Legal
Privacy Policy
Effective June 9, 2026
1. Summary
LumaGen (Helix Reserve LLC, “we,” “us”) is the provider of a subscription service that follows the public scientific guidance applicable to your previously obtained hereditary-cancer genetic test result and reaches out when a relevant change occurs. This policy explains what information we collect, how we use and share it, and the choices you have.
- We collect only what we need to operate the Service: account identity, subscription status, the gene and variant you enter, an optional lab report you upload, basic demographics that sharpen interpretation, and the family health history you build.
- Identifiable Protected Health Information (PHI) and identifiable genetic information are not sold and not licensed to third parties for their independent use.
- We may use, share, and commercialize (including sell) de-identified, aggregated information that meets the HIPAA de-identification standard (45 C.F.R. § 164.514(b), Safe Harbor or expert determination). You may opt out at any time on a going-forward basis.
- You can access, correct, export, or delete your information at any time by writing to hello@lumagen.me.
2. Information we collect
You provide
- Account identity. Email address (used for sign-in via single-use magic link and for communications).
- Subscription. Plan, billing interval, status, and Stripe customer / subscription identifiers. Card numbers and other payment instruments are handled by Stripe and never stored by LumaGen.
- Profile demographics. Sex assigned at birth, race (self-identified, multi-select), ethnicity, and date of birth. These are clinical inputs that sharpen interpretation, not marketing fields.
- Your result. The gene and variant you enter (including any Variant of Uncertain Significance entered as free text), the classification source, and ClinVar identifiers when applicable.
- Lab report (optional). A PDF or image you upload to Storage for the internal counselor’s reference. AI does not read uploaded reports in v1.
- Family health history. A name-free graph of relatives, their lineage, sex, living status, age, and any recorded cancer diagnoses (controlled vocabulary). The graph is snapshotted on material change for auditability.
- Questions for your doctor. Notes you keep to discuss at a clinical visit.
- Referral activity. Your referral code, who referred you (if anyone), and which relatives or friends used your code.
We generate
- Monitored changes. A record of every guideline update or variant reclassification relevant to your result, including the source citation, the internal counselor’s member-facing summary, and the body of the document prepared for your clinician.
- Notifications. In-app and email notifications, their status, and a small payload describing the channel result (for example, the Paubox delivery identifier).
- Documents. The PDF prepared for your clinician, stored in private object storage and accessible to you via short-lived signed URLs.
- Audit logs. References (actor, action, resource id, timestamp) describing every read and write of clinical data. Audit logs never contain the underlying PHI values.
We collect from your device and use
- Standard server logs (IP address, user agent, request path) used to operate the Service, detect abuse, and meet security obligations. We do not run advertising trackers.
- Error and performance information via Sentry to diagnose problems.
- A first-party preference cookie for referral attribution (
lumagen_ref) and standard authentication cookies set by Supabase Auth.
3. How we use information
- To provide the Service: capture your result, build your family graph, follow guidance and reclassification, deliver the internal counselor’s review, prepare your clinician document, and route notifications.
- To process payments and provide receipts (Stripe acts as our payment processor).
- To communicate with you about material changes to your result, account or billing matters, and material updates to these policies.
- To secure the Service, detect and prevent abuse, and satisfy legal obligations.
- To improve the Service in a manner consistent with this policy, including the de-identified-data uses described in Section 7.
4. Legal bases (for EU/UK residents)
Where the EU or UK GDPR applies, we process personal data on the following bases: performance of our contract with you; your explicit consent (for special-category data, including genetic and health data); our legitimate interests in operating and securing the Service; and compliance with legal obligations.
5. Who we share information with
We share personal information only with the following categories of recipients:
- The internal genetic counselor. A licensed genetic counselor employed or contracted by LumaGen reviews each monitored change in our internal admin console. The counselor sees your variant, your family graph, and the source change; she does not see your billing information.
- HIPAA-eligible service providers under Business Associate Agreements: our hosted database (Supabase, HIPAA-eligible tier), our HIPAA email provider (Paubox), and our hosting and observability vendors (Vercel, Sentry). Each provider is limited to its stated function.
