Skip to content

Privacy

Privacy Policy

How Lectern handles information across the public website, the intake form, the client portal, and the system we run for a business.

Last updated: August 21, 2026

Scope

This Privacy Policy explains how Lectern collects, uses, shares, and protects information when you use lectern.systems, our intake form, the client portal, and the Lectern system we build and run for a customer at its own address on lectern.systems.

Lectern is business software. It is bought by the owner of a small service business and used by that business's staff, and the records inside it are that business's records. Lectern Solo, at solo.lectern.systems, is a separate product with its own policy on that surface.

Whose information this covers

Three different groups of people show up in this policy, and the rules are not the same for each.

  • Visitors and prospective customers. These are people reading the public site or sending us an intake note, and we decide how that information is handled.
  • Customers and their staff. These are the people who sign in to a Lectern system or the client portal, and we handle their account information to run the service.
  • The people a customer keeps records about: its customers, clients, members, families, patients, students, applicants, and staff. Those records belong to the business. We process them on that business's instructions to provide the service, and this policy describes how. If you are one of those people and you want a record changed or removed, the business that holds it is the right place to start, and we will help them do it.

Information we collect

We collect what is needed to run the website, evaluate prospective customers, provide each customer's system, and protect the service.

  • Contact and account information, such as names, email addresses, roles, business name, and sign-in credentials handled through our authentication provider.
  • Intake information, which is what you tell us on the intake form: your name, your email, your business name, what kind of business you run, and whatever you write about how things work today.
  • Portal records, such as deliveries and approvals, support tickets, messages and their attachments, requests, announcements, and billing records for what we invoiced you and what you told us you paid.
  • Business records inside a customer's system. This is the operational data a business enters or generates: people records and their contact details, schedules, attendance and check-ins, jobs and orders, assignments and results, notes staff write, invoices and payment status, messages and drafts, uploaded files, documents, photos, and video.
  • Connected-account data. Where a business connects an outside account, we hold the access credentials that account issues to us and the data the connection is for. See Connected accounts below.
  • Usage and technical data, such as device, browser, IP address, server logs, and security events.
  • Communications with us, including support requests, sales email, and service messages.

Cookies and tracking

Cookies on our signed-in surfaces keep you logged in and keep the session secure. There are no advertising cookies, no cross-site tracking, no ad networks, and no analytics running on the public website.

The public intake form uses a bot check from Cloudflare, which reads request and device signals to tell a person from a script.

How we use information

We use information to provide, secure, support, and improve Lectern. We do not sell personal information, and we do not use any of it for targeted advertising.

  • Run the website, the intake form, the client portal, and each customer's system.
  • Create and manage accounts, roles, permissions, and which business a request belongs to.
  • Run the workflows a business turned on: records, scheduling, attendance, orders, invoicing, reporting, publishing, and the rest of the feature set that business enabled.
  • Prepare recurring work in advance and hold it for a person's approval, described below.
  • Answer requests, provide support, send service messages, and manage the customer relationship.
  • Monitor reliability, prevent abuse, debug problems, and protect against unauthorized access.
  • Improve the product using aggregated or de-identified information. One business's records are never shown to another business, and they are never used to answer a question for another business.

Prepared work and the approval gate

Lectern prepares recurring work ahead of a person: a reply drafted, an invoice prepared, a report assembled, a risk flagged, each with the records it was drawn from attached to it. That preparation reads the business's own data and writes a proposal.

Anything addressed to someone outside the business waits for a person in that business to click. That is a rule of the product, not a setting, and it means no message reaches a customer, client, family, or patient because software decided to send it.

Once a person schedules something, such as a post to a connected account or a reminder at a set date, it goes at the time they chose without a second click. Scheduling is the approval.

Connected accounts

Some features work by connecting an account a business already has, such as a social account it publishes from. A connection is set up deliberately by someone at the business, through that provider's own consent screen, and it grants only what the feature needs.

