Lumino Privacy Policy
Last Updated: September 4, 2025
Introduction and Our Commitment to Your Privacy
This Privacy Policy details how Lumino, a product dedicated to enhancing digital well-being through AI-powered conversational support, collects, utilizes, discloses, and safeguards your personal information. This policy applies to your interactions with Lumino through:
- The Lumino mobile application or web platform (collectively, the "Lumino Service"),
- Our official Lumino website,
- Participation in Lumino-hosted events, webinars, or marketing initiatives, or
- Any other direct provision of your personal data to Lumino.
Lumino operates as a Data Controller in direct relationships with individual users, meaning we determine the purposes and means of processing your personal data. If your access to the Lumino Service is facilitated by an organization (such as your employer or educational institution), our role as a Data Processor is governed by a separate Data Processing Agreement (DPA) established with that organization. Details of our DPA are available upon request.
By engaging with the Lumino Service, you signify your understanding and acceptance of the practices described within this Privacy Policy.
Important Notice: The Lumino Service is designed for general informational and supportive conversations and is not intended to provide, nor does it constitute, professional medical, psychological, or crisis intervention services. It is not a substitute for consultation with qualified healthcare professionals, licensed therapists, or emergency services. Users must refrain from using the Lumino Service for matters requiring immediate professional attention, including but not limited to: expressions of suicidal ideation, self-harm intentions, severe mental health crises, or any other content indicative of an urgent need for professional intervention. Should such topics arise, Lumino reserves the right to suspend or terminate your access and will direct you to appropriate professional or emergency resources.
Key Terms Defined:
- User Submissions: Refers to all textual inputs, messages, queries, or any other content you provide or upload to the Lumino Service or website.
- System Responses: Encompasses all generated replies, messages, or content produced by Lumino's artificial intelligence systems in direct response to your User Submissions.
- Individual User Data: Comprises all User Submissions, System Responses, and any other personal information directly furnished by you as an individual user of the Lumino Service.
- Organizational Client Data: Pertains to information supplied by entities (e.g., your employer or school) for the purpose of account setup and administration, such as your name, email address, and administrative details. This category of data is managed under our Data Processing Agreement (DPA) with the respective organization, not this Privacy Policy.
Disclaimer: Lumino is not subject to the Health Insurance Portability and Accountability Act (HIPAA) and does not deliver medical or clinical services. Consequently, you should not transmit any Protected Health Information (PHI) or sensitive medical data during your interactions with the Lumino Service.
Your continued use of the Lumino Service constitutes your explicit acknowledgment and agreement to the terms outlined in this Privacy Policy.
Information We Collect
Our data collection practices are designed to be transparent and are contingent upon your specific interactions with the Lumino Service. We gather different categories of information based on whether you are utilizing the Lumino Application, browsing our website, or engaging in our marketing activities.
Data Originating from Your Interactions (User Submissions and System Responses)
- User Submissions: This includes all content you actively input or upload into the Lumino Application or our website. Examples include your inquiries, messages, prompts, or any other textual data you provide.
- System Responses: This refers to the conversational outputs, generated messages, or other content produced by Lumino's AI systems as a direct result of your User Submissions.
- Interaction Data: This encompasses the complete record of your conversations and engagements with the Lumino Service, comprising both your User Submissions and the corresponding System Responses.
Account and Profile Information
- Account Registration Details: When you establish an account with Lumino, we collect essential information such as your full name, email address, contact number, and, where applicable, payment particulars.
- Voluntary Profile Enhancements: You may choose to provide additional, optional demographic information, personal preferences, or specific goals to enrich your Lumino profile.
Service Usage and Technical Data
- Operational Usage Metrics: We collect data on how you interact with the Lumino Service, including the specific features accessed, duration of sessions, frequency of use, and overall engagement patterns. This helps us understand service utilization and optimize performance.
- Device and Network Information: This category includes technical details about the device you use to access Lumino, such as device type, operating system, browser type, Internet Protocol (IP) address, and unique mobile device identifiers.
- General Geographic Data: We infer a general, non-precise location (e.g., city or region) based on your IP address. We do not collect precise GPS location data.
Website Visitors and Marketing Engagement Data
- Marketing Contact Details: This includes your name, email address, company affiliation, job title, and any other information you voluntarily provide when registering for our webinars, downloading informational resources, or subscribing to our marketing communications.
