Last updated: 3 October 2026 · Developer: Bhaskar Mehra · Contact: lucent.app.support@gmail.com
Lucent is a privacy-first, on-device toolkit. It has no backend server of its own, no user accounts, no advertising, and no analytics or tracking of its own. One library it bundles, Google's ML Kit, sends Google a usage report of its own; what that report carries is set out below. We (the developer) do not collect, store, or receive any of your personal data. This policy explains what stays on your device, what happens when you use a tool that makes an online lookup, and why each permission is requested.
Information stored on your device
Everything Lucent saves is kept locally on your device and is never uploaded to us or synced to any cloud:
Identifiers you choose to add to your Vault (e.g. an email, username, domain, or phone number you attest is your own).
Findings, your Exposure Score, hardening-checklist progress, and achievements derived from your own activity.
App settings (theme, sound/haptics, app-lock preference).
Things you create or import inside a tool: scripts you save in Code Lab, a logo you choose for the Geotag Camera's stamp, and a comparison model you import into Sample Match.
You can permanently erase all of this at any time from Settings → Wipe all local data. Uninstalling the app also removes it.
Information sent over the network
Lucent performs its lookups directly against public, keyless third-party services over encrypted (HTTPS) connections — there is no Lucent server in between. When you actively run a tool, the specific value you enter is sent to the relevant public service solely to answer your query. For example:
An IP address, domain, or URL you look up is sent to the corresponding public intelligence/DNS/WHOIS service. For a domain this can include its registrar's own RDAP server, public certificate-transparency logs and their search services, a public host-search service, the Internet Archive's index and one request to the domain itself; the Data Sources screen in the app names every service each tool asks.
A username you check is tested against public profile pages to see whether it exists.
Network tools send only infrastructure addresses: Traceroute looks up the router addresses of each public hop (never your own), the Speed Test makes one extra headers-only request to the same Cloudflare endpoint to read the edge's identity, and DNS Control's benchmark sends a whoami query through each public resolver it measures, which shows that resolver's egress address and whether it forwards your subnet.
An email you scan for breaches is sent to a public breach-lookup service. The Gravatar check sends a hash of your email, never the address itself, to Gravatar's public profile endpoints (gravatar.com and api.gravatar.com), and shows you everything they publish for it. That hash is Gravatar's own way of addressing a profile rather than a privacy measure: it stands for the same address every time, so Gravatar can still tell which account was asked about.
When checking a password against known breaches, only a partial, irreversible hash prefix leaves your device (k-anonymity) — never the password itself.
These lookups are ephemeral: Lucent does not log them, does not retain them, and does not combine them into a profile of you. Once a service returns its answer, Lucent keeps nothing about the request except any result you explicitly save to your Vault. The one qualification is an ordinary HTTP cache: a service's answer may be held for a short time in the app's private storage on your device so that repeating the same lookup does not ask again. That cache never leaves the device, is never read by us, and is emptied by Settings → Wipe all local data (which also removes saved scripts, the stamp logo, an imported comparison model, and any stamped or cleaned copies still in the cache). Each third-party service you query is subject to its own privacy policy. The complete, per-tool list of every service Lucent may contact is shown inside the app under Settings → Data Sources. Every lookup Lucent makes to a service on the internet is HTTPS, and the app is built so the operating system refuses a cleartext connection outright. Three things on your own equipment are deliberately not HTTPS, and none of them carries anything about you: LAN Remote speaks ordinary HTTP to the devices on your own network, because that is what a television or a media player speaks, and it refuses any address that is not a private one; the probing tools (Ping, Traceroute, the Port Scanner, the Network Scanner, Site Status) open plain TCP connections or send ICMP packets to the host or range you named, which is what probing a host means; and an ordinary name lookup goes to whatever resolver your network gives you, in the clear, exactly as it does for every other app on the phone — DNS Control exists to show you that and to help you encrypt it.
The value you look up is the query, so it necessarily reaches the service being asked, in the address of the request: a domain, a handle or an address appears in the URL path or as a parameter, depending on what that service accepts. Nothing else about you is added to those requests — no identifier of you or of your device, and no record of your other lookups. The password check is the one that never sends its value at all: only a short, irreversible hash prefix leaves the device.
