{
  "slug": "lucidchart",
  "category": "diagrams",
  "name": "Lucidchart",
  "description": "A web-based diagramming app from Lucid Software for flowcharts, org charts, network and architecture diagrams, with real-time collaboration, data linking and AI features.",
  "website": "https://lucid.co/lucidchart",
  "license": null,
  "platforms": [
    "web",
    "android",
    "ios"
  ],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "F",
  "score": 38,
  "coverage": 100,
  "summary": "Lucidchart scores 38 out of 100 (grade F) on the diagrams and whiteboards criteria. It meets 2 of 8 criteria: tells users about requests and TLS configuration. It partly meets no ads or data sales, independent audit and transparency report. It does not meet open source, no trackers or telemetry and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C.",
  "url": "https://privacyratings.com/diagrams/lucidchart/",
  "markdown": "https://privacyratings.com/diagrams/lucidchart/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://lucid.co/cookies",
      "note": "The website loads Google Tag Manager and Microsoft Clarity, and the cookie policy lists Google Analytics, Google Ads, LinkedIn, Meta and other analytics and marketing cookies."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://lucid.co/cookies",
      "note": "Sold by subscription with a free plan, but the cookie policy lists Google Ads, LinkedIn, Meta and other marketing cookies used to advertise its own products."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://trust.lucid.co/",
      "note": "Lists SOC 2 Type II, ISO 27001, ISO 27701 and FedRAMP Moderate audits, with reports provided through its trust center rather than published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://trust.lucid.co/",
      "note": "The trust center states that customer data is provided to governments only with a legal basis such as a subpoena, but no counts of requests are published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://trust.lucid.co/",
      "note": "The trust center states that Lucid notifies the customer before responding to a subpoena or other legal request, to the extent legally permitted."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=lucid.app&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=lucid.app",
      "note": "Grade C (50/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "C",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": null,
    "tested_at": "2026-10-01T07:25:52.061Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}