Last updated July 2026

Privacy Policy

This page is maintained by LumaLayer to explain what data the workspace holds, why it holds it, and how a clinician or district can get it back or have it removed. It describes current product behaviour, not a certification.

What we collect

  • Account data: your name, work email, organization and role, captured when you request access.
  • Student records you enter or import: name, date of birth, grade, district student ID, primary language, guardians, IEP goals, objectives, service minutes and accommodations.
  • Session data: trial counts, accuracy, cue levels, clinician notes and, when you enable it, an audio recording and its transcript.
  • Generated documents: SOAP notes, progress notes and family summaries, along with their review status.
  • Operational data: sign-in history, audit entries for exports and disclosures, and error logs.

Why we hold it

Student data is held solely to produce documentation for the clinician who entered it. We do not sell data, we do not use student data for advertising, and we do not use it to train third-party foundation models.

AI processing

Transcription, translation and document drafting are performed by third-party AI models reached through our gateway. Content is sent for processing and a result is returned; it is not used by us to train models. Every AI output is stored with a review record showing whether a clinician accepted, edited or rejected it. Recording and AI transcription are consent-gated per student.

Access and separation

Records are visible only to the clinician who created them, clinicians explicitly assigned to that student's caseload, and administrators of your organization. This is enforced at the database layer, not just in the interface.

Retention and deletion

Records persist until you delete them or your organization ends its agreement. You can request deletion or anonymization of an individual student at any time; anonymization strips identifying fields while preserving the audit trail. Deletion requests are actioned within 30 days.

Sub-processors

  • Cloud hosting, database, authentication and file storage for the application.
  • AI model providers for transcription, translation and document drafting.
  • Transactional email delivery for account and access-request messages.

Your rights

Clinicians and districts may request a copy of the records they control, correction of inaccurate data, or deletion. Guardians should direct requests to the district or practice that holds the educational record; we support that organization in responding.

Contact

Privacy requests: privacy@lumalayer.ai.