Contents
LumaCare is a care coordination platform for families and caregivers of loved ones who need support. This privacy policy describes how we collect, use, and protect personal data when you use our service.
Data controller: Tvermose IT, Denmark.
Contact: info@lumacare.dk
We process the following categories of personal data:
All data is stored within the European Union on Microsoft Azure infrastructure. Data is encrypted at rest and in transit. Access is restricted to authenticated family members and their authorised helpers.
We use the following third-party processors:
You can choose to connect a Google Calendar or Microsoft Outlook calendar so your shifts and appointments stay in sync with it. Connecting is optional, is done by each person for themselves, and can be undone at any time.
When you connect a calendar, we access:
We use this data only to provide calendar sync:
The access tokens that let us reach your calendar are encrypted at rest, with the encryption keys protected in Azure Key Vault. For synced events we store only identifiers and a fingerprint used to detect changes, not a copy of your calendar. Events you import become ordinary LumaCare appointments.
Disconnecting. When you disconnect a calendar, we revoke LumaCare's access with Google and delete the stored tokens and sync records. If LumaCare created the calendar, you can also choose to remove the events we added to it. Appointments that were already imported stay in LumaCare until you delete them. Deleting your LumaCare account disconnects all your calendars in the same way. Microsoft does not let apps revoke their own access, so for Outlook we delete our tokens and you can remove LumaCare from your Microsoft account's app permissions. You can also remove LumaCare's Google access yourself at any time at myaccount.google.com/permissions.
LumaCare's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Your data is retained for as long as your account is active. You can delete your account at any time from Account settings inside the app, or by contacting us at info@lumacare.dk.
When you delete your account it is locked immediately and permanently deleted 30 days later. During those 30 days you can restore it by signing in; afterwards it cannot be recovered. On deletion we erase your name, email address, profile picture, preferences and notification tokens.
Care records you created inside a family that continues to exist — care events, medication administration records, messages and posts — remain with that family as part of its shared care history, shown as written by a deleted user rather than by you. If a family is deleted along with your account, its data, including documents, photos, video clips and audio clips in our storage, is deleted with it. Consent and audit records are retained without your personal identifiers, because we are required to be able to demonstrate that consent was given and withdrawn.
Photos, video clips and audio clips are deleted from our storage when you remove them from a memory or delete the memory. A video upload that is cancelled or interrupted before it finishes is deleted automatically within 24 hours.
Your sign-in identity is held by Microsoft Entra External ID. Deleting your LumaCare account releases the link to it, but does not by itself delete the Microsoft account you signed in with.
Under GDPR you have the right to:
You can exercise the right to erasure yourself at any time from Account settings inside the app — see "Data retention" above for exactly what is deleted and what is retained. To exercise any of the other rights, contact us at info@lumacare.dk.
Inside the LumaCare app we use browser local storage and session state solely to maintain your authenticated session and UI preferences, and to remember that a video upload was in progress so we can tell you if it was interrupted. No third-party advertising or tracking cookies are used in the app.
On our public website (the pages you can see without signing in) we ask for your permission before using Google Ads cookies. If you accept, Google Ads measures which of our ads led you to the website, and we remember the ad click in a first-party cookie for up to 90 days. If you then create an account, we store that click identifier with your account and report back to Google Ads when the account is created, when your family logs its first entry, and when a subscription is paid. These reports contain only the click identifier, the type of milestone, its time and an estimated value — never your name, email address, or any information about the person you care for. Ad personalisation (remarketing) is always switched off.
If you decline, no Google cookies are set and nothing is reported. You can change your choice at any time via "Cookie settings" at the bottom of every public page. Your choice itself is stored in a cookie for 180 days. The click identifier is deleted from our systems when your account is deleted.
Separately, and without cookies, we count visits to our public website. When you open one of these pages, our server turns your IP address and browser type into an anonymous code using a random key that is kept only in memory and replaced every day, so the code cannot be traced back to you or linked to your visits on other days. We record that code together with the page you viewed, its language, your type of device, your country, and the website or campaign that brought you to us. Your IP address itself is not stored. We use this only to see how many people visit our pages and how they find us, based on our legitimate interest in understanding how our website is used. It is not used inside the app and is never shared with advertisers.
We may update this policy from time to time. Significant changes will be communicated via the app or by email. The date at the top of this page indicates when it was last revised.
For any privacy-related queries contact info@lumacare.dk.
You also have the right to lodge a complaint with your national data protection authority. In Denmark: Datatilsynet.