Privacy Policy

Privacy Policy

Effective date: September 15, 2026

This Privacy Policy explains how Luce ("we", "us", "our") collects, uses, shares, and protects your information when you use our platform at luce.space ("Service"). It applies to everyone who visits our website, creates an account, or is added to a team on Luce.

1. Who We Are and How to Reach Us

Luce is a product of Luce AI LLC, a Florida limited liability company with its principal office at 7901 4th St N, Suite 300, St. Petersburg, FL 33702, United States. Luce AI LLC is the data controller for the personal data described in this policy.

For any privacy question, request, or complaint, contact us at privacy@luce.space. We respond to privacy requests within 30 days.

2. Information We Collect

Information you provide

  • Account data: Name, email address, and password. Passwords are stored only as a salted hash — we never see them.
  • Team data: Team name, member roles, and invitations. Where a team uses our operations features, this also covers work records such as project names, tasks, schedules, and hours logged.
  • Content: Images, wireframes, 3D scenes, prompts, and files you upload for rendering or editing.
  • Billing data: Subscription plan, billing email, and invoice history. Card details go directly to Stripe and never reach our servers.
  • Support and communications: Messages you send us and their attachments.
  • Preferences: UI settings, default styles, and language preferences.

Information collected automatically

  • Usage data: Pages visited, features used, generation counts, and timestamps.
  • Device data: Browser type, operating system, screen resolution, IP address, and the approximate location derived from it.
  • Diagnostic data: Error reports and performance traces, used to keep the Service working.
  • Cookies and similar technologies: See our Cookie Policy.

Information from integrations you choose to connect

Every integration is optional and stays off until you turn it on. When you connect one, we receive only what that integration needs:

  • Google Calendar: Covered in detail in Section 6.
  • Slack and Google Chat: Workspace and channel identifiers, and the messages exchanged with Luce in those channels.
  • Payroll and HR connectors: The employment records your administrator chooses to import.

Disconnecting an integration stops the data flow and deletes the stored credential.

3. How We Use Your Information, and Our Legal Basis

Where the GDPR or UK GDPR applies, the legal basis for each purpose is named below.

  • Operate the Service, including AI rendering and image processing — performance of our contract with you.
  • Authenticate you and keep your account secure — performance of our contract, and our legitimate interest in a secure platform.
  • Process payments and manage subscriptions — performance of our contract, and legal obligation.
  • Send transactional email (confirmation, password reset, invoices, team invitations) — performance of our contract.
  • Investigate abuse, fraud, and Terms violations — our legitimate interest in protecting users and the Service.
  • Improve the Service through aggregated, de-identified analytics — our legitimate interest, and your consent where analytics cookies require it.
  • Send product or marketing email — your consent, which you can withdraw at any time.
  • Meet tax, accounting, and other legal duties — legal obligation.

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and you may object at any time using the contact address above.

4. What We Never Do

  • We never sell your personal data, and we never share it for cross-context behavioural advertising.
  • We never train AI models on your content. Your uploaded images, renders, prompts, project data, and generated outputs are never used to train, fine-tune, or improve any AI or machine learning model — ours or anyone else's. The AI providers we use are contractually bound to the same rule.
  • We never store payment card information. All card processing is handled by Stripe, Inc. under PCI-DSS. We receive only the payment status and a truncated card identifier for your records. Your full card number, CVV, and billing details are never transmitted to or stored on our servers.
  • We never use your private content to promote Luce without asking you first.

5. Automated Decision-Making

We do not make decisions that produce legal or similarly significant effects about you by automated means alone. AI models generate images and text at your request; they do not decide anything about you.

6. Google User Data

If you connect Google Calendar, Luce requests one read-only scope: https://www.googleapis.com/auth/calendar.events.readonly

What we access. Events on your primary Google Calendar, for the week you are currently viewing — the title, the start and end times, and the attendee email addresses. Nothing else in your Google Account is requested, and nothing else is accessible to us.

What we do with it. Events are read live, at the moment you open your timesheet, and turned into draft time entries shown only to you. You decide which drafts to keep. Attendee email domains are used to suggest whether the time was client-facing.

What we store. We do not store your calendar events. No event title, time, or attendee is written to our database. The only things we keep are the OAuth credential needed to make the request — an access token, a refresh token, the expiry, and the address of the Google account you connected — and the hours you explicitly confirm.

Who can see it. Calendar-derived drafts are visible only to you. Other members of your team, including administrators and owners, cannot see them. Only the entries you confirm become visible to your team, and only as hours recorded against a project.