Three on-device readers deserve a note. The Compass can ask for coarse location on an explicit tap, used only to evaluate magnetic declination on the device. Device ID asks the platform for the gated identifiers (serial, IMEI, MEID, IMSI, ICCID, GSF id) and displays the operating system's refusal as the answer, storing nothing. What Sites See assembles the signals a website or app could read from this device the moment you connect — including the advertising-adjacent ones such as the Android ID and the GPU's own strings — and shows them to you; that report is built and displayed entirely on the device, and the only thing sent is a lookup of your own public address, asked of two public providers and merged, so the report can show how your connection appears from outside.
Several behaviours deserve to be spelled out:
The Geotag Camera and your coordinates. Every other tool sends a value you typed. This one can send a value your phone measured, which is a different thing and is treated as such. Each stamp field is off until you switch it on, and a field is the only reason anything is sent: the weather fields send the coordinate to Open-Meteo, an address field sends it to your device's own geocoder (on a phone with Google Play services, that call reaches Google) and falls back to OpenStreetMap's Nominatim, and a map thumbnail fetches a tile from OpenStreetMap or Esri, which reveals the coordinate rounded to that tile's area. With no field switched on there is no panel to draw and nothing is requested. Nothing is sent to us, the coordinate is never stored anywhere but inside the file you captured, and each service is subject to its own privacy policy.
Active network tools. Tools such as Ping, Traceroute, the Port Scanner and the Network Scanner make direct connections to a host or address range you specify (or to your own local network) in order to map it. Before sweeping any network that is not your own private Wi-Fi, the app asks you to confirm you own it or are authorised to test it — this is standard for a network-diagnostic tool and remains your responsibility. Site Status may also retry the same host over your mobile data while you are on Wi-Fi (or vice versa) to tell a real outage from a network-specific block; this can use a small amount of your mobile-data allowance.
Code Lab and the scripts you run. Code Lab runs scripts you write or open on the device itself: shell scripts on the phone's own shell, and JavaScript and Lua on interpreters bundled in the app. Everything runs inside Lucent's own sandbox, with Lucent's permissions and no access to other apps' data, and nothing is downloaded to run. Lucent uploads nothing on a script's behalf, but a shell script can use the network (for example to ping or fetch a host), so anything such a script sends is sent by you. Scripts you save are stored in the app's private storage on the device.
Sample Match, faces and voices. This tool compares two samples you supply — two photographs, or two voice recordings — and reports how alike they are. Everything happens on your device: the comparison models are bundled inside the app, the files you choose are read locally, and neither the samples, the measurements taken from them nor the result are uploaded, to us or to anyone (the ML Kit usage report described next carries none of them). Lucent does not identify anyone: there is no database of faces or voices to search, only the two samples in front of you. Nothing about a comparison is kept once you leave the screen; the temporary working copy the tool makes in order to read a file's metadata is deleted as soon as it has been read. If you import a comparison model of your own it is stored in the app's private storage until you remove it. Faces and voices are sensitive; treat other people's samples as theirs, and use the tool only on material you are entitled to.
Google ML Kit's usage report. The QR Safety Scanner reads barcodes, and Sample Match finds faces, with Google's ML Kit. Its models are bundled in the app and run on the device, and nothing is downloaded. ML Kit also sends Google a usage report of its own, to firebaselogging.googleapis.com, and offers no way for an app to switch it off. The report carries the app's package name and version, an identifier ML Kit generates for its own installation, the operating system's build, which detector ran with which options, how long it took, any error code, and the format, size and rotation of the image it was given. It never carries what a barcode says, an image, a face, a measurement or a result. Android may send a report that is waiting later on, even while Lucent is closed. The report goes to Google, never to us, and Google's privacy policy governs it.
Tracker Watch. This listens for Bluetooth item finders (tags such as AirTag, SmartTag and Tile) around you and notes the phone's own position at each sighting, to report whether one has stayed with the phone as it moved. It listens only while its screen is in front and stops when you leave it: nothing runs in the background, nothing is sent and there is no notification. The sightings are held in memory, never written to storage, and are discarded when a new watch starts or when you clear them.
