Legal
Privacy Policy
Last updated: May 19, 2026
1. Responsible Party
My Superfood is an informational catalog page by Tilman Resch.
Tilman Resch
Knoebelstr. 30
80538 Munich
Germany
Email: info@luminaos.app
2. What This Page Does
My Superfood lets visitors browse foods, supplement kits, supplements, recipes, and saved lists. Public browsing does not require an account.
3. Legal Basis For Processing
Where GDPR applies, technical website delivery, security logging, and browser-local functionality are processed based on legitimate interests in operating a secure and useful website. Optional LuminaOS sync is processed to provide the requested account-backed saved-list functionality. If consent is requested for a future feature, that processing will be based on consent and can be withdrawn for the future.
4. Local Saved Lists
If you save foods, supplement kits, supplements, or recipes without signing in, the page stores a browser-local list and a random browser client identifier. This helps the saved list keep working on the same device and browser.
5. Optional LuminaOS Sync
If you choose to sign in with LuminaOS, My Superfood uses a server-side OAuth flow. The browser receives a My Superfood session cookie, not LuminaOS or Cognito tokens. Signed-in saved-list data can be synced to My Superfood's AWS-backed saved-list storage under the LuminaOS user identity.
6. Hosting And Technical Data
The site is served through AWS static hosting and CloudFront. Like most websites, hosting infrastructure may process technical request data such as IP address, browser type, requested URL, timestamps, and basic security logs to provide, protect, and troubleshoot the service.
7. Cookies And Browser Storage
My Superfood may use localStorage for saved-list functionality and a secure session cookie when LuminaOS sync is enabled. The site does not intentionally use advertising cookies in the current version.
8. Service Providers
My Superfood uses AWS infrastructure for static hosting, CloudFront delivery, Lambda APIs, and DynamoDB saved-list storage. Optional sign-in is provided through LuminaOS/Cognito. These providers process data only as needed to operate the site and requested sync features.
9. Data Retention
Browser-local saved lists stay in your browser until you clear them. Account-backed saved-list data is kept while the sync feature is used or until deletion is requested, unless a longer retention period is legally required. Technical logs are kept only as long as reasonably needed for security, troubleshooting, and operations.
10. Data Security
The production site uses HTTPS. My Superfood does not store LuminaOS passwords and does not expose LuminaOS/Cognito tokens to browser JavaScript or localStorage.
11. Third-Party Links
The site may link to LuminaOS, official product pages, or other external sources. Those websites have their own privacy practices and are not controlled by My Superfood.
12. Your Rights
If you are in the European Economic Area, you may have rights under GDPR, including access, correction, deletion, restriction, objection, withdrawal of consent, and data portability. You may also lodge a complaint with a data protection supervisory authority. Contact info@luminaos.app for privacy requests.
13. Changes
This policy may be updated as My Superfood evolves. The current version will be published on this page.