PRIVACY POLICY
Last Updated: July 24, 2026
This Privacy Policy describes how Lumena Systems, Inc. (“we”, “us”, or “our”) handles personal information that we collect through our websites on which a link to this Privacy Policy is displayed, through our marketing initiatives, and when you apply for a job with us (collectively, the “Service” or “Services”).
This Privacy Policy does not apply to our handling of personal information that we process on behalf of our business customers. Our processing of that personal information is governed by the agreements we have with our business customers.
Supplemental notice for the Lumena Health EHR platform and mobile application
Scope of this supplemental notice. This section supplements the Privacy Policy above by describing the data practices of the Lumena Health electronic health record platform and mobile application (collectively, the “Lumena Health Platform”). The Lumena Health Platform is intended for authorized workforce members of healthcare organizations that are Lumena customers and is not offered directly to patients or the general public.
When Lumena processes information, including protected health information (“PHI”), on behalf of a healthcare organization (collectively, “Customer Data”), Lumena acts as a service provider and, where applicable, as a business associate under the Health Insurance Portability and Accountability Act (“HIPAA”). That processing remains governed by our agreement and, where applicable, business associate agreement with the healthcare organization. This supplemental notice is not a healthcare provider’s HIPAA Notice of Privacy Practices. Patients and their representatives should review the Notice of Privacy Practices provided by their healthcare organization and direct requests concerning their health records to that organization.
Information processed through the Lumena Health Platform
Depending on the features used by a healthcare organization and its authorized users, the Lumena Health Platform may process:
- Account and organization information, such as an authorized user’s name, work email address, organization, professional role, branch or team assignments, permissions, authentication identifiers, and account status.
- Electronic health record and clinical information, including patient names and identifiers, contact and demographic information, insurance information, diagnoses, medications, orders, care plans, assessments, visit schedules, clinical observations, signatures, visit notes, and other information imported from, entered into, or generated through a healthcare organization’s records and workflows. This information may constitute PHI.
- Visit and electronic visit verification information, including visit dates and times, check-in and check-out events, clinician assignments, and, when the user grants location permission, a precise or approximate point-in-time location and location accuracy at check-in or check-out. The mobile application does not collect location continuously or in the background.
- Visit recordings, transcripts, and draft documentation. When an authorized user affirmatively starts the recording feature after confirming that the patient and other participants have consented, the mobile application captures visit audio. Lumena processes the audio to create a transcript and clinician-reviewable draft documentation, suggestions, supporting excerpts, and related quality or confidence information. The user remains responsible for reviewing and approving clinical documentation.
- Medication-label images. When an authorized user chooses the medication-photo feature and grants camera permission, the mobile application captures images of medication labels and processes them to propose medication information for clinician review. The application does not require access to the user’s photo library.
- Device, application, security, and audit information, such as device and operating-system type, application version, IP address, session and authentication events, feature interactions, synchronization status, error and diagnostic information, access logs, auditable actions taken in the Lumena Health Platform, and device motion information used to support reliable audio recording during an active recording.
- Information stored on the device, such as authentication tokens, encrypted offline EHR data, pending synchronization operations, and encrypted source recordings or medication images awaiting secure upload and processing. Device biometric authentication is performed by the device operating system; Lumena does not receive or store a user’s fingerprint, face image, or biometric template.
How information is collected
Information is provided by authorized users and their healthcare organizations; received from electronic health records, pharmacy or medication data sources, and other systems the healthcare organization directs us to connect; generated through use of the Lumena Health Platform; or collected from the user’s device after the user grants the applicable permission. The mobile application requests microphone, camera, and foreground location access only when needed for the corresponding feature.
How information is used
We process information through the Lumena Health Platform to:
- Authenticate authorized users and apply organization, role, and permission controls.
- Provide, synchronize, and maintain electronic health records, clinical workflows, visit documentation, medication workflows, and electronic visit verification.
- Transcribe consented visit recordings and generate draft documentation and suggestions for clinician review.
- Process medication-label images and propose extracted medication information for clinician review.