Where a connection exists we hold the access and refresh credentials that provider issued, stored server-side and never sent to the browser, plus the content and results the feature is for. Disconnecting the account in Lectern stops our use of it; revoking access at the provider is always available to the business as well.

We do not connect anything on a customer's behalf, and no connection appears because of a release.

AI processing

Some features use AI providers to read, extract, classify, summarize, verify, or draft from a business's own materials: an uploaded document, a record history, a caption, a message draft. We use those providers to deliver the feature that was asked for, and for nothing else.

Lectern does not use customer data to train general-purpose AI models, and we require providers that process this data to handle it under commercial terms appropriate for service delivery rather than for model training.

Where an AI-assisted feature drafts a message, it drafts and stops. It does not send, and it does not do the professional work of the trade: it does not grade, tutor, diagnose, advise, or decide anything about a person in the records. It reads what happened and writes what it found.

Records about children

Lectern accounts are for a business and its staff. We do not sell to consumers through this site, and we do not knowingly collect personal information directly from a child.

Some businesses keep records about minors, such as a family's contact details or a young member's schedule and attendance. Those records are the business's, submitted by the business, and it is the business that is responsible for the notices, permissions, and consents its own law requires. Where a business is subject to a student-privacy or children's-privacy regime, we support those obligations through the customer agreement, access controls, data-use restrictions, and export or deletion help. Where a Lectern system gives sign-in access to people under 18, that access is granted by the business, and users under 13 are not given accounts unless a separate written agreement covers it.

Sharing and subprocessors

We share information with vendors that help us provide the service, and only for the purposes described here or in a customer agreement. The Trust page lists the current subprocessors, what each is for, and what data reaches it.

  • Infrastructure and service vendors for hosting, database, authentication, file storage, background jobs, email delivery, abuse prevention, rate limiting, AI processing, and publishing to a connected account.
  • The provider of a connected account, when a feature sends content there at the business's instruction.
  • Professional advisors, where needed for legal, accounting, security, or business operations.
  • Authorities or other parties, when required by law, to protect rights and safety, or to investigate abuse.
  • A successor entity, if Lectern is involved in a merger, acquisition, financing, or sale of assets.

Retention and deletion

We keep information only as long as it is needed for the purposes above: running the service, supporting customers, protecting security, meeting legal obligations, and keeping ordinary business records.

A customer's business records are retained according to the customer relationship and the applicable agreement. On request or on termination we can help export or delete them, subject to backups, security logs, and legal requirements.

Deletion removes our copy. A message that already went out cannot be recalled by deleting the record of it.

Security

We use administrative, technical, and organizational safeguards designed to protect information: access scoped to the business a request belongs to, role-based permissions, authentication through a managed provider, private storage for uploads, credentials kept server-side, and monitoring. The Trust page describes the posture in specific terms, including where a control is a convention in our code rather than something the database enforces.

No online service can promise perfect security. If we learn of a security incident affecting personal information, we will investigate and notify affected customers or users as required by law or contract.

Where information is handled

Lectern is operated from the United States, and our vendors process information there or in other countries where they run infrastructure. Using the service means information may be transferred to and handled in those countries under the protections described in this policy and in our agreements with those vendors.

Your choices and rights

You can contact us to ask for access, correction, deletion, or export of personal information. If the information belongs to a business's records rather than to your relationship with us, we will direct the request to that business or work with them to answer it.

Some privacy laws give additional rights depending on where you live and how Lectern is used. We will respond to applicable requests as required.

Changes

We update this policy as the product changes, and the date at the top is the date of the current version. If a change is material, we will give reasonable notice by posting the update, emailing customers, or another appropriate channel.

Contact

Questions about privacy or data handling can be sent to jake@lectern.systems.

Need a data-processing agreement, an addendum for the records your industry regulates, or a vendor review packet? Email jake@lectern.systems.