Legal
Privacy Policy
This Privacy Policy explains what we collect, why, who can see it, and the choices you have. We treat grief data as among the most sensitive information that exists, and we hold it that way.
On this page
- A note before the legal text
- 1. Who and what this Policy covers, and where it applies
- 2. Information we collect
- 3. Sensitive and consumer health data
- 4. How we use your information
- 5. Artificial intelligence
- 6. How we share information
- 7. Crisis and safety data
- 8. No automated safety monitoring
- 9. Data about a person who died, and about other people
- 10. Improvement, de-identification, research, and AI training
- 11. Storage, security, and retention
- 12. Your rights and choices
- 13. Cookies and tracking
- 14. Children
- 15. Changes to this Policy
- 16. Governing law
- 17. Contact
A note before the legal text
We wrote this to be readable. Each section opens with a plain-language summary in italics, followed by the full terms. Our core promises in one place:
- We will never sell your personal information.
- We will never use your grief or your loss to serve you advertising, and we do not allow advertising trackers anywhere on this website.
- We collect only what helps us support you, and we tell you why.
- When we cannot state a fact honestly, we leave it out rather than guess.
What exists today. LumenUs today is this website: the Library, the personalized path tool, and the forms through which you can contact us, request a demo, join the waitlist, or apply as a provider. There are no member accounts, no mobile app, no AI chatbot or AI conversation feature of any kind, no payments, and no subscriptions. Where this Policy describes the LumenUs platform, those sections are written for the platform's launch and take effect only if and when those features become available. Until then, no data described in those sections is collected, because the features that would collect it do not exist.
1. Who and what this Policy covers, and where it applies
This covers everyone who touches LumenUs: members, the supporters they invite, the people we serve information about, and website visitors. The Service is directed to users in the United States.
This Policy applies to five groups:
(a) Members who use the LumenUs platform and app for grief support. (b) Supporters whom a member invites into their Circle of Care. A Supporter is also a person with their own rights under this Policy. (c) Information about other people, including the person who died and other members of a member's Circle, which a member may provide. (d) Visitors to our website, lumenus.life. (e) People who write to a family through a page a member shares, without a LumenUs account.
Jurisdictional scope. LumenUs is operated from the United States and is directed to users located in the United States. We do not offer the Service to, or direct it at, individuals in the European Economic Area, the United Kingdom, or other jurisdictions outside the United States, and this Policy is written to United States law. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
2. Information we collect
We collect what you give us, what is created as you use the Service, and, for our partner and outreach programs, certain information from public sources. Before or at the point we collect, we give you notice of what we collect and why, consistent with the CCPA notice at collection.
We provide notice of the categories of personal information we collect and the purposes for which we use them at or before the point of collection, consistent with the California Consumer Privacy Act (CCPA) notice-at-collection requirement. This Section, together with Sections 3 and 4, serves as that notice.
2.1 Information you provide
On this website today:
| Category | Examples | Why |
|---|---|---|
| Contact, demo, and waitlist forms | Name, email, organization, and the message you write | Respond to you and provide what you asked for |
| Personalized path | The situation answers you choose to provide (such as your relationship to the person who died and your state), your email, and your consent record | Build and send the path you requested |
| Provider applications | Professional information you submit, including credentials and certificate documents you upload | Review your application |
| Feedback and support | Messages you send us | Help you and improve the Service |
If and when the LumenUs platform launches with member accounts, it may also collect, and this Policy will be updated before it does:
| Category | Examples | Why |
|---|---|---|
| Account | Name, email, authentication credentials | Create and secure your account |
| Profile and onboarding | Relationship to the person who died, date and nature of loss, location, faith or cultural context, household and dependents, and the progressive questions you choose to answer | Personalize your support and surface what is relevant |
| Journals and reflections | Free-text entries, check-ins, practice responses | Provide your private reflective space and relevant support |
| Circle and supporters | Names and emails of people you invite, and the permissions you set | Enable the support you choose to share |
| Vault documents | Documents you upload, which may include certificates, insurance, and legal and financial records | Help you organize the practical tasks after a loss |
| Benefits inputs | Information you enter to check potential benefits | Surface benefits you may be eligible for |
| Papers you choose to have read | Photos or PDFs of papers such as a death certificate, a W-2, a pay stub, a bank or mortgage statement, a deed, or a bill, and the details read from them | Fill in the details your tasks, entries, and letters need, once you confirm each one (Section 5) |
| A page you choose to share | The name of the person who died, the years of their life if you show them, a photograph of them, the words you write to the people who knew them, the name you sign with, and the letters people write to you through the page | Let the people who knew them write to you, and show the letters you choose to show (Sections 5, 6.2, and 9) |
The platform uses artificial intelligence for two purposes only: reading papers you choose to add, and reading each letter written through a family's page before it reaches the family, both described in Section 5. It will not include an AI chatbot, AI companion, or AI conversation feature, and no conversation data is collected. If that ever changes, this Policy will describe the feature, the provider, and the protections before the feature is available to anyone.
