Last updated September 21, 2026
Privacy Policy
This Privacy Policy explains how Lucra handles information when brands and creators use our platform for creator submissions, paid ads, attribution, billing, and payouts.
Who We Are
Lucra is operated by On Lucra, Inc. References to Lucra, we, us, or our mean On Lucra, Inc. References to you mean brand users, creators, team members, invited users, connected-account users, and visitors to our public pages. This policy covers Lucra’s websites and native iOS app.
Information We Collect
We collect account and workspace information such as names, email addresses, organization names, roles, profile details, workspace settings, authentication events, invitations, permissions, and support communications, chat messages and attachments, message reactions, read status, online or typing status, chat safety preferences, and abuse reports.
We collect creator workflow information such as creator profiles, program participation, briefs, uploaded files, source filenames, thumbnails, preview images, video metadata, transcripts, captions, review decisions, revision notes, approval status, asset IDs, submission dates, earnings records, and payout status. Profile information can include your date of birth, gender selection, city, region, country, interests, creative styles, social handles, and portfolio selections.
We collect campaign and advertising information such as campaign names, objectives, destinations, budgets, launch records, platform ad IDs, creative IDs, media IDs, status changes, spend, impressions, clicks, conversions, installs, trials, purchases, revenue, cost metrics, attribution windows, and reporting snapshots.
If you connect Apple, Google, Meta, TikTok, Instagram, Shopify, Stripe, or another third-party service, we collect the information authorized by that connection. This may include account, business, page, app, pixel, advertiser, store, product, order, and campaign IDs; account names and settings; creator handles and profile metadata; content and engagement metadata; attribution and performance data; access and refresh tokens; token expiration data; and provider API or webhook events.
We collect billing, payout, referral, and finance information needed to calculate invoices, usage fees, platform fees, creator payouts, referral commissions, payment status, refunds, disputes, chargebacks, tax records, ledger entries, and reconciliation records.
We collect technical information such as IP address, device and browser details, approximate location derived from IP address, log events, session events, cookies or similar technologies, error data, performance data, and security signals.
iOS Permissions and Notifications
If you choose to use your device location, iOS asks for permission while you use the app. Apple’s location and mapping services resolve a city, region, and country for your creator profile. This profile flow sends those place names and a country code to Lucra, not your device’s exact coordinates or street address. You can enter your location manually instead and change location permission in iOS Settings. The app does not request background location access.
Lucra receives the photos, videos, and files you choose to upload for your profile, submissions, or conversations. Camera and photo-library access, when needed by a feature you choose, is controlled by iOS permission prompts and Settings. Choosing media does not give other Lucra users access to your device’s entire library.
With notification permission, Lucra registers an Apple push token and an installation identifier associated with your signed-in account to deliver notifications. You can turn notifications off in Lucra or iOS Settings. Notification permission is not required to maintain an account or receive creator earnings. Signing out initiates removal of that device’s notification registration from the account.
Chat and Safety
Messages and attachments are shared with authorized participants in the conversation. A brand conversation may be accessed by authorized team members using that brand’s shared chat identity. Program conversations are shared with their authorized participants. These conversations are not end-to-end encrypted.
We store reports and relevant conversation records to investigate misuse and enforce our Terms. Authorized personnel may access records for support, safety, security, legal obligations, and dispute handling. Reports can contain sensitive information; include only what is needed to explain the issue. Contact privacy@onlucra.com for safety or privacy concerns.
Sign in with Apple
If you choose Sign in with Apple, Lucra uses your Apple account identifier, the name you choose to share, and your email address to create or sign in to your Lucra account. If you choose Hide My Email, Apple provides a private relay address instead of your personal email. Lucra does not receive your Apple password. You can manage Lucra's access in your Apple Account settings and request account deletion in Lucra Settings.
Google Sign-In and Google Ads Data
Google Sign-In and Google Ads are separate, optional connections. Google Sign-In uses the OpenID, email, and profile permissions to authenticate you and may provide your Google account identifier, name, email address, and profile image. It does not give Lucra access to your Google Ads accounts.
