Clarē — Privacy Policy
Last updated: [DATE]
This Privacy Policy explains how Lumera Holdings Pty Ltd (ABN [INSERT ABN], ACN [INSERT ACN]) ("Lumera," "we," "us," or "our") collects, uses, holds, and discloses personal information in connection with the Clarē application and website (the "Service").
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). Additional rights for users in the European Economic Area / United Kingdom and California are described in Sections 11 and 12.
By using the Service, you consent to the collection and handling of your information as described in this Policy.
1. Our Privacy Approach
We are built around data minimisation. Much of the Service runs on your device, and information such as your product shelf, skin inputs, and routine history is stored locally on your device unless you create an account and choose to sync it. We collect only what we reasonably need to operate and improve the Service.
2. Information We Collect
a) Information you provide directly:
- Skincare inputs — information you enter about your skin, such as skin type, sensitivity, concerns, age band, and skin-reaction characteristics, and the products you add to your shelf. Some of this may relate to your skin's condition.
- Account information — if you create an account, your sign-in details are handled by our third-party authentication provider; we receive an account identifier and, if provided, your name and email address.
- Submissions — content you choose to submit, such as bug reports, feedback, product submissions, images, and any screenshot or contextual information captured when you submit a report.
b) Information collected automatically:
- Technical and usage data — such as device type, operating system, app version, general usage events, and diagnostic information, including information captured to help us diagnose issues you report.
- Approximate location — we do not collect precise GPS location. Limited location information may be inferred from your network/IP for security and regional functionality.
c) Information from third parties:
- Our authentication provider supplies the account identifier and limited profile information described above.
- Product and ingredient information in the Service is compiled from third-party and public sources; this is not your personal information.
Sensitive information: Some skincare inputs may be health-related. Where information is "sensitive information" under the Privacy Act, we collect it only with your consent and only to provide the Service's features, and you may choose not to provide it (though some features may then be limited).
3. How We Use Your Information
We use personal information to:
- provide, operate, personalise, and maintain the Service, including generating routines and suggestions;
- create and manage your account and sync your data across devices if you choose;
- respond to and diagnose bug reports, submissions, and support requests;
- develop, test, and improve the Service, our features, our scoring and rule systems, and our products;
- maintain the security, integrity, and proper functioning of the Service and prevent misuse;
- comply with our legal obligations and enforce our Terms; and
- communicate with you about the Service.
We may create and use de-identified or aggregated information (which is not personal information) for any purpose, including analytics and improving our products.
4. Third-Party Service Providers
We use third-party providers to operate the Service, who may process information on our behalf, including:
- Cloudflare — hosting, infrastructure, and security;
- Clerk — account authentication and session management;
- OCR / text-recognition providers — if you use label-scanning features, the relevant image may be sent to a third-party text-recognition service to extract text; we instruct such providers to process only what is needed and not to retain it beyond what is necessary;
- code hosting and operational tooling used to receive and manage submissions and reports.
These providers are bound by their own terms and privacy obligations. We share only what is necessary for them to perform their functions.
5. Disclosure of Information
We do not sell your personal information. We do not display third-party advertising in the Service, and we do not allow advertisers to pay to influence recommendations.
We may disclose personal information:
- to our service providers described above;
- as required or authorised by law, regulation, legal process, or governmental request;
- to protect our rights, property, safety, or that of our users or the public, and to investigate or prevent fraud, security issues, or misuse;
- in connection with a corporate transaction such as a merger, acquisition, financing, or sale of assets, in which case information may be transferred to the successor entity; and
- with your consent or at your direction.
Cross-app data sharing: If, in the future, you choose to link your account with another product in our ecosystem, data will only be shared between products with your explicit consent, and only the specific data you consent to share.
6. Overseas Disclosure
Some of our service providers store and process information outside Australia (including in the United States and other jurisdictions). By using the Service, you acknowledge that your information may be transferred to, stored, and processed overseas. We take reasonable steps to ensure your information is handled consistently with this Policy, but the privacy laws of those jurisdictions may differ from those in Australia.
7. Data Storage and Security
- Much of your data resides on your device; account-synced data is held by our infrastructure providers.
- We take reasonable technical and organisational measures to protect personal information from misuse, loss, unauthorised access, modification, or disclosure.
- No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security, and you provide information at your own risk.
- If a data breach occurs that is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches scheme.
8. Data Retention
We retain personal information for as long as necessary to provide the Service, for the purposes described in this Policy, and as required to comply with our legal obligations, resolve disputes, and enforce our agreements. We may retain de-identified or aggregated information indefinitely. When information is no longer required, we take reasonable steps to delete or de-identify it.
9. Your Choices and Rights (All Users)
- On-device data: you can delete locally stored data by clearing it within the app or removing the app from your device.
- Account data: you may request access to, correction of, or deletion of personal information we hold about you by contacting us. We will respond consistently with the APPs and applicable law.
- We may need to verify your identity before acting on a request, and some information may be retained where permitted or required by law.
10. Children's Privacy
The Service is not intended for, and we do not knowingly collect personal information from, children under 16. If you believe a child has provided us personal information, contact us and we will take reasonable steps to delete it.
11. Additional Rights — EEA / UK Users (GDPR)
If you are in the European Economic Area or the United Kingdom, you have rights including: access, rectification, erasure, restriction of processing, data portability, and objection to processing, and the right to lodge a complaint with a supervisory authority.
- Legal bases on which we process personal data include: performance of a contract (providing the Service), your consent (including for health-related inputs and label-scanning), our legitimate interests (operating, securing, and improving the Service, where not overridden by your rights), and compliance with legal obligations.
- Where processing is based on consent, you may withdraw consent at any time without affecting prior processing.
- To exercise these rights, contact us using the details below.
12. Additional Rights — California Users (CCPA/CPRA)
If you are a California resident, you have rights including: to know what personal information we collect and how we use and disclose it; to access and delete it; to correct inaccurate information; and to not be discriminated against for exercising your rights. We do not sell or "share" personal information as those terms are defined under California law. To exercise these rights, contact us using the details below.
13. Changes to this Policy
We may update this Policy from time to time. Changes are effective when posted (or as otherwise indicated). Where required by law, we will provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
14. How to Contact Us / Make a Complaint
For privacy questions, requests, or complaints:
Lumera Holdings Pty Ltd
[INSERT REGISTERED ADDRESS]
Email: [INSERT PRIVACY CONTACT EMAIL]
We will respond within a reasonable time. If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
This Privacy Policy is a general template and does not constitute legal advice. Because it involves health-related data and users across multiple jurisdictions, it should be reviewed by a qualified privacy lawyer before being relied upon.