Privacy Policy

Last updated: 2026-08-05

1. Data Controller

The data controller is MEMORA solutions, located at CP 64021, L'Ancienne-Lorette RPO St-Jac (QC) G2E 2X0, Canada.

2. Collected Data

When using LucidNest, we collect:

  • Identification data: name, email address.
  • Account data: organization name, role.
  • Technical data: IP address, connection logs, browser type.
  • Usage data: projects, notes, created spaces, interface interactions.

3. No Collection of Health Data and Inference Risk

LucidNest is positioned as an organizational tool for people with ADHD. This section clarifies how we handle this reality with respect to special categories of data (GDPR Article 9):

  • No collection: LucidNest does not request, store, or verify any medical diagnosis, ADHD status, or other explicit health data upon registration or use of the service.
  • Possible inference by third parties: the mere fact of using a tool positioned for people with ADHD may, on its own, be interpreted by a third party as an inference about a health condition, even in the absence of any explicit statement on your part.
  • Reinforced processing: as a precaution, we apply to this potential inference the same safeguards as to explicit health data - minimization of collected data, encryption at rest and in transit, and no sale or sharing for advertising purposes with third parties.

4. Processing Purposes

  • Providing and managing the service.
  • Managing billing and payments.
  • Customer support and technical assistance.
  • Improving service features.
  • Sending administrative communications.

5. Legal Bases

Processing is based on contract execution (TOS), legal obligations (billing) and our legitimate interest (security, product improvement).

6. Data Recipients

Your data is intended for our internal teams and subcontractors (hosting, payment) who comply with GDPR and PIPEDA.

7. Retention Period

Account data is retained as long as the account is active. Upon deletion, data is erased after 30 days except for legal obligations: contractual documents are retained for the duration of the relationship and then according to applicable legal deadlines; billing documents are retained for as long as required by tax law, generally six years after the end of the last taxation year concerned.

8. User Rights (GDPR/PIPEDA)

In accordance with GDPR and PIPEDA, you have the right to access, rectify, erase, restrict, port, and object to your data.

9. Transfers outside the EU/Canada

If data is transferred outside the EU or Canada, we ensure that these transfers are governed by standard contractual clauses or adequacy decisions.

10. Security

We implement appropriate technical measures: encryption, access controls, two-factor authentication, audit logs, and encrypted backups.

11. LucidNest Chrome Extension

The LucidNest Chrome extension is an optional companion that communicates exclusively with your LucidNest instance.

Locally stored data

The extension stores in chrome.storage.local (on your device only): an authentication token and the URL of your instance. No data is sent to third parties.

Permissions used

  • storage: storage of the authentication token and preferences.
  • activeTab: access to the active tab during a capture.
  • contextMenus: context menus "Capture in LucidNest".
  • sidePanel: side panel to view notes and tasks.
  • alarms: reminder notifications and Pomodoro timer.
  • notifications: alerts for overdue tasks and Pomodoro completion.
  • declarativeNetRequest: temporary blocking of distracting sites during Pomodoro sessions.

No tracking

The extension contains no analytics, tracking, or telemetry tools. No browsing data is collected or transmitted.

12. Cookies

To learn more, please refer to our cookie policy.

13. Changes

This policy may be updated. The new version will be published on this page.

14. DPO Contact

For any requests regarding your personal data: [email protected].

15. Use of Artificial Intelligence

In compliance with Article 50 of the EU AI Act and Article 12.1 of Quebec's Law 25, we transparently inform you of our AI usage. Any content generated by our assistant Orliva is clearly marked visually with a 'Generated by Orliva (AI)' badge.

Which features use AI

Four LucidNest surfaces use generative AI: (1) LucidNest conversational assistant (questions, summaries, navigation), (2) the smart 'Reorganize' task feature adapting to your energy, (3) LucidNest's planning advice (realistic estimate, break suggestions), and (4) inline suggestions in your notebooks. None of these features are used for automated decision-making about you nor for commercial profiling.

Voice dictation (voice inbox)

Voice dictation is an optional feature that uses the speech recognition built into your browser (Web Speech API). Depending on the browser you use, audio may be transmitted to and processed by a third-party service (Google, Apple, or Microsoft) for transcription - this processing is performed by your browser, not by LucidNest. LucidNest does NOT retain the audio recording or the raw transcription on its servers: only the final text of the note or task that you explicitly validate is saved.

