Trust
Trust and Security
A plain-language account of how we protect your information. Written for members and for the partners who entrust their people to us.
On this page
How we think about trust
Trust comes before intimacy. We earn it through correctness, restraint, privacy, and clarity, not through promises. The commitments below are ones we can keep, and we will not publish one we cannot.
No system is perfectly secure, and we will not claim otherwise. We do not describe LumenUs as unhackable or as one hundred percent secure. What we commit to is a serious, layered, continually improving security program, described honestly below.
What we protect, and how
- Encryption. Your data is encrypted in transit and at rest.
- Access controls. Database-level controls segregate data. Personnel access to production is least-privilege and limited to those who need it.
- Data residency. Your data is stored in the United States.
- Monitoring and response. We log relevant activity, monitor for issues, and maintain an incident-response process, including breach notification as required by law.
- Vendor diligence. The third parties that process data for us are vetted and bound by contract. The current list is published in our Privacy Policy.
Privacy commitments that are also security commitments
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We do not license identifiable personal data.
- We never use your grief, your health, or your loss for advertising, and we do not place advertising or cross-site tracking technologies anywhere on the Service. Our public marketing website measures visits with cookieless, aggregate analytics that set no cookies and store no personal identifiers. See our Cookie Policy for the full description of the technologies we do and do not use.
- We share your private content only as you direct, or where law or safety requires.
Consumer health data
Grief and mental-health-related information is treated as consumer health data. How we collect, use, share, and protect it, and the choices you have, are described in our separate Consumer Health Data Privacy Policy, available at lumenus.life/consumer-health-data.
Crisis and AI
LumenUs is not an emergency or crisis-counseling service. LumenUs has no AI chatbot, AI companion, or AI conversation feature, and nothing on the Service monitors anyone or screens for crisis. We publish crisis resources, always free and never gated; how that works, and its honest limits, are described in our Crisis Support Protocol at lumenus.life/crisis-support. Our commitments governing any future use of AI are published in our AI Disclosure at lumenus.life/ai-disclosure.
Where we are on formal certification
We do not yet hold a formal security certification, and we will not imply one we do not hold. Until we do, we describe our posture in plain language here.
For partners
Partners (hospices, employers, health systems, advisors) can request our security measures summary. Partner reporting is aggregate and de-identified only, with a minimum group-size threshold so no individual can be identified.
Reporting a security concern
If you believe you have found a security vulnerability, please tell us at hello@lumenus.life. We welcome responsible disclosure and will work with you in good faith under our Coordinated Vulnerability Disclosure Policy, which sets out scope, expectations, and a good-faith safe harbor. If you or someone is in danger, contact 988 or 911 first.