Privacy Policy
Last updated September 7, 2026
This Privacy Policy explains how Helix Reserve LLC ("we", "us") handles information in connection with LumaGen, our clinical genetics platform at lumagen.ai. It applies to our website, to the LumaGen console used by clinicians, and to the intake conversations patients have with us on behalf of a clinic.
LumaGen is sold to clinics and health systems. In most cases the clinic decides what patient information enters the platform and why, and we process that information on the clinic's behalf and under its instructions. Where that is the case the clinic, not us, is the party a patient should contact first about their own records.
1. The two roles we play
For information about the clinicians and organizations who buy and use LumaGen, meaning account details, billing contacts, support correspondence, and how the product is used, we decide what to collect and why. We are the controller of that information.
For patient health information that a clinic puts into LumaGen, or that a patient gives us during an intake conversation arranged by their clinic, we act only on the clinic's instructions. The clinic is the covered entity; we are its business associate under HIPAA and its processor under other privacy laws. We do not decide what to do with that information on our own account.
2. Information we collect
Account and organization information. When a clinician creates an account we collect their name, work email address, role, and the organization they belong to, together with authentication data such as a password hash and, if enabled, multi-factor authentication settings.
Information you send us directly. If you ask for a walkthrough or contact us, we collect what you put in that form: name, role, work email, organization, and the rough number of genetics patients your clinic sees. That form asks for no patient information and should never be used to send any.
Family health history. Clinicians record family health history in LumaGen. On the free plan the record holds a patient's name and date of birth, so that a pedigree can be labelled, and nothing else that identifies: the platform has no field for a medical record number, phone number, or email address, no free-text box, and no file upload, and the database refuses those fields on the free plan. On the paid plan, where the product handles identified records and intake conversations, this information is protected health information and is governed by the business associate agreement between us and the clinic.
Intake conversations. On the paid plan a patient may speak or write to an AI assistant to give their family history before an appointment. We process the conversation, and any recording or transcript the clinic has configured, to produce a draft record for the clinician.
Technical information. We collect ordinary server and security logs: IP address, browser and device type, pages requested, timestamps, and errors. We keep an audit log of actions taken in the console, which records who did what and when, and references to the records involved rather than the clinical values themselves.
3. How we use information
To provide the product: to run the console, draw and store pedigrees, evaluate testing criteria, produce documents, deliver intake conversations, and keep records available to the clinic that owns them.
To keep the product secure and working: to authenticate users, prevent and investigate abuse, diagnose faults, and maintain the audit trail a clinic needs for its own compliance.
To communicate: to answer enquiries, send service notices such as trial expiry or scheduled maintenance, and reply to support requests. We do not send marketing email to patients at any time.
To improve the product: to understand which features are used and where the product fails. Where the underlying information is a patient record, we do this using aggregate or de-identified information only, and only where the clinic has agreed to it as described in section 7.
4. What we do not do
We do not sell personal information, and we do not share it for advertising or cross-context behavioural advertising. We run no advertising trackers on the console.
We do not use patient information to train artificial intelligence models, and the model providers we use are contractually prohibited from training on it.
We do not contact patients on our own initiative. Communication with a patient happens because their clinic arranged it.
LumaGen supports clinical decisions. It does not make them, and it is not a diagnostic device. A clinician is responsible for every clinical decision.
5. Service providers
We use a small number of vendors to run the product. Each is bound by contract to use information only to provide its service to us, and each vendor that may handle protected health information does so under a business associate agreement before any such information reaches it.
Supabase provides our database, authentication, and file storage. Vercel provides application hosting. Paubox provides secure email delivery. Anthropic provides the language models behind drafting and intake; under our agreement it does not train on our data and retains it only briefly for abuse monitoring. Retell provides voice call handling for telephone intake where a clinic has enabled it. WorkOS provides enterprise single sign-on for organizations that use it.
We will update this list as it changes. A clinic that needs advance notice of a change in service providers should raise it in its agreement with us.
6. Security
Information is encrypted in transit and at rest. Access to production systems is limited to personnel who need it, and is logged.
Each organization's data is isolated at the database level rather than only in application code: every record carries the identity of the organization that owns it, and the database itself refuses to return one organization's records to another. Multi-factor authentication is available to every account and is required on the paid plan.
We keep an audit log of console actions and of every clinical decision recorded in the product, which the owning organization can read and export.
No system is perfectly secure. If a breach affects information we hold on a clinic's behalf, we will notify that clinic without unreasonable delay and in the manner and timeframe set by our agreement with them and by law.
7. De-identified and aggregate information
We may produce statistics that cannot identify any person or any clinic, for example counts of how often a category of testing criterion is met across the platform.
We do this only for organizations that have expressly turned it on. It is off by default, the setting is visible in the console, and turning it off stops any further use. Free-plan records are excluded from this entirely; no agreement with a free organization covers it.
8. How long we keep information
We keep information for as long as the clinic's account is active, and for as long afterwards as our agreement with them or the law requires.
On the free plan, an organization that does not sign in for twenty-four months is emailed a notice and its data is then deleted. Throughout, and after any trial ends, the organization can still open and export the pedigrees it created; we do not hold a clinician's own work hostage.
A clinic may ask us to return or delete its data at any time, subject to the terms of its agreement. When we delete, we delete from live systems promptly and from backups on our ordinary backup cycle.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information about you, to object to or restrict certain processing, and to complain to a data protection authority. We do not discriminate against anyone for exercising a right.
If you are a clinician or other user of the console, contact us and we will help. If you are a patient, contact the clinic that arranged your care: they hold the relationship with you and decide what happens to your record, and we will support them in responding to you.
10. Children
LumaGen is a professional tool. It is not directed to children and children do not hold accounts. Family health history recorded by a clinician may include relatives of any age, including children, because that is what a family history is; that information is handled the same way as the rest of the record.
11. Where information is processed
We process information in the United States. If you access the product from outside the United States, you are sending information to a country whose data protection laws may differ from your own. Where a transfer of personal information out of a region requires a specific safeguard, we put an appropriate one in place.
13. Changes to this policy
We will update this policy as the product changes. When a change is material we will say so on this page and, where the change affects a clinic's own obligations, tell that clinic directly. The date at the top shows when this version took effect.
14. Contact
Questions about this policy, or about information we hold, can be sent to Helix Reserve LLC through the contact form at lumagen.ai/learn-more. If you are a patient asking about your own record, please contact your clinic first.