- Website Interaction Analytics: We gather data concerning your engagement with our website and email communications, such as your IP address, browser type, device information, and how you interact with our marketing content (e.g., clicks, opens).
How We Utilize Your Information
Lumino processes the collected information for a variety of purposes, primarily centered around delivering and enhancing our services, managing user accounts, facilitating marketing outreach, and ensuring legal and security compliance. Our data utilization practices are designed to be efficient and user-centric.
Service Delivery and Continuous Improvement
- Personalized AI Interactions: We leverage your User Submissions to generate relevant System Responses, thereby providing a highly personalized and adaptive conversational experience. This includes tailoring the AI's behavior and content to your specific preferences and historical interactions.
- Analytical Enhancement: We meticulously analyze User Submissions, System Responses, and comprehensive usage patterns to continuously refine and optimize your experience. This analysis helps us identify areas for feature development, service enhancement, and overall user satisfaction.
- AI Model Development and Training: Anonymized and aggregated User Submissions and System Responses are instrumental in the ongoing development and training of our underlying AI models. This process is crucial for improving the accuracy, contextual understanding, and overall quality of Lumino's AI capabilities. Should Lumino ever consider using non-anonymized data for AI model training, we commit to obtaining explicit user opt-in and providing clear, detailed explanations within the in-app privacy settings.
- Synthetic Data Generation: To further enhance our service without compromising individual privacy, we generate synthetic data derived from anonymized user interactions. This synthetic data aids in robust testing and development of new features.
- Strategic Insight Generation: Aggregated insights derived from user data inform our support strategies, product roadmap, and overall service delivery, ensuring that Lumino evolves in a manner that best serves its user base.
Account Administration and Management
- Account Provisioning and Maintenance: Your information is used to establish and maintain your Lumino account, manage your subscription details, and ensure secure and seamless access to our services.
- Billing and Payment Processing: We utilize your payment information to process subscription fees and manage all aspects of your billing cycle, ensuring accurate and timely transactions.
- Essential Communications: We communicate with you regarding critical account-related information, service updates, changes to our terms, and provide necessary technical support. These communications are integral to your use of the Lumino Service.
- Customer Support and Inquiry Resolution: Your information enables us to effectively address your queries, troubleshoot technical issues, and provide comprehensive customer support, ensuring a smooth user experience.
Marketing Initiatives and Website Operations
- Website Optimization and Marketing Communication Refinement: We analyze website usage data to enhance the user experience on our platform and to optimize the effectiveness of our marketing communications, ensuring they are relevant and engaging.
- Targeted Marketing Outreach: With your explicit consent (opt-in), we may send you marketing communications, product updates, and invitations to webinars or events that we believe may be of interest to you.
- Audience Understanding: By analyzing how visitors interact with our website and marketing materials, we gain valuable insights into user preferences, allowing us to tailor our content and outreach strategies more effectively.
Legal Compliance and Security Protocols
- Service Integrity and Security: We employ your information to detect, prevent, and mitigate fraudulent activities, unauthorized access attempts, and other potential security threats, thereby safeguarding the integrity and security of the Lumino Service.
- Fraud Prevention: Our systems continuously monitor for suspicious behavior and implement proactive security measures to protect both our platform and our users from fraudulent activities.
- Regulatory Adherence: We process your information as mandated by applicable laws, regulations, legal processes, governmental requests, and subpoenas, ensuring full compliance with legal obligations.
- Terms of Use Enforcement: This includes the enforcement of our Acceptable Use Policy and guidelines regarding Prohibited Topics. Lumino reserves the right to suspend or terminate accounts for violations of these policies or if user content indicates a need for professional care, and may remove content that contravenes our guidelines or legal requirements.
Information Sharing and Disclosure
Lumino upholds a strict commitment to the confidentiality of your information. We do not engage in the sale of your personal data to third parties. Any sharing or disclosure of your information occurs only under specific, limited circumstances, and always in compliance with applicable legal frameworks.
We may disclose personal information when legally mandated, such as in response to valid laws, regulations, legal processes, subpoenas, or legitimate governmental requests.
