Skip to content

Privacy Policy

Last updated September 21, 2026 · Draft

This is a draft, not a finished legal document.

It was written to accurately describe what LensLogic actually collects and does today, but it has not been reviewed by a licensed attorney. Have one review this (and the Terms of Service) before relying on it, publishing it as final, or onboarding real customers under it.

Who this covers

This policy covers LensLogic (the "Service"), a sales-intelligence and optical-calculation tool for optical practices and managers. It applies to anyone who creates an account or uses the Service, referred to here as "you."

What we collect

Account information

Your email address, a securely hashed version of your password (we never store the password itself), your name if you give us one, and your practice/organization name.

Business data you choose to upload

Sales transaction records you upload: dates, dollar amounts, product categories (frame, lens type, contacts, etc.), which insurance panel was billed, and which employee made the sale, if your export includes that. Signing in and saving an upload is optional, everything on the dashboard works without an account too, in which case nothing about that session is sent to us at all.

A photo, only if you use Frame Finder

Frame Finder's photo-based face-shape tool is optional — you can pick a face shape yourself instead, and no photo is ever collected. If you do upload a photo, it's sent once to Anthropic's API to classify face shape (oval, round, square, and so on) so we can show you frame-shape guidance. That photo is never written to disk, never saved to our database, and never logged anywhere in the Service, it exists only for the single request that analyzes it.

What we deliberately do not collect

No patient or customer names, dates of birth, contact information, prescriptions, or any other health-related information. The Service is built around aggregated business sales data, not individual patient records, and there is nowhere in our data model to put that information even if it appeared in a file you uploaded. If your export happens to contain something like that in a free-text column, please remove it before uploading, we do not screen uploads for accidentally included patient data today.

Technical information

Standard web request information (like IP address) is processed transiently to serve pages and enforce basic security, and a session cookie keeps you signed in. Your explanation-level preference (Beginner/Optician/Manager) is stored only in your browser, never sent to us.

How we use it

We use what we collect to:

  • Operate your account and keep you signed in
  • Calculate the KPIs, charts, and findings you see on your dashboard
  • Generate an AI coaching insight when you specifically ask for one
  • Classify face shape when you upload a photo to Frame Finder
  • Remember settings you've chosen, like a target multi-pair rate
  • Communicate with you about your account or the Service

We do not sell your data, and we do not use your business data to train any AI model.

Who we share it with

We use a small number of service providers to run the Service, referred to in privacy law as subprocessors:

  • Anthropic (Claude API) — used in two places. When you click "Get coaching insight," we send only the already-calculated KPI figures you're looking at (e.g. "Multi-pair rate: 24%"), never raw transaction rows, employee names, or your account email. When you upload a photo to Frame Finder, that photo is sent once for face-shape classification and is never saved, stored, or logged anywhere in the Service.
  • Google Fonts — used to load this site's typefaces, which sends your IP address to Google as a normal side effect of loading a stylesheet.
  • Our database hosting provider — stores your account and business data. We rely on that provider's infrastructure protections (encryption at rest, physical security) rather than operating our own data centers.

We do not otherwise share your data with third parties, except if required by law or to protect the rights, property, or safety of LensLogic, our users, or the public.

A note on HIPAA

We are not claiming HIPAA compliance. The Service is built to avoid collecting patient-identifiable health information in the first place, so it's very likely outside HIPAA's scope entirely, rather than a system that has been evaluated and certified against a law written for a different category of data. If a future version of this product ever handles patient identifiers or prescription history, this policy will be updated, and that change will get its own real compliance evaluation first, not an assumption that this policy still covers it.

How we protect it

Passwords are hashed (never stored in plain text) before they're saved. Sessions use a signed, HTTP-only cookie that JavaScript on the page can't read. Every request for your business data checks that it actually belongs to your account's organization before returning it. No security measure is perfect, and we can't guarantee absolute security, but this is the standard we hold the Service to.

How long we keep it

We keep your account and saved uploads for as long as your account is active. If you ask us to delete your account, we'll delete your account data and saved uploads, except where we're required to keep something longer for legal reasons.

Your choices

You can use most of the Service without an account at all. If you do have an account, you can ask us to access, correct, or delete your data at any time by contacting us below. We don't yet have a self-service export or delete button in the product itself, that's on our near-term roadmap, until then this is a manual request we'll handle by hand.

Children's privacy

The Service is a business tool intended for optical practice managers and staff, not children, and we do not knowingly collect information from anyone under 18.

Changes to this policy

If we make a material change to this policy, we'll update the date at the top and, for significant changes, notify account holders directly.

Contact us

Questions about this policy, or a request to access/correct/delete your data: [add a contact email before publishing].