Privacy Policy

Last updated: February 10, 2026

1. Introduction

Lucent ("we", "us", or "our") operates the PRism browser extension and web platform. This Privacy Policy explains how we collect, use, and protect your personal information when you use our services.

2. Information We Collect

We collect the following categories of information:

  • Account data: name, email address, and password (stored as a bcrypt hash — we never store plain-text passwords)
  • Usage data: generation history including PR titles, descriptions, diff summaries, and repository URLs
  • Custom templates: template names and body text you create
  • Subscription and billing data: plan type, subscription status, usage count, billing period, and Razorpay customer and subscription identifiers

We do not collect your full source code, use analytics or tracking cookies, or perform device fingerprinting.

3. How We Use Your Information

  • Provide, maintain, and improve the PRism service
  • Process subscription payments through Razorpay
  • Improve AI generation quality over time
  • Communicate important service updates, billing notifications, and security alerts

4. Third-Party Services

We share limited data with the following third-party services:

  • Razorpay (payment processing): your name and email address are shared with Razorpay to process subscription payments. Razorpay's handling of your data is governed by their privacy policy.
  • Google Gemini API (AI generation): code diff content is sent to generate PR descriptions. No user identity or personal information is included in these requests.

5. Data Retention

  • Account data is retained for as long as your account remains active
  • Generation history is retained so you can access your past generations
  • All data is deleted upon account deletion request — see "Your Rights" below

6. Data Security

We implement the following security measures to protect your data:

  • Passwords are hashed using bcrypt before storage
  • Authentication is handled via JWT tokens with short-lived access tokens (15 minutes) and rotating refresh tokens
  • All data is transmitted over HTTPS encryption
  • No plain-text passwords are ever stored or logged

7. Your Rights

You have the right to:

  • Delete your account: email us at support@getlucent.dev to request full account and data deletion
  • Export your data: email us to request a copy of the personal data we hold about you
  • Update your information: you can update your profile information directly from your dashboard

8. Children's Privacy

Our service is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete that information promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this policy periodically for any changes.

10. Contact

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at support@getlucent.dev.