Table of Contents
This Privacy Policy describes how Lucitra, Inc. ("Lucitra," "we," "us," or "our") collects, uses, and protects your personal information when you use Lucitra Validate and related services (the "Services"). By using our Services, you agree to the practices described in this policy.
1. Information We Collect
We collect information you provide directly when you create an account, use our API, or contact us for support:
- Account information: Name, email address, organization name, and role
- API keys: Keys prefixed with
luci_that you generate for programmatic access - Dataset metadata: File names, sizes, format types, annotation schemas, and upload timestamps — we do not use the content of your training data images
- Validation results: Scores, reports, and recommendation data generated by our analysis
- Usage analytics: API call frequency, feature usage patterns, and performance metrics collected via PostHog
- Communications: Support requests, feedback, and correspondence
2. Synthetic Dataset Processing
When you upload synthetic datasets for validation:
- Datasets are processed solely for the purpose of validation — generating coverage, physics, distribution, and sim-to-real transfer scores
- Your datasets are never used to train Lucitra's own models
- Dataset files are stored encrypted at rest in Google Cloud Storage
- Processing occurs in Google Cloud Run instances in US regions
- You may delete your datasets at any time via the API or dashboard
3. How We Use Your Information
- Provide, operate, and maintain the Lucitra Validate service
- Generate validation reports with scores and recommendations
- Improve our validation algorithms using anonymized, aggregated metrics (never individual datasets)
- Communicate with you about your account, service updates, and support requests
- Detect and prevent abuse, fraud, and security incidents
- Comply with legal obligations
4. Data Retention
- Uploaded datasets: Retained for 90 days by default, then automatically deleted. Enterprise customers may configure custom retention periods.
- Validation reports: Retained indefinitely while your account is active, as they contain no raw dataset content.
- Account data: Retained while your account is active and for 30 days after deletion to allow recovery.
- Usage analytics: Retained for 24 months in anonymized, aggregated form.
5. Sub-processors
We use the following third-party service providers to operate our Services:
- Google Cloud Platform: Cloud infrastructure, compute, and storage (US regions)
- Stytch: Authentication and identity management
- PostHog: Product analytics (US-hosted)
- AWS SES: Transactional email delivery
6. International Data Transfers
Our Services are hosted in the United States. If you access our Services from outside the US, your information will be transferred to and processed in the US. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission and participate in the EU-US Data Privacy Framework to ensure adequate protection for data transferred from the European Economic Area, the UK, and Switzerland.
7. GDPR Rights (EEA, UK, Switzerland)
If you are located in the European Economic Area, the UK, or Switzerland, you have the following rights under the General Data Protection Regulation:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate personal data
- Right to erasure: Request deletion of your personal data
- Right to restriction: Request that we limit processing of your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
To exercise these rights, contact us at privacy@lucitra.ai. We will respond within 30 days.
8. CCPA Rights (California Residents)
California residents have the following rights under the California Consumer Privacy Act:
- Right to know: Request disclosure of the categories and specific pieces of personal information we collect
- Right to delete: Request deletion of your personal information
- Right to opt-out: We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights
9. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us:
- By email: privacy@lucitra.ai
- Lucitra, Inc., Austin, TX, United States