LUCAS Home / Privacy
Your data, explained.
How LUCAS Home uses information to provide your account, property search and AI conversations.
Effective 1 October 2026
Who is responsible
LUCAS Home is operated by SOBE OÜ (Sobe Invest), registry code 16119708, Paldiski mnt 161-1, 13518 Tallinn, Estonia. SOBE OÜ is the controller of the personal data described here.
What the app uses
- Account and sign-in
- Your email address, sign-in challenges and session records let you sign in, secure your account and synchronize your information.
- Profile and preferences
- The profile fields you fill in can include your name, date of birth, citizenship, country of residence, WhatsApp number, email and language. Your search preferences include criteria such as location, budget and household needs.
- Search and saved activity
- Search state, viewed and saved property references, comparisons, requests and related account data are stored to continue your search across sessions and devices.
- Conversations
- Your messages, replies, conversation identifiers and remembered context are used to continue conversations and respond with relevant property information.
- Voice
- When you use voice input, recorded audio is uploaded for transcription. When spoken replies are enabled, reply text is sent to generate audio.
- Appearance and background photo
- Theme preferences and a background photo you choose can be synchronized to your account. The photo is not simply kept on your phone.
- Technical records and support
- The server receives technical request information including an IP address, time, route and response status. The current API server has access logging enabled. Messages you email to support are also processed to answer your request.
AI services and the information sent
Anthropic (Claude) processes chat through our server. A request can include your message, conversation history, remembered context, name, preferences, household information, property references and profile context. The current client also attaches date-of-birth context when supplied. Free-text messages can contain personal information; they are not automatically anonymous. Anthropic states that standard API inputs and outputs are deleted within 30 days, subject to legal and misuse-prevention exceptions or a different agreement.
OpenAI processes voice recordings for transcription and reply text for speech generation through our server. A transcription sent as a chat message is then part of the chat flow described above. Property description translation and enrichment also use Anthropic. OpenAI states that API customer data is retained for no more than 30 days, subject to legal exceptions or an agreed alternative. These providers act as service providers under their commercial data-protection terms; their processing may take place outside the EEA and uses applicable contractual safeguards.
Why we use the information
We process account, profile, search and conversation information to provide the service you request and maintain your account (GDPR Article 6(1)(b)). We process limited technical and support information to keep the service secure, diagnose failures and answer requests (our legitimate interests under Article 6(1)(f)). We do not sell personal data or use it for advertising or cross-app tracking. We require service providers to protect personal data consistently with this policy and applicable law.
Your choices
Chat and voice are optional. Using them sends the information described above to Anthropic or OpenAI through our server. You can avoid future AI transfers by not using chat or voice; manual property search, saved properties and comparison remain available. Microphone access can be withdrawn in iOS Settings. You can edit optional profile fields in Profile and contact us to withdraw a consent or request deletion. Withdrawal does not undo processing already completed. A dedicated in-app AI-sharing control is being added before public App Store release.
Account deletion and retention
We keep account, profile, saved-property and conversation data while your account is active. Choosing Delete account in Profile revokes active sessions and starts a 60-day recovery period; signing in with a new email code during that period cancels deletion. After 60 days, the account service deletes the active account records, client and conversation data, saved state and background files. Sign-in codes expire after 10 minutes. API web access and error logs, which can include IP address and request details, rotate daily and are kept for up to 14 days. AI-provider copies follow the periods described above. Support email is kept only as long as needed to resolve the request and meet legal obligations. Legal, security and backup exceptions may require limited information to be retained longer.
Requests about your information
Contact us to request access, correction, export or erasure of your personal data, or to raise an objection or ask for processing to be restricted where applicable. We may verify your identity. You may also complain to the Estonian Data Protection Inspectorate or the supervisory authority where you live. Signing out is not an account-deletion request.
This website
This website has no analytics, advertising pixels, cookies, contact forms or third-party font requests. Email links open your email application. The hosting server processes standard request information, including IP address, requested page, time and response status, in security and access logs retained for up to 14 days.