Ultrasonic Beacons. While its screen is open, this listens with the microphone to the band above hearing (17 to 22 kHz) and reports any tone it measures there. The sound is analysed as it arrives and is never recorded, stored or sent.
LAN Remote and your own network. This tool finds devices on the network you are connected to by sending the standard discovery messages (SSDP and mDNS) that televisions, media players and hubs answer, then sends the commands you press to the one you pick. It refuses to contact any address that is not a private one, so nothing it does leaves your network, and it reaches no service of ours or anyone else's on the internet. What it learns about a device is shown to you and kept nowhere else.
Bluetooth Remote and what you type. The phone can present itself to a host you have already paired in Android's Bluetooth settings — a computer, a television, a set-top box — as a standard Bluetooth keyboard, trackpad and media remote. While that screen is open, the keystrokes, pointer movements and media keys you enter are sent to that paired host, exactly as a physical keyboard would send them. Nothing is sent anywhere else, and Lucent keeps no record of what you typed. Do not use it to enter a password on a host you do not trust.
IR Remote. On a phone with an infrared emitter, this sends the infrared codes you choose through that emitter. Infrared here is one-way: the phone transmits and receives nothing back, there is no pairing and no network involved.
Hardware Diagnostics. This exercises your device's own hardware and reports what it measures: the sensors against their drivers and against physics, the cameras, the torch, the vibration motor, the display and touch digitiser, and an audio loopback that plays a brief tone through the speaker and listens for it with the microphone. The loopback captures about a second and a half of audio in order to measure the tone that came back; it is analysed in memory, never written to a file and never sent anywhere.
Bluetooth services (GATT). From the Bluetooth Scanner you can connect to a low-energy device you select and read, and where the device allows it write, the characteristics it publishes. This is a direct radio connection between your phone and that device, with nothing in between and nothing uploaded. Connect only to devices you own or are authorised to use.
Optional breach monitoring. If — and only if — you switch on monitoring for one of your own emails, Lucent runs a periodic background job (about every 12 hours, and only while you are online and your battery is not low) that re-submits that email's address to the same public breach-lookup service, so it can notify you of a newly reported breach. You can turn this off at any time, and it never runs for an identifier you have not added and enabled yourself.
Device permissions and why they are used
Permissions are requested only when you open the tool that needs them, and are used strictly for that tool's on-device function:
Camera — scanning a QR code you point at, taking the photographs and recordings you capture in the Geotag Camera, a photograph you take to compare in Sample Match, and the camera test in Hardware Diagnostics.
Location (approximate/precise) — reading Wi-Fi, GNSS/satellite, and cellular signal properties and your own device's fix for the signal-analysis tools, stamping a photograph or recording with where it was taken in the Geotag Camera, and noting the phone's own position at each sighting in Tracker Watch. Lucent never uses this to locate any other person, and Wi-Fi/Bluetooth scanning is flagged neverForLocation.
Microphone — measuring ambient loudness for the live sound-level meter, which measures in real time and records nothing. The Geotag Camera also uses it in two ways you control: it records sound into a video while the sound switch is on, and, if you have switched on the ambient-noise field, it takes a reading lasting a fraction of a second at the moment the shutter fires. Hardware Diagnostics' audio loopback also captures about a second and a half in order to measure the tone it just played. Ultrasonic Beacons listens to the band above hearing while its screen is open and records nothing. Sample Match records a few seconds of a voice when you press its record button, to compare it on the device; the recording is held in memory and is gone when you leave the screen. Outside a video you have chosen to record with sound, no audio is kept.
Phone state / phone numbers — showing your cellular network and serving-cell details, and (for you only) your own SIM/line information.
Nearby Wi-Fi devices / Wi-Fi state / Bluetooth — reading the Wi-Fi network you are on and listing nearby radios in the scanner tools; connecting to a low-energy device you pick to read its services; listening for item finders in Tracker Watch; and, for Bluetooth Remote, letting the phone act as an input device for a host you have already paired. Wi-Fi and Bluetooth scanning are flagged neverForLocation.