- Stripe for payment processing under Stripe’s own terms and privacy policy.
- Anthropic, PBC for the internal AI extraction of structured updates from uploaded guideline PDFs. Only the guideline text is sent; subscriber data is never sent to the AI.
- ClinVar / NCBI. We query ClinVar to populate the variant picker and to detect reclassifications. These calls reference variant identifiers only, not your identity.
- As required by law, in response to lawful requests, subpoenas, or court orders, or to protect rights, property, or safety where permitted by law.
- Successors in a business transaction (merger, acquisition, financing, sale of assets), in which case we will require recipients to honor commitments at least as protective as this policy.
We do not sell or rent identifiable personal information, identifiable PHI, or identifiable genetic information for monetary or other valuable consideration.
6. The provider document
When the internal counselor approves a relevant change, the Service prepares a document in your name with a pinpoint citation of the source. We do not deliver the document to your clinician for you; we make it available to you so that you choose when and how to share it.
7. De-identified, aggregated data
By using the Service you authorize LumaGen to create, use, share, and commercialize (including sell) de-identified, aggregated information derived from your information and from the operation of the Service. We may combine such information with information from other subscribers and from third-party sources in datasets that no longer identify any individual.
De-identification will be performed in a manner that meets the HIPAA de-identification standard at 45 C.F.R. § 164.514(b), using either the Safe Harbor method (removing the specified identifiers and ensuring no actual knowledge that re-identification is possible) or the expert-determination method. We do not attempt to re-identify de-identified information and we contractually prohibit recipients from doing so.
Opt out. You may opt out of the de-identified-data uses described in this Section at any time by writing to hello@lumagen.me. Opt-out applies on a going-forward basis; we cannot retract information already incorporated into a de-identified dataset, because by definition it can no longer be linked back to you.
What we do not do with this authorization. We do not sell or license identifiable PHI or identifiable genetic information; we do not use your information for ad targeting; and we do not provide your raw information to brokers, advertisers, employers, or insurers.
8. Security
We follow the HIPAA Security Rule for PHI we hold. Practices include row-level security on every clinical table, owner-scoped access policies, service-role boundaries audited at the application layer, encrypted transit and at-rest storage, short-lived signed URLs for private documents, and HIPAA email delivery via Paubox. No security program is perfect, and we cannot guarantee absolute security; we will notify affected individuals and regulators of any reportable incident as required by law.
9. Retention
We retain personal information for as long as your account is active and for a period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. Family-history snapshots and audit logs are retained for as long as the underlying account exists, or as required by law. On account deletion, we delete or de-identify your information within a reasonable period, subject to legal retention requirements.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, delete, or restrict the processing of your personal information; to withdraw a consent you previously gave us; and to lodge a complaint with a supervisory authority. To exercise these rights, write to hello@lumagen.me from the email address associated with your account.
California residents have additional rights under the California Consumer Privacy Act (CCPA / CPRA), including the right to know, the right to delete, the right to correct, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights. We do not sell personal information for monetary consideration; for purposes of the “sharing” concept under CCPA, we do not share personal information for cross-context behavioral advertising.
For EU/UK residents, you have rights under the GDPR including access, rectification, erasure, restriction, portability, and objection.
11. Genetic-data handling
Genetic information is sensitive. We treat it with extra care: it is encrypted, access is owner-scoped, the internal counselor sees it only inside an audited admin console, and we do not provide it to insurers, employers, schools, advertisers, or data brokers. We support your ability to delete or export your genetic information at any time. We comply with the federal Genetic Information Nondiscrimination Act (GINA) and applicable state laws.
12. Children
The Service is not intended for individuals under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us information, please write to hello@lumagen.me and we will delete it.
13. International transfers
LumaGen is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate. Where required by law, we implement appropriate safeguards (such as the EU Standard Contractual Clauses) for cross-border transfers.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make a material change, we will give you reasonable advance notice (for example, by email or in-product notice) and update the “Effective” date above.
15. Contact
Privacy questions? Reach us at hello@lumagen.me. For HIPAA matters, please mark your message Attn: Privacy Officer.
