localizer pixel
Last Modified: Oct 17th, 2019

    Lumos Labs, Inc. ("Lumos Labs," "our," "us," or "we") knows your privacy is important to you, and we are committed to providing a safe and secure user experience. This Privacy Policy is incorporated into the Lumosity Terms of Service, and applies to the use of (1) Lumosity online at Lumosity.com, (2) Lumosity online on mobile devices, and (3) any other services that include a link to and/or copy of this Privacy Policy on the home page of the applicable website or similar location (e.g., a settings page) for any applicable mobile applications (collectively, "Lumosity"), which are owned and operated Lumos Labs. It describes how we collect, use, secure, and share information of our users and individuals whose payment details are used to purchase Lumosity (collectively, "you" or "your"). It also describes how to access, update, and correct your personal data and the choices available to you regarding your personal data. Under applicable law, Lumos Labs is the data controller of your personal data.

    Before you use or submit any information through or in connection with Lumosity, please carefully review this Privacy Policy. By using any part of Lumosity, you consent to the collection, use, and disclosure of your information as further outlined in this Privacy Policy.

    1. What Information We Collect
      1. Information You Provide Directly To Us
      2. Information That Is Passively Or Automatically Collected
        1. Device/Usage Information
        2. Cookies And Other Electronic Technology
      3. Information Provided By Social Networking Services And Others
    2. How We Use Your Information at Lumos Labs
    3. Legal Bases For Use Of Your Personal Data
    4. No Disclosure to Third Parties for Their Own Marketing Purposes
    5. When We Share Your Personal Information With Third Parties
    6. Online Analytics And Tailored Advertising
    7. Data Subject Rights And Your Choices
    8. Retention Of Personal Data And Security
    9. Outside The United States Consent To Processing And Transfer Of Information
    10. Additional Information
      1. Links To Third Party Websites
      2. Blog
      3. Referrals And Contacts
      4. Social Media Widgets
    11. EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield
    12. Children
    13. California "Do Not Track" Notice
    14. Change Policy
    15. Contact Information
    1. What Information We Collect
      1. Information You Provide Directly to Us
      2. We may collect information from you in a variety of ways, such as when you:

        • Register for a Lumosity account (“Account”);
        • Request certain features (e.g. newsletters);
        • Fill out a survey or provide us with feedback;
        • Play cognitive training games or engage in other activities that require your information to function (e.g., portions of Lumosity that require an Account to participate);
        • Apply for a job with us;
        • Communicate with us; or
        • Post user-generated content to Lumosity.

        You are not required to create an Account to gain access to some areas of Lumosity. If you do create an Account, we ask for certain information to process your registration, including an email address and password. If you subscribe to a paid Account, we request additional information, including your full name and payment method details.

        We may also collect (1) name, (2) gender, (3) date of birth, (4) education level, (5) other demographic information, and (6) other information you voluntarily provide to us. Providing most of this information is optional. We also allow you select your preferences for training, language, and receiving email communications.

      1. Information that is Passively or Automatically Collected
      2. In addition to the information you provide directly to us, when you use Lumosity, we automatically collect information about the computer, mobile device, or other devices you use to access Lumosity and about how you use Lumosity. For example, we receive data about the games you play and your performance in those games. We also receive information such as your browser type, IP address, language, the type of device you use, operating system version, unique device identifier ("UDID"), the date and time of your visit and files you viewed on our site (e.g., HTML pages, graphics, etc.), Internet service provider, clickstream data, the pages you view and the websites you visited immediately before and after visiting Lumosity. In some cases, we link this automatically collected data to other information we collect about you. We do this to improve the services and marketing we offer you.

        1. Device/Usage Information
        2. We may automatically collect certain information about the computer or devices (including mobile devices or tablets) you use to access Lumosity. As described further below, we may collect and analyze information such as (a) IP addresses, geolocation information (based on IP addresses), unique device identifiers, IMEI and TCP/IP address, and other information about your computer or device(s), browser types, browser language, operating system, mobile device carrier information, the state or country from which you accessed Lumosity; and (b) information related to the ways in which you interact with Lumosity, such as: referring and exit web pages and URLs, platform type, the number of clicks, domain names, landing pages, pages and content viewed and the order of those pages, statistical information about the use of Lumosity, the amount of time spent on particular pages, the date and time you used Lumosity, the frequency of your use of Lumosity, error logs, and other similar information. As described further below, we may use third-party analytics providers and technologies, including cookies and similar tools, to assist in collecting this information.

