Legal
Privacy Policy
This Privacy Policy explains what we collect, why, who can see it, and the choices you have. We treat grief data as among the most sensitive information that exists, and we hold it that way.
On this page
- A note before the legal text
- 1. Who and what this Policy covers, and where it applies
- 2. Information we collect
- 3. Sensitive and consumer health data
- 4. How we use your information
- 5. The AI support feature and how we process conversations
- 6. How we share information
- 7. Crisis and safety data
- 8. The automated safety feature
- 9. Data about a person who died, and about other people
- 10. Improvement, de-identification, research, and AI training
- 11. Storage, security, and retention
- 12. Your rights and choices
- 13. Cookies and tracking
- 14. Children
- 15. Changes to this Policy
- 16. Governing law
- 17. Contact
A note before the legal text
We wrote this to be readable. Each section opens with a plain-language summary in italics, followed by the full terms. Our core promises in one place:
- We will never sell your personal information.
- We will never use your grief, your journal, your conversations, or your loss to serve you advertising, and we do not allow advertising trackers on the pages where you do this private work.
- We collect only what helps us support you, and we tell you why.
- When we cannot source a value honestly, we leave it empty rather than guess. Empty beats wrong.
1. Who and what this Policy covers, and where it applies
This covers everyone who touches LumenUs: members, the supporters they invite, the people we serve information about, and website visitors. The Service is directed to users in the United States.
This Policy applies to four groups:
(a) Members who use the LumenUs platform and app for grief support. (b) Supporters whom a member invites into their Circle of Care. A Supporter is also a person with their own rights under this Policy. (c) Information about other people, including the person who died and other members of a member's Circle, which a member may provide. (d) Visitors to our website, lumenus.life.
Jurisdictional scope. LumenUs is operated from the United States and is directed to users located in the United States. We do not offer the Service to, or direct it at, individuals in the European Economic Area, the United Kingdom, or other jurisdictions outside the United States, and this Policy is written to United States law. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
2. Information we collect
We collect what you give us, what is created as you use the Service, and, for our partner and outreach programs, certain information from public sources. Before or at the point we collect, we give you notice of what we collect and why, consistent with the CCPA notice at collection.
We provide notice of the categories of personal information we collect and the purposes for which we use them at or before the point of collection, consistent with the California Consumer Privacy Act (CCPA) notice-at-collection requirement. This Section, together with Sections 3 and 4, serves as that notice.
2.1 Information you provide
| Category | Examples | Why |
|---|---|---|
| Account | Name, email, authentication credentials | Create and secure your account |
| Profile and onboarding | Relationship to the person who died, date and nature of loss, location, faith or cultural context, household and dependents, and the progressive questions you choose to answer | Personalize your support and surface what is relevant |
| Journals and reflections | Free-text entries, check-ins, practice responses | Provide your private reflective space and relevant support |
| Grief reflections (PG-13-R) | Your responses to a grief reflection based on the PG-13-R instrument, and any reflection we derive | Help you understand your own grief and decide whether to seek professional support |
| AI conversations | Your messages with the AI support feature and the context it retains | Provide contextual, ongoing support |
| Circle and supporters | Names and emails of people you invite, and the permissions you set | Enable the support you choose to share |
| Vault documents | Documents you upload, which may include certificates, insurance, and legal and financial records | Help you organize the practical tasks after a loss |
| Benefits inputs | Information you enter to check potential benefits | Surface benefits you may be eligible for |
| Payment | Billing details, processed by our payment processor; we do not store full card numbers | Process subscriptions and gifts |
| Feedback and support | Messages you send us | Help you and improve the Service |
2.2 Information created as you use the Service
| Category | Examples | Why |
|---|---|---|
| Usage | Features used, session activity, navigation | Operate and improve the Service |
| Device and log | Device and browser type, IP address, access times, error logs | Security, troubleshooting, abuse prevention |
| Self-reported state | The emotional state you choose to report | Adapt your experience to your current needs |
| Safety signals | Indicators the automated safety feature evaluates | Surface crisis resources when warranted (see Section 8) |
2.3 Information from other sources
We may receive information from partners who refer you, and from service providers. We do not conduct automated outreach to bereaved people who are not users.
We may receive information from a partner who refers you (such as a hospice or employer benefit program) and from service providers. We do not conduct automated marketing outreach to bereaved non-users. If we ever operate a partner program that uses limited information from public sources such as published obituaries, we will do so only as permitted by law and as described in Section 9, and any person may opt out and request deletion at hello@lumenus.life.