A brand workspace owner or administrator may separately connect Google Ads from Lucra's Integrations settings. Lucra requests the Google Ads permission only when that user starts the connection. We use it to discover the Google Ads customer and manager accounts the user can access and let the user select an advertiser account for the Google Ads features exposed in Lucra. Lucra may access and store the customer and manager account IDs and names, account status, currency, and time zone needed for this setup. Lucra takes further Google Ads actions or accesses campaign, creative, delivery, performance, or conversion data only when an authorized user selects or configures a corresponding feature that is available in Lucra.
Google OAuth tokens are encrypted at rest and are not exposed to workspace users. Lucra does not receive your Google password. We share Google user data only with service providers that process it for Lucra's user-facing features, security, or legal compliance, subject to appropriate confidentiality and data-protection obligations. We do not sell Google user data, use it for advertising or retargeting, transfer it to data brokers, use it to determine creditworthiness or for lending, use it for surveillance, or use it to train generalized or cross-customer artificial intelligence models. Human access is limited to a user's affirmative request, security or abuse investigation, legal compliance, or permitted internal operations involving aggregated data.
Lucra's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google Ads in Lucra and revoke Lucra from your Google Account connections. See our Data Deletion page for the exact steps and retention limits.
Other Connected Services
Google Ads, Meta, and TikTok advertising connections may provide business, advertiser, page, identity, pixel, campaign, creative, permission, delivery, spend, and performance data used for the campaign and reporting features you choose. Creator Instagram and TikTok connections may provide account identifiers, handles, profile images, public or authorized content metadata, media, and engagement metrics used for creator profiles, content syncing, and paid-social authorization workflows.
Shopify may provide store, product, variant, inventory, draft-order, order, fulfillment, shipping, and limited customer contact information needed to sync products and fulfill creator samples. Provider data may provide app identifiers and authorized attribution, install, conversion, campaign, and revenue reporting. Stripe processes payment, identity, tax, bank-account, card, billing, and payout information for billing and creator payouts; Lucra generally receives identifiers, status, amounts, and transaction records rather than complete card or bank credentials.
How We Use Information
We use information to provide and operate Lucra, including workspace access, creator invitations, creator profile management, content upload, transcription, creative review, revision workflows, paid ad creation, campaign controls, spend syncing, attribution reporting, earnings calculations, referral tracking, billing, payout operations, and reconciliation.
We use information to connect and maintain third-party integrations, verify permissions, upload or map creative assets, create or update campaigns, sync status and metrics, process webhook events, debug provider errors, and keep connected accounts, campaigns, billing, and payout records consistent.
We use information to secure Lucra, detect abuse, prevent fraud, enforce agreements, comply with platform obligations, respond to legal requests, investigate suspicious activity, support users, and maintain audit logs.
Legal Bases
Where applicable law requires a legal basis, we process information to perform our contract with you and provide the features you request; with your consent, including when you connect an optional provider; for our legitimate interests in securing, supporting, measuring, and improving Lucra where those interests are not overridden by your rights; and to comply with legal, tax, accounting, payment, fraud, and platform obligations. You may withdraw consent by disconnecting an optional integration or contacting us, without affecting processing that occurred before withdrawal.
Creative Analysis and Product Improvement
Creator-video transcription uses Cloudflare Workers AI to process submitted media and return a transcript for the creator-content workflow. This processing can include the audio and spoken information in a video. Transcripts may contain errors and should be reviewed before they are relied on. This policy does not replace any separate permission required before sharing personal information with an AI service.
We may use creative content, thumbnails, transcripts, captions, metadata, review outcomes, campaign settings, ad status, spend, conversion data, payout data, and support signals to improve the Lucra product experience, quality controls, measurement, fraud detection, creative performance analysis, recommendations, forecasting, benchmarks, and product features.
Where feasible, we use aggregated, anonymized, de-identified, or otherwise privacy-protective data for analytics and product improvement. We do not sell creator content or publicly use identifiable brand or creator content in marketing materials without permission, unless the information is already public or permitted by an applicable agreement.