        1. Cookies and Other Electronic Technology
        2. Like many other companies, we and third parties that we work with use cookies and other web and mobile tracking technologies, like HTML5, web beacons, scripts, pixels, server logs, and tags. We use these technologies for authentication, to store your preferences or progress, for analytics, and to help us advertise Lumosity. A web server log is a file where website activity is stored. A cookie is a small text file that is placed on your computer when you visit a website, that enables us to: (i) recognize your computer; (ii) store your preferences and settings; (iii) understand the web pages of Lumosity you have visited; (iv), enhance your user experience by delivering content specific to your interests; (v) perform searches and analytics; and (vi) assist with security administrative functions. Some cookies are placed in your browser cache while those associated with Flash technologies are stored with your Adobe Flash Player files. Tracking pixels (sometimes referred to as web beacons or clear GIFs) are tiny electronic tags with a unique identifier embedded in websites, online ads and/or email, and that are designed to provide usage information like ad impressions or clicks, measure popularity of Lumosity and associated advertising, and to access user cookies. As we adopt additional technologies, we may also gather additional information through other methods.

          Please note that you can change your settings to notify you when a cookie is being set or updated, or to block cookies altogether. Please consult the "Help" section of your browser for more information (e.g., Internet Explorer; Google Chrome; Mozilla Firefox; or Apple Safari). You can also manage the use of Flash technologies, including cookies and local storage objects with the Flash management tools available at Adobe's website. Please note that by blocking any or all cookies, you may not have access to certain features or offerings of Lumosity.

      1. Information Provided by Social Networking Services and Others
      2. We may supplement the information you provide to us with additional information gathered from other sources, such as publicly available information, or from third parties, such as marketers, partners, researchers and others. We may combine information that we collect from you with information about you that we obtain from such third parties and information derived from any other product or service we provide.

        If you sign in to Lumosity using your Facebook or other third party credentials, we will use that service to authenticate you. We may also receive other information that you have agreed may be provided by that third party, such as your username, name, e-mail address, photo, location, date of birth, gender, an ID associated with the applicable third party platform, user files like photos and videos, your list of friends, people you follow and/or who follow you, and/or your posts or "likes." We receive this information so that it can be used for the purposes explained in this Privacy Policy. If you do not wish to have this information shared by these third parties, do not use Facebook or another third party to access Lumosity. We may also collect other information through other social networks that you make available to us. For a description on how social networking and other third party sites handle and share your information, please refer to their privacy policies and terms of use, which may permit you to modify your privacy settings. We may combine information that we collect from or about you with information about you that we obtain from such social media and other content platforms and information derived from any other subscription, product, or service we provide.

        If you are a subject in a research project or study conducted by Lumos Labs in partnership with a researcher or educational institution, that project may involve the collection of different information than is described in this Section. Research participants may, for example, provide health-related information, including the existence of certain health conditions. Lumos Labs partners with researchers and educational institutions in conducting such studies. Such research projects are typically done on an anonymous basis, such that Lumos Labs acts only as a processor of anonymized or pseudononymized data. For further information on how we handle data associated with such research, please refer to the materials distributed to you as part of the study, contact the researcher leading your study, or contact us using the contact information below.

    2. How We Use Your Information at Lumos Labs
    3. We use your information to operate and provide you with Lumosity and other services. This includes, but is not limited to:

      1. For the purposes for which you provided it;
      2. Authenticating your login and processing your payments;
      3. Personalizing your Lumosity experience and customizing your training program;
      4. Allowing you to monitor your performance and progress in Lumosity, by, for example, presenting charts and graphs of your performance to you;
      5. Customizing and delivering information about our products and services by email;
      6. To contact you with information, surveys, or advertising that we believe may be of interest to you regarding us or Lumosity;
      7. To administer contests and surveys;
      8. Providing customer support and sending confirmations about your Account;
      9. For internal research and reporting;
      10. Protecting our intellectual property or other rights; and
      11. Managing and improving our business, our games, and our training.

      We also reserve the right to use and disclose non-personal data (e.g., de-identified or aggregate data) for any purpose. For example, we show aggregate performance measures to users to allow them to evaluate their performance against other Lumosity users. Also, in connection with our Human Cognition Project, we may disclose performance statistics to university collaborators to evaluate, study, and improve the effectiveness of our programs or human cognition more generally. In these situations, all data is disclosed either in aggregate form or with information that can identify you removed. In addition, when we work with university collaborators, we contractually prohibit them from attempting to re-identify individuals from data that has been de-identified.

      We also use reCAPTCHA v.3 feature of Google to determine whether inputs are made by a natural person or by potentially abusive automated tools (bots). reCAPTCHA uses data such as IP address and activity patterns (e.g., typing/mouse movements) to make such determination. reCAPTCHA is subject to Google’s Terms of Service and Privacy Policy.

