Privacy Policy

Luminer - Medical Documentation App

Last Updated

November 23, 2025

Introduction

Luminer ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.

Information We Collect

1. Personal Information

  • Email Address: Used for authentication and account management
  • User Account Data: Username and authentication credentials managed through Firebase Auth

2. Audio Recordings

  • Medical Consultation Audio: Voice recordings created during medical consultations
  • Purpose: Transcribed to generate SOAP (Subjective, Objective, Assessment, Plan) notes
  • Storage: Stored securely in Firebase Cloud Storage

3. Medical Documentation

  • SOAP Notes: Generated from audio transcriptions containing:
    • Patient ID (provided by healthcare professional)
    • Consultation date and timestamp
    • Subjective findings
    • Objective findings
    • Assessment
    • Treatment plan
  • Storage: Stored in Firebase Firestore database

How We Use Your Information

We use collected information to:

  • Authenticate users and maintain account security
  • Transcribe audio recordings into text using Google Cloud Speech-to-Text API
  • Generate structured SOAP notes from transcriptions using Google Gemini AI
  • Send SOAP notes via email as PDF attachments
  • Provide app functionality and improve user experience

Data Storage and Security

Firebase Services

All data is stored using Google Firebase services:

  • Firebase Authentication: Secure user authentication
  • Firebase Firestore: Encrypted cloud database for SOAP notes
  • Firebase Cloud Storage: Encrypted storage for audio files
  • Firebase Cloud Functions: Serverless processing for transcription and AI operations

Security Measures

  • Data transmission is encrypted using HTTPS/TLS
  • Firebase services employ industry-standard encryption at rest
  • Access controls limit data access to authenticated users only
  • Audio files and SOAP notes are accessible only by the creating user

Data Retention

  • Audio Files: Retained in Firebase Storage until manually deleted by the user
  • SOAP Notes: Retained in Firestore database until manually deleted by the user
  • Account Data: Retained while your account is active

Users can delete individual recordings and SOAP notes at any time through the app interface.

Third-Party Services

Luminer integrates with the following third-party services:

Google Cloud Services

  • Google Cloud Speech-to-Text API: Converts audio to text (audio data is processed but not stored by Google beyond processing time)
  • Google Gemini AI: Generates structured SOAP notes from transcription text
  • Firebase: All Firebase services comply with Google's privacy policies

Email Delivery

  • Gmail SMTP: Used to send SOAP notes via email
  • Email content (PDF attachments) is transmitted securely via TLS

HIPAA Compliance Considerations

Important Notice for Healthcare Professionals:

While Luminer uses enterprise-grade security measures through Firebase and Google Cloud, healthcare professionals must:

  • Evaluate if Luminer meets their organization's HIPAA compliance requirements
  • Obtain proper Business Associate Agreements (BAAs) with Google Cloud if required
  • Implement additional safeguards as needed per their compliance policies
  • Use strong authentication methods
  • Ensure devices running Luminer are secured

Luminer is a tool to assist with medical documentation. Healthcare professionals remain responsible for compliance with all applicable regulations including HIPAA.

Data Sharing

We do NOT:

  • Sell your personal information to third parties
  • Share your medical data with third parties for marketing purposes
  • Use your data for purposes other than providing app functionality

We MAY share information:

  • With Firebase/Google Cloud services as required to operate the app
  • When required by law or legal process
  • To protect our rights or the safety of users

Children's Privacy

Luminer is designed for use by healthcare professionals and is not intended for children under 13. We do not knowingly collect information from children.

Your Rights

You have the right to:

  • Access your data stored in Luminer
  • Delete your recordings and SOAP notes
  • Delete your account and associated data
  • Opt out of email notifications

To exercise these rights, contact us at: harj@panag.ca

International Data Transfers

Data is stored on Google Cloud servers located in us-central1 (United States). By using Luminer, you consent to the transfer and processing of data in the United States.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted within the app and on our website. Continued use after changes constitutes acceptance of the updated policy.

Contact Us

For questions about this Privacy Policy or your data:

  • Email: harj@panag.ca
  • Developer: Harj Panag
  • Organization: Harj Panag Development

Consent

By using Luminer, you consent to this Privacy Policy and agree to its terms.

For Healthcare Professionals Using Luminer

Please ensure you:

  1. Review this privacy policy with your organization's compliance team
  2. Obtain necessary Business Associate Agreements with Google Cloud if required
  3. Implement device-level security measures (screen locks, encryption, etc.)
  4. Train staff on proper use of the application
  5. Maintain compliance with all applicable healthcare regulations

For technical questions or to request BAA documentation for Google Cloud services, please contact Google Cloud directly.