Trust
Trust and Security
A plain-language account of how we protect your information. Written for members and for the partners who entrust their people to us. This is the public /trust page.
On this page
How we think about trust
Trust comes before intimacy. We earn it through correctness, restraint, privacy, and clarity, not through promises. The commitments below are ones we can keep, and we will not publish one we cannot.
No system is perfectly secure, and we will not claim otherwise. We do not describe LumenUs as unhackable or as one hundred percent secure. What we commit to is a serious, layered, continually improving security program, described honestly below.
What we protect, and how
- Encryption. Member data is encrypted in transit and at rest.
- Access controls. Database-level controls restrict each member to their own data. Personnel access to production is least-privilege and limited to those who need it.
- Authentication. Secure authentication, with additional protection such as a Vault PIN for sensitive documents.
- Data residency. Member data is stored in the United States.
- Monitoring and response. We log relevant activity, monitor for issues, and maintain an incident-response process, including breach notification as required by law.
- Vendor diligence. The third parties that process data for us are vetted and bound by contract. The current list is published at lumenus.life/subprocessors.
Privacy commitments that are also security commitments
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We do not license identifiable member data.
- We never use your grief, journals, conversations, health, or loss for advertising, and we do not place advertising or cross-site tracking technologies on the pages where you do private grief work or provide health information. On our public marketing website we may use analytics and advertising-measurement tools, which you can control through our cookie banner and the Global Privacy Control. See our Cookie Policy for the full description of the technologies we do and do not use.
- We share your private content only as you direct, or where law or safety requires.
Consumer health data
Grief and mental-health-related information is treated as consumer health data. How we collect, use, share, and protect it, and the choices you have, are described in our separate Consumer Health Data Privacy Policy, linked from our homepage and available at lumenus.life/consumer-health-data.
Crisis and AI
LumenUs is not an emergency or crisis-counseling service. Our AI support feature responds to expressed distress by surfacing crisis resources; it does not detect, screen for, or monitor for crisis. How this works, and its honest limits, are described in our Crisis Support Protocol at lumenus.life/crisis-support. How our AI support feature works, and what it is and is not, is described in our AI Disclosure Statement at lumenus.life/ai-disclosure.
Where we are on formal certification
We are building toward a recognized security certification (SOC 2). Until it is achieved, we describe our posture in plain language here rather than implying a certification we do not yet hold.
For partners
Partners (hospices, employers, health systems, advisors) can request our Data Processing Addendum, our security measures summary, and, where a covered entity routes Protected Health Information, our Business Associate Agreement. Partner reporting is aggregate and de-identified only, with a minimum group-size threshold so no individual can be identified.
Reporting a security concern
If you believe you have found a security vulnerability, please tell us at hello@lumenus.life. We welcome responsible disclosure and will work with you in good faith under our Coordinated Vulnerability Disclosure Policy, which sets out scope, expectations, and a good-faith safe harbor. If you or someone is in danger, contact 988 or 911 first.