Privacy Policy

Last updated: September 9, 2026

Lumno ("we", "us") provides practice-management software for therapists. This policy explains what we collect and how we use it. It covers the therapist accounts that sign up for Lumno and the clients they book through it.

What we collect

Account details (name, email) for therapists who sign up. Appointment, client, and note data that a therapist enters or that their clients submit through booking. Payment metadata from our payment processor — we do not store card numbers ourselves. If a therapist connects Google Calendar, we access only calendar events needed to create and manage appointments and Meet links.

Google user data

Connecting Google Calendar is optional. When a therapist connects it, we request the calendar.events scope only. We use it to create, update, and delete the calendar events and Google Meet links for that therapist's own appointments, and for nothing else. We do not read other events, contacts, email, or any other Google data. We store the OAuth tokens needed to do this on the therapist's behalf; the therapist can revoke access at any time from Settings or from their Google account permissions page, and we delete the tokens when they do.

Google user data is never sold, never used for advertising, never shared with any third party except as listed under "Who we share data with" below, and never used to create, train, or improve any machine learning or artificial intelligence model. Lumno's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use it

To run the core features of the product: scheduling, reminders, payments, and notes. To send transactional emails (booking confirmations, reminders). We do not sell client or therapist data, and we do not use client notes for any purpose beyond displaying them back to the therapist who wrote them. We do not run analytics, tracking, or advertising, and we collect no data beyond what is needed to provide the service.

Who we share data with

We do not sell, rent, or trade any data. We share, transfer, or disclose data only with the service providers below, each only for the purpose stated and only the data that purpose needs:

  • Vercel — hosts the application. Data passes through their servers while the app runs.
  • Supabase — hosts our PostgreSQL database, where account, appointment, client, note, and OAuth token data is stored.
  • Google — only when a therapist connects Google Calendar, we send that therapist's appointment times and attendee details to Google to create calendar events and Meet links.
  • Razorpay — processes payments. They receive the details needed to charge and pay out; we never see or store card numbers.
  • Resend — sends transactional email such as booking confirmations and reminders. They receive recipient email addresses and the message content.

We may also disclose data if required by law, or to protect the rights and safety of our users. Beyond this, Google user data and all other data is not shared with anyone.

How we protect it

All data is encrypted in transit using HTTPS/TLS, and encrypted at rest by our database host. Google OAuth tokens are stored server-side, are never exposed to the browser, and are deleted when the therapist disconnects Google Calendar. Access to production systems is limited to the people who operate Lumno and is protected by authentication and access controls. Client notes and appointment details are visible only to the therapist who owns that account; we do not access this data except as needed to provide support or maintain the service. We never share, transfer, or disclose sensitive data for advertising, profiling, or model training.

Data retention & deletion

Data is kept for as long as the account is active. Therapists can request deletion of their account and associated data by contacting us.

Contact

Questions about this policy can be sent to the address listed on our contact page.