Privacy Policy

Version 1.0 · Effective June 11, 2026

This Privacy Policy explains how TASHABAR LLC, doing business as Lucido ("Lucido," "we," "us," or "our") handles information in connection with the Lucido service and our website at lucido-go.com. Lucido processes protected health information ("PHI") on behalf of clinics as a Business Associate under HIPAA; that PHI is governed by our Business Associate Agreement (BAA) and HIPAA, which control over this Policy as to PHI. This Policy describes how we handle clinic account information, usage and security information, and website information, and it summarizes our role with respect to PHI.

Information we collect

We collect: (a) account information you provide — clinic name, address, DEA registration, owner email, and the names and roles of the staff you add; (b) usage and security information — sign-in events, IP address, browser and device information, audit records, and error logs generated as you use the Service; and (c) website information — limited information from visitors to our public pages. We do not operate third-party advertising networks, and we do not run third-party analytics on patient data.

Protected health information (our role as a Business Associate)

When you use the Service, Lucido creates and processes the minimum PHI the REMS workflow requires — such as patient identifiers, vital signs, dosing details, and session observations — solely to provide the Service to your clinic, as your Business Associate under HIPAA and the BAA. We do not sell PHI, and we do not use PHI for our own purposes or for marketing. Session records auto-delete after your clinic's configured retention window.

State mental-health confidentiality laws

Records created in connection with esketamine treatment are mental-health treatment records, and some state laws — such as the Illinois Mental Health and Developmental Disabilities Confidentiality Act (740 ILCS 110) — protect them more strictly than HIPAA. Where a more protective state law applies, we handle PHI in accordance with it: PHI is disclosed only to your clinic and to our infrastructure subprocessor (Amazon Web Services, under a signed Business Associate Addendum); we run no third-party analytics, advertising, or tracking on patient data; and records your clinic exports or transmits remain subject to any redisclosure restrictions those laws impose on recipients.

How we use information

We use account, usage, and security information to operate, secure, maintain, and support the Service; to generate the REMS documentation your clinic files; to maintain the audit log your clinic relies on; to communicate with you about the Service; and to comply with law. We do not use PHI for advertising or marketing.

No sale of information

We do not sell personal information or PHI, and we do not share it for cross-context behavioral advertising.

Sharing and subprocessors

Lucido runs on Amazon Web Services, which hosts the Service under a signed Business Associate Addendum. Billing is processed by Stripe, Inc. on Stripe-hosted pages: Stripe receives billing information — the clinic's name, the owner's contact details, and payment-card data — and never receives PHI; no Stripe code runs inside the clinical application, and we do not store payment-card numbers ourselves. We may disclose information if required by law or to protect rights and safety, and in connection with a merger, acquisition, or sale of assets, subject to the protections of the BAA for PHI. We do not otherwise share PHI.

Data retention

Session and PHI records auto-delete after your clinic's configured retention window. Account information is retained while your account is active and as needed to comply with our legal obligations, resolve disputes, and enforce our agreements. Security and audit logs are retained for the period required by HIPAA and our compliance program: we retain HIPAA-required compliance documentation — policies, audit records, and agreement acceptances — for at least six years, consistent with 45 CFR § 164.316(b)(2).

Security

We protect information with encryption in transit (TLS) and at rest, an append-only audit log, role-appropriate authentication (owner accounts via Amazon Cognito with optional multi-factor authentication, and staff PINs), least-privilege access controls, and a database that is not publicly reachable. No method of transmission or storage is completely secure, but we work to protect your information and to notify you of incidents as required by the BAA and applicable law.

Your clinic's and patients' rights

Your clinic can export its data and request deletion of its data. Patients' rights under HIPAA — including access, amendment, and an accounting of disclosures — are supported through your clinic, which is the Covered Entity and the patients' point of contact.

Cookies

The Service uses strictly necessary, httpOnly session cookies to keep owners, staff, and patients signed in and to secure the application. We do not use cookies for third-party advertising or cross-site tracking.

Where we operate

We operate the Service in the United States. If you access it from outside the United States, you understand that information is processed in the United States.

Changes to this Policy

We may update this Policy from time to time. For material changes we will provide notice and update the version and effective date shown above.

Contact

Questions about this Policy or our privacy practices can be sent to privacy@lucido-go.com, attention: Privacy Officer. A postal address for privacy correspondence is available on request.