      The laws in some jurisdictions require companies to tell you about the legal ground they rely on to use or disclose your personal data. To the extent those laws apply, our legal grounds are as follows:

      • To honor our contractual commitments to you: Much of our processing of personal data is to meet our contractual obligations to our users, or to take steps at users’ request in anticipation of entering into a contract with them. For example, we handle personal data on this basis for our premium users.
      • Consent: Where required by law, and in some other cases, we handle personal data on the basis of your implied or express consent. Where you have provided consent, you may withdraw your consent at any time, without affecting the lawfulness of the processing that was carried out prior to withdrawing your consent. To withdraw your consent, please contact us at legal@lumoslabs.com.
      • Legitimate interests: In many cases, we handle personal data on the ground that it furthers our legitimate interests in ways that are not overridden by the interests or fundamental rights and freedoms of the affected individuals, such as:
        • Providing a safe and enjoyable user experience;
        • Customer service;
        • Marketing;
        • Protecting our users, personnel, and property;
        • Analyzing and improving our business;
        • Processing job applications; and
        • Managing legal issues.
        • We may also process personal data for the legitimate interests of our research partners, such as to provide cognitive training, research, and analytics for such partners.
      • Legal compliance: We need to use and disclose personal data in certain ways to comply with our legal obligations.
      • To protect the vital interests of the individual or others: For example, we may collect or share personal data to help resolve an urgent safety situation.

    4. No Disclosure to Third Parties for Their Own Marketing Purposes
    5. We believe in protecting your privacy, and therefore do not provide your personal data to third parties for their own marketing purposes.

    6. When We Share Your Personal Information With Third Parties
    7. We may share your personal data only in the following ways:

      1. Service providers and agents
      2. We may share your information with certain third parties selected by us to help support our operations. These include, for example, services that help us process payments, analyze web traffic, send emails, and track customer support requests. In addition, we may share limited personal data to third parties that help us market or advertise Lumosity. These third parties may have access to your information only for purposes of performing these tasks on our behalf and we contractually require them to protect your information consistent with this Privacy Policy.

      1. Affiliates
      2. We may share your information with our corporate affiliates, such as entities under common ownership or control.

      1. Business transfers
      2. We may sell, transfer, or otherwise share some or all of our assets in connection with an actual or contemplated merger, reorganization, business transaction, or in the event of bankruptcy. In such scenarios, your information may be one of the assets transferred. We will post a notice or otherwise notify you and collect your consent, as may be required by law, before the information is transferred and becomes subject to a different privacy policy.

      1. Compliance with law and law enforcement requests, and protection of our rights.
      2. We may disclose your information when we have a good faith belief we are required to do so by law, or in response to a subpoena, court order, or other legal mechanism. We may also disclose your information when we have a good faith belief that disclosure may prevent fraud and abuse of Lumosity or its users or protect our property rights.

        We may disclose your information when we believe we have your consent to do so, such as when you contact customer support and ask us about your Account, or when we have the consent of someone we believe is authorized to consent on behalf of you, such as the individual associated with the payment method for your Account. If you have expressly agreed to participate in a research study with us or with a third party that incorporates your personal data collected by Lumosity, we also may disclose your information for the purpose of facilitating the research to which you have consented.

    8. Online Analytics And Tailored Advertising
    9. We may use third-party web analytics services on Lumosity, such as those of Google Analytics, Rollbar, and New Relic. These service providers use the sort of technology previously described in the "Cookies and other electronic technologies" section to help us analyze how users use Lumosity, including by noting the third-party website from which you arrive, how often you use our app, the events that occur within our app, where the app was downloaded from, and provide certain features to you. The information (including your IP address) collected by the technology will be disclosed to or collected directly by these service providers, who use the information to evaluate your use of Lumosity. To prevent Google Analytics from using your information for analytics, you may install the Google Analytics Opt-out Browser Add-on by clicking here.

      If you receive email from us, we may use certain tools, such as clear GIFs to capture data such as when you open our message or click on any links or banners our email contains. This data allows us to gauge the effectiveness of our communications.

      We may personalize the content and advertising that you see when using Lumosity through the use of third-party advertising technologies that allow for the delivery of relevant content and advertising on our websites, as well as other websites you visit and other applications you use. The ads may be based on various factors such as the content of the page you are visiting, information you provide such as your age and gender, your searches, demographic data, user-generated content, and other information we collect from you. These ads may be based on your current activity or your activity over time and may be tailored to your interests.

