What LucidSpec can actually see
Not a generic privacy policy — the real mechanics of what happens when you use LucidSpec, written for the person who has to approve it.
Nothing runs in the background
Only when you ask
LucidSpec only processes what you actually submit — a request you type in, or a ticket you ask it to generate and send. There’s no standing access to your connected tracker beyond creating the tickets you explicitly ask for, and nothing runs on a schedule.
No passive monitoring, no background jobs reading through your systems. Nothing happens until you take an action.
Exactly the access your tracker needs
Nothing broader than creating a ticket
Connect your own Jira, ServiceNow, or Linear with credentials scoped to creating tickets — not reading your existing backlog, not managing users, nothing beyond what it takes to send a finished ticket where you asked it to go.
Those credentials are encrypted before they’re ever written to the database, and only decrypted server-side, at the moment a connection is tested or a ticket is actually sent — never returned in an API response.
Sensitive data is masked first
Before anything reaches the AI
Emails, access keys, tokens, and other obvious secrets are automatically masked before any request is sent for analysis.
If a request is flagged as unsafe content, it’s rejected before any AI call happens at all.
Analysis runs on OpenAI’s API — never the consumer ChatGPT product. It only ever sees the masked version of your request, after the step above. Under OpenAI’s own API terms, data submitted this way isn’t used to train their models.
What’s stored, and what isn’t
Most checks leave no record
A readiness check isn’t stored anywhere by LucidSpec unless you explicitly save it — as a placeholder to finish later, or as a generated ticket. Check something and decide not to save it, and there’s nothing left behind.
What you do save is scoped to your account. Every read and write is checked against who’s asking before it happens.
Every claim is grounded
Not a black-box score
The AI can only mark something as present if it can point to the exact sentence in your request that says so. A separate check then confirms that sentence is really there before the result is trusted.
This is checked, not just claimed — disagreements between the AI and a simple keyword check are flagged for a second look instead of silently resolved.
Where this stands today
Connecting your own Jira, ServiceNow, or Linear is self-serve: sign in to a LucidSpec account, add your credentials on the Integrations page, and LucidSpec starts sending finished tickets there. No admin approval and no company-wide install required — it’s your own connection, scoped to your account. If you'd rather walk through it together first, that's still an option — just ask.
Nothing beyond creating tickets is ever requested, and nothing runs until you generate and send one.
Questions before you connect it?
Talk to us directly if you'd like a walkthrough first — or connect your own tracker yourself in a couple of clicks from the Integrations page.