Privacy Policy
Last updated: August 24, 2026
This Privacy Policy explains how LumiiCare collects, uses, and protects information when you use getlumiicare.com and the LumiiCare platform (the “Service”). Because LumiiCare is used by home-care agencies, much of the data in the Service is entered by an agency about its own staff and clients; for that data, the agency is the controller and LumiiCare is a service provider/processor acting on the agency’s instructions.
1. Information we collect
- Account & agency information: names, email addresses, roles, agency details, and login credentials.
- Operational data your agency enters: caregiver and client records, schedules, visits, clock-in/out and location data, timesheets, credentials, invoices, and notes. This may include protected health information (PHI).
- Payment information: handled by our payment provider (Paystack). We receive limited details (e.g., card brand and last four digits, subscription status) but not your full card number.
- Usage & device data: log data, IP address, and basic analytics needed to run and secure the Service.
2. How we use information
- To provide, maintain, and improve the Service.
- To process subscriptions and payments.
- To send transactional messages (e.g., approvals, reminders, receipts).
- To provide the Lumii AI assistant’s answers and actions, on a minimum-necessary basis (see below).
- To secure the Service, prevent abuse, and meet legal obligations.
3. The Lumii AI assistant
Lumii answers operational questions and, on your confirmation, prepares actions. It reads only what the signed-in user is authorized to see, and we send the AI provider the minimum necessary data — it does not receive clinical/health details, and contact details are stripped from what the model sees. LumiiCare’s own software, not the AI, performs all money and hours calculations.
4. Service providers (subprocessors)
We use trusted providers to run the Service, including:
- Hosting & database — Vercel (frontend) and Railway (backend/database).
- Email delivery — Resend.
- Payments — Paystack.
- AI assistant — Anthropic (Claude).
We share only the data needed for each provider’s function, under appropriate agreements. Where PHI is involved, providers are engaged under terms that support the required protections.
5. Healthcare data (PHI) & HIPAA
Where your use involves PHI, LumiiCare acts as a business associate to your agency. A Business Associate Agreement (BAA) is available and, where applicable, should be in place before PHI is processed. We do not use PHI except to provide the Service and as permitted by that agreement and law.
6. Data retention & deletion
We keep data for as long as your account is active and as needed to provide the Service and meet legal obligations. On request or account closure, we will delete or return your data within a reasonable period, subject to legal retention requirements.
7. Security
We use industry-standard measures including encryption in transit, access controls, and audit logging. No system is perfectly secure, but we work to protect your information and to notify affected parties of incidents as required by law.
8. Your choices & rights
Depending on your location and role, you (or your agency) may request access, correction, export, or deletion of personal data. For data your agency controls, direct requests to your agency; we will assist as its processor. Contact us to exercise rights that apply to LumiiCare directly.
9. Cookies
We use essential cookies to keep you signed in and to operate the Service. We do not sell personal information.
10. Children
The Service is for business use by agencies and is not directed to children.
11. Changes & contact
We may update this policy and will post changes here. Questions or privacy requests? Email support@getlumiicare.com.