Lucent

Privacy

Last updated 10 August 2026.

Lucent records what you choose to write down about your own recovery. That is sensitive information, and this page says plainly what happens to it. If anything here is unclear, use Contact support in Settings and ask.

What is stored

  • Your account — name, email address, a one-way hash of your password (never the password itself), your timezone, and when you signed up.
  • Daily logs — the date, whether you were sober or used, any substances you selected, and the optional mood, craving level and notes you add.
  • Journal entries and their tags.
  • Goals you set and whether you have completed them.
  • Check-ins — the date and type of meetings, therapy sessions or sponsor calls you record.
  • Support contacts — the names and phone numbers you save.
  • Reminder settings — the hour you chose, and an anonymous push token per device if you turn reminders on.

What is not stored

  • No advertising or analytics trackers are loaded on any page.
  • No location data, no contact list access, no device identifiers.
  • Your data is never sold, rented, or shared with advertisers or data brokers.
  • Nobody else using Lucent can see any part of your account.

Who can see it

Every record is tied to your account and only ever returned to a signed-in session for that account — with one exception you control. If you create an accountability link in Settings, anyone holding that URL can see your first name, your current and longest streak, days since last use, and your sobriety rate. Nothing else: no substances, no notes, no journal, no dates, no email address. The page is never indexed, you can see how many times it has been opened, and turning it off takes effect immediately.

Lucent's operator can technically access the database in order to run and repair the service, and will only do so for that purpose.

Third parties

  • Railway hosts the application and its PostgreSQL database.
  • An SMTP relay sends verification and password-reset email. It sees your email address and the message.
  • PayPal loads only if you open the donate panel, and only then. It handles any payment; Lucent never sees your card details.

Getting your data out

Settings → Export your data gives you everything on your account: a spreadsheet to read, or a JSON file that is a complete, portable copy.

Deleting your account

Settings → Delete your account permanently removes your account and every log, journal entry, goal, check-in and contact attached to it. It happens immediately and cannot be undone, so export first if you want to keep a copy. Backups of the database are cycled out on a rolling basis after deletion.

Cookies

Lucent sets one cookie, which keeps you signed in. It is marked HttpOnly and SameSite, and Secure in production. There are no advertising or tracking cookies. Your timezone is kept in your browser's local storage as well as on the server, so dates land on the right day.

Security

Passwords are hashed with Werkzeug's PBKDF2 implementation. Traffic is served over HTTPS. Sessions expire after 30 days. No system is perfectly secure, and this page does not claim otherwise — but nothing here is stored in plain text that does not need to be.

Not medical advice

Lucent is a self-tracking tool. It is not a medical device, not treatment, and not a substitute for professional care. If you are in crisis, call or text 988 in the US, or your local emergency number.

Back to Lucent