These product-improvement uses do not apply to Google user data or data derived from Google APIs except as needed to provide or improve the prominent, user-facing Google features the user authorized, for security, or as otherwise allowed by Google's Limited Use requirements.
Product Analytics
The native app does not request Apple’s advertising identifier or implement cross-app advertising tracking.
Analytics helps us understand feature use, maintain reliability, support users, investigate errors, prevent abuse, and improve Lucra. It does not change the provider data stored in Lucra's authoritative campaign, finance, payout, or integration records.
How We Share Information
We share information with service providers that help us operate Lucra, including hosting, database, authentication, file storage, email, analytics, error monitoring, observability, payment, payout, billing, tax, and customer support providers.
We share information with connected platforms such as Google, Meta, TikTok, Instagram, Shopify, Stripe, payment processors, payout providers, and app stores as needed to perform actions you request, maintain integrations, comply with platform rules, process payments, or keep campaigns, content, commerce, attribution, reporting, billing, and payouts in sync.
Brand users may see creator information, submitted content, review status, usage rights, campaign status, and payout-related information tied to their workspace. Creators may see program, submission, revision, approval, campaign, and earnings information tied to their own account or programs.
We may disclose information if required by law, subpoena, court order, governmental request, platform investigation, security incident, dispute, payment claim, or to protect Lucra, users, creators, brands, platforms, or the public. We may also disclose information in connection with a merger, acquisition, financing, reorganization, or sale of assets.
Connected Platform Data
Platform data from Google, Meta, TikTok, Instagram, Shopify, Stripe, and similar providers is used only for authorized Lucra workflows, such as account discovery, content and product syncing, campaign creation, creative upload, campaign controls, reporting, attribution, sample fulfillment, payout calculations, security, and compliance.
We do not sell platform data. We do not use platform data for cross-context behavioral advertising. We use platform data in accordance with the permissions granted by connected accounts, applicable platform terms, and applicable law.
Cookies and Similar Technologies
We use cookies and similar technologies for authentication, security, and user preferences. You can control cookies through your browser, but some authentication and preference features may not work if cookies are disabled.
Retention
We retain information for as long as needed to provide Lucra, maintain accurate campaign and payout records, comply with law, comply with tax and accounting obligations, resolve disputes, enforce agreements, prevent fraud, satisfy platform requirements, and protect the service.
We may retain billing records, payout records, transaction records, audit logs, campaign history, provider identifiers, fraud signals, dispute records, and de-identified or aggregated information after an account or integration is disconnected where retention is permitted or required.
OAuth and API credentials are kept only while the corresponding integration remains connected and are deleted from Lucra when the integration is disconnected. Provider account metadata, synced content, commerce records, attribution data, campaign reporting, and identifiable analytics data are deleted or de-identified after a verified deletion request when they are no longer needed for the purposes above. Shopify privacy requests are completed within the provider-required period, generally 30 days, unless a lawful retention exception applies.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls and operational security practices. No system is perfectly secure, and users are responsible for protecting credentials, connected account access, workspace permissions, and devices.
Your Choices and Rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, or information about how personal information is used or shared. You may also have the right to appeal a privacy decision or opt out of certain processing where required by law.
You can update certain profile and workspace information in Lucra, disconnect certain integrations, and initiate creator account deletion in the iOS app under Profile, Settings, Delete account. Our Data Deletion page explains the process and retention limits. You can request privacy assistance by emailing privacy@onlucra.com. We may need to verify your identity, account ownership, and workspace authority before completing a request.
Lucra does not sell personal information or share it for cross-context behavioral advertising. Where applicable, you may appeal a decision on a privacy request by replying to our response and asking for review.
International Transfers
Lucra is operated from the United States, and information may be processed in the United States and other countries where we or our service providers operate. Those countries may have privacy laws that differ from the laws where you live.
Children
Lucra is not intended for children under 13, and users who create accounts, connect integrations, submit payable content, or receive payouts must have legal authority to do so. We do not knowingly collect personal information from children under 13.
Changes
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new last updated date. Continued use of Lucra after an update means the updated Privacy Policy applies to your use of the service.
Contact
Questions or privacy requests can be sent to privacy@onlucra.com.