Collaborating with Service Providers (Sub-processors)
To facilitate the operation and improvement of the Lumino Service, we engage with carefully selected third-party service providers, often referred to as "sub-processors." These entities assist us with various functions, including but not limited to:
- Cloud Infrastructure: Providers for secure data storage and hosting services.
- Payment Processing: Entities responsible for securely handling subscription payments and billing transactions.
- Analytics Platforms: Services that help us understand user behavior and service performance in an aggregated and anonymized manner.
- Customer Support Systems: Tools and platforms that enable us to provide efficient and responsive user assistance.
Each of our service providers is contractually obligated to process your information solely for the purpose of delivering services to Lumino and must adhere to the principles outlined in this Privacy Policy, as well as all relevant privacy laws. A comprehensive list of our current sub-processors is available upon formal request.
Corporate Transactions and Business Transfers
In the event that Lumino undergoes a merger, acquisition, or the sale of its assets, your information may be transferred as part of that corporate transaction. Should such an event occur, we will provide timely notification via email and/or a prominent notice on our website, informing you of any change in ownership or how your information will be used.
Legal Obligations and Safety Imperatives
We may disclose your information if we are legally compelled to do so, for instance, by a court order, regulatory requirement, or governmental directive. Furthermore, we may disclose information if we genuinely believe it is necessary to protect our legal rights, investigate and prevent fraudulent activities, or safeguard the safety and well-being of our users or the general public.
Your Privacy Rights and Choices
Lumino is committed to empowering you with control over your personal information. Your privacy rights are influenced by your geographical location and applicable data protection laws. This section outlines the rights generally available to you concerning your Individual User Data, including your User Submissions and System Responses, as well as any other personal information you directly provide to Lumino as a user, website visitor, or marketing contact.
Universal Rights for All Users
Irrespective of your domicile, you are generally entitled to:
- Access and Review: Request access to and review the personal information we hold about you.
- Rectification: Seek correction of any inaccurate or incomplete personal information.
- Account and Data Deletion: Request the deletion of your Lumino account and associated personal information.
- Opt-Out of Marketing: Choose to opt out of receiving marketing communications from Lumino.
- Data Portability: Where technically feasible, request a copy of your User Submissions and System Responses in a structured, commonly used, and machine-readable format.
- Specific Data Deletion: Request the deletion of specific User Submissions and System Responses (where such functionality is available within the Lumino Application).
Rights Under the General Data Protection Regulation (GDPR) - EU, UK, and Switzerland
If you are located in the European Union, United Kingdom, or Switzerland, you benefit from additional rights under the GDPR, including:
- Right of Access: Obtain confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to the personal data.
- Right to Rectification: Have inaccurate personal data rectified, or incomplete personal data completed.
- Right to Erasure ('Right to be Forgotten'): Request the deletion of your personal data under certain conditions.
- Right to Restriction of Processing: Obtain restriction of processing under certain conditions.
- Right to Object: Object to the processing of your personal data under certain conditions.
- Right to Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format and transmit those data to another controller.
- Right to Withdraw Consent: Withdraw your consent at any time where processing is based on consent.
- Right to Lodge a Complaint: Lodge a complaint with a supervisory authority.
These rights specifically apply to your User Submissions, System Responses, and other Individual User Data. To exercise any of these GDPR-related rights, please contact us at privacy@getlumino.app.
California Consumer Privacy Act (CCPA/CPRA) - California Residents
California residents are afforded specific rights under the CCPA/CPRA, including:
- Right to Know: Understand what personal information is collected, used, shared, or sold.
- Right to Delete: Request the deletion of personal information held by businesses.
- Right to Opt-Out of Sale/Sharing: Opt out of the sale or sharing of personal information.
- Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights.
Lumino does not sell personal information, nor do we share your User Submissions or System Responses with third parties for advertising purposes. To exercise your CCPA/CPRA rights, please reach out to us at privacy@getlumino.app.
Other U.S. States with Comprehensive Privacy Laws
Residents of states such as Colorado, Connecticut, Utah, and Virginia, which have enacted comprehensive privacy legislation, may possess similar rights concerning the access, deletion, correction, and opt-out of certain processing activities related to their personal information. These rights extend to your User Submissions, System Responses, and other Individual User Data directly provided to Lumino.
