Privacy Policy
Updated: May 15, 2026
Lumion takes your privacy seriously. This Privacy Policy ("Policy") applies to all users, including school administrators and personnel ("School Users"), Students (defined below), Payers, and visitors of our website. Your use is also subject to our Terms of Use, which incorporate this Policy: the School Terms of Use govern School Users’ use; the Student Terms of Use govern Students’ and Payers’ use. We may update this Policy and will notify you of material changes by posting on lumion.ai, by email, or by other reasonable means. Posted notices govern your use even if you have not provided an email or have opted out of legal-notice emails.
Lumion’s Role
Lumion provides software that educational institutions ("Schools") use to operate their programs. For information a School puts into Lumion or that we collect on a School’s behalf, Lumion acts as a service provider under the School’s instructions and our agreement. For information Lumion collects directly from you (e.g., when you visit lumion.ai or contact support), we determine the purposes and means of processing as described here. The Services include AI-assisted communications and workflow tools that operate on behalf of your School; the School is the sender and Lumion provides the technology.
Key Defined Terms
"Student" means any natural person who is enrolled at, accepted for enrollment at, applying to (including through Lumion’s application or intake features), or expressing interest in enrollment at a School that uses Lumion.
"Career Connections and Offers" means Lumion’s program (described in this Policy) that helps Students discover employment opportunities, financial product offers, continuing education, and other commercial offers, including through automated and AI-driven matching.
"AI Agent" means any AI-generated, AI-assisted, or AI-automated feature of the Services, including AI-powered messaging, voice agents, account triage, matching, and similar features that operate on behalf of your School or Lumion.
"Privacy Policy" or "Policy" means this document, as updated from time to time.
"Student Data" means personally identifiable information about a Student that Lumion collects or processes in connection with the Services; Student Data is a subset of Personal Data.
Capitalized terms used in this Policy and not defined here have the meanings given in the applicable Terms of Use.
FERPA and Student Data Privacy Laws
Many Schools are subject to the Family Educational Rights and Privacy Act ("FERPA"), 20 U.S.C. § 1232g and 34 C.F.R. Part 99. Lumion typically acts as a "school official" with a "legitimate educational interest" in education records under 34 C.F.R. § 99.31(a)(1), under the School’s direct control, and doesn’t redisclose them except as permitted by FERPA, our agreement with the School, or law. Lumion also complies with applicable state student data privacy laws. We don’t sell student personal information, use it for targeted advertising, or train AI or ML models on it for purposes outside providing the Services (except where permitted by FERPA, our agreement with the School, or with consent). To exercise FERPA rights, contact your School.
How We Use Personal Data
We collect and use Personal Data to:
-
Create and manage your account; authenticate access; secure the Services
-
Provide your School with tools to administer enrollment, account, financial aid, billing, and communications
-
Process Student Payments and the application, electronic signing, and servicing of Retail Installment Contracts ("RICs") and Interest-Bearing Retail Installment Contracts ("IBRICs")
-
Send administrative and AI-assisted messages on behalf of your School by SMS, MMS, RCS, email, in-app, and push notification
-
Personalize the Services, content, and communications based on your preferences and activity, including for Career Connections and Offers matching
-
Respond to inquiries; provide support; improve, secure, and develop the Services through testing, research, internal analytics, and product development
-
Detect and prevent fraud, abuse, and unlawful activity, and conduct security and debugging
-
Operate Career Connections and Offers and produce aggregated and de-identified insights
-
Support collections your School directs for past-due student accounts
-
Comply with legal obligations and enforce our agreements
We may also use Personal Data to meet legal requirements: responding to court orders or law enforcement requests, investigating security incidents and unlawful activity, enforcing our agreements, responding to claims of third-party rights violations, protecting rights, property, or safety, and resolving disputes. We won’t use it for materially different, unrelated, or incompatible purposes without notice or consent.
Personal Data We Collect
We collect Personal Data from: (i) you, when you create an account, fill out forms, complete surveys, type into free-form text fields, contact us, or otherwise use the Services; (ii) automated collection through Cookies, your device, and our mobile application (which, with your permission, may receive precise location, device telemetry, and information about when you are logged on and available for notifications); (iii) your School, which provides information about your enrollment, account, education records, and similar matters; and (iv) third-party vendors, including payment processors (Centavo, Inc. d/b/a Payabli and Finix Payments, Inc.), identity verification, fraud prevention, security, and communications providers. If you sign in using third-party credentials, some content from those accounts may be transmitted to your account with us.