Provider and models

Requests are routed via OpenRouter LLC (USA), acting as a processor under GDPR Article 28 and Law 25 art. 18.3. OpenRouter may route to models from Anthropic (Claude), OpenAI (GPT), Google (Gemini), Mistral, Meta (Llama), or Qwen depending on availability and context. The actual model used is recorded in our audit logs.

Data transmitted

When you use an AI feature (summary, categorization, transformation, action extraction, enhanced search), the data required for that feature, including the content involved, is sent to the model provider. No transmission occurs outside these actions, and you can disable AI at any time, globally or per feature.

Retention and minimization

We retain an AI audit log for a maximum of 12 months, containing only: your identifier, timestamp, surface concerned, model used, and a cryptographic fingerprint (SHA-256) of your prompt. The raw content of your prompt is never stored in our logs. LucidNest chat messages are kept in your conversation history for a maximum of 12 months, or until you delete them yourself if that happens sooner.

Right to refuse (opt-out)

You can disable all AI features at any time in Settings > AI. LucidNest remains fully functional without AI: tasks, notebooks, spaces, and local planning work independently. Deactivation is immediate and does not delete your data.

Your rights on AI data

You may request access, correction, or deletion of your AI audit log by writing to [email protected]. Pursuant to GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing: LucidNest's suggestions are always presented as such and require your explicit validation to become actions.

16. Sub-processors and Recipients

In accordance with Law 25 (art. 8) and GDPR (art. 13-14), we inform you of the identity of third parties who process your personal data on our behalf or to whom it is transmitted, as well as the safeguards governing these transfers.

List of sub-processors and recipients

Sub-processorPurposeLocationMeasures / guarantees
Google LLCSSO authentication, Google Calendar synchronization, Google Drive integrationUnited StatesOAuth tokens encrypted in database; minimal scopes (dedicated LucidNest calendar only); EU-US Data Privacy Framework; Google DPA available
Microsoft (Entra ID)SSO authentication via Microsoft accountUnited StatesMinimal OAuth scopes (profile and email only); EU-US Data Privacy Framework; Microsoft DPA available
Stripe Inc.Subscription payment processing, invoicing and tax calculation (GST/QST via Stripe Tax)United StatesPCI-DSS Level 1 compliance; card number never transmitted to LucidNest servers (Stripe.js tokenization); Stripe DPA available
OpenRouter Inc.Routing requests to AI models for the LucidNest assistant (see AI section)United States (routing to global LLM providers)Opt-out available at /settings/ai; context filtering before sending (AIPrivacyService); request logs retained by OpenRouter (provider) for 30 days under its own retention policy - distinct from our internal AI audit log, retained for 12 months (see the "Use of artificial intelligence" section above); conscious opt-in recommended
Cloudflare Inc.Content delivery network (CDN), DNS proxy, DDoS protection, SSLUnited States (300+ global points of presence)Cloudflare Data Processing Agreement (DPA); no application data stored, transit processing only; HSTS and strict SSL
Google Analytics 4Anonymized audience measurement (only if consent granted)United StatesPrior consent required via cookie banner; script not loaded without consent; IP truncated by GA4
Hosting provider (cPanel/WHM)Application hosting infrastructure, database and file storageCanadaConfiguration files encrypted (chmod 600); daily GPG backups; data hosted in compliance with applicable laws

Data transfers outside Quebec and the European Union occur to the providers listed above (primarily located in the United States). These transfers are governed by recognized protection mechanisms: EU-US Data Privacy Framework, European Commission standard contractual clauses, or explicit user consent, as applicable.

Note - voice dictation: if you use the voice dictation feature, audio is processed by the speech recognition API built into your browser (Web Speech API). Depending on your browser, this processing may involve a transfer to the servers of Google (Chrome), Apple (Safari), or Microsoft (Edge). This processing is performed by your browser vendor, not by LucidNest.

For LucidNest AI assistant and LLM model providers, see the "Use of Artificial Intelligence" section above.