Personal Information Protection and Electronic Documents Act (PIPEDA) - Canadian Residents
Canadian residents are granted rights under PIPEDA, including:
- Right of Access: Access your personal information held by an organization.
- Right to Challenge Accuracy: Challenge the accuracy and completeness of your information.
- Consent: Provide informed consent for the collection, use, and disclosure of your personal information.
- Withdrawal of Consent: Withdraw your consent, subject to legal or contractual restrictions and reasonable notice.
To exercise your PIPEDA rights, please contact us at privacy@getlumino.app. Please note that if you access Lumino through an organizational client, certain information management may be governed by your organization.
Lei Geral de Proteção de Dados (LGPD) - Brazilian Residents
Brazilian residents possess rights akin to those under the GDPR, encompassing rights to access, correction, anonymization, deletion, and information regarding data sharing practices.
Personal Information Protection Law (PIPL) - Chinese Residents
Residents of China are entitled to rights under PIPL, including:
- Access and Copy: Access and obtain a copy of their personal information.
- Correction and Completion: Request correction or completion of inaccurate or incomplete information.
- Deletion: Request deletion under specific circumstances.
- Explanation of Processing Rules: Obtain an explanation of the rules for processing their personal information.
- Withdraw Consent: Withdraw consent for the processing of their personal information.
Procedure for Exercising Your Rights
To exercise any of the aforementioned rights, please submit your request to privacy@getlumino.app. We are committed to responding to your request within the legally mandated timeframe (typically 30-45 days). For verification purposes, and to ensure the security of your data, we may require additional information to confirm your identity before fulfilling your request.
These rights are applicable to your Individual User Data, encompassing your User Submissions and System Responses, and any other personal information you directly provide to Lumino as a user, website visitor, or marketing contact.
Data Retention and Deletion Practices
Lumino retains your personal information only for the duration necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy, or as required by applicable legal obligations or legitimate business interests. Our retention periods are carefully considered to balance service provision with privacy principles.
Account Information Retention
- Your account details are maintained for the entire period your Lumino account remains active.
- Following the termination of your account or cancellation of your subscription, we will initiate the deletion of your personal information within a 30-day period. Please note that if your account was established through an organizational client, certain Organizational Client Data may be retained for a longer period as stipulated by our agreement with that organization.
Conversation Data Management
- For Active Users: Your conversation history (User Submissions and System Responses) is retained to facilitate personalized service delivery and to enhance your ongoing experience with Lumino.
- Post-Account Termination: Conversation data will be systematically deleted within 30 days after account termination. However, in instances where an account is terminated due to violations of our Acceptable Use Policy, Lumino may retain specific information for a longer duration if mandated by law or for legitimate business purposes, such as legal defense or compliance with regulatory requirements.
- You possess the capability to request the deletion of individual conversations directly through the Lumino Application, where such functionality is provided.
- It is important to understand that Conversation Data encompasses both your direct inputs (User Submissions) and the AI-generated responses (System Responses).
- Upon account termination, your User Submissions and System Responses are purged within 30 days, unless their retention is legally required or justified by legitimate business purposes (e.g., for legal proceedings or regulatory compliance).
Anonymized and Aggregated Data Retention
- Lumino reserves the right to retain data that has been fully anonymized and aggregated indefinitely. This category of data may include anonymized versions of User Submissions and System Responses.
- Crucially, anonymized and aggregated data cannot be linked back to you personally, ensuring your individual privacy.
- This data is exclusively utilized for the continuous improvement of our services, for internal research initiatives, and for analytical purposes, contributing to the overall enhancement of the Lumino Service.
Usage Data Retention
- Basic usage statistics, which do not directly identify you, may be retained for a period of up to 24 months.
- Subsequent to this period, such usage data is either completely anonymized or permanently deleted.
- Anonymized usage patterns, which provide insights into general service trends, may be retained indefinitely to inform ongoing service improvements and strategic development.
Jurisdiction-Specific Retention Mandates
- European Union, UK, and Switzerland: Data retention practices adhere strictly to the requirements stipulated by the GDPR and other relevant data protection laws in these regions.
- Other Jurisdictions: Lumino is committed to complying with local data retention requirements in all applicable jurisdictions where our service operates.
Data Deletion Protocol
When a request for data deletion is processed, or when data reaches the end of its defined retention period:
- Personal information is permanently removed from all active Lumino systems.