Categories of Personal Data we collect, classified under California law (Cal. Civ. Code § 1798.140) and similar statutes, include: identifiers (name, email, account ID, IP address, device IDs); customer records (contact details, payment information); commercial information (transactions, RIC and IBRIC records); internet and network activity (logs, cookies, device information); geolocation (general; precise only with consent); professional and employment information (for School Users; for students, information shared in connection with employer matching); education information (subject to FERPA); and inferences (used to operate Career Connections and Offers and to personalize the Services).
Sensitive Personal Information
We process Sensitive Personal Information (as defined under CPRA and similar laws) only for: financial account information for Student Payments, RICs, and IBRICs; precise geolocation when you enable location services; and contents of communications you send through the Services. We use Sensitive PI only to provide and secure the Services, not to infer characteristics about you. California residents may request that we limit its use (see "Your Privacy Rights").
Communications: Email, SMS, MMS, RCS, Voice, and AI-Assisted Messages
Email. By providing your email address, you consent to administrative messages, service notices, and promotional or marketing messages about employment opportunities, partner offers, continuing education, and other commercial offers ("Offer Emails"). Some are required for the Services. You may unsubscribe from Offer Emails using the unsubscribe link.
SMS, MMS, and RCS. By providing your mobile phone number when you create an account or otherwise opt in, and by accepting the applicable Terms of Use and this Policy, you provide your prior express written consent to receive recurring SMS, MMS, and RCS messages from Lumion, your School, and Lumion’s messaging service providers, sent using automated technology, including (i) administrative and transactional messages, (ii) AI-assisted messages on behalf of your School, and (iii) promotional and marketing messages, including Career Connections and Offers messages. Consent to marketing messages isn’t required for transactional use, for receiving the Services, or as a condition of any purchase. You may opt out of marketing messages at any time, with no effect on transactional messages, by replying STOP, adjusting account settings, or contacting support@lumion.ai. Message and data rates may apply; frequency varies. Reply HELP for help. Mobile number and opt-in data are used only to deliver the messages you have agreed to and shared only with service providers who assist in transmitting them. Such opt-in data and consent are excluded from all other disclosure categories in this Policy and will not be shared with any third parties or affiliates for any purpose.
Voice and AI Voice Calls. By providing your phone number and accepting the applicable Terms of Use and this Policy, you provide your prior express written consent to receive voice calls (including AI-generated, prerecorded, and auto-dialed calls) from Lumion, your School, and our calling service providers for administrative, AI-assisted, and promotional or marketing purposes (including Career Connections and Offers). Consent to marketing calls isn’t required for transactional use, for receiving the Services, or as a condition of any purchase. You may opt out of marketing calls at any time, with no effect on transactional calls, by saying STOP during a call, adjusting account settings, or contacting support@lumion.ai. Calls may be recorded for quality, training, compliance, and dispute resolution. We comply with applicable single- and two-party-consent recording laws, including in California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. AI voice agents identify themselves as automated as required by law (including California Business and Professions Code § 17941).
AI-Assisted Messages and Push. Some communications are AI-generated or AI-assisted on behalf of your School. The School is the sender and Lumion provides the technology. The system identifies itself as automated as required by law. If you install our mobile app, you may receive push notifications and can disable them in device settings.
Electronic Records and Signatures. When you sign documents electronically through the Services (including RICs, IBRICs, payment authorizations, and ACH authorizations), you consent to receive related communications and disclosures electronically under the Electronic Signatures in Global and National Commerce Act ("E-SIGN," 15 U.S.C. §§ 7001-7006) and the Uniform Electronic Transactions Act ("UETA") as adopted in your state. We and your School retain signed records as required by E-SIGN, UETA, applicable record retention laws, and our agreements. You may withdraw consent to electronic records by contacting support@lumion.ai; we will provide paper copies on reasonable request, subject to any applicable fees, but withdrawing consent may limit your use of the Services.
Career Connections and Offers
Lumion’s Career Connections and Offers program helps students discover employment opportunities, financial product offers, continuing education, and other commercial offers. By using the Services, you participate by default.