If you write to a family through their page. A member can share a page that remembers the person who died, and anyone with its link can open it and write to the family without an account. When you write, we collect your name, how you knew the person, your email address, your letter, a photograph if you add one, and whether you allow the family to show your letter on the page. We use your email address to send you a six-number code that confirms the letter is yours, and we keep it with your letter so that we can answer a question about it. It is never shown to the family. We do not add you to any list, and we do not send you marketing. Once you confirm your address, the browser you used is remembered as confirmed for 30 days, so a second letter from it needs no second code. To prevent abuse, we count how often letters are sent from one network address and for one email address, and we keep those counts only in a scrambled form that does not reveal either address.
2.2 Information created as you use the Service
| Category | Examples | Why |
|---|---|---|
| Usage | Features used, session activity, navigation, measured through cookieless aggregate analytics | Operate and improve the Service |
| Device and log | Device and browser type, IP address, access times, error logs | Security, troubleshooting, abuse prevention |
2.3 Information from other sources
We may receive information from partners who refer you, and from service providers. We do not conduct automated outreach to bereaved people who are not users.
We may receive information from a partner who refers you (such as a hospice or employer benefit program) and from service providers. We do not conduct automated marketing outreach to bereaved non-users.
2.4 What we do not collect
We do not knowingly collect information from anyone under 18, and we do not collect biometric data. We do not use your grief, health, or loss to advertise to you. Our use of cookies and analytics, including limited analytics and advertising-measurement on our public marketing website, is described in Section 13 and in our Cookie Policy.
3. Sensitive and consumer health data
A lot of what you share with us is sensitive. We treat it that way, and we ask your consent before using it beyond the support you came for. We do not use it for purposes that would trigger the California right to limit its use.
Much of the information above is sensitive, including information that can reveal your mental or physical health, your religion, and the cause of a death (which may include suicide, overdose, or pregnancy and infant loss). This category also includes your responses to any grief reflection questions and any reflection we derive from them. These reflections are a self-reflection aid, developed by LumenUs. They are not a diagnostic tool, they are not a clinical assessment, and they do not diagnose any condition. Your consent to that reflection is obtained separately at the point of use, as described in the Consumer Health Data Privacy Policy. We treat all of this as sensitive personal information and, where it qualifies, as consumer health data under state law.
A paper you choose to have read, such as a death certificate, can show health information, including the cause of a death. The reader is instructed never to return the cause or manner of a death, and we never keep it from a paper (Section 5). Sensitive personal information also includes a Social Security number. If you give us the Social Security number of the person who died, or confirm the one read from their death certificate, it is kept apart from your other information, is never shown back to you, and is used only to fill in the letters that require it.
We will not use or disclose your sensitive information for any purpose other than providing the Service and the purposes you have consented to, and we obtain your affirmative, explicit consent before any use that requires it.
California right to limit the use of sensitive personal information. Under the California Privacy Rights Act (CPRA), a consumer may direct a business to limit its use of sensitive personal information to specified purposes. We use sensitive personal information only to perform the Service you have requested, to keep you safe, to maintain security and prevent fraud, and for the other purposes described in Section 4, all of which fall within the uses that the CPRA exempts from the right to limit (California Civil Code Section 1798.121 and its implementing regulations). We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for advertising. Because our use is confined to these exempt purposes, the right to limit does not restrict any additional use, and there is no further use for you to limit.
