Privacy Policy
Last updated July 23, 2026
This Privacy Policy explains how [Your Company Legal Name] ("Lucilamon", "we") collects, uses, and protects information when you use the Lucilamon service. We built Lucilamon to run on execution metadata, not on the contents of your workflows.
1. Information we collect
- Account data: your name, email, agency name, and password (stored only as a secure hash).
- Connection credentials: API keys for the instances you connect, which are encrypted at rest and used only to read execution metadata.
- Execution metadata: workflow and node names, run status, timestamps, durations, and error messages. We do not intentionally collect the business data (customer records, payloads) processed inside your workflows.
- Configuration: your clients, alert rules, and notification targets (for example, a Slack webhook URL, an email address, or a phone number).
- Billing data: subscription status and invoices. Card details are handled by Stripe and never stored on our servers.
- Usage & logs: basic technical logs needed to operate and secure the Service.
2. How we use information
We use this information to provide the Service — monitoring your workflows, detecting failures, sending alerts, generating reports — and to secure, maintain, bill for, and improve it. We do not sell your personal information.
3. Cookies
We use a single essential cookie to keep you signed in. We do not use advertising or third-party tracking cookies.
4. Sub-processors
We share data with service providers only as needed to run Lucilamon. These include our cloud hosting and database providers, Stripe (payments), Resend (transactional email), and messaging providers such as Twilio and Slack/Telegram when you enable those channels. Each processes data on our behalf under its own agreement.
5. Data retention
We keep account and configuration data for as long as your account is active. Execution records are retained for a rolling window (by default about 90 days) and then automatically purged. When you delete your account, we delete or anonymize your data within a reasonable period, except where we must retain it to meet legal or accounting obligations.
6. Security
We protect your data with encryption in transit, encryption of connection credentials at rest, hashed passwords, and access controls. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit what we collect in the first place.
7. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, or to object to or restrict certain processing. You can update your profile in the app or contact us to exercise these rights.
8. Your clients' data
When you connect instances that relate to your own clients, you act as the controller of that data and we act as your processor. You are responsible for having a lawful basis and any required consents for that monitoring.
9. International transfers
We and our sub-processors may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
10. Changes
We may update this Policy from time to time. Material changes will be announced with reasonable notice, and the “last updated” date above will change.
11. Contact
For privacy questions or requests, contact us at [email protected].