Lucid

Last updated: September 19, 2026.

1. Who is responsible for your data

Lucid (findlucid.com) is the data controller for your personal information. Questions or requests about your data go to support@findlucid.com — that inbox is monitored for privacy rights requests. We are a small team; we do not currently have a dedicated Data Protection Officer, which the law does not require at our size.

2. What we collect

Account: your email address (for magic-link sign-in), sign-in timestamps, and your acceptance of these terms. Profile: your display name and date of birth (required), plus anything you choose to add — bio, photos, height, intents, and preferences. Technical: device type, error logs, push notification tokens, and your approximate location when you use discovery. Billing: if you subscribe, Stripe processes your payment; we store only your subscription tier and status, never your card number. We set only strictly-necessary cookies (see section 13). No advertising cookies, no tracking pixels, no third-party analytics.

3. Sensitive information — your explicit consent

Some profile fields are sensitive under privacy law: HIV status, sexual orientation, gender identity, sobriety details, and precise location. These fields are always optional. The first time you set any of them, we ask for your explicit consent before saving. You can withdraw consent anytime by clearing the field — withdrawing is as easy as giving it. We never infer sensitive information about you, and we never use it for advertising.

4. Why we collect it (and the legal basis)

We process your data to operate Lucid. Under EU law our bases are: contract (running your account, matching, messaging, billing); consent (sensitive profile fields, push notifications, marketing emails — all opt-in); and legitimate interests (safety, fraud prevention, keeping the service working). Under US state laws we process data to provide the service you requested and with your consent where sensitive data is involved.

5. We do not sell or share your personal information

We do not sell your personal information as California law defines 'sell' or 'share' — not to advertisers, not to data brokers, not to anyone. We do not use cross-context behavioral advertising. We honor the Global Privacy Control signal (Sec-GPC): if your browser sends it, we record it as a standing opt-out of any future sale, sharing, or behavioral use of your data.

6. Who we share with

Only the service providers needed to run Lucid, each bound by data-protection obligations: Neon (database hosting), Vercel (app hosting), Resend (transactional email), and Stripe (payments). All are US-based. If you are in the EU/UK, your data is transferred to the US under each provider's standard contractual clauses and data processing terms. We disclose data if the law requires it, and our staff may access account data for safety reviews, verification, and support — those accesses are logged.

7. Your rights and how to exercise them

Wherever you live, you can: see the data we hold about you, correct it, download a machine-readable copy (Settings > Download my data), delete your account and data (Settings > Delete my account), and object to or limit certain processing. EU/UK users additionally have the right to restrict processing and to data portability under GDPR Articles 15-21. California and other US state residents have the rights to know, delete, correct, opt out of sale/sharing, and limit use of sensitive information, without discrimination for exercising them. Email support@findlucid.com with your request from your sign-in address; we respond within 30 days (EU) or 45 days (California). You may use an authorized agent with your written permission.

8. How long we keep data

We keep your account and profile data while your account is active. When you delete your account, we erase your profile, photos, likes, matches, messages, and settings, remove your email from our waitlist, and delete your Stripe customer record. Backups may retain encrypted copies for up to 30 days before rolling off. Sign-in tokens expire within hours; founder invitations expire after 30 days. We may retain minimal records where the law requires it (for example, billing records).

9. Security and breach notification

We use industry-standard measures: encrypted connections, passwordless sign-in (no password database to leak), and access controls on our systems. Private 1:1 chats and group chats are end-to-end encrypted: messages are locked on your device before they are sent, and only you and the people you are talking to can read them — not even Lucid. Your private encryption keys never leave your devices. Honest limits: posts from before encryption are labeled Not encrypted, and encryption hides what was said, not the fact it was said (we still know who posted and when). No system is perfect. If a breach exposes your personal data, we notify the relevant supervisory authority within 72 hours where required and notify affected users without undue delay.

10. Age: 18+ only, and your age display

Lucid is for adults 18 and older. You must provide your real date of birth at signup; our systems reject anyone under 18, and accounts found to be underage are removed. We do not knowingly collect data from anyone under 18, and we delete it if we learn it was provided. In profile settings you can choose whether your age is shown to other users (on by default); hiding it does not change the 18+ requirement. When government ID verification launches, the ID document must show you are 18 or older — we check only that you are an adult, and we never compare the ID date against your profile date. We verify adulthood; we do not certify that profile details match any document.

11. Verification

Profiles are reviewed by our team before appearing in discovery — that is what 'verified' means on Lucid today. Government ID verification is planned for a later release; until then, verification is a manual review, not an automated or document-based check. We work to keep profiles honest, but we cannot promise every profile is exactly as represented.

12. Push notifications

If you enable push notifications, we store a push subscription (endpoint and encryption keys) so we can deliver them. You can turn notifications off anytime in Settings or in your device settings; turning them off deletes the subscription.

13. Cookies

Lucid sets only strictly-necessary cookies, which do not require consent under EU law but are disclosed here: a sign-in session cookie (keeps you logged in, 30-day rolling expiry), a CSRF token cookie (protects sign-in from forgery, session only), and a privacy-choice cookie (remembers your Global Privacy Control opt-out for one year). There are no advertising cookies, no tracking pixels, and no third-party analytics. You can clear cookies in your browser settings; clearing the session cookie signs you out.

14. Changes

We'll post policy updates here before they take effect and keep prior versions available on request. Material changes are announced in the app.

Questions about this policy? Email us at support@findlucid.com.