Privacy Policy
Last updated: March 19, 2026
1. Information We Collect
We collect information you provide directly to us, including your name, email address, firm name, and any data you enter into assessments. We also collect usage data such as pages visited, features used, and access times through standard web analytics.
2. How We Use Your Information
We use collected information to: provide and maintain the Service; process your assessments and generate reports; send you important account notifications; improve and personalize the Service; and comply with legal obligations.
3. Assessment Data and Health Information
Assessments may include health-related information such as medical conditions (e.g., diabetes, heart disease, cancer history), tobacco use, biometric data (height and weight), and demographic information (date of birth, gender). This data is used solely to generate mortality projections and life settlement valuations.
Assessment data is stored securely and is accessible only to your account. We do not share individual assessment data with third parties. Assessment data may be used in aggregate, de-identified form to improve our analytical models, in which case all direct identifiers (names, dates of birth, geographic data) are removed.
HIPAA Disclaimer: Lumis Life is not a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA). This platform does not provide HIPAA-compliant data storage or handling. Users should not treat this platform as a repository for Protected Health Information (PHI) subject to HIPAA requirements. By entering health-related data into the platform, you represent that you have appropriate authorization to do so and that you understand the data is not subject to HIPAA protections.
4. Data Security
We implement industry-standard security measures to protect your personal information, including encryption in transit (TLS) and at rest, secure password hashing, and regular security assessments. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
5. Data Retention
We retain your account information for as long as your account is active. Assessment data is retained for the duration of your subscription plus 90 days after account closure. You may request deletion of your data at any time by contacting us.
6. Marketplace Data Handling
When an advisor posts a case to the broker marketplace, we create an anonymized listing using ranges and categories rather than exact values. Specifically: face amounts are shown as ranges (e.g., “$250K-$499K”), life expectancy as bands (e.g., “4-8 years”), age as 5-year bands, and carrier identity as a letter rating only. The insured's name, date of birth, exact policy amounts, health conditions, BMI, and carrier name are never disclosed to brokers through the marketplace.
When a broker's interest is accepted by an advisor, the broker receives the advisor's name, email, and firm name only. Insured information is never shared through the platform. Any further data sharing between advisor and broker occurs off-platform at the advisor's discretion and is governed by the parties' own agreements.
Broker profile information (company name, states licensed, specialty areas, and bio) is visible to advisors reviewing broker interests in their listings.
7. Broker Data Use Restrictions
Prohibited Uses: Brokers accessing the marketplace agree to the following data use restrictions. Marketplace listing data (including anonymized ranges, scores, and ratings) may only be used for the purpose of evaluating potential case interest through the platform. Brokers shall not:
- Attempt to re-identify insured individuals from anonymized listing data, whether by cross-referencing with external databases, combining data points, or any other method.
- Scrape, harvest, aggregate, or systematically download marketplace listing data for use outside the platform, including for building competing databases or market analyses.
- Share advisor contact information obtained through a paid connection with third parties not directly involved in the specific case for which the connection was established.
- Contact the insured or their family members directly using any information obtained through the marketplace, even after a connection is established with the advisor.
- Use marketplace data, including suitability scores and marketability scores, for marketing, advertising, or solicitation purposes outside the platform.
Enforcement: Violation of these data use restrictions may result in immediate account termination, forfeiture of any pending connections, and liability for damages as described in the Terms of Service. Lumis Life may audit broker activity patterns to detect systematic data harvesting or re-identification attempts.
8. Review and Reputation Data
After marketplace connections, advisors may submit reviews rating broker responsiveness, professionalism, and offer quality. Reviews are stored on the platform and are visible to other advisors to support informed broker selection. Aggregated reputation scores (average ratings, review count, deal history) are also visible.
Review content does not include insured information and should not reference specific policy details, case outcomes, or settlement amounts. We reserve the right to remove reviews that contain personally identifiable information about insureds, are defamatory, or violate our review guidelines.
Broker reputation data (aggregate ratings and review counts) is only available through the platform and is not shared with external parties. This data is retained for the duration of the broker's account plus twelve (12) months after account closure.
