entries. There is no alternative mechanism that would achieve the same protective outcome without processing the transcript content.

Could the purpose be achieved with less data or less intrusive means?

The processing is already minimised: the keyword check runs locally on the server before any external API call is made, uses pattern matching only (not AI analysis), does not store the result beyond a flag value, and does not involve human review at any point. The check is a single pass — it does not build a profile or retain keyword match data.

Part 3 — Balancing test
Passes strongly
Nature of the data

The same sensitive personal data as LI-1 — journal transcripts that may contain health and emotional content. The keyword check specifically targets the most sensitive content.

Reasonable expectations

Users are informed during onboarding and in the beta disclaimer that lumi. monitors entries for signs of distress and may surface support information. This is a reasonable expectation for a tool handling sensitive personal content, and users actively acknowledge it before first use.

Impact on individuals

The impact is protective, not harmful. The check either does nothing (the vast majority of entries) or surfaces support resources. No data leaves the system as a result. No third party is alerted. The user retains full control throughout.

Conflict with individual interests

There is no meaningful conflict. A user in distress has an interest in being signposted to support — which is exactly what the system does. A false positive shows resources the user does not need, which is a minor inconvenience rather than a harm.

Conclusion

This is one of the clearest cases for legitimate interests available — the processing exists to protect the very person whose data is being processed. The balance falls strongly in favour of the controller's legitimate interest.

Assessment outcome — LI-2

Legitimate interests is an appropriate legal basis for safety monitoring. The three-part test is satisfied — and the individual's interests and the controller's interests align rather than conflict. Processing should continue with the safeguards documented above maintained.


Safeguards — both processing activities
Encryption at rest
AES-256-CBC on all sensitive fields before storage. Metadata only stored unencrypted.
Audio deletion
Voice recordings deleted immediately after successful transcription. Never stored long-term.
No content logging
Readable journal content never appears in application logs at any point in the pipeline.
User deletion
Full data deletion available at any time via Settings — immediate and permanent across all tables.
No human review
No entry content reviewed by any human, including anyone at lumi., at any tier of processing.
Full disclosure
AI processing and safety monitoring disclosed before first use. Active acknowledgement required.
Local safety check
Keyword check runs locally before any external API call — distress signals processed server-side only.
Minimal sub-processors
Content shared only with Anthropic, OpenAI, and Railway — each with published data commitments.

Review schedule
TriggerAction
Every 12 monthsRoutine review — confirm processing activities, purposes, and safeguards remain accurate
New processing activity addedNew LIA required before processing begins if legitimate interests is the intended basis
Material change to safety systemRe-assess LI-2 — particularly if human review is ever introduced
Change to sub-processorsRe-assess whether safeguards remain sufficient under LI-1
ICO guidance updateReview both assessments against new guidance within 60 days

Sign-off

Prepared by: Sarah-Jane Barton trading as lumi., data controller

ICO registration: C1942494

Date prepared: May 2026

Next review due: May 2027

This assessment should be reviewed by a qualified solicitor before public launch and updated as the processing activities or safeguards materially change.