01Who this policy covers
This policy explains how LucidFrame handles personal information when you visit lucidframe.cc, use app.lucidframe.cc, create an account, save a project, buy AI credits or contact us. The data controller for LucidFrame’s processing described here is FOP Yaremko Volodymyr Mykhailovich, an individual entrepreneur based in Ukraine. Contact: legal@lucidframe.cc.
Images, prompts and project text can contain personal information about you or someone else. Please only provide material you are entitled to share and process.
02Information we process
- Account information: email address, display name, a password hash, verification status, account identifiers, preferences and creation or update dates. We store a password hash rather than your readable password.
- Projects and assets: saved project names, dimensions, layers, text, masks, image files, thumbnails and related file metadata.
- AI requests: prompts, reference images, the selected canvas or image area, masks, operation and model settings, generated results, request identifiers, status, errors and credits charged.
- Purchases: plan, credit balance, order and subscription references, payment status and billing periods. Payment details you enter at checkout are handled by the payment provider; LucidFrame does not store full card numbers or card security codes.
- Service and support information: messages you send us and technical information involved in serving requests, such as IP address, browser or device information, request times and errors.
03What stays in your browser
Ordinary editing operations run in your browser. Opening an image for local editing does not by itself create a cloud-saved project. When you save or sync a project, its assets and document data are uploaded. If you enable automatic saving, this also applies to automatically saved projects.
When you request an AI operation, the relevant input must leave your browser to be processed. This may include a selected region, mask, reference image or a wider canvas context, depending on your input settings.
Hosted image assets can be delivered through direct file URLs. Anyone who receives such a URL may be able to view the file. A project not being listed publicly does not mean its asset URLs are access-controlled; avoid putting confidential material into cloud or AI workflows.
04Why we use information
We use information to authenticate accounts, verify email addresses, provide the editor and AI operations, save and retrieve projects, manage payments and credits, answer requests, diagnose faults, prevent abuse and meet legal obligations.
Where GDPR or similar rules apply, processing necessary to deliver a requested service is based on performance of a contract; required accounting or other records are based on legal obligations; proportionate security and troubleshooting are based on legitimate interests, subject to your rights. Where consent is required for an optional activity, it must be obtained separately and can be withdrawn.
05Providers and other recipients
Service providers receive the information necessary for the work they perform:
- AI processing: Kie.ai or fal, depending on the configured model and operation, receive prompts, image inputs and settings needed to produce results. Their model and infrastructure providers may also be involved.
- Payments: Paddle processes purchases as Merchant of Record and supplies order or subscription updates to LucidFrame. Paddle handles payment, billing, tax and fraud-prevention information under its Privacy Policy.
- Account emails: Brevo handles delivery of messages such as verification emails.
- Infrastructure: hosting, database and object-storage providers process service records and hosted assets.
We may also disclose relevant information when lawfully required, to address fraud or security incidents, to protect legal rights, or in a business transfer subject to appropriate safeguards and notices. We do not sell your personal information.
Relevant provider notices include Kie.ai’s Privacy Policy and the privacy information supplied by other providers at the point where you use them. Provider processing and retention rules may differ; this policy does not promise that every external model provider has the same training or retention practices.
06Browser storage and cookies
The editor uses browser storage to remember your signed-in session and interface preferences. Signing out removes the locally stored session used by the editor. You can also clear site data in your browser, which may remove preferences and unsaved local state.
The current landing page does not include advertising or analytics scripts. The editor supports Google Analytics when enabled, for page visits and feature usage. You can disable analytics in the editor’s settings. Where consent is required, optional tracking must only run with that consent. Checkout and other external services may use their own cookies or similar technologies under their privacy notices.
07How long information is kept
Retention depends on why the information is needed:
- Account data and saved projects are retained to maintain your account and provide access to your work, unless you delete them or request deletion.
- AI job records and outputs are kept for result delivery, project use, troubleshooting and credit reconciliation. Temporary input uploads have a separate cleanup lifecycle from saved project assets.
- Payment records may be retained for accounting, tax, fraud prevention and dispute obligations after an account is closed.
- Support and technical records are kept for the time needed to resolve the issue, protect the Service and handle associated legal claims.
Deletion can take time to propagate through storage, caches and backups, and limited records may need to remain where the law requires them. Ask legal@lucidframe.cc for information about a particular record or deletion request. Clearing browser data does not delete cloud records or copies held by processing providers.
08Security
Account passwords are hashed, authenticated requests are checked and project operations are associated with the relevant account. These measures reduce risk but cannot make an online service completely secure. File-link access is described separately above.
Use a unique password, protect devices on which you remain signed in and contact us if you suspect an account or data incident. Where a breach triggers a legal notification obligation, affected people and authorities must be informed as required by law.
09International processing
AI, payment, email and hosting services may process information in countries different from yours. The destination depends on the provider and operation. Where data-protection law restricts an international transfer, an appropriate legal mechanism is required, such as an adequacy decision or approved contractual safeguards.
Using LucidFrame is not a blanket waiver of international-transfer protections. You can contact legal@lucidframe.cc for information about recipients, locations and the safeguards applicable to your data.
10Your choices and rights
You can choose to use local editing without an account, decide what to send to AI processing, export your work, manage saved projects and cancel subscription renewal through billing settings.
Depending on the law that applies, you may request access to your information, correction, erasure, restriction of processing or a portable copy. You may object to processing based on legitimate interests and withdraw consent for consent-based activities without affecting earlier lawful processing. You may also complain to your local data-protection authority.
Send requests to legal@lucidframe.cc from your account email where possible. We may need proportionate information to verify identity and will respond within the period required by applicable law. Do not send a password or payment-card details. A request may be subject to legal exceptions, which we will explain where relevant.
11Children and sensitive information
LucidFrame is intended for adults aged 18 and over. If you believe a child has provided personal information through the Service, contact us so we can investigate and take appropriate action.
The editor does not need sensitive personal information to function. Avoid uploading identity documents, medical information or similarly sensitive material, particularly where an AI request would send it to another provider.
12Updates and contact
We will update this page when the Service or its information practices change. The revision date appears above. Material changes will be brought to your attention where required, and new consent will be sought when the law requires it.
For privacy questions, access requests, deletion requests or concerns about an image depicting you, email legal@lucidframe.cc.