Privacy Policy
Effective date: July 19, 2026
LucidCare, Inc. ("LucidCare," "we," "us," or "our") is built on one principle: your health data belongs to you and stays on your device. This policy explains exactly what stays local, the small amount we do receive (and why), and what we never do. One scoped exception exists for employers who connect their group health plan (part of the employer-paid Premium tier, described below) — and even there, what you see in the app is your own on-device copy. This policy is written to match what the app actually does, and it forms part of our Terms of Service.
What stays on your device (we never receive this)
- Insurance plan details (carrier, plan name, deductible, out-of-pocket max, coinsurance)
- Deductible and out-of-pocket progress (year-to-date amounts)
- Medical bills you scan (the photo and its text are processed on your device and never uploaded) and claims you enter
- Saved searches, savings events, to-do items, reminders
- Your saved location / ZIP and any demographic info you enter
All of the above lives only in your browser's on-device storage (IndexedDB via Dexie). It is not currently encrypted at rest on your device; clearing your browser data deletes it permanently. We are evaluating optional at-rest encryption.
What we do receive
Anonymous aggregate counters (no personal data)
To understand demand and show our community impact, the app sends anonymous, aggregate-only signals. These fire automatically as you use the app — and they contain no name, IP linkage, procedure name, search text, or facility:
- Savings counter — a single dollar amount when a savings opportunity is surfaced or you mark one as used. Just the number.
- Procedure demand — a +1 tally for an internal procedure code when a procedure is viewed, so we know what services people look for. Just a code and a count.
- Employer program counters (only if you joined through an employer link) — if your profile carries an employer code, the app also counts program usage for that employer: event tallies like "a price comparison was viewed," "a bill was checked," "an appeal letter was generated," "the assistance screener was run," plus the same anonymous dollar amounts. Each event carries a random device ID (generated on your device, linked to no account, name, or email) so your employer's dashboard can count how many unique people are active. What we never send: which procedure you looked at, what you typed, your bills, or anything identifying. Employers see group totals only, and only once at least 5 devices are active — below that, we suppress the breakdown entirely so small-team numbers can't describe an individual. Users without an employer code send none of this.
None of it can be traced back to you. Signals are stored as running totals and anonymous device-ID sets (Upstash/Vercel KV), not per-user activity records.
If your employer's health plan connects LucidCare (Premium plan integration)
Some employers connect LucidCare to their group health plan so the app can do two more things for you: confirm you're covered without you typing plan details, and keep your deductible and out-of-pocket progress up to date automatically. This tier only exists for you if your employer's plan has connected it. If it has:
- We receive limited plan records about you from your health plan — enrollment (eligibility) information and, where your plan includes it, claims information used to calculate your deductible/out-of-pocket status.
- This happens under a Business Associate Agreement (BAA) with your health plan — a HIPAA contract that restricts what we may do with those records: we may use them only to provide these services, we must protect them with specific safeguards, and we must report any breach.
- These records live in a dedicated, encrypted, access-logged environment, separate from everything else in this policy. They are never used for advertising, never sold, and never fed into the anonymous counters or your employer's dashboard. Your employer does not see them — the dashboard your employer sees remains the anonymous group totals described above.
- The results you see in the app (your coverage status, your deductible progress) are delivered to your device and stored there as your own copy, like everything else you keep in LucidCare.
- HIPAA rights over plan records (getting a copy, correcting them, an accounting of disclosures) run through your health plan; we support those requests when your plan directs us. Ask HR who administers your plan, or contact us and we'll point you to the right place.
- If your employer hasn't connected a plan, none of this applies to you, and the app works exactly as described in the rest of this policy.
Coarse location (city-level)
To show relevant local prices before you type anything, we read the approximate city/region your network resolves to from standard hosting headers (Vercel edge geolocation). This is city-level only — not precise location, and not stored against you.
Beta tester sessions (during the gated beta only)
If you enter via a tester/marketer access code (not the standard access code), we record that session's activity so we can measure the beta: pages/paths viewed, UI interactions, timestamps, and your IP address and browser user-agent. This is used to improve the product and is retained for a limited window (currently ~2 days) before automatic deletion. Tester sessions also use PostHog (product analytics), consented to in the Beta Terms: explicit page-views only (no autocapture), session replays with all text and inputs masked, no replay at all on the bill, appeal, and assistance screens (real bills render there), attribution by your invite-code label — never your name — and deletion of recordings at beta end. Standard beta access does not trigger any of this session logging. We will disclose and re-confirm tracking when the app leaves beta.
Healthcare.gov plan finder (only if you use it)
If you use the plan picker, the ZIP code, ages, and income you enter are sent to the federal Healthcare.gov Marketplace API to look up plans available to you. That request is governed by the federal government's privacy practices. We don't store the results on our servers.
Waitlist email (only if you submit it)
If you join the launch waitlist, we store your email to notify you when we reach your area. You can ask us to remove it anytime.
Email (if you contact us)
If you email us, we retain your address to respond. Transactional/launch email is processed by Resend, Inc. We don't add you to marketing lists without consent.
What we never do
- We never sell, rent, or trade your personal data.
- We never store what you enter in the app — your plan details, scanned bills, and searches stay on your device. The one exception: if your employer's health plan connects LucidCare, we hold the plan-provided records described in the plan-integrated section above, under a BAA, in a separate encrypted environment.
- We never use your health data for advertising or build individual health profiles.
- We never share anything that identifies you with insurers, employers, or providers. If your employer sponsors LucidCare, they see only anonymous group totals (see "Employer program counters" above) — never who, never what condition, never a bill.
- We accept no payment from insurers, hospitals, or pharma to rank results.
Third-party services we use
- Vercel — hosting, edge geolocation, and the KV store behind the anonymous counters / tester sessions. Standard server logs (IP, user-agent, path) apply.
- Healthcare.gov Marketplace API — plan search, only when you use the plan picker (receives the ZIP/ages/income you enter).
- Yelp and Google — facility reviews/ratings shown on the care map. Requests include the facility name and location; no health data is sent.
- OpenStreetMap / Leaflet — map tiles (approximate map coordinates only).
- Resend — transactional/launch email.
- PostHog — product analytics, beta testers only (see "Beta tester sessions" above): explicit page-views, fully-masked replays, no replay on bill/appeal/assistance screens, attributed by invite label, deleted at beta end.
- Google Fonts — typography, served from Google's CDN.
Pricing data sources
Prices come from licensed and public data. For our live metro (Greenville / Upstate SC) we parse insurers' own federally-mandated Transparency-in-Coverage files ourselves (BCBS-SC, Cigna, Aetna, UnitedHealthcare, Ambetter, and Promise/Prisma), plus CMS Hospital Price Transparency machine-readable files, providers' published cash/self-pay prices, and the NPI provider registry. Data for metros not yet open is licensed from Turquoise Health. None of this data contains your personal information.
Children's privacy
LucidCare is not directed at children under 13, and we do not knowingly collect their information.
Your rights
Your health data lives on your device, so you control it directly — delete it anytime by clearing your browser storage. For the limited data we hold (waitlist email, tester session logs, support email), email privacy@lucidcare.app to request deletion.
California (CCPA) & other state privacy rights
We do not sell or share personal information as defined by the CCPA. Residents of California and other states with privacy laws may exercise applicable rights by contacting privacy@lucidcare.app.
Changes to this policy
Material changes will be announced via in-app notice before taking effect. We will never retroactively apply a weaker policy to data already collected.