- Any backups containing your information are systematically cycled out and securely erased within a 90-day timeframe.
- It is important to reiterate that anonymized data derived from your usage, which cannot be used to identify you, may be retained for the purposes previously described.
Initiating a Deletion Request
You may request the deletion of your User Submissions, System Responses, and other Individual User Data at any time through the following channels:
- Utilizing any in-app deletion tools provided within the Lumino Application.
- Submitting a formal request via email to privacy@getlumino.app.
- Initiating the termination of your Lumino account.
Robust Security Measures
Lumino employs a multi-layered security framework designed to protect your information against unauthorized access, alteration, disclosure, or destruction. Our commitment to data security is paramount, integrating both cutting-edge technology and stringent organizational practices.
Technological Safeguards
- Advanced Encryption Protocols: We utilize industry-standard encryption techniques for all data, both in transit (e.g., using TLS/SSL) and at rest (e.g., AES-256 encryption for stored data). This ensures that your information is scrambled and unreadable to unauthorized parties as it travels across networks and while it resides on our servers.
- Proactive Vulnerability Management: Our systems undergo continuous and rigorous security assessments, including regular penetration testing conducted by independent third parties and automated vulnerability scanning. This proactive approach allows us to identify and remediate potential security weaknesses before they can be exploited.
- Granular Access Controls: Access to personal information is strictly limited to authorized Lumino personnel who require it to perform their job functions. We implement role-based access controls, ensuring that employees can only access the data necessary for their specific responsibilities. Strong authentication mechanisms, including multi-factor authentication (MFA), are mandatory for all internal access to sensitive systems.
- Real-time Threat Detection and Monitoring: Our infrastructure is equipped with sophisticated monitoring tools that provide real-time alerts for suspicious activities, unauthorized access attempts, and potential security incidents. This enables our security team to respond swiftly to emerging threats.
Organizational and Procedural Controls
- Comprehensive Employee Training: All Lumino employees, particularly those with access to personal data, receive mandatory and ongoing training on data privacy principles, security best practices, and our internal security policies. This fosters a culture of security awareness throughout the organization.
- Rigorous Personnel Vetting: We conduct thorough background checks and due diligence for all employees, especially those in roles that involve access to sensitive data, to ensure trustworthiness and adherence to our security standards.
- Formalized Security Policies: Lumino maintains a comprehensive suite of documented security policies and procedures that govern every aspect of data handling, from collection and processing to storage and deletion. These policies are regularly reviewed and updated to reflect the latest security standards and regulatory requirements.
- Structured Incident Response Plan: In the event of a suspected or confirmed data breach, Lumino has a meticulously designed incident response plan. This plan outlines clear steps for containment, investigation, eradication, recovery, and post-incident analysis, ensuring a rapid and effective response to minimize potential impact.
Third-Party Security Assurance
- Independent Security Audits: We regularly engage reputable, independent third-party firms to conduct comprehensive security audits and assessments of our systems, processes, and compliance posture. These audits provide an objective evaluation of our security effectiveness.
- Compliance with Industry Standards: Lumino strives to align its security practices with recognized industry standards and certifications, demonstrating our commitment to maintaining a high level of data protection.
- Vendor Security Due Diligence: Before engaging any third-party service provider, we conduct extensive security reviews and due diligence to ensure that their security practices meet or exceed our own stringent requirements. Our contracts with vendors include robust data protection clauses.
Data Breach Notification Protocol
In the unlikely event of a data breach that compromises your personal information, Lumino is committed to transparency and prompt action. We will:
- Notify affected individuals in strict accordance with applicable laws and regulatory requirements.
- Provide clear and timely information regarding the nature of the breach, the types of data involved, and the measures we are taking in response.
- Offer guidance and recommendations on steps you can take to protect yourself from potential harm resulting from the breach.
International Data Transfers
Lumino operates as a global service, which means your information may be processed and stored in countries outside of your country of residence. We are committed to ensuring that any such international transfers of personal data are conducted in full compliance with applicable data protection laws and that your data remains protected to a high standard, regardless of its location.
