Lucy is a proactive AI coach from Lucy Labs that lives on your desktop as a cloud-backed app.

How We Earn Trust

Why trust comes first

Lucy Labs' mission is to benefit humanity. That requires people to actually use AI capability at human scale, and nobody adopts what they don't trust. Trust unlocks value; value drives adoption; adoption builds capability; capability lets it scale. Break the first link and the mission fails.

So trust is not our compliance posture. It is the load-bearing wall of the company, and the strongest guarantee we can offer: the boundary holds because the mission dies without it, which is sturdier than any policy.

The same boundary that disqualifies surveillance buyers earns adoption from everyone else.

The Evolutionary Framework

An AI investment your people don't trust is an AI investment that doesn't land. That is wasted money.

The Privacy Paradox

Personalized coaching gets better the more context Lucy has, and adoption collapses the moment people feel watched or lose control of their own data. Those two facts create tension, and every observation-shaped product has to answer for it.

Most monitoring tools answered by collecting more and explaining less. That is exactly why they read as surveillance, feel resistance, and why every new observation-shaped deployment inherits the suspicion they created.

Lucy refuses to be used as surveillance and answers the other way around: prefer behavior signal over content, make every capture visible and explainable, and put enforceable controls in the hands of both users and admins.

The distrust is rational, not resistance: most workplace AI has served the company at the worker's expense, so people reasonably assume the next deployment is being done TO them. Lucy answers the assumption with architecture and evidence, not reassurance.

Visibility, Confidence, and Control are the architecture that resolves the paradox, not a settings page bolted on top of it.

more context more suspicion architecture

Privacy isn't a setting on top of Lucy; it's the architecture underneath her.

Visibility · Confidence · Control

Lucy's trust architecture: Visibility (I can see), Confidence (I know), and Control (I decide).

Visibility: I can see

What Lucy captures: screen text at meaningful moments, application and window context, AI tool interactions, and behavioral signals like tool switching and time-on-task. The point is personalization, not collection.

What Lucy never captures: keystrokes, passwords, camera or webcam, anything outside configured hours, and any file contents from disk not directly related to coaching. If a file is open on your screen, only what is visible and permissioned is captured, like any other on-screen content.

The transparency dashboard: search, redact, and export your captured data, in real time. (planned)

Confidence: I know

Read-only is structural, not a setting: Lucy observes what you share and never writes to your systems. IT can verify it, and application behavior is auditable.

Retention is structural, not a promise: content is held up to 7 days by default, long enough to ask Lucy about an earlier session and for us to process it to extract context for coaching and plan development, then removed. Your organization can dial the window to zero. Sensitive data is filtered before any retention; where authorized, only anonymized content is kept to improve the platform. (design-partner engagements run a temporary window up to 60 days, for build and test)

7 daysDefault retention window, then removed
0Your organization can dial the window to zero
60 daysTemporary ceiling for design-partner build and test

Encryption in transit and at rest; today content processing runs in Lucy Labs' own infrastructure, not a third-party model provider. Subject to change; customers will be notified in advance and provided with a DPA to ensure data privacy.

On-device processing is on the roadmap: the near-term goal is that content never leaves your machine; today the screen-to-context conversion happens in Lucy's encrypted cloud and content is discarded after processing. (planned)

Signal + Content → Context: Lucy works from the lightest layer up.

SignalThe raw observation: events, app and window context, the rhythm of the work.
ContentWhat is actually on the screen: the most sensitive layer, strictest defaults.
ContextThe understanding coaching runs on.

Content is discarded once its context is derived.

How Lucy works from Signal + Content → Context

Control: I decide

Six user controls, the user-side parallel of the org-side five:

  • pause anytime (available)
  • disable content retention
  • redact by keyword or time window
  • delete your profile
  • export your full profile
  • dial coaching intensity (planned)

Refusal carries no penalty: "maybe later" and "no" cost nothing, and Lucy doesn't nag, re-ask, or tattle.

Whose side is Lucy on?

Lucy works for you, even though your company pays for her. The mission guides it and the architecture forces it. The trust posture isn't a setting your employer can flip.

Your coaching is private. Managers see team-level patterns, gated by a minimum team size, and never your prompts, your struggles, or your mistakes. Small teams stay opaque even in aggregate.

The one individual exception is yours to grant: you can choose to share your own progress and skill stats with your manager. Never your content, never your conversations.

You decide, design, and direct; Lucy guides and coaches the process; the solutions and agents you build do the work and deliver more value. She never acts on your data or systems.

The agency model, owned at What Lucy Is

For managers: what you see, what you never see, what you control

Lucy gives managers team-level truth, never individual surveillance, and the floor is architectural.