9. Beneficiary and Suitability Data
Assessments may include beneficiary information such as dependent count, youngest dependent age, coverage purpose, other insurance coverage, and policy ownership structure. This data is used to generate suitability scores and compliance documentation. Beneficiary data is never shared with brokers through the marketplace or any other channel.
Suitability scores (a numerical rating of whether settlement may be appropriate) are stored alongside assessment results. The score itself (without underlying beneficiary data) may appear on marketplace listings as a quality signal. The detailed suitability analysis, including factor breakdowns, warnings, and beneficiary-specific insights, is visible only to the advisor who created the assessment.
10. Third-Party Services
We use trusted third-party services for payment processing (Stripe), email delivery (Resend), and infrastructure hosting. These providers have their own privacy policies and are bound by data processing agreements. We do not sell your personal information to third parties.
11. Cookies and Analytics
We use essential cookies to maintain your session and preferences. In addition, we use Google Analytics 4 (GA4) to understand how visitors find and use our site. GA4 collects anonymized usage data such as pages visited, traffic sources, and general geographic region. Google may use cookies to distinguish unique users and sessions. This data helps us improve the site and measure the effectiveness of our content.
You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on, or by adjusting your browser's cookie settings. For more information on how Google processes this data, see Google's Privacy Policy.
12. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information. To exercise any of these rights, contact us at privacy@lumislife.com. We will respond to verifiable requests within the timeframes required by applicable law.
All Users:
- Access, correct, or delete your personal information
- Export your assessment data in a portable format
- Opt out of non-essential communications
- Request information about how your data is processed
California Residents (CCPA/CPRA): If you are a California resident, you have additional rights under the California Consumer Privacy Act and its amendments:
- Right to Know: You may request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions (e.g., data needed to complete a transaction or comply with a legal obligation).
- Right to Opt-Out of Sale: We do not sell personal information as defined by the CCPA. We do not share personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
- Authorized Agents: You may designate an authorized agent to submit requests on your behalf. The agent must provide proof of authorization.
Categories of Information Collected (CCPA Disclosure): We collect the following categories of personal information: identifiers (name, email), professional information (firm name, CRD number, license state), financial information (payment method via Stripe — we do not store card numbers), health-related information (entered into assessments for actuarial analysis), and Internet activity (pages visited, features used). We collect this information for the business purposes described in Section 2.
European Economic Area, UK, and Swiss Users (GDPR): If you are located in the EEA, UK, or Switzerland:
- Lawful Basis: We process your personal data on the following bases: performance of a contract (providing the Service), legitimate interests (improving the Service, preventing fraud), and consent (where required, such as for marketing communications).
- Data Controller: Lumis Life is the data controller for personal data processed through the Service. For advisor-entered data about insureds, the advisor acts as the data controller and Lumis Life acts as a data processor.
- Additional Rights: In addition to the rights above, you have the right to: restrict processing of your data, object to processing based on legitimate interests, withdraw consent at any time (without affecting prior processing), and lodge a complaint with your local data protection authority.
- International Transfers: Your data is stored and processed in the United States. By using the Service, you consent to the transfer of your data to the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the transfer mechanism for data originating in the EEA/UK.
- Data Protection Officer: You may contact our data protection representative at privacy@lumislife.com.
13. Data Processing Roles
Platform Data: For data you provide about yourself (account information, payment details, usage data), Lumis Life acts as the data controller and determines the purposes and means of processing.
Assessment Data: For data advisors enter about third parties (insured individuals), the advisor (or their firm) acts as the data controller and Lumis Life acts as a data processor. Advisors are responsible for establishing a lawful basis for processing insured data, obtaining necessary consents, and providing appropriate privacy notices to their clients.
Data Processing Agreement: If your use of the Service requires a formal Data Processing Agreement (DPA) — for example, to comply with GDPR, state privacy laws, or organizational policies — please contact privacy@lumislife.com and we will provide one for execution.
14. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18, we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes at least fifteen (15) days in advance via email or a prominent notice on the Service. Your continued use of the Service after the effective date constitutes acceptance of the revised policy. If you do not agree to the updated policy, you must stop using the Service.
16. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or need to request a Data Processing Agreement, please contact us at privacy@lumislife.com.