Legal & Privacy

Privacy Policy

Last updated: 2026-09-18

Contents

1

Who we are

LumaCare is a care coordination platform for families and caregivers of loved ones who need support. This privacy policy describes how we collect, use, and protect personal data when you use our service.

Data controller: Tvermose IT, Denmark.
Contact: info@lumacare.dk

2

What data we collect

We process the following categories of personal data:

  • Account data – name, email address, and authentication identifiers provided during sign-up.
  • Care recipient and family data – names, dates of birth, care notes, schedules, appointments, and event records you create.
  • Health-related data – care notes and event records may contain health information about your care recipient (Article 9 GDPR). We only process this data on your explicit instruction.
  • Usage data – anonymised logs of feature use for improving the platform. No personal identifiers are retained in logs.
  • Media uploads – photos, video clips and audio clips you upload to Memory events. Video clips are compressed on your own device (in the app or your browser) before they are uploaded; the original recording never leaves your device, and no third party processes the video.
  • Connected calendar data – only if you choose to connect a Google or Microsoft calendar. See "Connected calendars" below for exactly what we access and why.
3

Legal basis for processing

  • Contract – to deliver the service you have signed up for.
  • Explicit consent – for processing special-category health data about your care recipient (Article 9(2)(a) GDPR).
  • Legitimate interest – for platform security and abuse prevention.
4

How we store and protect your data

All data is stored within the European Union on Microsoft Azure infrastructure. Data is encrypted at rest and in transit. Access is restricted to authenticated family members and their authorised helpers.

5

Third-party services

We use the following third-party processors:

  • Microsoft Azure – cloud hosting, storage, and authentication (Microsoft Entra External ID).
  • Azure OpenAI Service – voice-to-event transcription and AI assistant features. Transcripts are not retained by the AI service beyond the request.
  • Stripe – payment processing. We do not store your payment card details. Stripe's privacy policy governs how Stripe processes your payment data.
6

Connected calendars (Google and Microsoft)

You can choose to connect a Google Calendar or Microsoft Outlook calendar so your shifts and appointments stay in sync with it. Connecting is optional, is done by each person for themselves, and can be undone at any time.

When you connect a calendar, we access:

  • Your list of calendars – their names, so you can choose which one to sync with. You can also let LumaCare create a separate calendar just for this.
  • Events on the calendar you choose – title, description, start and end time – so changes made in your calendar can be applied back in LumaCare.
  • Your account email address and account ID – so the app can show which account is connected.

We use this data only to provide calendar sync:

  • We write your family's shifts and appointments into the chosen calendar, and apply changes you make to those events back in LumaCare. A parent can set the family to minimise calendar detail, in which case only times and generic titles are written, with no names or notes.
  • If you turn on importing, upcoming events from that calendar are copied into LumaCare as appointments, visible to the family members who can see appointments. Like any other appointment, they can be used by the LumaCare AI assistant to answer questions you ask it (processed by Azure OpenAI, not retained beyond the request, and never used to train AI models).
  • We do not sell calendar data, use it for advertising, or share it with anyone except as needed to run the service, to keep it secure, or to comply with the law. LumaCare staff do not read your calendar data unless you ask us to, it is needed for security, or the law requires it.

The access tokens that let us reach your calendar are encrypted at rest, with the encryption keys protected in Azure Key Vault. For synced events we store only identifiers and a fingerprint used to detect changes, not a copy of your calendar. Events you import become ordinary LumaCare appointments.

Disconnecting. When you disconnect a calendar, we revoke LumaCare's access with Google and delete the stored tokens and sync records. If LumaCare created the calendar, you can also choose to remove the events we added to it. Appointments that were already imported stay in LumaCare until you delete them. Deleting your LumaCare account disconnects all your calendars in the same way. Microsoft does not let apps revoke their own access, so for Outlook we delete our tokens and you can remove LumaCare from your Microsoft account's app permissions. You can also remove LumaCare's Google access yourself at any time at myaccount.google.com/permissions.

LumaCare's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7

Data retention

Your data is retained for as long as your account is active. You can delete your account at any time from Account settings inside the app, or by contacting us at info@lumacare.dk.

When you delete your account it is locked immediately and permanently deleted 30 days later. During those 30 days you can restore it by signing in; afterwards it cannot be recovered. On deletion we erase your name, email address, profile picture, preferences and notification tokens.

Care records you created inside a family that continues to exist — care events, medication administration records, messages and posts — remain with that family as part of its shared care history, shown as written by a deleted user rather than by you. If a family is deleted along with your account, its data, including documents, photos, video clips and audio clips in our storage, is deleted with it. Consent and audit records are retained without your personal identifiers, because we are required to be able to demonstrate that consent was given and withdrawn.

Photos, video clips and audio clips are deleted from our storage when you remove them from a memory or delete the memory. A video upload that is cancelled or interrupted before it finishes is deleted automatically within 24 hours.

Your sign-in identity is held by Microsoft Entra External ID. Deleting your LumaCare account releases the link to it, but does not by itself delete the Microsoft account you signed in with.

8

Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time (without affecting prior processing)

You can exercise the right to erasure yourself at any time from Account settings inside the app — see "Data retention" above for exactly what is deleted and what is retained. To exercise any of the other rights, contact us at info@lumacare.dk.

9

Cookies and local storage

Inside the LumaCare app we use browser local storage and session state solely to maintain your authenticated session and UI preferences, and to remember that a video upload was in progress so we can tell you if it was interrupted. No third-party advertising or tracking cookies are used in the app.

On our public website (the pages you can see without signing in) we ask for your permission before using Google Ads cookies. If you accept, Google Ads measures which of our ads led you to the website, and we remember the ad click in a first-party cookie for up to 90 days. If you then create an account, we store that click identifier with your account and report back to Google Ads when the account is created, when your family logs its first entry, and when a subscription is paid. These reports contain only the click identifier, the type of milestone, its time and an estimated value — never your name, email address, or any information about the person you care for. Ad personalisation (remarketing) is always switched off.

If you decline, no Google cookies are set and nothing is reported. You can change your choice at any time via "Cookie settings" at the bottom of every public page. Your choice itself is stored in a cookie for 180 days. The click identifier is deleted from our systems when your account is deleted.

Separately, and without cookies, we count visits to our public website. When you open one of these pages, our server turns your IP address and browser type into an anonymous code using a random key that is kept only in memory and replaced every day, so the code cannot be traced back to you or linked to your visits on other days. We record that code together with the page you viewed, its language, your type of device, your country, and the website or campaign that brought you to us. Your IP address itself is not stored. We use this only to see how many people visit our pages and how they find us, based on our legitimate interest in understanding how our website is used. It is not used inside the app and is never shared with advertisers.

10

Changes to this policy

We may update this policy from time to time. Significant changes will be communicated via the app or by email. The date at the top of this page indicates when it was last revised.

11

Contact and complaints

For any privacy-related queries contact info@lumacare.dk.

You also have the right to lodge a complaint with your national data protection authority. In Denmark: Datatilsynet.