Residents of Washington, Nevada, and Connecticut should also read our separate Consumer Health Data Privacy Policy, which describes our handling of consumer health data and the specific consents and authorizations involved.
4. How we use your information
We use your information to support you, keep you safe, and improve the Service. We never use it to advertise to you, and we never sell it.
We use information to:
- Provide what you asked for: respond to your message, send the path you requested, review your application, or provide a demo.
- Provide and improve the Library and the tools on this website.
- Communicate with you about your request and, with your choices respected, optional updates.
- Improve the Service using aggregated, de-identified data (Section 10).
- Maintain security, prevent abuse, and comply with law.
If and when the platform launches, we will also use information to provide and personalize its grief support features, and this Policy will be updated first.
We will never: sell your personal information; use your grief or your loss for advertising; or place advertising trackers anywhere on the Service.
We will not use your personal content to train general-purpose AI models without your explicit, separate consent.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act.
5. Artificial intelligence
LumenUs uses artificial intelligence for two purposes: reading papers you choose to add, so you do not have to type what is printed on them, and reading each letter written through a family's page before it reaches the family, to hold back the few that would hurt them. LumenUs has no AI chatbot, AI companion, or AI conversation feature, and we process no conversations.
Reading your papers. In the LumenUs app, you can photograph or upload papers such as a death certificate, a W-2, a pay stub, a bank statement, a mortgage statement, a deed, or a utility bill. Each page you add is sent to Anthropic, PBC, whose Claude model reads it and returns the details printed on it, such as a name, a date, an employer, a loan number, or a box on a tax form. The app tells you this on the screen where you add papers. It then shows you what was read, beside your photo, and nothing is added to your account until you confirm it. You can set aside anything that is wrong.
What Anthropic does with a page. Anthropic processes each page only to provide this service to us, under its commercial terms and data processing addendum. It does not use your pages, or what it reads from them, to train its models. It deletes each page and its reply within 30 days, except where it must keep them longer to comply with the law or to enforce its usage policy.
What we keep. We keep no copy of your photos. While you go through what was found, your photos and the details read from them stay on your own device, in your browser's storage, and they are deleted from it when you have gone through everything and it is saved, when you sign out, or after 30 days. Only the details you confirm are saved to your account, as if you had typed them yourself. We also record that a page was read, by which model, and what it cost, to apply daily reading limits. We do not record what the page said.
What the reader never keeps. The reader is instructed never to return the cause or manner of a death, how an injury happened, whether an autopsy was done, or a parent's name, and the app discards them if they appear. On a death certificate, the reader may read the Social Security number of the person who died. That number is sealed on our servers, so your device never holds it in a form anyone can read. The app shows you only its last four digits to check against the paper, and the number is stored only if you confirm it. Once stored, it is kept apart from your other information, is never shown back to you, and is used only to fill in the letters that require it. A full Social Security number on any other paper is discarded.
Reading letters before they reach a family. A member can share a page that remembers the person who died, and anyone with its link can write to the family (Section 2.1). Before a letter reaches the family, its words and any photograph, the writer's name and how they knew the person, and the name of the person who died are sent to Anthropic, PBC, whose Claude model reads them for one thing: to hold back the few letters that would hurt or exploit the family, such as cruelty, threats, hateful or sexual content, graphic descriptions, requests for money, advertising, or other people's private details. The writer's email address is never sent. When the model is unsure, the letter goes through. A letter it holds back never reaches the family, and we delete it after 30 days. The model does not judge or assess the person who wrote, and it does not look for signs of crisis. It can be wrong in either direction, and the family can remove any letter at any time. The page tells the writer about this reading before they send, and the member is told before making a page. Anthropic processes letters only to provide this service to us, under the same commercial terms and data processing addendum as for papers. It does not use letters to train its models, and it deletes each letter and its reply within 30 days, except where it must keep them longer to comply with the law or to enforce its usage policy.