Network state / change network state — checking whether you are online, and (for Site Status' second-opinion check) asking to try a host over a specific transport such as mobile data while you are on Wi-Fi.
NFC — reading a tag or card you physically tap to the phone. This reads what the tag broadcasts on contact: its chip model and identifiers, any stored NDEF records (links, text, Wi-Fi/Bluetooth pairing tags), and — only after you turn on an in-tool authorisation switch — a contactless payment card's number and expiry, or a MIFARE access card's unprotected sectors. It is entirely on-device and nothing is uploaded. Read mode never alters a tag. Write mode, which you switch to deliberately, writes only a record you composed (a link, text, a Wi-Fi network, a contact and the like) to the tag you are holding, and can lock that tag permanently if you ask it to; a payment or transit card cannot be written to at all. A contactless read never exposes the printed security code (CVV) or a usable payment cryptogram, so it cannot be used to pay or clone a card. Read and write only tags and cards you own or are authorised to.
Photos/media — reading a photo you select to display or strip its metadata (embedded GPS is shown only if you explicitly ask to reveal it), and saving what the Geotag Camera captures to your gallery; nothing is uploaded.
Notifications — sending you a breach alert, only if you switch on breach-monitoring for one of your own emails.
Infrared — transmitting the codes you choose from the IR Remote through the phone's infrared emitter, on phones that have one. It cannot receive.
Wi-Fi multicast — allowing LAN Remote's discovery messages to reach the devices on your own network for the length of one search; Android otherwise discards them. It gives the app no reach of its own.
Vibration — the app's own haptic feedback, and the vibration-motor test in Hardware Diagnostics.
Biometric — the optional app-lock (fingerprint/face/PIN) that gates the app; authentication is handled by the operating system.
Reading files you choose
File Metadata, and the provenance report inside it, read the file you select and nothing else. The file stays on your device: its metadata, and any Content Credentials (C2PA) it carries, are parsed and their signatures checked on the device against a certificate set bundled in the app, with no lookup and no upload. When you ask the tool to strip metadata, it writes a cleaned copy beside the original in the app's private cache for you to share or save; the original is never altered. Those copies are removed by Settings → Wipe all local data.
Document Check reads a PDF you choose and reports what it holds beyond what a reader shows, such as text still under a redaction box or an earlier revision. Capture Reader reads a packet capture (pcap or pcapng) you choose and lists the connections in it, naming each destination only from what the capture itself contains. Message Inspector reads text you paste into it. All three work on the device, with no lookup and no upload; Message Inspector hands a link to Threat Lookup only when you tap it, and that lookup is the one described above.
Checking whether specific apps are installed
The Device Integrity tool checks your device for signs of rooting or tampering. As part of this, it asks the operating system whether a fixed, built-in list of known root-management, hooking and root-hiding apps is present (for example Magisk, KernelSU, Xposed/LSposed). It can only ask about the specific packages on that list — it cannot and does not enumerate your other installed apps. The result is computed on your device, shown to you, and never transmitted. This is disclosed here because checking for named packages is a form of reading your app inventory.
Data sharing and selling
We do not sell your data, and we do not share it with anyone — because we never receive it in the first place. The only data that leaves your device is the query you personally submit to a public service while using a tool, and ML Kit's usage report to Google, both as described above.
Children
Lucent is a security and privacy utility intended for users aged 16 and over. It is not directed at children under 16, and it does not knowingly collect any information from them.
Security
Lookups to internet services are HTTPS-only, and cleartext connections to the internet are blocked by the operating system at the app's request; see above for the three deliberate exceptions on your own network and equipment. The optional File Encryptor performs AES-256 encryption entirely on your device with a passphrase you choose; the passphrase and files never leave the device, and there is no recovery mechanism. The optional biometric app-lock adds a device-level gate. Because no data is transmitted to or held by us, there is no server-side store to be breached.
Changes to this policy
If this policy changes, the updated version will be posted at this URL with a new "Last updated" date.
Contact
Questions about this policy or Lucent's privacy practices can be sent to lucent.app.support@gmail.com.