1. Overview
Lucas' World (“the App”) is a private invoice-management service used by carers, plan managers, coordinators and administrators within a closed group. This policy explains what personal data the App collects, why it collects it, how it is used and shared, and the choices and rights you have.
The App handles only the data needed to manage invoices and to send them, from the sender’s own Gmail address, to a plan manager. It does not sell data, does not show advertising, and does not collect data for unrelated purposes.
2. Data we collect
Account data. To set up and operate your account we hold your name, email address, role (carer, admin or superadmin), a securely hashed password, an optional profile photo, and the contact details (ABN, address, phone) that appear on your invoices.
Invoice data. The NDIS support items, rates, hours, dates, notes, status and PDF documents you create in the App, plus records of actions taken on invoices (for example who approved or archived them).
Gmail connection data. If you connect your Gmail so invoices can be sent from your own address, we receive and store your Gmail address and the OAuth authorisation tokens Google issues. We never receive or store your Gmail password.
Technical data. Session cookies, push-notification subscription details, and basic request logs (such as IP address and browser) used to keep the App secure and to rate-limit logins.
3. How we use your data
- to operate your account and the App;
- to create, store and share invoices with the people you choose;
- to send invoice emails to your plan manager when you press “Send to plan manager”;
- to send service messages such as password resets or notifications;
- to keep the App secure and meet legal or NDIS record-keeping obligations.
4. Gmail data and Google’s Limited Use requirements
The App asks for one Gmail permission, gmail.send (“Send email on your behalf”), and only after you choose to connect your Gmail on your profile page.
How your Gmail data is accessed: only when you press “Send to plan manager”, at which point the App creates and sends the invoice email (with the invoice PDF attached) from your own address to the plan manager email you have selected. The message appears in your Gmail Sent folder like any email you send.
How your Gmail data is used: solely to send emails that you initiate. The App never reads, scans or analyses your inbox, drafts, contacts, labels or other mail, and never uses your Gmail data for any purpose other than sending the invoices you choose to send.
How your Gmail data is stored: your Gmail address and OAuth tokens are stored in the App's database, with access restricted to the App's administrators, so the connection keeps working until you disconnect Gmail (or revoke access in your Google Account). No email content is stored by the App.
How your Gmail data is shared: your Gmail address is shown to administrators only so they can see who has connected Gmail. It is never sold, rented or transferred to any third party for their own use.
The App’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. How we share data
Your data is shared only where needed to run the service:
- Plan managers — only the invoice information you choose to send to them.
- Service providers — the App is hosted by Vercel, data is stored in a Turso (libSQL) database, profile photos in Cloudflare R2, some system emails are sent via Resend, and login rate limiting uses Upstash. Each provider processes data only to provide that service and under its own terms.
Other than the above, personal data is not shared with any other party, except where required by law or with your consent.
6. Data retention
We keep your account and invoice data while your account is active, as well as any longer period needed to meet NDIS record-keeping or other legal obligations. Gmail OAuth tokens are kept until you disconnect Gmail or close your account. When you ask us to delete data, we remove it as soon as we no longer need to keep it, subject to those obligations.
7. Security
We use encryption in transit (TLS), securely hashed passwords, role-based access controls (carer, admin, superadmin), rate limiting on sign-in, and OAuth for Gmail access so no password is ever handled by the App. No security measure is perfect, and you can help by keeping your sign-in details private.
8. Your rights and choices
- See and update your data — most account details can be reviewed and corrected on your profile page.
- Disconnect Gmail — you can disconnect your Gmail in the App at any time; the App will then no longer be able to send emails on your behalf.
- Revoke access with Google — you can also remove the App’s access entirely at myaccount.google.com/permissions.
- Request deletion — contact us and we will delete the personal data we hold about you to the extent we are able.
9. Changes to this policy
We may update this policy from time to time; the date above shows when it was last updated. Material changes will be notified within the App. Continuing to use the App after a change means you accept the updated policy.
10. Contact
Questions, requests or complaints about this policy should be sent to arungurung2215@gmail.com .