LucidYour tasks, beautifully unified.

Your data & your choices

Privacy Policy

Last updated:

Lucid brings your tasks together on your Apple devices. A Lucid account is optional, and the account service does not receive your tasks or your connected-service passwords.

Who is responsible

Lucid is operated by Lilia Omet, the controller for the processing described here. For privacy questions, support or a request about your personal data, contact info@lucidtodo.de.

This policy covers the Lucid iOS, macOS and watchOS apps, their widgets, this website and the optional Lucid account service. Services you choose to connect, and Apple services such as iCloud and TestFlight, also have their own privacy information.

Tasks stay with the storage you choose

Lucid stores tasks and settings on your device. If you enable iCloud synchronization, relevant tasks, reminders, saved views, automation rules, integration-account metadata and preferences are synchronized through Apple services. Widgets and Apple Watch use app-generated task snapshots and commands to show and update your tasks.

Connecting Apple Reminders, Todoist, Google Tasks, Home Assistant, Habitica, a Lucid API provider, Nextcloud or a CalDAV server lets the app exchange the task data needed for that integration directly with the chosen service. Its operator controls that service's storage and retention. Integration credentials are stored in Apple's Keychain; optional credential synchronization uses the app's existing iCloud Keychain setting.

Lucid requests system permissions when a feature needs them, for example Reminders, calendar access, notifications or location-based reminders. You can manage these permissions in system settings. Permission to access a device feature does not give the Lucid account server access to its data.

Apple Intelligence features use supported on-device models. Lucid does not send your task text to a Lucid-hosted AI service. Features depend on your device, operating system and Apple's availability requirements.

You can edit or delete your tasks in the app. Deletions affecting a connected service must synchronize successfully, and copies or backups held by Apple or that provider follow its own rules. Removing an integration or uninstalling Lucid is not a request to erase the provider's account.

Diagnostics are your choice

Lucid's diagnostic recording is opt-in and stored on your device. It can include app version and build, device and operating-system information, timings, errors and technical details about synchronization, networking, iCloud, widgets and Watch communication. Recording automatically ends after seven days; the normal local log-retention window is seven days.

Diagnostic detail depends on the settings you select. If you explicitly include content, records or exports may contain task or service content. Credential redaction is applied, but you should still review what you share. Lucid does not automatically upload these diagnostic bundles: you choose whether to export and send them, for example when asking for support. Copies you share are no longer controlled by the app's local cleanup.

Apple may separately process TestFlight feedback and crash information under its own terms and your Apple settings. This is distinct from Lucid's optional diagnostic recording.

Optional Lucid accounts

Account registration is being prepared and is not yet enabled as of the date above. This section describes the implemented account service for its upcoming beta activation. Cloud-hosted tasks, a task web interface and task end-to-end encryption are not available.

Local tasks, integrations and optional iCloud synchronization work without a Lucid account. When account registration is available, Sign in with Apple authenticates you. The app requests neither your name nor your email address from Apple. We store Apple's app-specific identifier, a separate Lucid account identifier, account status and timestamps, session identifiers or token hashes, session expiry and iOS/macOS platform information. Account records can also contain an operator-verified tester badge and account feature settings.

The account API does not collect task contents, connected-service credentials, a hardware identifier, precise location or an advertising identifier. It does not use your account for advertising or tracking across other companies' apps.

Lucid session credentials stay in a device-only Keychain and are not synchronized through iCloud. Apple authorization credentials needed for authentication checks and revocation are encrypted in the server database with a separate server key. The server can decrypt those service credentials; this is not end-to-end encryption.

Apple account-change notifications are used to update authorization and account state, including revocation and deletion. The account API retains the relevant event type, time and state, not incoming email fields. A verified tester badge does not by itself promise a paid tier or future entitlement.

Deleting an account and retention

You can request Lucid account deletion in the app after confirming your Apple identity again, or contact us about a privacy request. Once the deletion commits, account/profile information, sessions, badges and feature overrides are removed and Apple authorization revocation is queued. A connection error is not confirmation of deletion. Deleting a Lucid account does not erase your local, iCloud or connected-provider tasks.

Sessions have limited lifetimes: access tokens expire after 15 minutes, refresh sessions after 30 days of inactivity, and sessions have a 90-day absolute limit. Short-lived authentication challenges and retry records have separate expiry cleanup. Minimal security/deletion and processed-notification records normally expire after 35 days. Unfinished revocation or notification work remains until it can be processed; operational failures can delay cleanup.

Encrypted daily database backups retain approximately 30 days of history, plus version and storage-lifecycle processing delays. Deletion from backups is not immediate. A restoration must account for subsequent deletion requests before the restored service accepts traffic.

Hosting, service providers and this website

Hetzner hosts this website, the account backend and encrypted database backups. Apple supplies Sign in with Apple and the Apple services you choose to use. Your selected task providers receive the data needed for their integrations. These providers may process data under their own applicable terms, locations and transfer arrangements; choosing iCloud or another provider is separate from creating a Lucid account.

Network addresses are necessarily processed to deliver requests; the account service also uses short-lived, in-memory rate limits for security. Lucid's API and web proxy do not enable request access logs or record authorization headers and request bodies. Limited operational error logs are retained in size-bounded rotation. Hosting-provider infrastructure processing is separate.

This static website uses no cookies, analytics, advertising, forms, JavaScript or third-party fonts. Links to other sites only contact those sites when you follow them. The page is publicly accessible, with instructions asking search engines not to index it; these instructions are not access controls.

For those providers' own processing, see Apple's privacy information and Hetzner's privacy information, as well as the policy of each service you connect.

Purposes, choices and your rights

Data needed to provide the features you request is processed to provide that service (Article 6(1)(b) GDPR). Protecting the service against abuse and maintaining its security are legitimate interests (Article 6(1)(f)). Optional diagnostic recording is based on your consent (Article 6(1)(a)); you can stop it in the app. Withdrawing consent does not affect processing that was lawful before withdrawal. Information you choose to send with a support request is used to respond to that request.

Subject to the applicable legal conditions, you may request access, correction, erasure, restriction or portability of personal data, and object to processing based on legitimate interests. Contact info@lucidtodo.de; we may need information sufficient to verify your identity without collecting more than necessary. You may also complain to a competent data-protection supervisory authority, including where you live, work or believe an infringement occurred.

A Lucid account is not required by law or to use local tasks and existing integrations. Account authentication data is needed only if you choose account features. Lucid does not use automated decision-making that produces legal or similarly significant effects about you.

We will update this policy when relevant features or data practices change. The date at the top identifies this version.