Privacy Policy

Last updated August 29, 2026

Lucid Dream Finance is bookkeeping software. You trust us with your business's financial records, so this page sets out plainly what we collect, why, who else can see it, and what control you have. We've kept it specific rather than generic — every claim here describes how the product actually works.

Who we are

Lucid Dream Finance (“we”, “us”) provides double-entry bookkeeping software delivered over the web. This policy covers the Lucid Dream Finance website and application.

For the business records you enter, you are the data controller and we are your processor: it’s your data, we hold it on your behalf, and we act on your instructions.

What we collect

Account information. Your name, email address, and a securely hashed password. We never store your password in a readable form. If you sign in with Google instead, we receive your name and email address from Google and store no password for you at all.

Business records you enter. Customers, vendors, invoices, bills, payments, items, tax rates, journal entries, and any files you upload such as receipts or bills.

Employee records, if you use payroll. Names, contact details, job title, pay type, pay rate, and employment dates. We do not collect or store Social Security numbers or other government identifiers.

Bank information. Where you link a bank account, we store the institution name and the last four digits only. We do not store full account numbers or routing numbers.

What we deliberately don't collect

Some of the most sensitive data in financial software never touches our servers by design:

  • Card numbers. Payments for your subscription are handled on Stripe's own hosted checkout — card details never reach us.
  • Bank login credentials. If you connect a bank, credentials are entered directly with our bank-data provider and are never visible to us.
  • Social Security numbers, full bank account numbers, or routing numbers.
  • We do not use advertising trackers, sell your data, or share it with data brokers.

How we use it

  • To operate the product — recording transactions, generating reports, and producing invoices and statements.
  • To send transactional email you've asked for, such as an invoice to your customer or an overdue-payment reminder.
  • To bill you for your subscription.
  • To keep the service secure and diagnose faults.

We do not use your business records to train machine-learning models, and we do not use them for advertising.

Website analytics

We use Google Analytics on our public pages — the marketing site, pricing and these policies — to understand how people find us and which pages help them decide. It records the pages viewed, an approximate location from a truncated IP address, and the browser and referring site.

It is not loaded once you sign in. Nothing inside your books is measured, so no company name, customer, document or balance is ever sent to Google Analytics. If you would rather not be counted at all, any standard tracker blocker or your browser’s “do not track” setting will prevent it loading.

Artificial intelligence features

AI features are included with eligible plans and run through Google’s Gemini API under our agreement with Google, which does not permit your data to be used for training their models. You do not need to supply anything to use them.

Data is sent only at the moment you actively use a feature, and only the part the feature needs — a bank transaction’s description and amount when you ask for a category suggestion, or summary financial totals when you ask a question about a report. We do not send your customer list, your bank credentials, or your ledger in bulk.

You can connect your own API key from Google or Anthropic instead, in which case requests go to that provider under your own account rather than ours. Keys you supply are encrypted before storage. If you never use an AI feature, nothing is sent to an AI provider at all.

Who else processes your data

We use a small number of infrastructure providers to run the service. Each one is listed, along with exactly what reaches it, on our subprocessors page. We update that page when the list changes.

How we protect it

  • All traffic is encrypted in transit using TLS.
  • Data is stored in an access-controlled managed database, encrypted at rest by our hosting provider.
  • Third-party credentials you provide — such as an AI provider key — are additionally encrypted by us before storage.
  • Every request is scoped to your organization, so one customer's records are never reachable from another's account.
  • Passwords are stored only as salted hashes.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay.

How long we keep it

We keep your data for as long as your account is open. Bookkeeping records often need to be retained for several years for tax and audit purposes, so we don’t delete them automatically.

You can delete your company’s books, or your entire account, from Settings at any time. Deleting a company permanently removes its records, including uploaded files. Because this is irreversible, export anything you need first.

Your rights

You can access, correct, export, or delete your data from within the application. Depending on where you live, you may also have statutory rights to request a copy of your data or ask us to delete it. Contact us and we’ll help.

One limit worth stating honestly: where records are required to be retained by law, or are needed to keep another party’s books accurate, we may not be able to delete them immediately.

Children

The service is intended for business use and is not directed at anyone under 18. We do not knowingly collect data from children.

Changes

If we make a material change to this policy, we’ll update the date above and notify account holders. Continuing to use the service after a change means you accept it.

Contact

Questions about privacy, or a request about your data, can be sent to privacy@luciddreamfinance.com.