Trust at Lumi

Last updated

To help your family, Lumi must earn your trust.

Lumi uses the context you share about your family to build strategies that fit. That creates a responsibility: to collect with purpose, protect what you share, keep clear boundaries around who can see it, and tell you plainly where our practices stand today.

This page explains who can see your family’s information, where it goes to make Lumi work, what stays private, and what we are still improving.

The short version

The promises we want every family to understand.

Your household is a boundary

Families cannot see one another’s information. Inside a household, shared profiles and strategies help caregivers work from the same context—but not everything one person shares becomes visible to everyone else.

Your context has a job

We use the information you provide to operate Lumi, generate relevant coaching, support your family, protect the service, and improve how it works. We do not collect personal details simply because we can.

We name the services that help Lumi work

Lumi relies on outside providers for AI processing, authentication, storage, analytics, communication, and billing. We explain what the important providers do instead of pretending your information never leaves Lumi’s systems.

We tell you what is still maturing

Lumi is an early-stage product. Some controls are already built into the way the product works; others are becoming more formal as we grow. We would rather tell you the current truth than borrow the language of a larger company.

Why this page exists

You should not need a law degree to understand what happens here.

Families often tell Lumi things they would not put in an ordinary app: what mornings feel like, what repeatedly goes off track, how a child responds under stress, and where caregivers see the same situation differently.

That context is what makes Lumi useful. It is also why a conventional privacy policy is not enough.

The policy explains the legal terms. This page answers the questions families ask before they decide whether Lumi belongs in their home.

Who can see what I share?

Shared context does not mean shared conversations.

Lumi is organized around a household. The child profiles, strategies, routines, and other context meant to help a family work together can be shared with the caregivers you invite.

A coaching chat started by one adult caregiver is private from the other adult caregivers in the household. A co-parent cannot open and read the chat you started, and you cannot open and read theirs.

Lumi is parent-led. In the currently enabled product, children do not have a direct login, chat, or assessment experience. Checklist audio plays prompts a caregiver has set up; it does not open a direct conversation in which Lumi records or receives a child’s spoken or typed response.

Can people at Lumi see family information?

Yes. As a small, early-stage team, Lumi team members may access user data when needed to operate, debug, support, protect, and improve the service. That can include assessment inputs, chat messages, and AI-generated insights.

This is not anonymous access, and it is not access we describe as private from Lumi itself. We are working toward more granular roles, narrower access, and stronger auditability as the team and product grow.

Can another family see ours?

No. Families cannot browse, search, or access one another’s profiles, chats, assessments, strategies, or household information.

Does an AI company read what I write about my child?

AI helps Lumi respond. It does not remove our responsibility.

Lumi uses several AI services for specific jobs. We name them because “powered by AI” is not enough information for a family deciding what to share.

Anthropic Claude

Claude is the primary model behind Lumi’s coaching. Lumi sends the context needed to respond—such as the current message and relevant information from your family’s profile, assessments, strategies, or recent activity.

Lumi uses Anthropic through a commercial API account. Anthropic’s handling of API data is governed by the terms that apply to that account.

Voyage AI

Lumi uses Voyage AI to turn a chat query into an embedding—a numerical representation that helps Lumi find the most relevant material for a response. This means the text of the query is processed by Voyage AI for that purpose.

Google Gemini

Lumi uses Google Gemini to create spoken prompts for checklists. Lumi sends text for this purpose, which may include a child’s first name and motivational language connected to the checklist steps. Google returns the generated audio to Lumi.

Checklist audio does not record or send a child’s voice to Google. A child’s spoken or typed response is not part of this flow; the parent remains in control of what Lumi receives and sends.

Does Lumi train its own AI model on my family?

No. Lumi does not train a general-purpose AI model on your family’s chats or profiles.

Lumi does use information from a household to keep guidance consistent with that household’s own history—for example, whether a strategy was tried before or what happened next.

Can AI-generated guidance be wrong?

Yes. AI-generated guidance can be incomplete, inaccurate, or a poor fit for the moment. Lumi is designed to offer practical ideas and help caregivers think through situations—not to make decisions for your family.