Mechanisms for Data Transfer
- For Transfers from the European Economic Area (EEA), UK, and Switzerland: We rely on recognized legal mechanisms to ensure adequate protection for personal data transferred from these regions. This primarily includes the use of Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally sanctioned safeguards that provide an equivalent level of data protection as required by the GDPR and related regulations.
- For Transfers from Other Jurisdictions: In other parts of the world, we implement appropriate safeguards as mandated by local data protection laws. These safeguards may include entering into data transfer agreements that incorporate robust data protection clauses, or relying on other legal frameworks designed to ensure the security and privacy of your data during cross-border transfers.
- Adequacy Assessment: Prior to transferring data to a new jurisdiction, Lumino conducts thorough assessments of the recipient country's data protection laws and practices to ascertain that they offer a level of protection for personal data that is substantially equivalent to that of the originating jurisdiction.
Data Localization Considerations
- Regional Data Storage: Where specific legal requirements or contractual obligations necessitate, Lumino may store certain categories of data within designated geographic regions. This ensures compliance with local data residency laws while maintaining the global accessibility and efficiency of our service.
- Global Infrastructure: We leverage cloud service providers that operate a globally distributed infrastructure. This allows us the flexibility to meet regional data storage requirements while simultaneously supporting the seamless operation and scalability of the Lumino Service worldwide.
Safeguards for Cross-Border Transfers
- Technical Protections: All data transferred across borders is subject to the same stringent technical safeguards applied to data at rest and in transit, including robust encryption, secure network configurations, and access controls, to prevent unauthorized access or interception.
- Contractual Commitments: Our agreements with all third-party service providers involved in international data transfers include explicit contractual commitments. These clauses legally bind them to adhere to Lumino's data protection standards and to comply with all relevant data transfer regulations.
- Ongoing Risk Assessment: We continuously monitor and assess the risks associated with international data transfers, adapting our safeguards and practices as necessary to respond to evolving legal landscapes and security threats, thereby ensuring the ongoing protection of your personal data.
Revisions to This Privacy Policy
Lumino reserves the right to update or modify this Privacy Policy periodically to reflect changes in our operational practices, legal and regulatory requirements, or the introduction of new service features. We encourage you to review this policy regularly to remain informed about how Lumino is committed to safeguarding your information.
- Notification of Significant Amendments: In the event of any material changes to this Privacy Policy that may substantially affect your rights or the processing of your personal data, Lumino will provide advance notification. This notification will typically be delivered via email to your registered address or through a prominent announcement within the Lumino Application or on our official website.
- Publication of Updates: All revisions to this Privacy Policy will be published on our website, accompanied by a revised "Effective Date" prominently displayed at the beginning of the document. This date indicates when the latest version of the policy came into effect.
- Continued Engagement: Your continued use of the Lumino Service subsequent to the publication of any modifications to this Privacy Policy will signify your acknowledgment and acceptance of the updated terms.
- Reaffirmation of Consent: For certain significant changes, particularly those that may alter the fundamental nature of data processing or your privacy rights, Lumino may, at its discretion, request your explicit reaffirmation of consent to the revised policy.
Contacting Lumino Regarding Your Privacy
Should you have any inquiries, concerns, or requests pertaining to this Privacy Policy or Lumino's data handling practices, please do not hesitate to reach out to us through the following dedicated channels:
For Privacy-Related Questions: privacy@getlumino.app
For Immediate Assistance or Technical Support: support@getlumino.app
Important Information Regarding the Lumino Service
Nature of the Lumino Service: Non-Medical and Non-Clinical
The Lumino Service is designed to provide AI-powered conversational support for general well-being and informational purposes. It is crucial to understand that Lumino does not offer medical advice, clinical therapy, psychological counseling, or any form of professional healthcare services. Our artificial intelligence is not a licensed therapist, medical doctor, or healthcare provider. The Lumino Service is explicitly not a substitute for professional medical diagnosis, treatment, or advice from qualified healthcare professionals.
Automated Processing and Data Handling
The core functionality of the Lumino Service relies predominantly on automated processing by our advanced AI systems. We do not routinely engage in human monitoring or review of individual user conversations. Our automated systems analyze conversational data to continuously enhance the AI's responsiveness, accuracy, and overall functionality. Any instances of human review of data are strictly limited to anonymized or aggregated datasets, conducted solely for the purpose of service improvement, research, and development, ensuring that individual privacy is maintained.