2.4 What we do not collect
We do not knowingly collect information from anyone under 18, and we do not collect biometric data. We do not use your grief, health, or loss to advertise to you. Our use of cookies and analytics, including limited analytics and advertising-measurement on our public marketing website, is described in Section 13 and in our Cookie Policy.
3. Sensitive and consumer health data
A lot of what you share with us is sensitive. We treat it that way, and we ask your consent before using it beyond the support you came for. We do not use it for purposes that would trigger the California right to limit its use.
Much of the information above is sensitive, including information that can reveal your mental or physical health, your religion, and the cause of a death (which may include suicide, overdose, or pregnancy and infant loss). This category also includes your responses to any grief reflection based on the PG-13-R instrument and any reflection we derive from them. The PG-13-R based reflection is a self-reflection aid. It is not a diagnostic tool, it is not a clinical assessment, and it does not diagnose any condition. Your consent to that reflection is obtained separately at the point of use, as described in the Consumer Health Data Privacy Policy. We treat all of this as sensitive personal information and, where it qualifies, as consumer health data under state law.
We will not use or disclose your sensitive information for any purpose other than providing the Service and the purposes you have consented to, and we obtain your affirmative, explicit consent before any use that requires it.
California right to limit the use of sensitive personal information. Under the California Privacy Rights Act (CPRA), a consumer may direct a business to limit its use of sensitive personal information to specified purposes. We use sensitive personal information only to perform the Service you have requested, to keep you safe, to maintain security and prevent fraud, and for the other purposes described in Section 4, all of which fall within the uses that the CPRA exempts from the right to limit (California Civil Code Section 1798.121 and its implementing regulations). We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for advertising. Because our use is confined to these exempt purposes, the right to limit does not restrict any additional use, and there is no further use for you to limit.
Residents of Washington, Nevada, and Connecticut should also read our separate Consumer Health Data Privacy Policy, which describes our handling of consumer health data and the specific consents and authorizations involved.
4. How we use your information
We use your information to support you, keep you safe, and improve the Service. We never use it to advertise to you, and we never sell it.
We use information to:
- Provide and personalize the Service, including grief support practices, your Circle, your Vault, and benefits tools.
- Operate the AI support feature and retain conversation context so support is continuous (Section 5).
- Adapt the experience to the emotional state you report.
- Operate the automated safety feature that surfaces crisis resources (Section 8).
- Communicate with you about your account and, with your choices respected, optional updates.
- Improve the Service using aggregated, de-identified data (Section 10).
- Maintain security, prevent abuse, and comply with law.
We will never: sell your personal information; use your grief, journals, conversations, or loss for advertising; place advertising trackers on the pages where you do private grief work; or share your journals or AI conversations with other users except where you explicitly choose to.
We will not use your personal content to train general-purpose AI models without your explicit, separate consent.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act.
5. The AI support feature and how we process conversations
Your conversations are processed by an AI provider under contract, retained to give you continuity, and not used for ads. Under that agreement we do not let the provider train its models on your content, and we hold the provider to a zero-retention posture.
Your messages with AI features are processed through a third-party AI provider (currently OpenAI) under an agreement that prohibits the provider from using your content to train its models and holds the provider to a zero-retention posture for the content we send. Conversation context and any insights we derive to personalize your support are stored in our systems, not by the provider. We do not use the content of your conversations for advertising, and we do not sell it. Any use of de-identified conversation data to improve the Service is governed by Section 10 and the consents you provide.
6. How we share information
We share only with the vendors who run the Service for us, with people and providers you choose, and where law or safety requires. We do not sell or share your data for advertising.
6.1 Service providers (subprocessors)
We use a limited set of vendors who process data on our behalf under contract, restricted to providing their service to us:
| Provider | Purpose | Data |
|---|---|---|
| Supabase (on AWS) | Hosting, database, authentication, file storage | Account and content data (encrypted) |
| OpenAI | AI support feature and AI features | Conversation content (not used to train provider models per contract) |
| Resend | Transactional email and notifications | Name, email |
| Google (Custom Search) | Obituary discovery for partner/outreach programs, where applicable | Public-source content |
| ElevenLabs | Audio for certain practices | Practice text/audio only |
| Stripe | Payment processing | Payment information (we do not store full card numbers) |
| Analytics provider | Aggregate product analytics | De-identified usage data |
The current subprocessor list is published at lumenus.life/subprocessors and kept up to date.
