Yours alone
Privacy Policy
Your home is yours. The faces in your photographs, the videos of your children, the cameras at your doors, where the family will be on Saturday — none of it is anyone's business but your own, and none of it is ours to gather. This page says exactly what that means in practice, including what happens when you connect a Google account.
The short version
Lucarnia reads what you already keep — your photographs and home videos, your calendars, your cameras — and paints it on a wall in your house. That reading happens on the device in your home. The content is not uploaded to us, and there is nowhere in our systems for it to go.
We run two small services, and it is worth being precise about them rather than waving at "the cloud":
- A fleet service, which a device may check in with so we know it is alive and can offer it a software update. It carries liveness, a version string and coarse health — nothing else. You can switch it off.
- This website, which has a form you can use to reserve early access. If you fill it in, we hold your email address until you ask us not to.
We do not sell personal information, we do not run advertising, and we do not share your household's content with anyone.
What stays in your home
The following are read on your own network, held on your own device, shown on your own wall, and never uploaded to Lucarnia:
- Photographs and home videos
- Camera views, read over your own local network
- Calendar events and their details
- Weather, solar, music and home-automation readings
- Anything shown on the screen
Settings you enter — the address of a camera, a calendar feed, an account you have connected — are stored on the device. Credentials (passwords, tokens, private feed links) are held in a separate encrypted store on the device, not in the ordinary settings file.
If you ask the device for a diagnostics bundle to send us with a support question, it is assembled on the device, credentials and precise location are stripped out of it before it is written, and nothing is sent anywhere until you choose to send it.
Google account data
If you choose to connect a Google account, Lucarnia can show your Google Calendar on the wall — including each calendar's own colours, so one glance tells you whose day is whose. Connecting is optional. Lucarnia works without it, and calendars can also be added as a plain subscription link instead.
What we ask for, and why
One scope, and only one:
https://www.googleapis.com/auth/calendar.readonly. It is
read-only: Lucarnia cannot create, change or delete anything in your
calendar. We ask for it because per-event colour — the thing that makes
a family calendar legible on a wall — is only available through
Google's Calendar API, and only to a signed-in read.
What we access
From that scope, the device requests a deliberately narrow set of fields, listed here in full:
- The list of calendars in your account — their names, identifiers and colours — so you can tick the ones you want on the wall
- For the calendars you tick, events in a window around today: title, start and end time, location, status, event identifier, and colour
- Google's colour palette, so the colours we paint match the ones you chose
We deliberately do not request event descriptions, attendees, guest lists, attachments, conferencing links, or the free-text notes people put in calendar entries. Those fields are excluded at the request itself, so they never reach the device at all.
Lucarnia does not sign in to, or request any scope for, Google Photos, Gmail, Drive, Contacts, Tasks or any other Google service. If that ever changes, this section will say so before the feature ships.
One related thing, said plainly so it cannot look like a gap: the screensaver can show photographs from a shared album link you paste in yourself. That link is public to whoever holds it, needs no sign-in, and gives Lucarnia no access to your Google account. The photographs are fetched by your device, cached on your device, and are not uploaded to us.
What we do with it
Exactly one thing: draw the day on the wall in your home. Calendar data is held in memory on the device for as long as it is being shown, refreshed periodically, and discarded. It is not uploaded to Lucarnia, not stored on our servers, not shared with anybody, and not used for any purpose other than displaying your calendar to you.
Limited Use
Lucarnia's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, we do not:
- use Google user data for advertising, or for any form of profiling
- sell, rent or trade Google user data — to anyone, ever
- transfer Google user data to third parties, except as strictly necessary to provide or improve the feature you asked for, to comply with applicable law, or as part of a merger or acquisition with your consent
- allow humans to read your Google user data, except with your explicit consent (for example, if you send us a support bundle), where it is necessary for security purposes such as investigating abuse, or where the law requires it
Because your calendar data stays on your device, we are not in a position to read it even if we wanted to.
Signing in, and the tokens that result
Sign-in uses Google's standard OAuth consent screen. You sign in to Google directly — Lucarnia never sees or handles your Google password.
Google requires the address it returns you to after consent to be a secure (HTTPS) address, which a device inside your house cannot provide. So the final step passes through a small Lucarnia-operated endpoint whose only job is to hand the one-time authorization code back to your device. The code is single-use, expires in minutes, and is not stored by us.