No conversation and no advice. Neither reader converses with anyone, gives advice, or decides anything for you. If we ever introduce another feature that uses artificial intelligence, it will be described here, with the provider named and the contractual protections stated, including a prohibition on training on your content, before it is available to you. Our standing commitments for any use of AI are published in our AI Disclosure at lumenus.life/ai-disclosure.
6. How we share information
We share only with the vendors who run the Service for us, with people and providers you choose, and where law or safety requires. We do not sell or share your data for advertising.
6.1 Service providers (subprocessors)
We use a limited set of vendors who process data on our behalf under contract, restricted to providing their service to us:
| Provider | Purpose | Data |
|---|---|---|
| Supabase (on AWS) | Database and file storage | Form submissions, uploaded documents, and letters written through a family's page (encrypted) |
| Resend | Transactional email and notifications, including the code that confirms a letter written through a family's page | Name, email |
| Vercel | Website hosting and cookieless, aggregate site analytics | De-identified usage data |
| Cloudflare (Turnstile) | Security verification on forms, under Cloudflare's Turnstile Privacy Addendum | Browser signals used to distinguish people from bots |
| Anthropic | Reading papers you choose to add in the LumenUs app, and reading each letter written through a family's page before it reaches the family (Section 5), under its commercial terms and data processing addendum, with no training on your content | The image of each page you add and the details read from it; the words and any photograph of each letter, with the writer's name and how they knew the person. Deleted by Anthropic within 30 days |
We keep the list above current, and update it as our providers change. The current list is always available at lumenus.life/subprocessors.
6.2 At your direction (your Circle, when the platform launches)
If and when the platform's Circle feature launches: when you invite a Supporter, they will see only the specific information and permissions you grant. Your private content is not shared with Supporters unless you explicitly choose to share specific items.
A page you share. If you make a page for the person who died, anyone with its link can see what you put on it: their name, the years of their life if you show them, the photograph you choose, your words, the name you sign with, and the letters you choose to show on it, each with its writer's name and how they knew the person. Nothing else from your account appears on it. We do not list the page anywhere, and we ask search engines not to index it, but anyone who has the link can open it and pass it on. When the link is shared in a message or a post, the app or site it is shared in may fetch the page's title, your words, and the photograph to show a preview. You can pause the page so it takes no letters, and you can close it at any time, which removes the page and every letter on it.
6.3 Professionals and vendors you engage
If you choose to connect with a professional through LumenUs, we share only the limited information needed to make that connection. We do not share your private content or documents with professionals, partners, or employers.
6.4 Legal, safety, and business transfers
We may disclose information where required by law or legal process, or where we believe in good faith it is necessary to protect the safety of any person, prevent fraud or abuse, or protect our rights. We will notify you of legal requests for your data unless prohibited. If LumenUs is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this Policy.
6.5 Affiliates
We do not currently have corporate affiliates. If that changes, we will update this Policy, and we will not share your personal information with any affiliate for that affiliate's own purposes without a lawful basis and, where the information is consumer health data or sensitive personal information, your consent.
6.6 We do not sell or share for advertising
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We do not sell or share personal information under any other state privacy law either. Because we do not, your opt-out right is satisfied by default.
7. Crisis and safety data
If you report a safety concern to us, we keep a record of it, and we keep it longer than ordinary data, on purpose. The retention period is set in Section 11.
If you report a safety concern to us, we retain a record of the report and our response. Safety records are used only to respond to the concern, investigate incidents, respond to legal obligations, and demonstrate reasonable care. They are never used for marketing or unrelated analytics. They are retained for the period stated in the retention schedule in Section 11 (three years, or longer if subject to a legal hold).
8. No automated safety monitoring
This website does not monitor you and has no automated crisis-detection feature. Crisis resources are published, always free, and never gated.
The Service does not include any automated safety-detection or crisis-monitoring feature, and we do not monitor visitors. We publish crisis resources (988 Suicide and Crisis Lifeline; Crisis Text Line, text HOME to 741741; and 911) on our Crisis Support Protocol page and in the footer of every page. They are always free and never gated. You must not rely on this website to detect or respond to an emergency. The reader that goes over each letter written through a family's page before it reaches the family (Section 5) looks only at what the letter would do to the family. It does not assess the person who wrote, and it is not a crisis-detection feature. A family's page shows the same crisis resources in its footer. If and when the platform introduces any safety-related feature, this section will describe it, and its honest limits, before it operates. Please also read Section 5 of the Terms of Service.