6.2 At your direction (your Circle)
When you invite a Supporter, they can see only the specific information and permissions you grant. Your private content, including journals and AI conversations, is not shared with Supporters unless you explicitly choose to share specific items.
6.3 Professionals and vendors you engage
If you choose to connect with a professional through the marketplace, we share only the limited information needed to make that connection. We do not share your journals, AI conversations, or Vault contents with professionals, partners, or employers.
6.4 Legal, safety, and business transfers
We may disclose information where required by law or legal process, or where we believe in good faith it is necessary to protect the safety of any person, prevent fraud or abuse, or protect our rights. We will notify you of legal requests for your data unless prohibited. If LumenUs is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this Policy.
6.5 Affiliates
We do not currently have corporate affiliates. If that changes, we will update this Policy, and we will not share your personal information with any affiliate for that affiliate's own purposes without a lawful basis and, where the information is consumer health data or sensitive personal information, your consent.
6.6 We do not sell or share for advertising
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We do not sell or share personal information under any other state privacy law either. Because we do not, your opt-out right is satisfied by default.
7. Crisis and safety data
If the safety feature activates, we log only what is needed for safety, and we keep it longer than ordinary data, on purpose. The retention period is set in Section 11.
We collect and retain limited data specifically for safety: crisis-detection events (such as the event type, timestamp, and the system's response), safety flags on AI interactions, and any safety concerns you report. Crisis-event logs record that an event occurred and how the system responded; they are distinct from the storage of your journals and conversations described above. Safety data is used only to operate and improve the safety feature, investigate incidents, respond to legal obligations, and demonstrate reasonable care. It is never used for marketing or unrelated analytics. It is retained for the period stated in the retention schedule in Section 11 (three years, regardless of account deletion, or longer if subject to a legal hold).
8. The automated safety feature
It is an aid that can surface crisis resources. It is not a monitoring or emergency service, and it cannot catch everything.
The Service includes an automated feature that may detect possible indicators of acute distress and surface crisis resources (988 Suicide and Crisis Lifeline; Crisis Text Line, text HOME to 741741; and 911). This feature is a supplementary aid, not a clinical or monitoring service, and it cannot reliably detect every crisis. Crisis resources are always free and never gated. Please also read Section 5 of the Terms of Service.
9. Data about a person who died, and about other people
We hold information about the person you lost, and sometimes about others. You confirm you have the right to give it to us, and we handle it with dignity.
The Service is designed to hold information about the person who died and, at times, about other living people in your Circle. When you provide that information, you confirm you have the authority to do so. We handle information about a person who died with dignity and use it only to provide the Service. We do not conduct automated outreach to bereaved non-users. If we ever obtain information about a person from a public source such as an obituary for an approved partner program, that person may opt out and request deletion at hello@lumenus.life, and we honor those requests.
10. Improvement, de-identification, research, and AI training
We learn from aggregated, de-identified data to improve grief support. We do not sell your personal information, and any research or model training uses de-identified data with the protections below.
We use aggregated and de-identified data to understand what helps during grief and to improve the Service. When we report or study outcomes, we apply de-identification and minimum-group thresholds so individuals cannot be re-identified (our standard floors are a minimum of ten individuals for cross-cohort aggregates and a minimum of five for finer views). Any research conducted with our research partners follows an appropriate review process, and any use of data to train models, or any licensing of de-identified data, is done only on de-identified data and, where personal content is involved, only with your explicit, separate consent. We disclose these uses here so there is no surprise.
11. Storage, security, and retention
We encrypt your data and limit who can reach it. Deletion is real but completes over a defined period, and backups exist. This Section is the single source of truth for retention across all of our policies.
Your data is stored in the United States via Supabase on AWS infrastructure, encrypted in transit (TLS) and at rest. We use database-level access controls so members reach only their own data, limited personnel access to production systems, and access controls such as a Vault PIN (which limits access within the Service and is not a representation of a specific encryption standard beyond what is stated here). We retain data while your account is active. When you delete your account, we remove personal content over a defined period; because we use soft-deletion and maintain backups for recovery and security, deletion may take time to propagate, and we may retain limited records as required by law or for safety (Section 7). In the event of a breach affecting your personal information, we will notify affected users and authorities as required by law.