- Support encrypted offline use and synchronize authorized changes when connectivity is available.
- Maintain security, prevent unauthorized access, troubleshoot errors, monitor availability, preserve audit trails, and support our customers and their authorized users.
- Comply with applicable law and our contractual obligations to healthcare organizations.
We do not sell PHI or other Lumena Health Platform data, use it for targeted advertising, or disclose it to advertising networks or data brokers. We do not use patient information for independent marketing purposes.
Artificial intelligence and transcription processing
To provide transcription, medication-image processing, and clinician-reviewable drafting features, relevant audio, transcripts, images, and clinical context may be disclosed to third-party transcription, cloud infrastructure, and artificial intelligence service providers acting on our behalf. We limit this processing to providing and securing the Lumena Health Platform and require contractual safeguards appropriate to the sensitivity of the information, including HIPAA business associate terms where required. Artificial intelligence output is a draft or suggestion and is not a substitute for the independent professional judgment of an authorized clinician.
How information is disclosed
Information processed through the Lumena Health Platform may be disclosed:
- To the healthcare organization that provided the user’s access and to its authorized workforce members, according to their roles and permissions.
- To service providers and subprocessors that support cloud hosting, secure storage, authentication, transcription, artificial intelligence processing, communications, application monitoring, support, and security. These providers may access information only as necessary to perform services for us and are required to protect it through contractual and other safeguards appropriate to the information.
- To connected systems, such as a healthcare organization’s electronic health record or other integration, at the healthcare organization’s direction.
- For legal, safety, and compliance purposes when required by law or permitted by the applicable customer agreement and business associate agreement.
Permissions and user choices
An authorized user may decline or revoke microphone, camera, or location permission through device settings. Declining microphone access prevents visit recording and transcription, but the user may document a visit manually. Declining camera access prevents medication-label capture, but the user may enter medication information manually. Declining location access prevents a location stamp from being added, but the application permits check-in and check-out without it. Revoking a permission does not delete information that was previously collected and incorporated into the healthcare organization’s records.
User accounts are created and administered by the healthcare organization. Authorized users should contact their organization to deactivate an account or request access to or correction of account information. Patients and their representatives should direct requests concerning access, amendment, restriction, deletion where applicable, or an accounting of disclosures of PHI to the healthcare organization responsible for the record. We assist healthcare organizations with those requests as required by our agreements and applicable law.
Retention and deletion
We retain EHR data, visit recordings, transcripts, draft and finalized documentation, audit records, and related information according to the healthcare organization’s instructions, our agreements with that organization, applicable legal and clinical-record requirements, and our retention policies. Source medication-label images stored for processing are configured to be deleted from our cloud storage within seven days; extracted medication information that an authorized clinician accepts may become part of the EHR. Encrypted source media stored on the mobile device is deleted after successful upload and processing or pursuant to application cleanup procedures.
When our customer relationship ends, Customer Data is returned or deleted as provided in the applicable agreement and business associate agreement, subject to legal obligations and secure backup retention. Signing out ends the user’s authenticated session and closes access to the encrypted local database; uninstalling the application removes locally stored application data according to the device operating system. Neither action deletes records maintained for the healthcare organization.
Security of mobile and health information
In addition to the safeguards described in the “Security” section below, the Lumena Health Platform uses measures designed for sensitive health information, including encryption in transit and at rest, encrypted on-device storage, exclusion of locally stored PHI from device backups where supported, role-based access controls, automatic application locking, operating-system biometric or device-passcode authentication, audit logging, and controls designed to reduce disclosure through screen capture. No method of storage or transmission is completely secure.
Children and patient records
The Lumena Health Platform is intended for use by authorized adult healthcare workforce members and not by children as application users. A healthcare organization may use the Lumena Health Platform to maintain records concerning patients who are minors when permitted by law. Such patient information is processed on behalf of the healthcare organization under the applicable customer agreement and, where applicable, business associate agreement.
Personal information we collect
Information you provide to us:
- Contact information, such as your first and last name, email address, professional role, company name, and professional title.
