Lumicura is in soft launch.  Founding-school program open through August 2026. See terms →
Legal

Privacy policy

Plain language, no surprises. This is the full version of the privacy summary on our security page — the same commitments, spelled out.

v1.3 · effective Jul 28, 2026

The version and effective date above reflect the current release. If anything here conflicts with a separately signed agreement between your organization and Lumiqosophy, LLC, that signed agreement controls.

Plain-language summary

Lumicura collects only the family-directory information a parent organization needs to run — contact details, who's signed up for which volunteer shift, that sort of thing. That's it.

  • We don't sell your data, and we don't share it for advertising.
  • We don't train machine-learning models on it.
  • We don't touch student grades, attendance, or health information — those stay in your school's student information system (SIS), where they belong.

The rest of this page is the detailed version of those promises.

What we collect

To run a parent organization, we collect:

  • Family contact information — names, email addresses, phone numbers, and the relationships within a family unit.
  • Opt-in mobile push tokens — only if you choose to enable push notifications on your device.
  • Announcements you've read — so we can show you what's new without re-notifying you about old news.
  • Volunteer shifts you sign up for — what you committed to, and when.
  • Commitment-point activity tied to your family — the volunteer-hour and participation records your parent organization tracks.
  • Messages you send — the announcements, class and committee chats, and direct messages you post through the service.
  • Operational and diagnostic data — device and browser type, approximate location (city and region, derived from a shortened IP address that we do not store in full), app version, and error and performance logs. Alongside these we record first-party product-usage analytics: pages viewed, and interactions with things we have deliberately marked for measurement, such as which call-to-action was clicked or where a pricing slider came to rest. Inside the signed-in product these are recorded against your school and a pseudonymous account identifier — a random code, not your name or email — so we can tell how many distinct people used a feature rather than only how many times it was used. We use these to keep the service secure and reliable and to see which features earn their place.

Nothing else is pulled from the school's data. We never touch student grades, attendance, or health records.

What we do NOT collect

  • No advertising trackers. None, anywhere.
  • No third-party analytics or advertising pixels. No Google Analytics, no ad networks — inside the app or on our marketing pages.
  • No data brokers. We don't buy, enrich, or sell profiles.

We do collect first-party operational telemetry and product-usage analytics — both on our marketing pages and inside the signed-in product — using Microsoft Application Insights and our own platform metrics. We use it only to keep the service reliable and secure and to see which features earn their place; we never sell it, share it with advertisers, or use it to build cross-site profiles. See Cookies & analytics for the details.

How we use information

We use the information above solely to operate the service for your parent organization:

  • Maintaining the family directory and keeping it accurate.
  • Delivering announcements, reminders, and — if you opt in — push and SMS notifications (reply STOP to opt out of texts).
  • Coordinating volunteer shifts and tracking commitment-point activity.
  • Securing accounts, preventing abuse, and keeping an audit trail of state-changing actions.
  • Monitoring reliability, performance, and security, and diagnosing errors.
  • Screening messages for safety through automated content moderation (see Automated processing & AI).
  • Providing support when you or your administrators ask for it.

We do not use your information for advertising, profiling, resale, or model training.

Sharing & subprocessors

We never sell or share data for advertising — full stop.

We use a deliberately short list of subprocessors to run the service (cloud hosting, transactional email and SMS, payment processing, AI content moderation and knowledge-base search, and operational telemetry). The current list, with the 30-day notice we give before adding any new one, lives on our trust page.

Data residency

Customer data is stored in the United States by default. We run on mainstream US-region infrastructure (Microsoft Azure), with strict per-school isolation. Cross-border transfer only comes up for district- or diocese-level customers with affiliated international schools, and is governed by the standard contractual clauses in the DPA.

Retention

We keep family-directory information for as long as your organization maintains an active account and the data is needed to run it. When a family or an organization leaves, the controlling organization can export or delete the relevant data, and we remove it from active systems on request.

Concretely: after an account is cancelled the controlling organization keeps a 90-day read-only window to retrieve data, after which we delete it from active systems and let encrypted backups age out on our standard backup-retention cycle. Operational and diagnostic logs are kept only as long as needed to run and secure the service. Where law requires us to retain certain records longer — billing records, for example — we keep only what is required.

On cancellation or wind-down, the data-handling, read-only access window, and export commitments described in the DPA apply.

Your rights

You can access, correct, delete, and export your data — within 30 days, at no charge.

  • Tenant administrators can self-serve most of these directly in the app.
  • For anything that can't be self-served, email privacy@lumicura.org and we'll handle it.

Because your organization is the controller, requests about its records may be routed through it — but we'll always help.

US state privacy rights

Because your organization is the controller, most rights requests run through it — but here is how US state privacy laws apply to the data we hold.