17. Use of Google Data (Google API Services User Data Policy)

LucidNest offers optional integrations with certain Google APIs (Google Calendar, Google Tasks, and Google Drive), enabled only when you explicitly connect them from Settings > Integrations. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Google data accessed and created

Depending on the integrations you enable: (1) read access to your primary Google Calendar over a rolling window of 30 days in the past and future (calendar.readonly scope); (2) creating, updating, and deleting events only in a dedicated secondary calendar that LucidNest creates itself ("LucidNest - Planning"), never on your primary calendar (calendar.app.created scope); (3) reading and writing your Google Tasks lists for two-way synchronization with your LucidNest todos (tasks scope); (4) creating files in a single Google Drive folder created by the app ("LucidNest" by default, renamable) to export your notebooks - drive.file scope, which limits LucidNest to only the files it creates itself and never allows it to see the rest of your Drive.

How this data is used

This data is used exclusively to power the features you explicitly requested: displaying your Google Calendar events alongside your LucidNest tasks, creating events matching your due dates in the dedicated calendar, keeping your tasks in sync with Google Tasks, and backing up a copy of your notebooks to your Google Drive. It is never used for advertising, profiling, credit or insurance scoring, or to train generalized AI models.

How this data is stored

OAuth access and refresh tokens are encrypted at rest in our database. Synced events, tasks, and file metadata are stored in your LucidNest account, protected by the same security measures as the rest of your data (see the Security section above). All communication with Google APIs is encrypted in transit (TLS).

Sharing of Google data

Data obtained through Google APIs is never sold, rented, traded, or shared with third parties for advertising or any purpose other than the features described above. It is never transferred to any other application. No one at MEMORA solutions manually reviews this data's content, except where strictly necessary (resolving a security incident, a legal obligation, or technical support you explicitly request).

Retention and deletion

Tokens and data synced through Google APIs are kept only while the corresponding integration remains active. As soon as you disconnect an integration (Google Calendar, Tasks, or Drive) from Settings > Integrations, the associated tokens are immediately revoked and deleted from our database. Deleting your LucidNest account deletes all associated Google data on the same timelines described in the Retention Period section.

Limited Use commitment

LucidNest's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice: Google data is only used to provide or improve features visible to you within LucidNest, is never used for advertising, never resold, and never used to train general-purpose AI models.

Revoke access at any time

You can disconnect each Google integration at any time from Settings > Integrations in LucidNest (the "Disconnect" button), or revoke LucidNest's access to your Google account directly from your Google Account permissions page (myaccount.google.com/permissions).

18. Specific Rights - California (CCPA/CPRA)

If you reside in California, you have rights under the CCPA and CPRA.

Right to Know

You have the right to request information about the personal data we collect and use.

Right to Delete

You have the right to request the deletion of your personal data.

Right to Opt-Out of Sale

We do NOT sell your personal data.

Right to Non-Discrimination

We will not discriminate against you for exercising your rights.

To exercise these rights, contact us at [email protected].

19. Specific Rights - Brazil (LGPD)

If you reside in Brazil, you have rights under the LGPD.

Confirmation and Access

You can confirm that your data is being processed and access it.

Deletion and Revocation

You can request the deletion of your data and revoke your consent.

Information on Sharing

We will inform you of the entities with which we share your data.

Competent Authority

For more information, contact the ANPD in Brazil.

20. Specific Rights - Quebec (Law 25)

Under Quebec's Law 25:

Rights of Access, Rectification, and Deletion

You have the right to access, rectify, or delete your personal information.

Right to Portability

Receive your information in a structured, machine-readable format.

Explicit Consent

Explicit consent required, revocable at any time.

Data Protection Officer

Privacy officer: Stéphane Lapointe. They can be reached at [email protected] or by mail at the address indicated in section 1.

Privacy Impact Assessment

We conduct PIAs for every new initiative.

Privacy Incidents

In case of a serious incident, we will notify the DPA and affected individuals.

21. Minors and minimum age

The service is reserved for individuals aged 14 and older. We do not knowingly collect personal information from anyone under 14.

Detection and deletion

If we discover that an account was created by a person under 14, that account is suspended or closed and the associated personal information is deleted as soon as possible.

Reporting

If you believe a person under 14 has provided us with personal information, please contact us at [email protected] so we can take appropriate action.