- Feedback or correspondence, such as information you provide when you contact us with questions, feedback, or otherwise correspond with us online.
- Marketing information, such as your preferences for receiving our communications, and details about how you engage with our communications.
- Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Information we obtain from third parties:
- Social media information. We may maintain pages on social media platforms, such as LinkedIn, and other third-party platforms. When you visit or interact with our pages on those platforms, the platform provider’s privacy policy will apply to your interactions and their collection, use, and processing of your personal information. You or the platforms may provide us with personal information about you through the platform, and we will treat such information in accordance with this Privacy Policy.
- Other sources. We may obtain personal information from other third parties, such as marketing partners, publicly-available sources, and data providers.
Automatic data collection. We and our service providers may automatically log information about you, your computer or mobile device, and your interactions over time with our website, our communications and other online services, such as:
- Device data, such as your computer’s or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type (e.g., phone, tablet), IP address, unique identifiers, language settings, mobile device carrier, radio/network information (e.g., WiFi, LTE, 4G), and general location information such as city, state or geographic area.
- Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, browsing history, navigation paths between pages or screens, information about your activity on a page or screen, access times, and duration of access.
- Email open/click information. We may use pixels in our email campaigns that allow us to collect your email and IP address as well as the date and time you open an email or click on any links in the email that we may send to you.
We use the following tools for automatic data collection:
- Cookies, which are text files that websites store on a visitor’s device to uniquely identify the visitor’s browser or to store information or settings in the browser for the purpose of helping you navigate between pages efficiently, remembering your preferences, enabling functionality, and helping us understand website user activity and patterns. For example, Google Analytics collects information about how users use our website, which we then use to compile reports that disclose trends without identifying individual visitors, and help us improve our website. For more information on Google Analytics, click here.
- Local storage technologies, like HTML5, that provide cookie-equivalent functionality but can store larger amounts of data, including on your device outside of your browser in connection with specific applications.
- Web beacons, also known as pixel tags or clear GIFs, which are used to demonstrate that a webpage or email was accessed or opened, or that certain content was viewed or clicked.
How we use your personal information
Providing our Services. We use personal information to operate, maintain, and provide you with our Services.
To communicate with you. We use personal information to respond to your requests, provide customer support, and otherwise communicate with you about our Services, including by sending announcements, surveys, updates, security alerts, and support and administrative messages.
To improve, monitor, and personalize our Services. We use personal information to improve our Services, including by understanding your needs and interests, and personalizing your experience with the Services and our communications.
For research and development. We may use your personal information for research and development purposes, including to analyze and improve our Services and our business. As part of these activities, we may create aggregated, de-identified, or other anonymous data from personal information we collect. We may use this data and disclose it to third parties for our lawful business purposes, including to analyze and improve our Services and promote our business.
Direct marketing. We may from time-to-time send you direct marketing communications as permitted by law, including, but not limited to, newsletters, and updates on news and events. You may opt out of our marketing emails as described in the “Opt out of marketing communications” section below.
For interest-based advertising. We may engage advertising partners, including third party advertising companies and social media companies, to display ads around the web. These companies may use cookies and similar technologies to collect information (including the automatically-collected data described above) about your interactions over time across our website, our communications, and other online services, and use that information to serve online ads that they think will interest you.
Compliance and protection. We may use personal information to comply with legal obligations, and to defend our company against legal claims or disputes, including to:
- Comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.
- Protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims).
- Audit our internal processes for compliance with legal and contractual requirements and internal policies.
- Enforce the terms and conditions that govern our website.
- Prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.
How we disclose your personal information
Service providers. We may disclose your personal information to third party companies and individuals that provide services on our behalf or help us operate our Services (such as lawyers, bankers, auditors, insurers, customer support, hosting, analytics, email delivery, marketing, and database management).
Authorities and others. We may disclose your personal information to law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.
Advertising partners. Third party advertising companies, including for the interest-based advertising purposes described above.
Business transfers. We may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business transaction (or potential business transaction) such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution. In such a case, we will make reasonable efforts to require the recipient to honor this Privacy Policy.