California (CCPA/CPRA). In the past 12 months we have collected these categories of personal information: identifiers (name, email, phone, mailing address), commercial information (subscription and, where applicable, transaction records), internet or network activity (operational and diagnostic logs), and your own content (messages you post). We collect it from two sources: you, and your organization. We use it only for the purposes described on this page, and we disclose it only to the service providers that help us run the service — cloud hosting, email/SMS delivery, payment processing, AI moderation and knowledge-base search, and telemetry (see our trust page) — never to advertisers or data brokers.

We do not sell or share personal information — including for cross-context behavioral advertising — and we have not done so in the past 12 months. We do not use or disclose sensitive personal information beyond the purposes CCPA permits for a service provider, so the "limit the use of my sensitive personal information" right does not apply; and because we never sell or share, the CCPA rules for consumers under 16 do not come into play. We retain each category only as long as needed for the purpose it was collected and as described under Retention. California residents have the right to know, delete, correct, and limit, and we will not discriminate against you for exercising them.

Other states. Residents of Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws have comparable rights to access, correct, delete, and obtain a copy of their data, and to appeal a declined request. Exercise any of these — or use an authorized agent — by emailing privacy@lumicura.org. We verify requests before acting and respond within the timeframe the applicable law requires.

Do Not Track & Global Privacy Control. We don't track visitors across third-party sites, so there's nothing to sell or share and nothing to opt out of on that front. We honor Global Privacy Control (GPC) and Do Not Track signals anyway: when either is present, we do not start analytics at all — on our marketing and help pages or inside the signed-in app — so no cookie is written and no measurement is sent. See Cookies & analytics.

Children's data, COPPA & FERPA

Lumicura holds family-directory information, not student academic records. Where any field touches student-adjacent data, Lumicura is configured to act as a "school official" with a "legitimate educational interest" under FERPA — a tool the school uses to coordinate its parent community.

COPPA. Lumicura is not directed to children, and we do not knowingly collect personal information from children under 13 for our own purposes. Where a child under 13 appears in the service — typically just a first name and grade that tie a family to the roster — that information is almost always entered by the child's own parent or guardian, who thereby provides the parental consent the Children's Online Privacy Protection Act contemplates. Where instead a school deploys the service and supplies roster data directly, the school provides that consent as the parent's agent, for the school-authorized educational purpose. In either case a parent or the school may, on request, review the information we hold about a child, have it deleted, and prevent its further collection, and we do not condition a child's participation on disclosing more than is reasonably necessary.

No commercial use of student data. Consistent with California's SOPIPA and similar state student-privacy laws, we do not sell student data, use it for targeted advertising, or build student profiles for any non-educational purpose. We will sign the SDPC National Data Privacy Agreement (NDPA) or a state-specific student-data-privacy addendum on request — email privacy@lumicura.org.

We are never the parent-facing record system. Grades, attendance, and health records stay in the school's SIS. We support a BAA on District / Diocese plans for organizations that prefer the stricter posture.

Cookies & analytics

Inside the signed-in product we use only the cookies required to keep you logged in and secure — no advertising or cross-site tracking cookies.

For analytics we use Microsoft Application Insights and our own first-party platform metrics, both on our public marketing pages and within the product. This tells us the app is up, where it's slow, and which features are actually used. There are no Google Analytics tags, no advertising pixels, and no third-party trackers anywhere.

The cookies this sets. Three first-party cookies, on our own domains only:

  • ai_user — a random identifier that lets us tell a returning visitor from a new one. It expires after a year.
  • ai_session — groups one sitting into a single visit. It expires after 30 minutes of inactivity.
  • ai_authUser — set only once you are signed in to the app, so we can tell that a sequence of actions came from one account. It holds a pseudonymous account code and your school's code — never your name or email — and it is deleted when you sign out.

None of them contains your name, your email address, or anything derived from them: the first two hold a random code and a timestamp, and the third holds internal codes that mean nothing outside our systems. They are not readable by any other website, and we do not use them to follow you anywhere else — the only two properties involved are this site and the Lumicura app itself.

How to opt out. If your browser sends a Global Privacy Control or Do Not Track signal, we do not start analytics at all — on our marketing and help pages or inside the app: no cookie is written and no measurement is sent. Nothing to click, and nothing to opt back into.

Automated processing & AI

Two features rely on an AI subprocessor (Anthropic):

  • Content moderation. Messages may be screened by an automated classifier to catch harassment, unsafe content, and spam before they reach other families. Some messages are screened as they're sent; others are sampled afterward.
  • Knowledge-base search. When a parent asks a question in plain language, the question and the relevant excerpts from your school's own documents are processed to generate a cited answer.

Content sent to Anthropic for these purposes is not used to train AI models. Automated moderation supports human review; we do not use it on its own to make legal or similarly significant decisions about a person.

Changes to this policy

We may update this policy as the product evolves. For material changes, we announce them to super-admins 30 days in advance so there are no surprises. The version and effective date at the top of this page always reflect the current release.