In-Platform Matching. We use automated and AI-driven matching based on School, program of study, location, completion status, platform activity, and similar factors. Some matches and offers are sponsored or paid placements; offers may include time-limited promotions. In-platform display alone doesn’t share your personal information with any employer or partner. Employers may target audience segments (such as students in a region or program); we don’t enable targeting of individual identifiable students. Employers and partners may pay Lumion for placement, sponsored offers, student-initiated introductions, and aggregated or de-identified data products.
Notifications. We notify you about matches and offers via the channels above; opt out via unsubscribe link or STOP.
Student-Initiated Disclosures. When you affirmatively apply, request to be contacted, redeem an offer, or take similar action requiring sharing of your information with an employer or partner, your action authorizes that sharing. The receiving party’s use is then governed by its own privacy practices and law. We log student-initiated disclosures so you may later request a list under your privacy rights.
FERPA. For FERPA-covered Schools, we do not disclose education records to employers or partners except as permitted by FERPA (including with prior written consent obtained by the School) or in de-identified form. Your acceptance of this Policy is not FERPA consent.
Aggregated Insights. We create and may license or sell aggregated and de-identified data sets that do not identify any individual.
Your Choices. Turn off Career Connections communications using the opt-outs above or in account settings. Residents of states recognizing the right may opt out of profiling in furtherance of decisions producing legal or similarly significant effects (see "Your Privacy Rights"). Lumion doesn’t use individual student data to charge different prices to different students.
AI, Machine Learning, and Automated Decision-Making
Lumion is an AI-first company. Our Services use AI and machine learning to power Career Connections matching, AI-assisted communications, account triage, and similar features. We may use information collected to develop, evaluate, train, and improve these features, with safeguards (including aggregation or de-identification) to limit re-identification. We don’t use student personal information to develop products for unrelated third parties. Some features involve automated processing and profiling, but our systems don’t make decisions producing legal or similarly significant effects on you without human involvement. Residents of states granting the right may opt out of profiling for such decisions by contacting support@lumion.ai.
How We Disclose Personal Data
We disclose Personal Data to the categories below. Some may constitute a "sale" or "share" under state law (see "Your Privacy Rights").
Your School. Authorized School personnel, in accordance with the School’s policies and applicable law.
Service Providers and Vendors. Hosting and infrastructure, analytics, security and fraud prevention, support, identity verification, messaging, AI/ML, and payment processors. Centavo, Inc. d/b/a Payabli ("Payabli") and Finix Payments, Inc. ("Finix") collect payment card information necessary to process Student Payments under their own terms; see Payabli (https://www.payabli.com/documents-payabli-terms-of-use/) and Finix (https://finix.com/terms-and-policies). Service providers and vendors are contractually limited to the engaged purposes and reasonable safeguards.
Affiliates. Current or future affiliates (parent, subsidiary, commonly controlled), subject to this Policy or a successor with equivalent protections.
Advertising Partners. On lumion.ai and similar properties, we work with advertising partners to promote Lumion to potential School customers. Some are members of the Network Advertising Initiative (https://www.networkadvertising.org) or the Digital Advertising Alliance (https://www.aboutads.info), which provide opt-out tools.
Business Partners. Joint promotional partners, employers, financial product partners, continuing education partners, and other commercial partners participating in Career Connections and Offers.
Parties You Authorize. Third parties you access through the Services, social media, other users, and employers or partners you choose to share with by applying, requesting contact, or similar action.
Collection Agencies. If amounts owed to your School become past due, your School may direct Lumion to provide your information to a third-party collection agency.
Legal Obligations. As described above.
Merger, Sale, or Asset Transfers. In connection with a transaction in which we are acquired, merged, or sell or transfer assets (including financing, reorganization, or bankruptcy). Use after such an event will be governed by this Policy or a successor with equivalent protections.
Aggregated and De-identified Data
We may create aggregated, de-identified, or anonymized data and own all right, title, and interest in it. We may use and disclose such data for any lawful purpose, including improving and promoting the Services and developing and training AI and machine-learning systems, provided we will not disclose it in a manner that could identify you.
Cookies and Tracking
We use cookies and similar technologies (pixel tags, web beacons, clear GIFs, JavaScript) (collectively, "Cookies") to recognize your browser, understand usage, and operate and improve the Services. We may supplement information we collect with information from third parties, including those that have placed their own Cookies on your device. We use Essential Cookies (sign-in and core functionality), Functional Cookies (preferences), and Performance and Analytics Cookies (including Google Analytics). The Services do not currently respond to "Do Not Track" signals. Control Cookies in your browser settings; disabling some may limit functionality. To opt out of Google Analytics, visit https://tools.google.com/dlpage/gaoptout/ and https://www.google.com/privacy_ads.html. For more, see http://www.allaboutcookies.org/.