      Also, third parties whose products or services are accessible or advertised via Lumosity may also place cookies or other tracking technologies on your computer, mobile phone, or other device to collect information about your use of Lumosity in order to (i) inform, optimize, and serve ads based on past visits to our websites and other sites and (ii) report how our ad impressions, other uses of ad services, and interactions with these ad impressions and ad services are related to visits to our websites and use of Lumosity. We also may allow other third parties (e.g., ad networks and ad servers such as Google Analytics, DoubleClick, and others) to serve tailored ads to you on Lumosity, other sites, and in other applications, and to access their own cookies or other tracking technologies on your computer, mobile phone, or other device you use to access Lumosity. We also may share with third-party advertisers a hashed version of your email address, solely in non-human readable form for purposes of delivering tailored advertising. We neither have access to, nor does this Privacy Policy govern, the use of cookies or other tracking technologies that may be placed on your computer, mobile phone, or other device you use to access Lumosity by non-affiliated, third-party ad technology, ad servers, ad networks or any other non-affiliated third parties. Those parties that use these technologies may offer you a way to opt out of ad targeting as described below. If you are interested in more information about tailored browser advertising and how you can generally control cookies from being put on your computer to deliver tailored advertising, you may visit the Network Advertising Initiative’s Consumer Opt-Out link or the Digital Advertising Alliance’s Consumer Opt-Out link to opt-out of receiving tailored advertising from companies that participate in those programs.

      To opt out of Google Analytics for display advertising or customize Google display network ads, you can visit the Google Ads Settings page. Please note that to the extent advertising technology is integrated into Lumosity, you may still receive advertisements even if you opt-out of tailored advertising. In that case, the ads will just not be tailored. Also, we do not control any of the above opt-out links and are not responsible for any choices you make using these mechanisms or the continued availability or accuracy of these mechanisms.

    10. Data Subject Rights And Your Choices
    11. Account Review

      You may access, review, correct, and delete certain of your personal data by logging into your Account.

      Analytics and Advertising

      You also can exercise certain opt-out rights by following the instructions at the end of the "Online Analytics and Tailored Advertising" section above.

      Your Legal Rights

      In addition, individuals in the European Union and some other jurisdictions outside the United States have certain legal rights to request that we:

      • confirm whether we hold personal data about them,
      • provide access to personal data we hold about them (including, in some cases, in portable form),
      • update, amend and/or correct personal data we hold;
      • delete certain personal data in appropriate circumstances;
      • transfer personal data to a third party provider of services;
      To exercise any of the above rights (or any other rights under applicable law), please contact us via our help center.

      In addition, individuals in the European Union and some other jurisdictions outside the United States have certain legal rights to obtain confirmation of whether we hold personal data about them, to access personal data we hold about them (including, in some cases, in portable form), and to obtain its correction, update, amendment or deletion in appropriate circumstances. They may also object to our uses or disclosures of personal data or exercise legal rights to withdraw consent, though such actions typically will not have retroactive effect. To exercise any of the above rights (or any other rights under applicable law), please contact us via our help center.

      The rights described herein are subject to limitations and exceptions under applicable law. In situations in which we process personal data on behalf of our research partners, we may refer the request to the relevant research partner and cooperate with their handling of the request, subject to any special contractual arrangement with that research partner.

      In addition to the rights above, residents of the European Economic Area also have the right to lodge a complaint with your relevant supervisory authority. However, we encourage you to contact us first, and we will do our very best to resolve your concern.

      Marketing

      You can opt out of receiving marketing emails by navigating to your Email Notifications page or by following the unsubscribe instructions included in each email. Please note you may not opt out of certain transactional emails, such as when we email you to confirm transactions, address Account issues, or communicate about customer support.

      Push Notifications

      From time to time, we use push notifications in our mobile applications to send you messages about Lumosity or your Account. You may opt out from receiving push notifications through your device settings.

    12. Retention Of Personal Data And Security
    13. We keep your information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws. To dispose of personal data, we may anonymize it, delete it or take other appropriate steps. Data may persist in copies made for backup and business continuity purposes for additional time.

      We have implemented and maintain security practices to protect against the unauthorized access, use, modification, destruction or disclosure of your personal data. For example, when you enter sensitive information on our order forms, we encrypt the transmission of that information using secure socket layer technology (SSL). We follow generally accepted standards to protect the personal data submitted to us, both during transmission and once we receive it. However, no method of transmission or storage is completely secure, and we therefore cannot guarantee absolute security. If you have any questions about security on our website, please contact us using the contact information below.