Your privacy rights and choices
Opt out of marketing communications. You may opt out of marketing-related emails by following the opt-out or unsubscribe instructions contained in the marketing communication we send you. You may continue to receive service-related and other non-marketing emails.
Limit online tracking. There are a number of ways to limit online tracking, which we have summarized below. Please note that these tools are not associated with us and we cannot guarantee that they work as their providers advertise them:
- Blocking cookies in your browser. Most browsers let you remove or reject cookies. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. For more information about cookies, including how to see what cookies have been set on your device and how to manage and delete them, visit https://www.allaboutcookies.org/.
- Using privacy plug-ins or browsers. You can block our websites from setting cookies by using a browser with privacy features, like Brave, or installing browser plugins like Privacy Badger, Ghostery, or uBlock Origin, and configuring them to block third party cookies/trackers. You can also opt out of Google Analytics by downloading and installing the browser plug-in available at: https://tools.google.com/dlpage/gaoptout.
- Advertising industry opt out tools. You can also use these opt out options to limit use of your information for interest-based advertising by participating companies:
- Digital Advertising Alliance for Websites: optout.aboutads.info and https://www.aboutads.info/appchoices (for mobile opt outs);
- Network Advertising Initiative: optout.networkadvertising.org
- Platform Opt-Outs. You can also use the opt-out features offered by third-party advertising platforms, such as:
Note that because these opt-out mechanisms are specific to the device or browser on which they are exercised, you will need to opt out on every browser and device that you use.
Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
Other sites, mobile applications and services
Our website may contain links to other websites, mobile applications, and other online services operated by third parties. These links are not an endorsement of, or representation that we are affiliated with, any third party. In addition, our content may be included on web pages or in mobile applications or online services that are not associated with us. We do not control third party websites, mobile applications or online services, and we are not responsible for their actions. Other websites and services follow different rules regarding the collection, use and disclosure of your personal information. We encourage you to read the privacy policies of the other websites and mobile applications and online services you use.
Security
We employ a number of technical, organizational, and physical safeguards designed to protect the personal information we collect. For example, our personnel receive adequate training on our internal privacy and data security policies, consistent with our obligations under applicable law, we limit access to your data to personnel based on role, and we protect personal information in-transit and at rest using encryption and other security measures. However, no security measures are failsafe and we cannot guarantee the security of your personal information.
Retention of personal information
Where required under applicable laws, we retain personal information only for as long as is necessary to fulfill the purposes for which it was collected and processed, in accordance with our retention policies, and in accordance with applicable laws and regulatory obligations.
To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of personal information, the purposes for which we use personal information and whether we can achieve those purposes through other means, and the applicable legal and regulatory requirements.
Job applicants
When you apply for one of our open positions, we collect the information that you provide in connection with your job application. This includes but is not limited to business and personal contact information, professional credentials and skills, educational and work history, and other information that may be included in a resume or that you may provide during the interview process. This may also include demographic or diversity information that you voluntarily provide. We may also conduct background checks and receive related information. We also collect personal information from other sources where relevant for your application, such as employment research firms, recruiters, identity verification services, and information that you make publicly available on websites or social media platforms (for example, LinkedIn).
Throughout the recruitment process, we may supplement your personal information in connection with the assessment of your application. For example, we may record the views of those considering your application about your suitability for the role for which you have applied and retain interview notes. If you accept an offer from us, your personal information will be incorporated into and used as part of your employee record.
We use applicants' information to facilitate our recruitment activities, process employment applications and personalize candidate communication, including evaluating candidates and monitoring recruitment statistics. We also use successful applicants' information to administer the employment relationship. We may also use and disclose applicants' information to improve our Services and for the compliance and protection purposes described above.
Children
Our website is not intended for use by children under 18 years of age. If we learn that we have collected personal information through the website from a child under 18 without the consent of the child’s parent or guardian as required by law, we will delete it.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the website.
How to contact us
Please direct any questions or comments about this Policy or our privacy practices to admin@lumena.ai