Your device — not our server — exchanges that code with Google for the tokens it needs, and those tokens stay on the device:
- The access token is short-lived, held in memory only, and never written to disk.
- The refresh token — the long-lived one that lets the wall keep showing your calendar without you signing in every hour — is written to the device's encrypted secrets store, kept out of the settings file, out of the admin screens, out of logs, and out of any diagnostics bundle. It is never sent to Lucarnia.
It is kept for as long as the integration is connected, and destroyed when you disconnect. There is no copy anywhere else.
Taking it back
Two ways, and either is enough:
- Disconnect Google Calendar in Lucarnia's settings. The device asks Google to revoke the grant and erases the stored token.
- Revoke Lucarnia at myaccount.google.com/permissions. The token stops working immediately.
Either way, the calendar simply stops appearing on the wall. Everything else keeps working.
What the device sends us
Only what keeps it healthy and current. This is the whole list:
- That it is online, and when it last checked in
- Which software version it is running
- Coarse health — things like uptime and spare storage
- A public key generated on the device at first start, which identifies it and lets us verify that a check-in is genuinely from it
Every check-in is signed by a private key generated on the device that never leaves it. We hold only the matching public half. As with any internet request, the connection itself reveals the network address it came from; we do not store it against your device record.
The service can also queue a small, closed set of instructions for a device to collect the next time it checks in — restart, install an update, or collect logs for a support case. The list is fixed in the software and there is deliberately no "run anything" instruction. If logs are ever collected for a support case, that is at your request and the same redaction applies as to a diagnostics bundle.
There is nowhere in our system for a photo, a camera frame or a calendar entry to go — no column, no bucket, no field. That is a design decision, not a policy promise.
You can switch the check-ins off entirely, and everything on the wall keeps working exactly as before — you keep it current yourself.
This website, and writing to us
There are no advertising trackers, no analytics scripts and no third-party cookies on this site. Fonts are served from our own domain rather than a font service, so visiting this page does not tell anyone else that you did.
The early-access form
If you reserve early access we store what you type: your email address, and optionally your name and whatever you tell us about your home. We use it for one thing — to write to you about Lucarnia. It is not sold, not rented, and not used for advertising. Submitting the same address twice does not create a second record.
Two operational details, since we would rather over-disclose: a new reservation raises a notification in our own private team chat, which is how a very small company notices one; and the network address your submission came from is briefly recorded to stop the form being flooded, separately from your reservation and not linked to it in any report we produce.
If you write to us at our contact address, we keep the message so we can answer it.
Who else is involved
Kept short on purpose, because the list is short:
- Cloudflare hosts this website and our fleet service, and screens the form for automated abuse.
- Google, only if you connect a Google account, and only between your device and Google.
- Where the law requires it, or to protect someone's safety.
Nobody else. We do not sell or share personal information, and we do not use it for advertising or profiling.
Deleting your data
Write to hello@lucarnia.com and ask. We will delete what we hold and confirm when it is done. You do not need to give a reason, and you can also ask for a copy of it, or for a correction.
To do it yourself, immediately:
- Google data: disconnect in Lucarnia's settings, or revoke at myaccount.google.com/permissions. Nothing of yours is on our servers to delete.
- Anything on the device: it is your hardware. Disconnect an integration, or factory-reset the device, and the settings and the encrypted secrets store go with it.
- An early-access reservation: ask us and the record is deleted.
Depending on where you live you may have further rights over personal information — access, correction, deletion, portability, or objecting to a use. We honour those requests regardless of where you live, because keeping two standards would be sillier than keeping one.
Children, and other people in your home
Lucarnia is bought and set up by an adult, and it shows that household's own photographs and calendars on that household's own wall. It has no accounts for children, collects nothing from anyone who walks past it, and does not recognise faces or identify people.
Anyone in the house can see what is on the wall — that is the point of a wall. Choosing what goes on it is up to whoever set it up.
Changes to this policy
If we change what Lucarnia collects or how it is used, we will update this page and change the date at the top. Material changes will be announced to customers rather than quietly slipped in. Earlier versions are recoverable from our source history on request.
Contact
Lucarnia — privacy questions, data requests, or anything on this page that reads as untrue: hello@lucarnia.com.
We would genuinely rather hear that a sentence here is wrong than have it stand.