Privacy Policy

Lumera Learning LLC · Effective date: July 14, 2026

Who we are and what this policy covers

Lumera Learning LLC ("Lumera," "we," "us") is a school-based music therapy practice in the Rochester, New York area. We contract with school districts to provide music therapy services to students, most of whom receive services under an Individualized Education Program (IEP).

This policy covers lumeralearning.com and all of its subdomains. That includes two very different things, and this policy addresses them separately:

  1. Our public website (www.lumeralearning.com) — informational pages and a contact form. Anyone can visit it.
  2. The Lumera service (app.lumeralearning.com) — the private system our therapists and school district partners use to schedule, document, and report on services. It is not open to the public and holds student information under contracts with school districts.

The plain-language summary: we do not sell personal information, we do not run advertising or ad tracking of any kind, our public website uses no cookies that require a consent banner, and student information never touches our public website. Student information lives only in the Lumera service, governed by a Data Privacy Addendum signed with each school district.


Part 1 — The public website

The contact form

The only personal information our public website collects is what you choose to send us through the contact form: your name, your email address, which role you are reaching out as, your school district or organization (optional), and your message. We use it for exactly one purpose: reading and responding to your inquiry.

Please do not include student names or any details about a specific student in your message. The form says this too. If a message arrives containing student details anyway, we treat those details under the same care described in Part 2 and delete them when they are not needed.

Here is what happens to a submission:

  • It is stored in our database, hosted on Google Cloud infrastructure.
  • A notification email is sent to us through our Google Workspace email. That email contains the sender's name only — not the message itself.
  • Submissions are read only by Lumera's owner and the site's administrator. They are not shared with, sold to, or used by anyone else.
  • Every submission is automatically deleted 24 months after it is received. This deletion is enforced by the system itself, not by a manual process.

If you would like your submission deleted sooner, email privacy@lumeralearning.com and we will delete it.

Keeping spam off the contact form

We use Cloudflare Turnstile to check that a submission comes from a person rather than an automated script. Turnstile is cookieless, does not profile you, and usually resolves on its own without asking you to do anything. It does require JavaScript — if you would rather not run it, email privacy@lumeralearning.com or call us, and those paths always work.

To prevent abuse, we also briefly keep a small anti-abuse record derived from your submission: a salted, one-way hash of your IP address, so that one source cannot flood the form, and a salted, one-way hash of your email and message together, so that an accidental double-submission is not stored twice. We do not keep your IP address itself in these records, the hashes cannot be turned back into the values they came from, and the records delete themselves within a day.

Analytics — no cookies, no tracking

We use Cloudflare Web Analytics to understand, in aggregate, how the website is used: page views, referrers, and country-level location. This tool is deliberately chosen because it is cookieless and privacy-first:

  • No cookies are set for analytics, which is why you do not see a cookie consent banner on this site — there are no non-essential cookies to consent to.
  • No persistent identifier is stored on your device.
  • We do not use Google Analytics, advertising pixels, remarketing tags, or any cross-site tracking of any kind.
  • We cannot identify you personally from our analytics, and neither can anyone else from the data we receive.

Hosting logs

The website is served by Firebase Hosting (a Google service). Like essentially every web server, the hosting layer keeps standard technical logs, which include IP addresses and browser information. These logs exist for security and operational purposes and are handled under Google's own retention practices. We do not use them to identify or profile visitors.

What the public website does not have

No login. No student portal. No file uploads. No payments. No connection of any kind to the Lumera service's database. No student data ever touches the public website or its backend. That separation is a design rule, not a coincidence: the public website runs on entirely separate infrastructure from the Lumera service.


Part 2 — The Lumera service and student information

Our role

When Lumera provides services to a school district, the district owns and controls its students' information. Lumera acts as a third-party contractor under New York Education Law §2-d and the Family Educational Rights and Privacy Act (FERPA). Our specific, binding obligations — data security, retention, deletion, breach notification, sub-processors, and more — are set out in a Data Privacy Addendum (part of our Data Privacy Compliance Packet) attached to our contract with each district.

