Lucid Privacy

Lucid Privacy Notice

This notice explains how Imagine Tech Limited handles personal information in connection with Lucid. It focuses on a minimal-collection, self-custody posture while still covering browser routing, wallet-related requests, extension delivery, support operations, and security controls.

Lucid is designed as a self-custody product. Our privacy posture is to minimize collection, avoid custody of wallet secrets, and process only the information reasonably needed to operate the product, support legitimate routing and security, and satisfy the transparency and rights obligations that apply to the relevant user jurisdiction.
Ghost-native legal layerNon-custodial posture21 sectionsDocs-ready presentation
Last updated May 31, 2026

Need to exercise a Lucid privacy right?

Use the Privacy Request Center for Lucid access, deletion, correction, export, objection, opt-out, or appeal requests. We may still ask for additional identity or authorization evidence before fulfilling the request.

Open Privacy Request Center

Need the wider regulatory view?

The Regulatory Atlas maps how the Lucid legal layer is intended to align with GDPR, US state privacy laws, Latin American rights regimes, and sectoral overlays. The Regulatory Annexes go one layer deeper and map those laws back to the live privacy, terms, and cookie documents.

Regional deltas

Regional privacy supplements

These supplements summarize how the published privacy baseline is intended to map to specific regional laws. They complement the main policy, preserve mandatory local rights, and clarify response timing, complaint routes, verification expectations, and consent posture where those details matter to the user.

Regions
13
Active cards
3
Official sources
16
EEA, UK, and similar European regimes

GDPR

The privacy baseline is written to disclose controller identity, purposes, legal bases, recipients, transfers, retention, rights, and complaint paths in a GDPR-style format.

Interpretation note

Each card below is written as an operational supplement to the baseline document family, not as a standalone contract. It highlights where timing, appeal rights, complaint routes, or consent posture need to diverge by jurisdiction.

01
Regional supplement

Core rights

  • Access, rectification, erasure, restriction, objection, portability, and consent withdrawal routes are preserved where applicable.
  • A rights request can be submitted through the Privacy Request Center or by email to privacy-requests@imagine-tech.org.
  • We disclose transfer safeguards, retention categories, and complaint escalation expectations in the main notice.
  • Where verification is required, it should be proportionate to the request and should not collect more identity data than is reasonably necessary.
02
Regional supplement

Cookie and consent position

  • Non-essential cookies and trackers are intended to remain behind prior consent on covered surfaces.
  • Consent can be refused or withdrawn without losing access to strictly necessary functions.
  • A supported Global Privacy Control signal is treated as a restrictive browser-layer baseline on the covered repository surfaces until the user makes an explicit site-specific choice.
  • Where product-specific analytics or ad-tech changes the scope, the notice and controls should be refreshed before activation.
03
Regional supplement

Response timing

  • Requests are generally handled within one month.
  • Where complexity or volume justifies it, the period may be extended by up to two additional months with notice.
  • Users may also complain to a supervisory authority in their habitual residence, place of work, or place of the alleged infringement where the law provides that route.