Five admin controls, the org-side parallel of the user-side six:

  • set the tool policy (Approved, Restricted, Banned)
  • pause AI pipelines at org, team, or role level
  • configure what Lucy can collect and retain
  • see team-level capability trends
  • see an audit trail of your own configuration choices

(planned for GA; the architectural posture holds today)

The floor is architectural, not configurable:

  • No individual rankings
  • No private prompt feeds
  • Team-size gating no admin can switch off

One trust architecture clears every gate

Lucy's one trust architecture clears employees, procurement, IT, Legal, and the Works Council in one pass.

Trust at the org level isn't compliance theater; it's how the AI investment actually lands. The same architecture that earns adoption from your people clears procurement, IT, Legal, and the Works Council. They aren't separate gates with different answers.

IT keeps the keys: access is revocable at the team, role, or org level at any time, and your tool policy is the floor Lucy coaches within, not a layer she works around.

Your organization is the data controller; Lucy Labs is the data processor. At GA: US datacenter by default, EU datacenter on request, so GDPR workloads need no cross-border transfers. Today, the Lucy Labs cloud is hosted in Spain on private infrastructure.

Exit is structural: cancel, and retained user data is deleted within 30 days; content was already gone within 7 by default. The capability your people built stays with you.

Employees Procurement IT Legal Works Council

A standardized procurement package ships on request: DPA template, privacy FAQ, employee-facing summary, and works-council material. One posture, four documents.

For government, public sector, and compliance

EU AI Act, Article 4: the law requires AI literacy in every organization deploying AI. Lucy delivers it as coaching in real work, so literacy is provable in changed behavior, not certificate completion rates.

EU AI Act, Article 14: human oversight is structural, not bolted on. Admins can pause or disable AI pipelines at any level, and every coaching session leaves an audit trail.

Works councils get commitments in writing: audit rights, consultation rights, configuration co-determination where the jurisdiction requires it, and deletion-on-departure as the default.

US posture: NIST AI RMF alignment today; FedRAMP and GovRAMP (formerly StateRAMP; renamed February 2025) paths are on the certification roadmap, said honestly. (planned)

Addressable structurally today In progress On the roadmap
  • GDPR
  • CCPA
  • EU AI Act deployer obligations
  • NIST AI RMF alignment
  • SOC 2 Type II
  • HIPAA-ready architecture
  • ENS HIGH
  • FedRAMP path
  • GovRAMP path

Good regulation, transparency, and value are trust enablers.

We don't sell surveillance

The ask we sometimes get

"I want to know exactly how much time each employee spends on every task. I need visibility into who's productive and who isn't for staffing decisions."

No.

Even when it costs us the deal.

The floor is contractual: our Terms of Service prohibit using Lucy for employee surveillance, punitive ranking, or disciplinary action based on platform data. Violations are grounds for ending the customer relationship.

Why the boundary holds: surveillance breaks the chain at trust, and everything we are depends on that chain. We refuse it because it doesn't work, not only because we don't like it.

Why trust comes first

Ask Lucy the hard trust questions yourself

You have seen the architecture. Now test it.

Frequently asked questions

What does Lucy capture from my screen?

Lucy captures screen text at meaningful moments, application and window context, AI tool interactions, and behavioral signals like tool switching and time-on-task. The point is personalization, not collection.

Does Lucy record keystrokes, passwords, or my camera?

No. Lucy never captures keystrokes, passwords, camera or webcam, anything outside configured hours, or any file contents from disk not directly related to coaching. If a file is open on your screen, only what is visible and permissioned is captured, like any other on-screen content.

Can my manager see my conversations with Lucy?

No. Your coaching with Lucy is private. Managers see team-level patterns, gated by a minimum team size, and never your prompts, your struggles, or your mistakes. The one individual exception is yours to grant: you can choose to share your own progress and skill stats with your manager.

How long does Lucy keep captured content?

Content is held up to 7 days by default, long enough to ask Lucy about an earlier session and for us to process it to extract context for coaching and plan development, then removed. Your organization can dial the window to zero. Sensitive data is filtered before any retention; where authorized, only anonymized content is kept to improve the platform. (design-partner engagements run a temporary window up to 60 days, for build and test)

Does Lucy write to my company's systems?

No. Read-only is structural, not a setting: Lucy observes what you share and never writes to your systems. IT can verify it, and application behavior is auditable.

Can Lucy be used for employee surveillance?

No. Lucy Labs' Terms of Service prohibit using Lucy for employee surveillance, punitive ranking, or disciplinary action based on platform data. Violations are grounds for ending the customer relationship. We refuse it because it doesn't work, not only because we don't like it.

What happens to our data if we cancel?

Exit is structural: cancel, and retained user data is deleted within 30 days; content was already gone within 7 by default. The capability your people built with Lucy stays with you.

How does Lucy address the EU AI Act?

The EU AI Act's Article 4 requires AI literacy in every organization deploying AI, and Lucy delivers it as coaching in real work, so literacy is provable in changed behavior, not certificate completion rates. Human oversight is structural, not bolted on: admins can pause or disable AI pipelines at any level, and every coaching session leaves an audit trail. EU AI Act deployer obligations are addressable structurally today.

Talk to Lucy