Privacy Policy (Declaration)
App: Polis
Last updated: July 1, 2026
Operator: Lux Corp ("Polis", "we", "us")
Contact: lux.corp.app@gmail.com
This Privacy Policy explains how Polis collects, uses, and shares information when you use the Polis mobile application and related services (the "Service").
What we collect
Information you provide
We may collect information you choose to provide, including:
- Account and profile information such as email address, username, display name, profile photo/avatar, and bio.
- Home area information such as home address components like street/city/state/ZIP, or state/district.
- User content such as posts, uploaded images/videos, descriptions, comments/replies, and event details.
- Reports and safety submissions such as report category and free-text details.
- Candidate or organization information where candidate tools are used, which may include legal name, campaign address, relevant identifiers such as FEC IDs, and optional public contact fields.
Information collected from your device or generated by your use
Depending on your settings and usage, we may collect:
- Location information: if enabled, GPS-based location for local features, plus manually provided location information.
- Usage and engagement data: session identifiers, impressions/views, and related metrics used to improve the service.
- Diagnostics and log data: timestamps, error details, and performance logs.
- IP address and user-agent in connection with certain actions such as abuse reporting and security controls.
Connected calendar and Google API data
Calendar integrations are optional. If you choose to connect a Google Calendar account, Polis may access the Google Calendar data you authorize through Google's OAuth consent flow. This may include:
- Calendar list information such as calendar names, calendar IDs, primary-calendar status, and which calendars you choose to import from or publish to.
- Availability information such as free/busy blocks used to prevent scheduling conflicts and to show available appointment times.
- Calendar event information such as event titles, start and end times, recurrence, locations, descriptions, attendees, reminders, status, and provider event IDs when needed to sync the calendar item.
- OAuth account and token information needed to keep the calendar connection active, refresh access, and disconnect the integration when requested.
Polis currently requests Google Calendar permissions for viewing and editing calendar events, reading the user's calendar list, and reading free/busy availability. Polis uses these permissions only for the calendar features shown in the app, including importing availability, building a master Polis calendar, detecting conflicts, publishing Polis-created calendar items to selected external calendars, and updating or deleting external calendar copies that Polis created or that you instruct Polis to manage.
Notifications
If enabled, the app may show notifications related to app activity such as reminders. Notification settings can be controlled in device settings.
How we use information
- Provide and operate core service features including accounts, profiles, posting, and events.
- Power local experiences relevant to home area and/or enabled location.
- Maintain safety and integrity, including abuse prevention and rule enforcement.
- Analyze and improve reliability and performance.
- Comply with legal obligations and protect rights and safety.
- Sync connected calendars, show combined availability, prevent scheduling conflicts, process appointment requests, and publish, update, or delete calendar items on connected calendars when requested through Polis.
How we share information
Public and social sharing
Polis includes social features. Depending on settings and usage, profile information and posted content may be visible to other users or the public. Polis generally does not intend to display full home address details to other users.
Service providers
We use service providers for hosting, storage, media processing/delivery, and location-related services.
Connected calendar providers
If you connect Google Calendar or another external calendar provider, Polis exchanges data with that provider only as needed to provide the calendar integration you enabled. For example, Polis may retrieve calendar lists and free/busy information, import event data into the Polis calendar view, or send event create, update, and delete requests to a selected external calendar. Public booking pages show available time slots and do not expose private calendar details. Candidate or campaign staff may see or manage calendar information only if the candidate or authorized administrator grants them permission in Polis.
Legal and safety
We may disclose information if required by law, or to protect users, enforce terms, and prevent fraud or abuse.
Google API Limited Use
Polis's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements. Polis does not sell Google user data, does not use Google Calendar data for advertising or retargeting, does not transfer Google Calendar data to data brokers or information resellers, and does not use Google Calendar data to train general machine learning or artificial intelligence models.
Human access to Google Calendar data is limited to the account owner, authorized candidate or campaign staff within Polis permissions, and Polis personnel only when necessary for user-requested support, security, abuse investigation, legal compliance, or service maintenance.
Data protection and security
Polis uses administrative, technical, and organizational safeguards designed to protect personal information and sensitive connected account data, including Google Calendar data, from unauthorized access, use, alteration, disclosure, or destruction. These safeguards include:
- Encryption in transit: communication with Polis, Google APIs, and other service providers is transmitted using secure protocols such as HTTPS/TLS.
- Encryption at rest: production databases, storage systems, backups, and sensitive calendar connection records are protected using encryption at rest where supported by the hosting or storage provider.
- OAuth token protection: Google OAuth access tokens, refresh tokens, and similar connected-account credentials are stored server-side, are not stored in the mobile app, and are encrypted at rest using server-side key-management controls.
- Access controls: access to production systems and sensitive user data is limited to authorized personnel and service components that need access to operate, secure, debug, or support the Service.
- Least-privilege calendar access: Polis requests calendar permissions only for the calendar integration features provided in the app and lets users choose which connected calendars are imported from or written to where supported.
- Monitoring and audit controls: Polis may use logs, alerts, and operational reviews to detect errors, abuse, unauthorized access, and synchronization failures.
- Deletion and disconnect controls: users can disconnect connected calendars in Polis, revoke Google access from their Google Account settings, request deletion of Polis account data, and contact us for privacy requests.
Data retention
Information is retained as needed to provide the Service and for legitimate business purposes such as security, abuse prevention, dispute resolution, and compliance. Some records may be retained for longer where required.
Connected calendar data and OAuth tokens are retained while the calendar integration remains connected or as needed for security, abuse prevention, audit, backup, dispute resolution, or legal compliance. When a calendar connection is disconnected, Polis stops using that connection for new sync activity and deletes or deactivates stored tokens according to our operational deletion processes, subject to limited backup, security, and legal-retention needs.
Your choices and controls
- Update profile information in-app where available.
- Control permissions for location, camera, photos/media, and notifications through device settings.
- Connect or disconnect external calendar accounts and choose which calendars Polis imports from or publishes to where these controls are available.
- Revoke Polis's Google access at any time through your Google Account permissions page.
- Report content and block/mute users through in-app tools.
- Request account deletion:
- In-app: Settings to Delete Account
- Web: https://www.luxcorp.solutions/delete-account.html
Privacy questions or requests: lux.corp.app@gmail.com
Children's privacy
Polis is not intended for children under 13 (or the minimum age required in your jurisdiction). If you believe a child provided personal information, contact lux.corp.app@gmail.com.
Changes
This policy may be updated from time to time. The last-updated date above will reflect the latest revision.