Privacy Policy
This Privacy Policy explains how Many Labs LLC, doing business as Lucidly (“Lucidly,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you visit lucidly.so (the “Website”) or use the Lucidly web application at app.lucidly.so and related services (together, the “Service”).
Lucidly is a website feedback and visual QA tool. Our customers use it to load websites, pin comments on them, and track feedback with their teams and clients. If you have questions about this policy, email us at support@lucidly.so.
Who this policy applies to
- Account holders: people who sign up for Lucidly, including workspace owners, team members, and collaborators.
- Guests: people who leave feedback through a comment-only link shared by a Lucidly customer, without creating an account.
- Visitors: people who browse our marketing Website.
When a customer uses Lucidly to collect feedback from their team or clients, the customer decides what projects to create, which websites to load, and who to invite. For that content, we process information on the customer’s behalf and according to their instructions.
Information we collect
Information you give us
- Account information: your name, email address, and password (stored only in hashed form). If you sign up or log in with Google or GitHub, we receive your name and email address from that provider. We do not receive your Google or GitHub password.
- Signup details: optional answers you give during signup, such as how you heard about Lucidly.
- Guest information: when you join a project through a comment-only link, we collect the name and email address you enter so your feedback can be attributed to you and so you can receive notifications.
- Project content: website URLs and page lists, comments, replies, @mentions, comment statuses, ticket numbers, folders, workspace names, and files you attach to comments.
- Passwords for protected websites: if you load a password-protected website (for example, a Webflow staging site or Shopify store), you may enter that site’s password. We use it to sign in to that site on your behalf and keep the resulting access session so the site loads in your project.
- Billing information: when you subscribe, our payment processor, Stripe, collects your payment details. We do not store full card numbers. We receive limited information from Stripe, such as your plan, billing status, and the last four digits and expiry of your card.
- Support requests: when you contact us or use the in-app support form, we collect what you send us, including your message, any files you attach, the page you were on, and basic browser information to help us diagnose issues.
Information created when you use the Service
- Screenshots: when a comment is posted, Lucidly automatically captures a screenshot of the page being reviewed, at the device size selected, and stores it with the comment. Screenshots may include whatever was visible on that page.
- Activity information: actions you take in the Service, such as comments posted, status changes, page views within projects, and when you were last active. We use this to power features like the activity feed, notifications, daily digests, and collaborator presence indicators.
- Real-time presence: while you are in a project, your cursor position and presence may be shared live with other people in the same project so you can collaborate.
- Device and log information: IP address, browser type, operating system, and timestamps, collected through server logs and session records for security, rate limiting, and troubleshooting.
- Product analytics: we use PostHog to understand how the Service is used and to detect errors, for example which features are used and where errors happen. Analytics are paused when the Lucidly tab is not in view.
Information from the websites you review
To show a website inside Lucidly, our servers fetch that website and display it to you and the people in your project. We remove known trackers and hidden tracking frames from these previews. We do not use the content of the websites you review for any purpose other than providing the Service to you.
Cookies and similar technologies
- On the Service, we use cookies that are necessary to keep you logged in, keep guest sessions active, protect against fraud and abuse, and remember your preferences (such as light or dark mode and the last page you viewed). We also use cookies or local storage for product analytics.
- On our marketing Website, we use Google Analytics to understand how visitors use the Website, and Google Ads tags to measure the effectiveness of our advertising.
You can control cookies through your browser settings. Blocking necessary cookies will prevent you from logging in to the Service.
How we use information
We use information to:
- Provide, operate, and maintain the Service, including loading websites, capturing screenshots, storing comments and attachments, and syncing changes in real time.
- Create and manage accounts, workspaces, and guest access.
- Send service messages, such as @mention notifications, reply notifications, invitation emails, daily digests, password resets, and billing receipts.
- Process payments and manage subscriptions and trials.
- Respond to support requests, bug reports, and feature requests.
- Understand how the Service is used so we can fix problems and improve it.
- Send product news and updates. You can unsubscribe from these emails at any time using the link in the email.
- Keep the Service secure, prevent abuse, and enforce our Terms of Service.
