Legal

Privacy Policy

Effective July 29, 2026MAD STACK, LLC
This policy explains what LucidOS collects, why we collect it, who we share it with, and what you can do about it — including a specific accounting of the Google data we access and the Limited Use commitments we make about it. It applies from July 29, 2026.
01

Who we are

LucidOS is a multi-tenant property operations platform for multifamily owner-operators, operated by MAD STACK, LLC (“MAD STACK, LLC”, “we”, “us”). This policy covers the LucidOS web application at lucidcre.com, our marketing site, and the property marketing websites we host on behalf of customers.

LucidOS is sold to businesses. In most cases the organization that subscribes is the controller of the data it puts into the platform and MAD STACK, LLC acts as a processor on that organization’s instructions. If you are a tenant, prospect, or investor whose information reached us through one of our customers, contact that organization first — we will support them in responding to you.

02

Information we collect

We collect only what the platform needs to function:

  • Account information — name, work email, avatar, organization, and role, supplied at signup or by an administrator who invites you.
  • Customer data — the property, unit, occupancy, financial, deal, contact, and communication records your organization creates in LucidOS or imports from a connected system.
  • Connected system data — records synced from third-party services you authorize, such as your property management system (for example AppFolio) and Google (see section 4).
  • Usage and diagnostic data — pages viewed, features used, IP address, browser and device type, and error traces. We use this to keep the service reliable and to diagnose faults.
  • Communications — messages you send us for support, demo requests, and the contents of forms you submit on our sites.

We do not collect biometric data, government identifiers, or payment card numbers. Card details are handled directly by our payment processor and never touch our servers.

03

How we use information

  • Provide, operate, secure, and support the platform and the features your organization has activated.
  • Authenticate you and enforce your organization's role-based access controls.
  • Sync and reconcile data with the third-party systems you connect.
  • Generate the reports, dashboards, and AI-assisted summaries you request.
  • Detect, investigate, and prevent abuse, fraud, and security incidents.
  • Send service messages about outages, security, billing, and material changes.
  • Comply with legal obligations and enforce our agreements.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use customer data to train general-purpose machine learning models.

04

Google user data

When an administrator connects a Google account to LucidOS, we request the scopes below. Google shows you exactly what is being requested before you approve, and you may decline any connection. Every scope we request is read-onlyLucidOS cannot create, edit, or delete anything in your Google Analytics or Search Console accounts, and we request no scope that grants write access.

ScopeWhy we request it
openid · emailIdentifies which Google account is connected so the right account appears in your integration settings and we can tell two connected accounts apart.
analytics.readonlyReads Google Analytics 4 traffic, acquisition, and conversion metrics for the properties you select, so they can be shown in your site's analytics dashboard.
webmasters.readonlyReads Google Search Console impressions, clicks, positions, and indexing status for the sites you select, so search performance appears alongside your traffic data.

Storage. OAuth refresh and access tokens are stored encrypted at rest, restricted at the database layer so they are readable only by the server processes that call Google on your behalf, and never exposed to browsers or to other organizations on the platform. Metrics retrieved from Google are cached so dashboards load quickly.

Retention and deletion. Disconnecting a Google account in Settings → Integrations revokes the token with Google and deletes the stored credentials immediately. Cached Google-derived metrics are deleted within 30 days of disconnection, and all Google user data is deleted within 30 days of your organization closing its account. You may also revoke LucidOS’s access at any time from your Google Account permissions page.

Limited Use disclosure

LucidOS’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we do not transfer Google user data to third parties except as necessary to provide or improve the features you authorized, to comply with applicable law, or as part of a merger or acquisition; we do not use Google user data for advertising; we do not sell it; and we do not allow humans to read it except with your explicit consent for a specific support request, where required by law, for security investigations, or on data that has been aggregated and anonymized.

05

How we share information

We disclose information only in these circumstances, and never in exchange for money:

  • Within your organization — to other members, subject to the role and property permissions your administrators configure.
  • Service providers — vendors that host and run the platform under contract, bound to confidentiality and permitted to use data only to perform services for us. These currently include our cloud application host, our managed Postgres provider, our transactional email provider, our error-monitoring provider, and the AI model providers that power assistant features.
  • Systems you connect — data flows to and from third-party services at your direction, such as pushing a website lead into your property management system.
  • Legal and safety — when required by law, valid legal process, or to protect the rights, property, or safety of MAD STACK, LLC, our customers, or the public.
  • Corporate transactions — in connection with a merger, acquisition, or asset sale, with notice to affected customers and subject to this policy.
06

Retention and security

We retain customer data for as long as your organization maintains an account, then delete or anonymize it within 90 days of termination unless a longer period is required by law. Certain audit and financial ledger records are immutable by design and retained for the period required by applicable accounting and tax rules. Backups age out on a rolling schedule.

Data is encrypted in transit with TLS and at rest. Access between organizations is isolated at both the application layer and the database layer through row-level security keyed to your organization. Administrative access is limited to personnel who need it, and credentials for connected systems are stored in tables no client request can read. No system is perfectly secure; we will notify affected customers without undue delay if a breach affecting their data occurs.

07

Your choices and rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. Residents of California may request disclosure of the categories of information collected and may opt out of sale or sharing — we do neither.

To exercise a right, email support@madstack.io. We will verify your request and respond within the time your jurisdiction requires. We will not discriminate against you for exercising a right. Where we act as a processor for one of our customers, we will refer your request to them and assist in responding.

You can opt out of marketing email at any time using the unsubscribe link in any such message. Service and security notices cannot be opted out of while your account is active.

08

Cookies and tracking

We use strictly necessary cookies to keep you signed in, remember interface preferences such as sidebar state and theme, and protect forms against abuse. We use a small amount of first-party analytics to understand aggregate product usage. We do not run third-party advertising trackers on the LucidOS application, and we do not respond to Do Not Track signals because no common standard for them exists.

09

International transfers and children

LucidOS is operated from the United States and data is processed there. If you access the service from outside the United States, you understand your information will be transferred to and processed in the United States, where data protection law may differ from your own. Where required, we rely on Standard Contractual Clauses for such transfers.

The service is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

10

Changes and contact

We may update this policy as the product changes. When we make material changes we will revise the effective date above and notify account administrators by email or in-app notice before the change takes effect. Continued use after the effective date constitutes acceptance.

Privacy questions, requests, and complaints go to support@madstack.io, which also handles general enquiries. Postal enquiries may be addressed to MAD STACK, LLC.

Questions about this document?

Write to support@madstack.io and a human will answer. You may also want to read our Terms of Service.