Privacy
Privacy Policy
How Lectern handles information across the public website, the intake form, the client portal, and the system we run for a business.
Last updated: August 21, 2026
Scope
This Privacy Policy explains how Lectern collects, uses, shares, and protects information when you use lectern.systems, our intake form, the client portal, and the Lectern system we build and run for a customer at its own address on lectern.systems.
Lectern is business software. It is bought by the owner of a small service business and used by that business's staff, and the records inside it are that business's records. Lectern Solo, at solo.lectern.systems, is a separate product with its own policy on that surface.
Whose information this covers
Three different groups of people show up in this policy, and the rules are not the same for each.
- Visitors and prospective customers. These are people reading the public site or sending us an intake note, and we decide how that information is handled.
- Customers and their staff. These are the people who sign in to a Lectern system or the client portal, and we handle their account information to run the service.
- The people a customer keeps records about: its customers, clients, members, families, patients, students, applicants, and staff. Those records belong to the business. We process them on that business's instructions to provide the service, and this policy describes how. If you are one of those people and you want a record changed or removed, the business that holds it is the right place to start, and we will help them do it.
Information we collect
We collect what is needed to run the website, evaluate prospective customers, provide each customer's system, and protect the service.
- Contact and account information, such as names, email addresses, roles, business name, and sign-in credentials handled through our authentication provider.
- Intake information, which is what you tell us on the intake form: your name, your email, your business name, what kind of business you run, and whatever you write about how things work today.
- Portal records, such as deliveries and approvals, support tickets, messages and their attachments, requests, announcements, and billing records for what we invoiced you and what you told us you paid.
- Business records inside a customer's system. This is the operational data a business enters or generates: people records and their contact details, schedules, attendance and check-ins, jobs and orders, assignments and results, notes staff write, invoices and payment status, messages and drafts, uploaded files, documents, photos, and video.
- Connected-account data. Where a business connects an outside account, we hold the access credentials that account issues to us and the data the connection is for. See Connected accounts below.
- Usage and technical data, such as device, browser, IP address, server logs, and security events.
- Communications with us, including support requests, sales email, and service messages.
How we use information
We use information to provide, secure, support, and improve Lectern. We do not sell personal information, and we do not use any of it for targeted advertising.
- Run the website, the intake form, the client portal, and each customer's system.
- Create and manage accounts, roles, permissions, and which business a request belongs to.
- Run the workflows a business turned on: records, scheduling, attendance, orders, invoicing, reporting, publishing, and the rest of the feature set that business enabled.
- Prepare recurring work in advance and hold it for a person's approval, described below.
- Answer requests, provide support, send service messages, and manage the customer relationship.
- Monitor reliability, prevent abuse, debug problems, and protect against unauthorized access.
- Improve the product using aggregated or de-identified information. One business's records are never shown to another business, and they are never used to answer a question for another business.
Prepared work and the approval gate
Lectern prepares recurring work ahead of a person: a reply drafted, an invoice prepared, a report assembled, a risk flagged, each with the records it was drawn from attached to it. That preparation reads the business's own data and writes a proposal.
Anything addressed to someone outside the business waits for a person in that business to click. That is a rule of the product, not a setting, and it means no message reaches a customer, client, family, or patient because software decided to send it.
Once a person schedules something, such as a post to a connected account or a reminder at a set date, it goes at the time they chose without a second click. Scheduling is the approval.
Connected accounts
Some features work by connecting an account a business already has, such as a social account it publishes from. A connection is set up deliberately by someone at the business, through that provider's own consent screen, and it grants only what the feature needs.
Where a connection exists we hold the access and refresh credentials that provider issued, stored server-side and never sent to the browser, plus the content and results the feature is for. Disconnecting the account in Lectern stops our use of it; revoking access at the provider is always available to the business as well.
We do not connect anything on a customer's behalf, and no connection appears because of a release.
AI processing
Some features use AI providers to read, extract, classify, summarize, verify, or draft from a business's own materials: an uploaded document, a record history, a caption, a message draft. We use those providers to deliver the feature that was asked for, and for nothing else.
Lectern does not use customer data to train general-purpose AI models, and we require providers that process this data to handle it under commercial terms appropriate for service delivery rather than for model training.
Where an AI-assisted feature drafts a message, it drafts and stops. It does not send, and it does not do the professional work of the trade: it does not grade, tutor, diagnose, advise, or decide anything about a person in the records. It reads what happened and writes what it found.
Records about children
Lectern accounts are for a business and its staff. We do not sell to consumers through this site, and we do not knowingly collect personal information directly from a child.
Some businesses keep records about minors, such as a family's contact details or a young member's schedule and attendance. Those records are the business's, submitted by the business, and it is the business that is responsible for the notices, permissions, and consents its own law requires. Where a business is subject to a student-privacy or children's-privacy regime, we support those obligations through the customer agreement, access controls, data-use restrictions, and export or deletion help. Where a Lectern system gives sign-in access to people under 18, that access is granted by the business, and users under 13 are not given accounts unless a separate written agreement covers it.
Retention and deletion
We keep information only as long as it is needed for the purposes above: running the service, supporting customers, protecting security, meeting legal obligations, and keeping ordinary business records.
A customer's business records are retained according to the customer relationship and the applicable agreement. On request or on termination we can help export or delete them, subject to backups, security logs, and legal requirements.
Deletion removes our copy. A message that already went out cannot be recalled by deleting the record of it.
Security
We use administrative, technical, and organizational safeguards designed to protect information: access scoped to the business a request belongs to, role-based permissions, authentication through a managed provider, private storage for uploads, credentials kept server-side, and monitoring. The Trust page describes the posture in specific terms, including where a control is a convention in our code rather than something the database enforces.
No online service can promise perfect security. If we learn of a security incident affecting personal information, we will investigate and notify affected customers or users as required by law or contract.
Where information is handled
Lectern is operated from the United States, and our vendors process information there or in other countries where they run infrastructure. Using the service means information may be transferred to and handled in those countries under the protections described in this policy and in our agreements with those vendors.
Your choices and rights
You can contact us to ask for access, correction, deletion, or export of personal information. If the information belongs to a business's records rather than to your relationship with us, we will direct the request to that business or work with them to answer it.
Some privacy laws give additional rights depending on where you live and how Lectern is used. We will respond to applicable requests as required.
Changes
We update this policy as the product changes, and the date at the top is the date of the current version. If a change is material, we will give reasonable notice by posting the update, emailing customers, or another appropriate channel.
Contact
Questions about privacy or data handling can be sent to jake@lectern.systems.