9. Data about a person who died, and about other people
We hold information about the person you lost, and sometimes about others. You confirm you have the right to give it to us, and we handle it with dignity.
The Service is designed to hold information about the person who died and, at times, about other living people in your Circle. When you provide that information, you confirm you have the authority to do so. We handle information about a person who died with dignity and use it only to provide the Service. We do not conduct automated outreach to bereaved non-users.
Letters people write to you. A letter someone writes to you through your page waits for you, sealed, and only you can open it: not the people in your Circle, and not anyone at LumenUs in the ordinary course. Until you open it, its writer can take it back from the browser they sent it from. Once you open it, you decide what happens to it. If you keep it, its words become one of your notes and its photograph joins your photographs, and they stay with you even after the page is closed. A letter appears on the page itself only when its writer allowed that and you chose to show it, and you can take it off at any time.
If you wrote a letter. You can ask us at hello@lumenus.life to delete a letter you wrote, together with your email address, and we will delete it from the family's page and from our records. A copy the family already chose to keep is theirs, and we will not remove it from their account.
10. Improvement, de-identification, research, and AI training
We learn from aggregated, de-identified data to improve grief support. We do not sell your personal information, and any research or model training uses de-identified data with the protections below.
We use aggregated and de-identified data to understand what helps during grief and to improve the Service. When we report or study outcomes, we apply de-identification and minimum-group thresholds so individuals cannot be re-identified (our standard floors are a minimum of ten individuals for cross-cohort aggregates and a minimum of five for finer views). Any research conducted with our research partners follows an appropriate review process, and any use of data to train models, or any licensing of de-identified data, is done only on de-identified data and, where personal content is involved, only with your explicit, separate consent. We disclose these uses here so there is no surprise.
11. Storage, security, and retention
We encrypt your data and limit who can reach it. Deletion is real but completes over a defined period, and backups exist. This Section is the single source of truth for retention across all of our policies.
Your data is stored in the United States via Supabase on AWS infrastructure, encrypted in transit (TLS) and at rest. We use database-level access controls so members reach only their own data, limited personnel access to production systems, and access controls such as a Vault PIN (which limits access within the Service and is not a representation of a specific encryption standard beyond what is stated here). We retain data while your account is active. When you delete your account, we remove personal content over a defined period; because we use soft-deletion and maintain backups for recovery and security, deletion may take time to propagate, and we may retain limited records as required by law or for safety (Section 7). In the event of a breach affecting your personal information, we will notify affected users and authorities as required by law.
Our standard retention periods, which govern for the entire LumenUs policy suite, are:
| Data | Retention after deletion or trigger |
|---|---|
| Form submissions and personalized-path data | Deleted on your verified request, and otherwise retained only as long as needed for the purpose you submitted them for |
| Account data, journals, reflections, and Vault documents (platform, when launched) | Deleted approximately 30 days after you delete your account or the item |
| Photos of papers you add for reading (platform) | Not kept by LumenUs. Kept on your own device until you have gone through what was found, you sign out, or 30 days pass. Deleted by Anthropic within 30 days of reading, unless the law requires longer |
| Records that a page was read, by which model and at what cost (platform) | Deleted when you delete your account |
| A page a member shares, and the letters written through it (platform) | Kept until the member closes the page, removes a letter, leaves the Circle, or deletes their account, or until a writer asks us to delete their letter. Letters the member chose to keep stay with the member's own content |
| A letter whose confirmation code is never typed | Removed in our routine cleanup after 1 day |
| A letter held back before it reaches the family (Section 5) | Removed in our routine cleanup after 30 days |
| A writer's email address | Kept with the writer's letter and deleted with it. A browser's record that an address was confirmed: 30 days |
| Counts used to prevent abuse of a family's page (scrambled network and email addresses) | 8 days |
| Safety records (Section 7) | 3 years |
| Payment and transaction records (if payments are ever offered) | 7 years, as required by tax and financial law |
| Server and access logs | 90 days |
| Backups | Cycled and overwritten on a rolling basis |
Where the law requires a longer or shorter period, or where data is subject to a legal hold, that period governs.
