Privacy Policy
Last updated: August 27, 2026
LucidOpus ("LucidOpus," "we," "us," or "our") operates the website https://lucidopus.ai (the "Service"), an evidence-based job matching product for software engineers. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
1. Information we collect
Account information
When you create an account, our third-party authentication provider collects your sign-in credentials on our behalf. If you sign in with Google, we receive your name, email address, and profile picture from your Google account. If you sign up with email, we receive your email address.
Profile information
Information you add to your profile, such as your name, professional title, years of experience, location (ZIP code, city, state, country), and job preferences (commute radius, company size, seniority, relocation openness).
Resume data
When you upload a resume (PDF or DOCX), we store the file and extract its text and structured details — such as work history, skills, and education — to pre-fill your profile, generate your skill report, and power job matching.
GitHub data
If you choose to connect your GitHub account, we access your GitHub profile, public repositories, languages, and activity using the OAuth token you grant. We use this as evidence for your skill report and job matches. You can disconnect GitHub at any time from your profile, which stops further syncing.
Product activity
Feedback board posts, comments, and votes; match ratings (thumbs up/down and notes); "applied," "interviewing," and saved markers you set on job matches; and whether you expanded a match's details or clicked through to apply.
Usage and device data
Server logs (IP address, browser type, pages visited, timestamps) used for security and debugging, and aggregate, privacy-friendly product analytics from our hosting provider. On the public landing and sign-in pages only — never inside a signed-in session — we also record session replay (mouse movement, clicks, and scroll) so we can see where visitors drop off before creating an account. That replay uses two first-party cookies (_clck and _clsk) and does not capture pages that show your resume, matches, or other account data. Typed input on those pages is masked.
2. How we use your information
- Provide and operate the Service (authentication, profiles, job matching)
- Parse your resume and pre-fill your profile
- Generate your AI skill report (strengths, gaps, seniority signal)
- Rank real job postings against your evidence and show cited match reasons
- Personalize filters such as location radius, company size, and seniority band
- Maintain security, prevent abuse, and debug problems
- Improve the product, including through the feedback board
We do not sell your personal information, and we do not show advertising.
3. AI processing
LucidOpus uses third-party large language models to parse resumes, generate report cards, and evaluate job matches. This means relevant portions of your profile, resume text, and a bounded summary of your GitHub data are sent to our AI provider's API for processing. Our AI providers process this data on our behalf as service providers; under our agreements with them, API inputs are not used to train their models.
4. Who we share your information with
We share personal information only with the service providers needed to operate LucidOpus:
- Authentication provider — sign-in and user account management
- Cloud database and storage provider — profile data and resume files
- AI processing provider — resume parsing, report cards, and job matching
- Cloud hosting and analytics provider — serving the app and aggregate usage analytics
- Session replay provider — mouse, click, and scroll recordings on the public landing and sign-in pages only
- Google and GitHub — only when you choose to sign in or connect those accounts
We may also disclose information if required by law, to protect our rights or users, or as part of a merger, acquisition, or sale of assets (with notice where required).
5. Google user data
If you sign in to LucidOpus with Google, our use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- What we access: only your basic profile information — name, email address, and profile picture — via Google Sign-In.
- How we use it: solely to create and authenticate your LucidOpus account and to display your name and avatar in the product.
- What we store: your name, email address, and profile image URL in our database. We never see or store your Google password.
- Sharing: Google user data is never sold and never shared with third parties except the service providers required to operate authentication, and never for advertising.
6. Data retention and deletion
We keep your information while your account is active. You can request deletion of your account and associated data — profile, resume files and extracted data, GitHub data, matches, and feedback — at any time by emailing us at the address below. When you delete your account, we remove your personal data from our active systems within 30 days; encrypted backups cycle out on their normal schedule. Abandoned resume uploads that you never saved may be retained for up to 30 days so you can resume where you left off, and are then deleted.
7. Security
We protect your data with encryption in transit (HTTPS) and at rest. GitHub OAuth tokens are encrypted with AES-256-GCM before storage, database access is enforced with row-level security, and all data access goes through authenticated server-side code. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard practices.
8. Your rights and choices
- View and edit your profile information at any time from your Profile page
- Disconnect your GitHub account to stop further syncing
- Request a copy, correction, or deletion of your personal data by emailing us
- Depending on where you live (for example, the EEA, UK, or California), you may have additional legal rights over your personal data — contact us to exercise them
9. Cookies
We use session cookies from our authentication provider that keep you signed in, a local preference for your light/dark theme, and — on the public landing and sign-in pages only — two first-party cookies (_clck and _clsk) used for session replay. We do not use advertising or cross-site tracking cookies.
10. Children's privacy
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
11. International users
LucidOpus is operated from the United States, and your information is processed and stored in the United States. By using the Service, you understand that your information will be transferred to and processed in the United States.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. For material changes, we will make reasonable efforts to notify you through the Service or by email.
13. Contact us
Questions about this Privacy Policy or your data? Email us at support@lucidopus.ai.