Lumi is not a diagnostic tool, medical care, therapy, or emergency support. For concerns about a child’s health, development, safety, or wellbeing, use qualified professional or emergency support.

What information does Lumi ask for?

Enough context to be useful. Not every detail available.

Depending on the features you use, Lumi may ask for:

  • a caregiver’s first name, email address, phone number, profile picture, and notification preferences;
  • a child’s first name and birth month and year;
  • behavioral assessment responses and executive-function scores;
  • neurological context a parent chooses to provide;
  • the situations a family wants help with;
  • chats, strategies, routines, checklists, and feedback about what worked;
  • a caregiver’s voice input when voice features are used; and
  • files or images a caregiver chooses to upload where uploads are available.

What does Lumi deliberately avoid asking for?

Current child-profile forms ask for a child’s first name and birth month and year—not a last name, grade, or day of birth. Some historic child-profile records may still contain a grade that Lumi collected previously; grade is not requested in the current product experience.

Lumi does not ask for a family’s physical home address or government identifiers as part of its household or coaching profiles. If you choose a paid plan, Stripe may collect billing information through its own checkout.

Free-text fields can contain information you choose to write. Please do not include passwords or government identifiers in those fields.

How is the information protected?

Protection starts with boundaries, not adjectives.

Information sent between your device, Lumi, and the providers that help operate the service is encrypted in transit.

Lumi uses MongoDB Atlas as its primary application database. Authentication is handled by Clerk. Uploaded files use managed object storage. Each provider has its own role; no single provider operates the whole experience.

We do not describe any system as perfectly secure. Security is a continuing practice: limiting access, keeping software current, reviewing how data moves, correcting weak points, and being direct when a control is not yet where it needs to be.

Who handles payment information?

Stripe handles card and billing details through its hosted checkout. Lumi stores the Stripe customer and subscription identifiers needed to manage your plan, along with subscription status and period information. Lumi does not store your card number or security code.

What happens to files I upload?

A file should follow the same boundaries as the conversation it belongs to.

Lumi checks access before serving files linked to a private coaching conversation. Access to a file is not granted solely because someone has a storage link.

Lumi limits the document types it accepts while private file handling continues to mature. Unless a feature explicitly asks for a record and explains why, do not upload neuropsychological evaluations, IEPs, medical records, government identifiers, or other documents containing information Lumi does not need.

When a current file-deletion workflow runs, Lumi records work to remove the associated stored object rather than only hiding the file’s reference in the app.

Does Lumi use analytics or advertising tools?

We measure how the experience works while protecting inputs and designated private regions.

On permitted Lumi marketing pages and in the App, PostHog helps us understand navigation, acquisition funnels, interactions, performance, errors, and where a flow is not working as intended. Analytics can include pseudonymous device and session identifiers, referrer and campaign attribution, page context, and click or form-submission structure.

PostHog session replay may run on customer-facing marketing pages and in the App. Lumi masks all form-input values and editable text surfaces, blocks regions explicitly marked as protected, and removes credentials and query strings from captured URL attributes and network metadata. Ordinary non-input text may remain visible so a replay has enough context to diagnose a broken journey; on marketing and App pages, that can include names or family context rendered on screen. The following route exclusions apply only to the marketing site. Direct visits to internal administration, studio, test, and debug pages do not initialize PostHog. After client-side navigation to an excluded internal page, Lumi stops replay, clears queued telemetry, and discards rather than sends telemetry for that page.

Lumi may use Meta’s advertising tools only on paid campaign landing pages under /c/*. The browser integration measures page visits and lead actions; it does not send a signup or completed-registration event.

If you have a question about an analytics or advertising tool, email us for the current information about that integration.

How long does Lumi keep information?

Different information needs different limits.

Lumi does not apply one retention period to every kind of information. Account records, coaching history, uploaded files, analytics, billing records, logs, and provider-held information serve different purposes and may have different limits.

If you have a question about a particular type of information, email us and we will answer it directly.

We will not publish a precise retention promise here until the systems enforcing it match the words.

Can I access, correct, or delete our information?

You can ask a person, not only navigate a settings screen.