How to revoke. Disconnect at any time from Settings → Integrations. That deletes the stored credential and asks Google to revoke the grant. You can also revoke access directly at myaccount.google.com/permissions. Once revoked, the credential is deleted within 24 hours.

Limited Use. Luce's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertising. We do not sell it. We do not transfer it except as necessary to provide or improve the feature you enabled, to comply with applicable law, or as part of a merger or acquisition. And we do not allow humans to read it, except with your explicit consent, where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and de-identified.

7. Who We Share Data With

We share personal data only with service providers acting on our instructions under written data-processing terms, and only as far as running the Service requires:

  • Google Cloud and Firebase — infrastructure, authentication, database, and file storage.
  • Vercel — website and application hosting.
  • Cloudflare (R2) — media storage and delivery.
  • Stripe, Inc. — payment processing and invoicing.
  • Postmark — transactional email delivery.
  • Google (Gemini API) — AI image and text generation.
  • Anthropic — AI text generation.
  • Replicate — AI image and video generation.
  • RunPod — GPU compute for rendering.
  • Google Analytics and Google Tag Manager — website analytics, loaded only where you have consented.

We may also disclose data where the law requires it, to enforce our Terms, to protect the rights or safety of our users or the public, or in connection with a merger, acquisition, or sale of assets — in which case we will tell you before your data becomes subject to a different privacy policy.

We do not hand data to law-enforcement or government bodies without a valid legal order, and where we are permitted to tell you, we will.

8. International Transfers

Luce AI LLC is established in the United States, so if you are in the European Economic Area, the United Kingdom, or Switzerland, using Luce means your personal data is processed in the United States. Several of our providers operate there and elsewhere too.

Where we pass personal data to a provider outside your region, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision such as the EU–US Data Privacy Framework, alongside technical measures including encryption in transit and at rest. A copy of the safeguards applying to a particular transfer is available on request.

9. How Long We Keep Data

  • Account and profile data — while your account is active, then deleted within 30 days of account deletion.
  • Uploaded content and generated renders — while your account is active. You can delete individual items at any time.
  • Project, task, and time records — while the team is active, then deleted within 30 days of team deletion.
  • Google Calendar credential — until you disconnect or revoke, then deleted within 24 hours.
  • Google Calendar events — never stored.
  • Usage and diagnostic logs — up to 12 months.
  • Payment and invoice records — for as long as tax and accounting law requires, typically 7 to 10 years.
  • Backups — rolling backups are overwritten within 90 days.

After a deletion request, residual copies can persist in backups until those backups are overwritten on the schedule above. They are never restored into the live Service.

10. Security

  • Data is encrypted in transit (TLS) and at rest.
  • Access to production data is limited to the few people who need it, and is logged.
  • Team content is isolated by team, enforced by server-side rules rather than trusted to the browser.
  • Personal integration credentials, such as your Google Calendar token, are held server-side with no client read path at all.
  • We review our infrastructure and dependencies for security issues on a regular basis.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.

11. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your account and the data associated with it.
  • Export your data in a portable, machine-readable format.
  • Restrict or object to certain processing, including direct marketing.
  • Withdraw consent at any time where processing is based on consent, without affecting what was processed before.

You can delete individual projects, canvases, and renders at any time from the app, and download your generated content whenever you like. To delete your whole account, to request a copy of your data, or to exercise any other right, write to privacy@luce.space and we will act within 30 days. Exercising a right is free and we will not treat you differently for it. We may ask you to verify your identity before we act on a request.

If you are in the EEA, the UK, or Switzerland and you believe we have handled your data improperly, you may lodge a complaint with your local data-protection supervisory authority. We would appreciate the chance to put it right first.

If your team is run by an employer or client: they act as the controller of the work records they put into Luce, and Luce acts as their processor. Requests about that data are best sent to them; we will help them respond.

12. California Privacy Rights

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to request its deletion or correction, to request a portable copy, and to limit the use of sensitive personal information. We do not sell or share personal information as the CCPA defines those terms, and we have not done so in the preceding 12 months. We do not knowingly collect or sell the personal information of minors. To exercise a California right, or to submit a request through an authorised agent, write to privacy@luce.space. We will not discriminate against you for exercising any of these rights.

13. Children's Privacy

The Service is not intended for anyone under 18, no part of it is directed at children, and we do not knowingly collect their data. If you believe a child has given us personal data, write to privacy@luce.space and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time, and the effective date at the top always reflects the current version. If a change materially affects how we use your data, we will notify you by email or in-app notice at least 30 days before it takes effect, and ask for your consent where the law requires it.

15. Contact

For privacy-related questions, requests, or complaints, contact us at privacy@luce.space.

Privacy Policy