Back to Lucid

Privacy Policy

Last updated 7 August 2026

1. Who we are

Lucid is operated by Prashanth Nimmagadda (“we”, “us”, “our”), an individual developer based in England & Wales. Lucid is a non-commercial educational portfolio project. It charges nothing and collects no payment details, and on that basis it is exempt from mandatory ICO registration under the ICO’s self-assessment framework.

This policy explains what Lucid stores, what it sends elsewhere, and what you can do about either.

2. How your prompts are processed

Lucid is designed so that the AI account is yours, not ours. You connect your own provider credential, and requests are billed to your account by that provider directly. We hold no provider API keys of our own, so there is no shared pool of credit that your prompts are drawn against.

When you send a message, Lucid passes it to the model provider you selected, along with any conversation summary, text extracted from files you attached, and web search results if you enabled search. It does not silently reroute your prompt to a different model than the one you chose.

What the provider does with that content is governed by their terms, not by ours. Some providers use input sent on free or evaluation tiers to improve their models. We cannot promise otherwise on their behalf, and we would rather say so than imply a guarantee we have no way to enforce. If this matters to you, read the terms of the provider whose model you are using and choose accordingly.

3. Data we collect

Account

Your email address, and a display name and avatar if you set one. Your email is how you sign in and how we send your sign-in link.

Conversations

The messages you send, the replies you receive, which model produced them, and a running summary used to give the model context on longer threads. We also record token counts and computed cost per reply so you can see your own usage.

Files

Files you upload and the text extracted from them so a model can read them. These are deleted within 48 hours of upload.

Connected accounts

If you connect an OpenRouter account, the resulting API key is stored in your own browser and is never sent to our database. If you link a ChatGPT subscription, we store an access and refresh token, encrypted, because that connection cannot work any other way in a web application. It is used only to make the requests you ask for, and you can disconnect it at any time.

Sessions

A signed session token, stored in an httpOnly cookie and in our database, so you stay signed in for 30 days.

Diagnostics

When something breaks, the exception and its stack trace go to Sentry. We do not attach message content to error reports.

4. Legal bases for processing

  • Performance of a contract — running the service you asked for: your account, your conversations, your files, and the provider connections you set up.
  • Legitimate interests — keeping the service secure, applying rate limits, and diagnosing faults.
  • Legal obligation — where we are required by law to retain or disclose something.

We do not rely on consent for analytics, because Lucid has no analytics. See section 9.

5. Data retention

  • Files expire 24 hours after upload and are deleted by an automated job that sweeps once a day, and again whenever you use Lucid. Worst case, a file you upload and never return to is removed within 48 hours. This is enforced in code, not a policy we intend to follow.
  • Conversations are kept until you delete them or delete your account.
  • Sessions expire after 30 days, or immediately when you sign out.
  • Connected accounts are kept until you disconnect them or delete your account.
  • Your account is kept until you delete it.

6. Your rights

If you are in the UK or the EU you have the right to access your data, correct it, export it, restrict or object to how it is processed, and have it erased.

Deletion is available directly in the product, from your settings, and it is permanent rather than a deactivation. It removes your account record, every conversation and message, every uploaded file including the stored file itself, your usage history, any connected accounts, and every active session. Your email address goes with it, which means it becomes available for signing up again later. We do not keep a shadow copy, so we cannot restore it for you afterwards.

For anything other than deletion, contact us and we will respond within 30 days. You also have the right to complain to the Information Commissioner’s Office, or to your local supervisory authority. We’d appreciate the chance to help first.

7. Processors and third-party services

ServicePurposeData shared
VercelHostingRequest metadata, IP address
SupabaseDatabase and file storage (eu-west-1)Account, conversations, files
ResendSign-in emailsEmail address
SentryError monitoringExceptions and stack traces
Model providersGenerating repliesPrompt content, on your credential
Serper, TavilyWeb search, when you enable itYour message, as the search query

Model providers are only contacted for the provider you have connected and the model you have selected. Depending on that choice the recipient may be Anthropic, OpenAI, Google, Groq, DeepSeek, Perplexity, Moonshot, Z.ai, or OpenRouter acting as a router on your behalf.

There is no analytics provider on this list, and that is deliberate. No conversation content, file, or prompt is shared with any analytics or advertising service, because Lucid uses none.

8. International transfers

Some of our providers process data outside the UK, including in the United States. Where that happens we rely on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, with appropriate safeguards in place.

Your account data, conversations and files are stored in the eu-west-1 region. Model providers process prompts in their own regions, which vary by provider.

9. Cookies

We use one cookie: lucid_session, which signs you in. It is httpOnly, SameSite=Lax, Secure in production, and lasts 30 days. It is strictly necessary, so there is no cookie banner to dismiss.

There is no analytics cookie, no advertising cookie, and no third-party tracker of any kind. No analytics or advertising SDK exists in the application, and its absence is checked as part of our release process.

10. Children

Lucid is not directed at children under 16. If we learn that a child under 16 has created an account, we will delete it.

11. Changes to this policy

If this policy changes in a way that materially affects what we collect or where it goes, we will update the date at the top and tell you by email or in the app before the change takes effect.

12. Contact

Data controller: Prashanth Nimmagadda, Birmingham, England.

Questions about this policy, or about your data, can be sent to privacy@lucid.stillform.app.