You can update many profile details inside Lumi. You can also ask us to access, correct, or delete information associated with your family by emailing hey@withlumi.ai.

Some requests may require us to verify that you are authorized to act for the household. We will explain the scope of the request, what has been completed, and whether any information must remain for billing, security, legal, backup, or provider-retention reasons.

We are continuing to make these controls more complete and easier to use without needing to email us.

Private beta · Last reviewed September 10, 2026

We are building trust at the same time we are building Lumi.

Lumi began as a small team working directly with early families. That makes it possible to answer questions personally and change the product quickly. It also means we should not present ourselves as if we have the processes or certifications of a mature healthcare or enterprise platform.

In place today

  • Household boundaries that prevent families from accessing one another’s information
  • Private adult caregiver chats within a household
  • Named AI, authentication, storage, analytics, communication, and billing providers
  • Encryption in transit
  • Stripe-hosted card and billing collection
  • PostHog input and editable-text masking, protected-region blocking, URL-credential removal, internal-route initialization exclusion, and replay stop plus telemetry discard on navigation to an excluded internal page
  • Direct access to the people building and supporting Lumi

Still maturing

  • More granular internal access roles and stronger access auditability
  • Easier self-service access, export, correction, and deletion controls
  • Automated retention and deletion across every internal and provider system
  • Formal incident-response and security-review processes
  • Independent security and privacy reviews as Lumi grows

What we do not claim

Lumi does not claim SOC 2 or ISO 27001 certification, HIPAA compliance, diagnosis, therapy, or emergency support. We do not claim that any internet service can eliminate every risk.

When our practices change, we will update this page and its review date. If something here does not match what you experience in the product, tell us.

Questions families ask us

Can my co-parent read my coaching chats?

No. A chat started by one adult caregiver is private from other adult caregivers in the household.

Can my child talk to Lumi directly?

No. Lumi is parent-led. Children do not have a direct login, chat, or assessment experience in the currently enabled product. A child may hear generated prompts while following an audio-supported checklist, but Lumi does not record or receive the child’s voice or typed responses through that experience.

Does Anthropic train Claude on our conversations?

Lumi uses Anthropic through a commercial API account. Anthropic’s handling of API data is governed by the terms that apply to that account. Lumi does not train a general-purpose Lumi model on family conversations.

Do other AI providers receive information?

Yes. Voyage AI processes chat-query text to help retrieve relevant context. For checklist audio, Google Gemini receives text—which may include a child’s first name and motivational checklist content—and returns a spoken prompt. It does not receive a recording of the child’s voice through this flow.

Does Lumi sell our family’s information?

Lumi does not sell family profiles, chats, assessments, or coaching information to data brokers or advertisers. Meta advertising tools, when used, are limited to paid campaign landing pages under /c/* and do not generate coaching or determine a family’s strategies.

Does Lumi use our family to train its own model?

No. Lumi does not train a general-purpose AI model on family profiles or conversations. Information from your family may be used within your household to keep guidance consistent with your own history.

Where is our information stored?

Lumi uses managed providers, including MongoDB Atlas for primary application data and managed object storage for uploaded files. Our Privacy Policy lists the providers involved. Contact us if you need current information about a particular provider or processing location.

Is Lumi HIPAA compliant?

Lumi is a behavioral coaching product and does not claim HIPAA compliance. We still treat behavioral and neurodevelopmental information as sensitive and design our practices around the trust families place in us.

Does Lumi diagnose ADHD or autism?

No. Lumi does not diagnose. A diagnosis is not required to use Lumi. Its assessments and guidance are informational and educational, not clinical instruments or professional care.

What should I do in an emergency?

Do not use Lumi for emergency or crisis support. Contact local emergency services or an appropriate qualified professional.

Who should I contact with a privacy or security question?

Email hey@withlumi.ai. Your question will reach the Lumi team rather than an outsourced support center.

A question we have not answered?

Ask us before you decide what to share.

A page can answer the questions families ask most often. It cannot anticipate every concern or every family’s circumstances.

If you want to understand a specific provider, feature, data flow, or control, email us. Thoughtful questions make Lumi more accountable—and better for every family using it.