Your privacy and data security are our top priorities. Learn how we protect your mental health information.
This page explains what information we collect, why we collect it, how we protect it, and what choices you have. If you have questions, contact us at support@lumamh.ca.
Age Requirement: LumaMH is designed for people age 13 and older. If you are under 18, please use the app with parent or guardian consent.
We use technical and organizational safeguards to protect your information. No system is perfect, but we work continuously to keep your data safe:
Under GDPR, CCPA, and other applicable privacy laws, you have the following rights:
Contact us at support@lumamh.ca with "Privacy Rights Request" in the subject line.
We will respond within 30 days (GDPR) or 45 days (CCPA) and may require identity verification.
We work with trusted partners to provide core features:
International transfers: If data moves across borders, we use safeguards required by law.
Contact us if you need transfer details for your privacy review.
If you have questions about our privacy practices or want to exercise your data rights:
Email: support@lumamh.ca
Data Protection Officer: support@lumamh.ca
Response time: We aim to acknowledge privacy inquiries within 48 hours where practicable; completing a verified data-rights request follows the legal timelines above.
In the event of a breach affecting personal data, we will follow applicable notification requirements (including timelines such as GDPR’s 72-hour rule to supervisory authorities where it applies) and notify affected users when the law requires it. We maintain incident response procedures; insurance coverage, if any, is subject to our policies at the time of an incident.
We may update this privacy policy to reflect changes in our practices or applicable laws. Material changes will be communicated via email and/or prominent notice on our platform at least 30 days before taking effect. Continued use after changes indicates acceptance of the updated policy.
Last Updated: March 31, 2026
Version: 3.1 (clarity pass—GDPR/CCPA-aligned practices; not legal advice)
Effective Date: March 31, 2026
Next Review: September 30, 2026