Our standard retention periods, which govern for the entire LumenUs policy suite, are:
| Data | Retention after deletion or trigger |
|---|---|
| Account data, journals, reflections, and Vault documents | Deleted approximately 30 days after you delete your account or the item |
| Crisis and safety logs (Section 7) | 3 years, regardless of account deletion |
| Payment and transaction records | 7 years, as required by tax and financial law |
| Server and access logs | 90 days |
| Backups | Cycled and overwritten on a rolling basis |
Where the law requires a longer or shorter period, or where data is subject to a legal hold, that period governs.
12. Your rights and choices
You can see, correct, export, and delete your data, withdraw consent, and appeal a decision. Here is how.
All members may: access and export your data; correct your profile; delete your account and content; opt out of non-essential communications; and withdraw consent for optional processing.
California residents (CCPA/CPRA) may: know what we collect and how it is used; access, correct, and delete personal information; limit the use of sensitive personal information (see Section 3 for our determination on this right); and opt out of sale or sharing (which we do not do). We honor the Global Privacy Control. You will not be discriminated against for exercising your rights.
California auto-renewal (Automatic Renewal Law). Paid subscriptions renew automatically. Consistent with the California Automatic Renewal Law (California Business and Professions Code Sections 17600 through 17606), we present the renewal terms clearly before you buy, obtain your affirmative consent to the automatic-renewal terms, send an acknowledgment, and provide an easy online way to cancel. The specific price, billing frequency, cancellation mechanics, and refund terms are set out in Section 14 of the Terms of Service.
Residents of Colorado, Connecticut, Texas, Virginia, and other states with comprehensive privacy laws have analogous rights to access, correct, delete, and port personal data, to opt out of targeted advertising and sale (which we do not do), and to appeal a decision on a rights request. To appeal, reply to our response or contact hello@lumenus.life. We will respond to an appeal within forty-five days of receipt; where reasonably necessary, we may extend that period once by an additional sixty days and will tell you of the extension and the reason. If you have concerns about the outcome of an appeal, you may contact your state Attorney General to submit a complaint.
Residents of Washington, Nevada, and Connecticut have specific rights regarding consumer health data described in our Consumer Health Data Privacy Policy.
How to exercise rights: in-app under Settings, or by email to hello@lumenus.life. You may use an authorized agent. We will verify your identity and respond within the time the law requires (generally 45 days, extendable with notice).
13. Cookies and tracking
We use what the Service needs, plus analytics you can control. On our public marketing website we may also use advertising-measurement tools. We do not place advertising trackers on the pages where you do private grief work or enter health information, and we do not use your grief or health data for advertising.
We use cookies and similar technologies that are necessary for the Service to function, plus analytics and preference technologies that help us understand and improve it and that you can control. On our public marketing website we may also use analytics and advertising-measurement tools, for example to understand how visitors find us and how our marketing performs. You control non-essential cookies through our cookie banner and a "Your Privacy Choices" control, and we honor the Global Privacy Control. We hold a firm line where it matters most: we do not place advertising trackers, ad pixels, or cross-site tracking technologies on the pages where you do private grief work or provide health information, and we do not use your grief, journals, conversations, health, or loss to target advertising to you. We do not sell your personal information. Full detail is in our Cookie Policy.
14. Children
LumenUs is for adults.
LumenUs is intended for adults 18 and older. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect from children under 13. If we learn we have, we will delete it. Contact hello@lumenus.life with any concern.
15. Changes to this Policy
We may update this Policy. For material changes we will provide notice by email or in-app at least 30 days before they take effect, and we will note the update date above.
For any material change that affects how we collect, use, or disclose sensitive personal information or consumer health data, we will not rely on your continued use as acceptance. Instead, we will obtain your fresh affirmative consent before the change applies to that data. For other changes, continued use after the changes take effect constitutes acceptance.
16. Governing law
This Policy and any dispute arising out of or relating to it or to our processing of your personal information are governed by the laws of the State of California and applicable United States federal law, without regard to conflict-of-laws principles. This governing-law provision does not limit any non-waivable statutory rights you have under the privacy law of your state of residence. Any dispute is subject to the venue and dispute-resolution provisions of our Terms of Service.
17. Contact
LumenUs Platform, Inc., a Delaware corporation with its principal operations in California. Privacy and rights requests: hello@lumenus.life Data protection inquiries: hello@lumenus.life General: hello@lumenus.life