LucieSync

Privacy Policy

Effective August 11, 2026

Lucie Sync is a scheduling tool. To do its job it needs to know when you are free — and that is a uniquely sensitive thing to hand over. This policy describes exactly what we collect, what we deliberately do not keep, and who else touches it.

Your calendar, specifically

When you connect a Google Calendar, we ask for permission to read your calendars and to create events on them. We use that access for two things only:

  • Working out when you are free. We read the start and end times of events on your connected calendars so your booking page only offers times you are actually available.
  • Creating your bookings. When someone books you, we create the calendar event and invite both parties, and we update or cancel it if the meeting is rescheduled or called off.

We do not store the contents of your calendar. Event details are read to compute your availability and to display your own calendar back to you, and are never written to our database. What we retain is the shape of your time — the meetings you book through Lucie — not what is on it otherwise.

People viewing your public booking page see only open time slots. They never see your events, your other meetings, or who you are meeting with.

You can disconnect a calendar at any time in Settings. Disconnecting deletes the stored credentials for that account. Events already created on your calendar remain yours and are unaffected.

Google API Services disclosure

Lucie Sync's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request the calendar scope so we can both read availability and write booking events. We do not use Google user data for advertising, do not sell or transfer it, and do not use it to train generalized AI or machine learning models. No human reads your Google data except with your explicit permission, where necessary for security purposes such as investigating abuse, or to comply with applicable law.

What we collect

  • Account details. Your email address, and a securely hashed password if you use one.
  • Your profile. Your @handle, display name, optional bio, time zone, contact email, and booking preferences such as meeting lengths and notice periods.
  • Calendar credentials. The email address of each connected Google account and the access tokens that let us act on your behalf. Refresh tokens are encrypted at rest and are never exposed to a browser.
  • Availability. The weekly hours you publish as bookable.
  • Bookings. For each meeting booked through Lucie: the name, email address and any note supplied by the person booking, plus the time and length.
  • Group scheduling. Events you create and the availability responses participants give.
  • Billing. If you subscribe, Stripe processes your payment and we store your subscription status. We never see or store card numbers.
  • Usage and diagnostics. Basic analytics on booking page visits, plus error reports when something breaks.
  • Anything you send us. Feedback and support messages.

How we use it

To run the service: computing availability, creating bookings, sending confirmations, reminders and notices such as telling you that a calendar connection needs reconnecting. To keep the service working and safe — rate-limiting abuse of public booking pages, diagnosing errors, and troubleshooting problems you report. To bill you, if you are a paying subscriber.

We do not sell your data, we do not share it with advertisers, and we do not use it to train AI models.

Who else touches it

We keep the list of companies involved deliberately short. We use service providers to run the parts of Lucie we don't build ourselves, and each may process your data only to provide its part of the service, on our instructions:

  • Hosting and infrastructure — running the application and storing our database.
  • Email delivery — sending booking confirmations, reminders and account notices.
  • Payment processing — handling subscription billing. Card details go directly to our payment provider; we never see or store them.
  • Error monitoring and analytics — diagnosing failures and measuring page visits.

Google is named separately because it isn't a vendor we chose on your behalf — it's the calendar account you explicitly connected, and it is covered by the Google disclosure above.

Want to know exactly which companies these are? Ask us at privacy@lucie.network and we'll tell you — we're happy to name them, we just don't want this page to quietly go stale.

We may also disclose information if legally required to, or where necessary to investigate abuse or protect someone's safety. We do not sell your personal information.

Cookies and analytics

We set a small number of cookies that are necessary for the service to work — chiefly keeping you signed in. These cannot be turned off without breaking sign-in.

We also use Google Analytics across the site, including public booking pages, which sets cookies to measure visits and understand which pages people find. You can opt out with Google's browser opt-out add-on, or by blocking cookies in your browser. Separately, we record basic counts of booking-page visits and bookings so hosts can see how their page is performing.

Support access

When you ask us for help, we can view your account's configuration and setup status — things like whether your calendar is connected and what durations you offer. This view never exposes your calendar contents or your credentials, and we do not log in as you or act on your behalf.

How long we keep it

Account and booking records are kept while your account is active. Disconnecting a calendar immediately deletes that account's stored credentials. Ask us to delete your account and we will remove your profile, availability, calendar connections and booking history, except where we are required to retain records — for example, billing records for tax purposes.

Your rights

You can access, correct, export or delete your data. Much of it is editable directly in Settings — your profile, your availability, and your calendar connections, which you can disconnect at any time. For anything else, use the feedback form in your account or email privacy@lucie.network, and we will respond within 30 days. Depending on where you live — in the EEA, the UK, or California, for instance — you may have additional rights over your personal data, and we honour those requests regardless of where you are.

Security

Calendar refresh tokens are encrypted at rest. Access to your data is enforced at the database level rather than only in the application, so a bug in the interface cannot expose another user's records. All traffic is encrypted in transit. No system is perfectly secure, but security is the product here, and we treat it that way.

Where your data lives

Our infrastructure is hosted in the United States. If you use Lucie Sync from elsewhere, your data is transferred to and processed there.

Children

Lucie Sync is not intended for anyone under 16, and we do not knowingly collect data from children.

Changes

If we make a material change to this policy, we will update the effective date above and notify account holders by email before it takes effect.

Contact

For questions about this policy, or to make a request about your data, email privacy@lucie.network. You do not need a Lucie account to contact us — if someone booked a meeting with you through Lucie, or you booked one, you can reach us the same way. Account holders can also use the feedback form in the app.