Last updated: 9 August 2026 · Developer: Bhaskar Mehra · Contact: lucent.app.support@gmail.com

Lucent is a privacy-first, on-device toolkit. It has no backend server of its own, no user accounts, no advertising, no analytics, and no third-party tracking libraries. We (the developer) do not collect, store, or receive any of your personal data. This policy explains what stays on your device, what happens when you use a tool that makes an online lookup, and why each permission is requested.

Information stored on your device

Everything Lucent saves is kept locally on your device and is never uploaded to us or synced to any cloud:

You can permanently erase all of this at any time from Settings → Wipe all local data. Uninstalling the app also removes it.

Information sent over the network

Lucent performs its lookups directly against public, keyless third-party services over encrypted (HTTPS) connections — there is no Lucent server in between. When you actively run a tool, the specific value you enter is sent to the relevant public service solely to answer your query. For example:

These lookups are ephemeral: Lucent does not log them, does not retain them, and does not combine them into a profile of you. Once a service returns its answer, Lucent keeps nothing about the request except any result you explicitly save to your Vault. Each third-party service you query is subject to its own privacy policy. The complete, per-tool list of every service Lucent may contact is shown inside the app under Settings → Data Sources. Nothing is ever sent to a non-encrypted destination. Personal data is kept out of URL query strings, with one unavoidable exception: the public breach-lookup service accepts an email address only as a URL parameter, so checking an address for breaches necessarily sends it that way. That request is encrypted in transit like every other one, and the address is still never sent to us.

Three behaviours deserve to be spelled out:

Device permissions and why they are used

Permissions are requested only when you open the tool that needs them, and are used strictly for that tool's on-device function:

Checking whether specific apps are installed

The Device Integrity tool checks your device for signs of rooting or tampering. As part of this, it asks the operating system whether a fixed, built-in list of known root-management, hooking and root-hiding apps is present (for example Magisk, KernelSU, Xposed/LSposed). It can only ask about the specific packages on that list — it cannot and does not enumerate your other installed apps. The result is computed on your device, shown to you, and never transmitted. This is disclosed here because checking for named packages is a form of reading your app inventory.

Data sharing and selling

We do not sell your data, and we do not share it with anyone — because we never receive it in the first place. The only data that leaves your device is the query you personally submit to a public service while using a tool, as described above.

Children

Lucent is a security and privacy utility intended for users aged 16 and over. It is not directed at children under 16, and it does not knowingly collect any information from them.

Security

Network requests are HTTPS-only. The optional File Encryptor performs AES-256 encryption entirely on your device with a passphrase you choose; the passphrase and files never leave the device, and there is no recovery mechanism. The optional biometric app-lock adds a device-level gate. Because no data is transmitted to or held by us, there is no server-side store to be breached.

Changes to this policy

If this policy changes, the updated version will be posted at this URL with a new "Last updated" date.

Contact

Questions about this policy or Lucent's privacy practices can be sent to lucent.app.support@gmail.com.