If you are a parent or guardian with questions about your child's information, your school district is the right first contact — the district controls the data and maintains its Parent Bill of Rights for Data Privacy and Security. You are also welcome to contact us at privacy@lumeralearning.com, and we will cooperate with your district to respond.

If anything in this policy differs from a signed Data Privacy Addendum, the signed addendum controls for that district.

What we collect, and what we deliberately don't

We collect only the student information necessary to deliver, document, and report on music therapy services — for example, the IEP-related fields that define a student's mandated services, session attendance, and clinical documentation of the sessions we provide.

We do not store full IEP documents. We do not operate a medical records system; health or disability information is captured only when necessary for safe service delivery. Student information is never placed in personal email accounts, personal cloud storage, or unauthorized systems.

How we protect it

  • Student information is encrypted in transit and at rest using the platform protections of the Google infrastructure it lives on.
  • Access is role-based and least-privilege: each person sees only what their role requires. Multi-factor authentication is required for accounts that can access student information, and access is revoked promptly when someone leaves or changes roles.
  • Every change to student records is captured in an audit log recording what changed, when, and by whom. Districts may request audit records relating to their students in writing.
  • Each client organization's data is kept in logically isolated storage — no commingling between clients.

Artificial intelligence

We never transmit student personally identifiable information to public or consumer AI services, or to any AI service that uses submitted data to train public or shared models. Where an AI-assisted feature is used, either the data involved is de-identified, or the AI service operates within enterprise infrastructure already covered by the district's existing data privacy agreements (for example, Google Vertex AI under the district's Google Workspace for Education agreement). Every AI-assisted feature goes through an internal review of its data flow and de-identification approach before it is built.

Retention and deletion

We retain student information only as long as reasonably necessary to provide and document services, support district reporting and billing, and meet legal, contractual, professional, audit, insurance, and tax obligations.

Upon a district's written request, and where deletion is legally and technically feasible, we delete student information from active systems within 30 days, unless a longer period is required or permitted by legal, professional, insurance, audit, billing, backup, dispute-resolution, or technical constraints. Backup copies age out under our standard 30-day backup rotation and are protected from active use in the meantime. Written confirmation of deletion is available on request.

If something goes wrong

If we confirm that a security incident resulted in unauthorized access to or disclosure of student personally identifiable information, we notify the affected district without unreasonable delay and no later than 72 hours after confirming the incident, and we cooperate fully with the district's investigation and response.


Service providers

We keep our list of service providers short and disclose it plainly:

  • Google LLC — our primary infrastructure for both the website and the Lumera service: Google Workspace (including email), Google Cloud Platform, Firebase (hosting, database, authentication, and sign-in), and Google enterprise AI services as described above.
  • Cloudflare, Inc. — website analytics and contact-form spam protection, as described in Part 1. Cloudflare's services run only on the public website and never process student information.

We maintain an internal Approved Subprocessors List; districts may request the current list at any time by contacting privacy@lumeralearning.com. We provide reasonable advance notice through normal contracting channels before adding a new category of sub-processor that materially changes how district data flows.

What we never do

We do not sell personal information — anyone's, ever. We do not use personal information for advertising. We do not use student information for marketing. We do not use data from our website or the Lumera service to train public or shared AI models.

Children's privacy

Our public website is not directed at children, and we do not knowingly collect personal information from children through it. Student information exists only within the Lumera service, only under contracts with school districts, and only as described in Part 2.

Your choices

If you submitted the contact form and want your submission corrected or deleted, email privacy@lumeralearning.com. If you are a parent or guardian with questions about student information, start with your school district, and feel free to copy us. There is nothing to opt out of on the public website itself — no tracking, no marketing lists, no profiles.

Changes to this policy

If we change this policy, we will post the updated version here with a new effective date. If a change meaningfully affects how we handle personal information, we will say so plainly at the top of the policy rather than bury it.

Contact

Lumera Learning LLC
20 Office Park Way, Ste 109, Pittsford, NY 14534
Privacy/Security contact: privacy@lumeralearning.com
Internal Privacy/Security Officer: Jon Ferguson