• Features
  • Screenshots
  • Download
  • Contact
Request Demo
Lumen Steps LLC
  • Features
  • Screenshots
  • Download
  • Contact

Privacy Policy

How we collect, use, and protect information in the Lumen Steps LLC app.

Last Updated: 7/8/2026

1. Introduction

This Privacy Policy explains how Lumen Steps LLC ("Lumen Steps," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the Lumen Steps application (the "App"), a practice-management tool used by Applied Behavior Analysis ("ABA") providers — including Board Certified Behavior Analysts ("BCBAs") and Registered Behavior Technicians ("RBTs") — to manage client programs, session documentation, and related clinical workflows.

Lumen Steps is provided to licensed ABA clinics and practices ("Clinics," "Customers," or "you," when referring to an organization using the App). If you are a client, patient, or the parent/guardian of a client receiving services from a Clinic that uses Lumen Steps, please also refer to that Clinic's own privacy notice — the Clinic, not Lumen Steps, is your direct healthcare provider and is responsible for how your protected health information is used in the course of your care.

2. Scope — Two Categories of Information

This policy covers two distinct categories of data, and they are handled differently:

(a) Protected Health Information ("PHI"). This includes client/patient names, dates of birth, session notes, behavioral and clinical data, program and target data, signatures, and any uploaded documents related to a specific client's care. Lumen Steps processes this information solely on behalf of, and under the direction of, the Clinic that is our customer. Our handling of PHI is governed by a signed Business Associate Agreement ("BAA") with each Clinic, consistent with the Health Insurance Portability and Accountability Act ("HIPAA"). If there is ever a conflict between this Privacy Policy and a BAA in effect with a Clinic, the BAA controls with respect to PHI.

(b) Account & Usage Information. This includes information about the Clinic itself and its staff users (BCBAs, RBTs, administrators) — such as names, email addresses, login credentials, roles, and general app usage data — that is not itself a client's clinical record.

3. Information We Collect

3.1 Information Clinics and Staff Provide

  • Staff account information: name, email address, role (BCBA/RBT/admin), and authentication credentials.
  • Clinic information: clinic name, service codes, and configuration settings.
  • Client/patient records entered by clinic staff: name, date of birth, service/session details, behavior and program data, session notes, signatures, and documents uploaded in connection with a client's care.

3.2 Information Collected Automatically

  • Basic device and app usage information (e.g., app version, general error/diagnostic logs) used to keep the App running reliably.
  • Audit log entries recording actions taken within the App (e.g., who created, edited, or viewed a given record, and when) — maintained for security and compliance purposes.

We do not currently use third-party advertising, analytics, or tracking SDKs within the App.

4. How We Use Information

We use information collected through the App only to:

  • Provide, operate, and maintain the App's core functionality (client program management, session documentation, scheduling, reporting, and related tools).
  • Authenticate users and enforce role-based access controls.
  • Generate clinical documentation (e.g., session note exports) at the direction of Clinic staff.
  • Maintain audit logs for security, accountability, and compliance purposes.
  • Provide customer support to Clinics.
  • Improve, maintain, and troubleshoot the App.
  • Comply with legal obligations.

We do not sell personal information or PHI. We do not use client/patient data for advertising or marketing purposes.

5. How Information Is Stored and Who Can Access It

  • App data is stored using Google Cloud Platform / Firebase services (Cloud Firestore, Firebase Authentication, and Cloud Storage). These services operate under a Business Associate Agreement between Lumen Steps and Google, consistent with HIPAA requirements, for the specific services covered under that agreement.
  • Data is logically separated by Clinic. Clinic staff can only access data associated with their own Clinic and consistent with their assigned role (BCBA, RBT, or admin) — access controls are enforced through both application logic and backend security rules.
  • Lumen Steps personnel do not access client/patient PHI except as necessary to provide technical support, troubleshoot an issue at a Clinic's request, or as required by law — and any such access is logged.

6. Subprocessors

We use the following categories of subprocessors to operate the App. We will update this list if it changes materially.

SubprocessorPurposeData Involved
Google Cloud / FirebaseDatabase (Firestore), authentication, file storage, backend infrastructureAccount data and PHI, under BAA

7. Data Retention

  • Client/patient records are retained for as long as the Clinic maintains an active account, and thereafter for the period required by applicable law and professional recordkeeping requirements (which vary by state and typically range from 5–7+ years for behavioral health records) or as directed by the Clinic.
  • Upon a Clinic's request, and consistent with our BAA and applicable law, we will return or securely delete PHI at the end of the relationship, except where retention is required by law.
  • Staff account information is retained for as long as the account is active and for a reasonable period afterward for security and audit purposes.

8. Your Choices and Rights

If you are a Clinic or staff user: you may access, update, or request deletion of account information by contacting us at the email below, or through in-app account settings where available.

If you are a client, patient, or parent/guardian: requests regarding your (or your child's) health information should be directed to your Clinic directly, as they are the party responsible for your care and your health record under HIPAA. Lumen Steps will support the Clinic in fulfilling such requests as required by our BAA.

9. Children's Information

Lumen Steps is designed to be used by adult professional staff (BCBAs and RBTs) — it is not directed at children, and children do not create their own accounts or directly provide information to the App. Client/patient information belonging to minors is entered into the App by clinic staff, on behalf of the Clinic, under the Clinic's own authority and with parental/guardian consent obtained by the Clinic as part of its intake and consent process. Lumen Steps does not knowingly collect personal information directly from children.

10. Data Security

We use administrative, technical, and physical safeguards designed to protect information processed through the App, including:

  • Role-based access controls limiting staff to data relevant to their role and Clinic.
  • Encryption of data in transit and at rest (provided by our infrastructure provider).
  • Audit logging of sensitive actions.
  • Session timeout controls.
  • Ongoing internal review of access rules and logging practices.

No system can guarantee perfect security. If we become aware of a breach involving PHI, we will notify affected Clinics in accordance with our BAA and the HIPAA Breach Notification Rule.

11. International Data Transfers

All data is stored/processed within the United States.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to Clinics in advance where required by our agreements with them. The "Last Updated" date at the top of this policy reflects the most recent revision.

13. Contact Us

Questions about this Privacy Policy or our data practices can be directed to:

Lumen Steps LLC
Attn: Dylan Ranshaw
Email: lumensteps@gmail.com

© 2026 Lumen Steps LLC. All rights reserved.

Features Screenshots Privacy Policy Terms of Service lumensteps@gmail.com