      If you access Lumosity outside of the United States, you fully understand and unambiguously consent to the transfer of your personal data to, and the collection and processing of such personal data in the United States. The recipients of the personal data disclosures described in the "When We Share Your Personal Data with Third Parties" section above may be located in the United States or elsewhere in the world. Privacy laws in these countries may not provide protections equivalent to those of your country of residence, and your government may or may not deem such protections adequate.

    14. Additional Information
      1. Our website includes links to other sites that may collect personal data, and whose privacy practices may differ from those of Lumos Labs. Please be aware that we are not responsible for the privacy practices of such other sites. We encourage you to review their privacy policies.

      1. Blog
      2. Our website offers publicly accessible blogs. Some blog posts allow comments via Facebook. You may need to login or contact Facebook both to post comments and to delete personal data that previously was posted in the comments. You can review Facebook’s privacy policy at this link: https://www.facebook.com/policy.php.

      1. Referrals And Contacts
      2. We allow you to refer your friends and contacts to Lumosity, either by manually entering their email addresses or by importing contacts from email accounts you have with third parties. If you choose to utilize these features, we’ll use and store the email addresses only for purposes of sending the invitation emails you have requested. If you utilize these features, the friends or contacts that you refer may contact us at the contact information listed below to request that we delete their personal data. Please note that we do not collect the username and password to your email accounts; the import features route you to the third party email provider to log in through their services.

      1. Social Media Widgets
      2. Our website may include social media features, such as Facebook and Twitter buttons. Such features may collect your IP address and information about the page you are visiting, and may set cookies to function properly. Your interactions with these features are governed by the privacy policies of the company providing them.

    15. EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield
    16. Lumos Labs participates in and has certified its compliance with the EU – U.S. Privacy Shield Framework and the Swiss – U.S. Privacy Shield Framework. Lumos Labs is committed to subjecting all personal data received from European Union (EU) member countries and Switzerland, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List. https://www.privacyshield.gov/list

      Lumos Labs is responsible for the processing of personal data it receives under the Privacy Shield Framework. When Lumos Labs receives information under the Privacy Shield and then transfers it to a third-party service provider acting as an agent on Lumos Labs’s behalf, Lumos Labs has certain liability under the Privacy Shield if both (a) the agent processes the information in a manner inconsistent with the Privacy Shield and (b) Lumos Labs is responsible for the event giving rise to the damage. Lumos Labs complies with the Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland, including the onward transfer liability provisions.

      With respect to personal data received or transferred pursuant to the Privacy Shield Framework, Lumos Labs is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Lumos Labs may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

      Please contact us at the contact information below if you have an unresolved privacy or data use concern, If after that you feel that we have not addressed your privacy or data use concern satisfactorily, please contact our U.S.-based third party dispute resolution provider (at no cost) at https://www.jamsadr.com/eu-us-privacy-shield.

      Under certain conditions, more fully described on the Privacy Shield website https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, you may invoke binding arbitration when other dispute resolution procedures have been exhausted. Prior to initiating such arbitration, you must: (1) contact Lumos Labs and afford us the opportunity to resolve the issue; (2) seek assistance from Lumos Labs’ designated independent recourse mechanism above; and (3) contact the U.S. Department of Commerce (either directly or through a European Data Protection Authority) and afford the Department of Commerce time to attempt to resolve the issue. Each party shall be responsible for its own attorney’s fees. Please be advised that, pursuant to the Privacy Shield, the arbitrator(s) may only impose individual-specific, non-monetary, equitable relief necessary to remedy any violation of the Privacy Shield Principles with respect to the individual.

    17. Children
    18. Lumosity is not directed to individuals under 13 years old. As appropriate under applicable law, parents or legal guardians with questions or requests regarding their children’s personal data may contact us as described below.

    19. California "Do Not Track" Notice
    20. We do not track our customers’ personal data over time and across third-party websites to provide targeted advertising and therefore do not respond to "Do Not Track" (DNT) signals.

    21. Change Policy
    22. This Privacy Policy may be updated from time to time. If we make material changes, we will provide notice to you either by email, by posting a notification on Lumosity or by posting an updated privacy policy on Lumosity 45 days in advance of the effective date of the updated Privacy Policy. Please note that, for existing users, unless otherwise provided by applicable law, your continued use of Lumosity following the effective date means that you agree with, and consent to be bound by, the updated Privacy Policy.

    23. Contact Information
    24. We welcome inquiries or comments about our Privacy Policy via our help center. You may also send a letter to the following address:

      Director of Legal
      Lumos Labs, Inc.
      140 New Montgomery Street, Floor 19
      San Francisco, CA 94105