Data Security
We use administrative, technical, and physical safeguards to protect your Personal Data, including encryption in transit and at rest, access controls, and personnel training. Our information security program is aligned with the Gramm-Leach-Bliley Act Safeguards Rule (16 C.F.R. Part 314) where applicable to Schools and Student Payments. No system is perfectly secure. Use a strong password, keep credentials confidential, and sign out after use.
Data Retention
We retain Personal Data as long as needed to provide the Services, fulfill the purposes for which we collected it, comply with law, resolve disputes, and enforce our agreements. When setting a retention period, we consider the source, our need, why we collected it, and the data’s sensitivity. Retention is also driven by your School (for school-controlled records), applicable law (federal and state student records, financial aid, consumer credit, payment, and tax requirements), and our agreements. We retain SMS, MMS, and RCS opt-in and opt-out records as required by the Telephone Consumer Protection Act. We may retain aggregated, de-identified, or anonymized data indefinitely.
Children’s Information
The Services are designed primarily for adult students (18+) and School employees. Some Schools enroll students 13-17, including in dual-enrollment programs. If a School allows under-18 students to use the Services, the School is responsible for obtaining required parental or guardian consent (including under the Children’s Online Privacy Protection Act ("COPPA"), 15 U.S.C. §§ 6501-6506, for users under 13) and complying with applicable student privacy laws. We don’t knowingly collect personal information directly from children under 13 without verifiable parental consent; don’t knowingly sell or share for cross-context behavioral advertising the personal information of users known to be under 16; and don’t direct Career Connections marketing to users known to be under 18 except where the School has authorized it.
Health Information
We do not knowingly process protected health information. Disability accommodations and wellness-related information you submit to your School are administered by the School subject to FERPA and applicable law.
Your Privacy Rights
Depending on where you live, you have rights regarding your Personal Data, including the right to know and access; the right to correct; the right to delete (subject to legal exceptions); the right to opt out of "sales" or "shares" and of profiling in furtherance of decisions producing legal or similarly significant effects; the right (in California) to limit use of Sensitive Personal Information; the right not to be discriminated against for exercising these rights; and the right to appeal a denied request (Virginia, Colorado, Connecticut, Texas, Oregon).
How to exercise. For education records, contact your School first; the School administers FERPA rights. For other information, email support@lumion.ai with subject "Privacy Request." We respond within 45 days (extendable by 45 more where permitted), or 60 days in certain states, and notify you of any extension.
Identity verification. We verify identity by matching information you provide against information we hold (account email, name, recent activity). We may request additional verification for sensitive requests.
Authorized agents. California residents may use an authorized agent to submit a request by providing the agent with written, signed authorization (or a power of attorney) and confirming identity directly with us.
Denials and appeals. We may decline a request where required or permitted by law (for example, where deletion would conflict with legal recordkeeping, education records integrity, or fraud prevention). Where state law provides an appeal right, you may appeal a denial by replying to our response.
No financial incentives. We don’t offer financial incentives or differential pricing for personal information.
State-specific notices. California (Civil Code §§ 1798.83-1798.84 and the CCPA, as amended by the CPRA); Nevada (we do not currently sell as defined in NRS Chapter 603A); Colorado, Connecticut, Virginia, Oregon (rights under those states’ consumer privacy statutes, including profiling opt-out); Texas (rights under the Texas Data Privacy and Security Act, including notice-at-collection requirements for sensitive categories); Utah (rights under the Utah Consumer Privacy Act). To opt out, email support@lumion.ai with subject "Do Not Sell or Share My Personal Information."
Accessibility
Lumion is committed to making the Services accessible to people with disabilities. We work toward conformance with the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA and continue to improve the accessibility of our Services. If you have difficulty accessing any feature, need an accommodation, or want to report an accessibility issue, contact support@lumion.ai and we will respond promptly. The Services are provided as described in our Terms of Use; no specific accessibility outcome is warranted.
Contact
Mia Share, Inc. d/b/a Lumion
168 E Midvillage Blvd, Sandy, Utah 84070
Email: support@lumion.ai | Phone: (307) 241-5031 | Website: lumion.ai