- Comply with legal obligations.
We do not sell your personal information, and we do not share it with third parties for their own advertising.
How information is shared
Within your projects
Information you add to a project is visible to the other people with access to it. Depending on how the project owner has set things up, this can include workspace team members, collaborators, and guests using a comment-only link. Your name, comments, replies, attachments, color, presence, and cursor may be visible to them. Anyone with an active comment-only link can join as a guest, so share those links only with people you trust. Project owners can turn links off at any time.
With service providers
We use trusted providers to run Lucidly. They process information only on our behalf and only as needed to provide their services. These include:
| Provider | Purpose |
|---|---|
| Stripe | Payment processing and subscription billing |
| PostHog | Product analytics and error tracking |
| Resend | Sending transactional and product emails |
| Google and GitHub | Optional sign-in, if you choose to use them |
| Cloudflare | Website hosting, content delivery, and file storage for screenshots and attachments |
| Cloud hosting and database providers | Running the application, database, website previews, and real-time services |
| Linear and Slack | Routing support requests, bug reports, and feature requests to our team |
| Google Analytics and Google Ads | Measuring visits and advertising on our marketing Website |
Connected apps and AI assistants
If you connect Lucidly to a third-party app or AI assistant that you authorize (for example, through our API or Model Context Protocol connection), that app can access the Lucidly data you allow it to. Its use of that data is governed by its own terms and privacy policy. You can revoke access at any time.
For legal reasons and business transfers
We may disclose information if required by law, or if we believe in good faith that disclosure is needed to protect the rights, property, or safety of Lucidly, our users, or others. If Lucidly is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, and we will notify you of any change in who controls your information.
How long we keep information
We keep account information and project content for as long as your account is active. If you delete a comment, its replies and attachments are deleted with it. If you archive a project, its content is kept until you delete it.
When you delete your account, most of your personal information is deleted immediately. Some information, such as data held in backups and by our service providers, may take up to 30 days to be fully deleted or anonymized. We may keep information longer where we need to keep it to comply with legal obligations (such as billing records), resolve disputes, or enforce our agreements. Comments you left on projects owned by others may remain in those projects, attributed to a deleted user. Backups are overwritten on a regular schedule.
If a project owner removes a guest, the guest loses access, but their existing comments remain in the project.
Security
We use reasonable technical and organizational measures to protect information, including encrypted connections (HTTPS), hashed passwords, access controls on projects and comments, signed and expiring links for protected resources, and limits on what our website preview system can access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe your account has been compromised, contact us right away at support@lucidly.so.
Your rights and choices
- Access and update: you can view and update your name, email address, and password in your account settings.
- Delete your account: you can delete your account from your profile settings, or ask us to do it for you.
- Marketing emails: you can unsubscribe from product news at any time. We will still send service messages, such as billing receipts and security notices.
- Notifications: you can manage some notification emails from the Service.
- Cookies: you can block or delete cookies in your browser.
Depending on where you live, you may have additional rights, such as the right to request a copy of your information, correct it, delete it, restrict or object to certain processing, or receive it in a portable format. If you are in the European Economic Area or the United Kingdom, our legal bases for processing are: performing our contract with you, our legitimate interests in operating and improving the Service, your consent (where we ask for it), and compliance with legal obligations. You also have the right to complain to your local data protection authority.
If you are a California resident, you have the right to know what personal information we collect, to request deletion or correction, and to not be discriminated against for exercising these rights. We do not sell or “share” personal information as those terms are defined under California law.
To make a request, email support@lucidly.so. We may need to verify your identity before responding. If your information is part of a project owned by a Lucidly customer, we may direct your request to that customer.
International transfers
Lucidly is based in the United States, and our service providers may process information in the United States and other countries. When we transfer personal information internationally, we use appropriate safeguards, such as standard contractual clauses, where required by law.
Children
Lucidly is not intended for children under 16, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you by email or in the Service.
Contact us
Many Labs LLC, doing business as Lucidly
PO Box 4066
Copley, OH 44321
United States
Email: support@lucidly.so