12. Your rights and choices
You can see, correct, export, and delete your data, withdraw consent, and appeal a decision. Here is how.
All members may: access and export your data; correct your profile; delete your account and content; opt out of non-essential communications; and withdraw consent for optional processing.
California residents (CCPA/CPRA) may: know what we collect and how it is used; access, correct, and delete personal information; limit the use of sensitive personal information (see Section 3 for our determination on this right); and opt out of sale or sharing (which we do not do). We honor the Global Privacy Control. You will not be discriminated against for exercising your rights.
California auto-renewal (Automatic Renewal Law). We do not offer paid subscriptions at this time, so nothing renews and nothing is charged. If and when we introduce a paid subscription, we will comply with the California Automatic Renewal Law (California Business and Professions Code Sections 17600 through 17606): the renewal terms will be presented clearly before you buy, we will obtain your affirmative consent, send an acknowledgment, and provide an easy online way to cancel, as set out in Section 14 of the Terms of Service.
Residents of Colorado, Connecticut, Texas, Virginia, and other states with comprehensive privacy laws have analogous rights to access, correct, delete, and port personal data, to opt out of targeted advertising and sale (which we do not do), and to appeal a decision on a rights request. To appeal, reply to our response or contact hello@lumenus.life. We will respond to an appeal within forty-five days of receipt; where reasonably necessary, we may extend that period once by an additional sixty days and will tell you of the extension and the reason. If you have concerns about the outcome of an appeal, you may contact your state Attorney General to submit a complaint.
Residents of Washington, Nevada, and Connecticut have specific rights regarding consumer health data described in our Consumer Health Data Privacy Policy.
How to exercise rights: by email to hello@lumenus.life (and, when the platform launches, in-app under Settings). You may use an authorized agent. We will verify your identity and respond within the time the law requires (generally 45 days, extendable with notice).
13. Cookies and tracking
We use what the Service needs, and we measure website usage without cookies. We do not place advertising trackers anywhere, and we do not use your grief or health data for advertising.
We use cookies and similar technologies that are necessary for the Service to function, plus preference technologies stored in your own browser that you can clear at any time. Our website analytics are cookieless and aggregate: they set no cookies and store no personal identifiers, so no consent banner is required and none is shown. Because we set no non-essential cookies and do not sell or share personal information for advertising, the protection a Global Privacy Control signal requests is already our default for every visitor. We hold a firm line where it matters most: we do not place advertising trackers, ad pixels, or cross-site tracking technologies anywhere on the Service, and we do not use your grief, your health, or your loss to target advertising to you. We do not sell your personal information. Full detail is in our Cookie Policy.
14. Children
LumenUs is for adults.
LumenUs is intended for adults 18 and older. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect from children under 13. If we learn we have, we will delete it. Contact hello@lumenus.life with any concern.
15. Changes to this Policy
We may update this Policy. For material changes we will provide notice by email or in-app at least 30 days before they take effect, and we will note the update date above.
For any material change that affects how we collect, use, or disclose sensitive personal information or consumer health data, we will not rely on your continued use as acceptance. Instead, we will obtain your fresh affirmative consent before the change applies to that data. For other changes, continued use after the changes take effect constitutes acceptance.
16. Governing law
This Policy and any dispute arising out of or relating to it or to our processing of your personal information are governed by the laws of the State of California and applicable United States federal law, without regard to conflict-of-laws principles. This governing-law provision does not limit any non-waivable statutory rights you have under the privacy law of your state of residence. Any dispute is subject to the venue and dispute-resolution provisions of our Terms of Service.
17. Contact
LumenUs Platform, Inc., a Delaware corporation with its principal operations in California. Privacy and rights requests: hello@lumenus.life Data protection inquiries: hello@lumenus.life General: hello@lumenus.life