Privacy at a glance

A short guide to the main points. The full policy below is the official, up-to-date source of truth.

Account sync Your app data syncs with Firebase

It is tied to your account and may be cached locally for smoother use.

Location Stored primarily in the US

Lightli is UK-based, while Firebase/Google Cloud hosts the main app data.

Security Encrypted, but not end-to-end

Firebase uses HTTPS/TLS and encryption at rest; app content is not E2E encrypted.

Access Admin access is limited

As a one-person company, founder access is limited to support, maintenance, security, or legal needs.

Sensitive data Some apps may hold health data

Cycle and Journalmi can include sensitive details you choose to add.

Your choices Export and deletion are available

Signed-in users can request export or delete their account and data in-app.

Analytics Used for app health

Analytics and diagnostics help improve reliability and investigate issues while avoiding app content.

No selling Your personal data is not sold

Lightli does not sell personal data or use app-created content for advertising.

Privacy Introduction

This Privacy Policy explains how Lightli LTD ("Lightli", "we", "us", or "our") handles personal data when you use our apps, website, subscriptions, support, and related services.

Lightli apps are account-based, cloud-backed apps. App data syncs with Firebase and may be cached on your device so features work smoothly. Firebase uses HTTPS/TLS in transit and Google-managed encryption at rest, but app content is not end-to-end encrypted or zero-knowledge.

We collect data to run the apps, sync and back up your content, manage accounts and purchases, improve reliability, fix bugs, keep services secure, and respond to support requests. We do not sell personal data or use app-created content for advertising.

Who Controls Your Data

Lightli LTD is the data controller for personal data processed through Lightli services, unless this policy says otherwise. Lightli is currently an independent one-person company, so privacy and support requests are handled directly by the founder unless a trusted provider or future contractor is needed.

Lightli has not appointed a separate Data Protection Officer. You can contact us about privacy matters at hello@lightli.uk.

What Data We Collect

The data we collect depends on the app and features you use. It may include:

Google, Apple, Firebase, RevenueCat, and app stores may process data under their own terms and privacy notices when you use their services.

App-Specific Data

Lightli apps collect the content and settings needed to provide the features you choose to use:

Health Information

Cycle processes menstrual, pregnancy, symptom, fertility, and related health data. Journalmi and Gymly may also contain health information if you choose to add it. This can be special category data under UK GDPR.

We process health-related app data to provide the features you request, such as cycle tracking, journaling, workout tracking, predictions, and personal records. Where UK GDPR requires an Article 9 condition, we rely on your explicit consent. You can delete your account and data, and you can withdraw consent, although this may limit or disable features that need health data.

Medical disclaimer: Lightli apps are not medical devices and should not be used for medical diagnosis, treatment, or emergency decisions. Please speak to a qualified healthcare professional for medical advice.

How We Use Data and Legal Bases

We use personal data only where we have a lawful basis to do so. The main purposes are:

Storage, Security, and Access

Your main app data is stored using Firebase and Google Cloud, currently with primary storage in the United States. Uploaded images, such as Journalmi images, are stored in Firebase Storage. Some service, support, analytics, or security data may also be processed in the United Kingdom, the United States, or other countries where our providers operate.

No online service can guarantee absolute security. If Lightli works with future contractors or support providers, access will be limited to what they need for their role and subject to confidentiality and data protection obligations.

Sharing and Service Providers

We do not sell your personal data. We share personal data only where needed to operate Lightli, comply with law, or protect the service:

International Transfers

Lightli is based in the United Kingdom, while the main Firebase-backed app infrastructure currently stores data primarily in the United States. Our providers may also process personal data in other countries.

Where UK GDPR requires safeguards for international transfers, we rely on appropriate mechanisms such as adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses, Standard Contractual Clauses, and technical and organisational protections.

Retention, Export, and Deletion

We keep personal data only for as long as reasonably needed for the purposes in this policy, including to provide the apps, comply with law, resolve disputes, maintain security, and enforce our terms.

Signed-in users can request a JSON data export in-app from Settings and can delete their account and data from within the app. Export should be requested before account deletion because deletion removes active account data.

Self-service export is designed to include your account profile, app-created content, app settings, and user-readable file metadata where available. It does not include authentication secrets, payment provider secrets, internal support notes, raw diagnostics, analytics, product telemetry, security logs, raw database paths, backend bucket names, backend object paths, or records we are allowed to withhold for security, legal, or third-party privacy reasons.

When you delete your account, active account data is deleted or anonymised. Residual copies may remain in backups for a limited period until overwritten or deleted according to backup cycles, unless retention is required by law.

Your Rights Under UK GDPR

Under UK GDPR and the Data Protection Act 2018, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal data. You may also withdraw consent where we rely on consent, and you can complain to the UK Information Commissioner's Office (ICO).

Some rights are not absolute, and we may need to verify your identity before acting on a request. To exercise your rights, email hello@lightli.uk or use the in-app account settings where available. We will respond within one month unless UK GDPR allows more time for complex or multiple requests.

Analytics, Cookies, and Diagnostics

Lightli uses analytics and diagnostics to keep the apps working, improve quality, and investigate issues while avoiding your app content. This may include Google Analytics, Google Tag Manager, Firebase Analytics, crash reports, and similar technical tools.

On the website, essential cookies or similar technologies may be needed for basic operation. Optional Google Analytics and Google Tag Manager cookies or similar technologies are used only after you accept analytics. They help us understand page views, link clicks, approximate location (not GPS), device/browser details, traffic sources, site performance, and which apps are popular in different countries. They do not include your app content, and Lightli does not sell this data. You can change your choice using the Cookies button on the site, and you can also opt out of Google Analytics with the Google Analytics Opt-out Browser Add-on.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Children's Privacy

Lightli services are not directed at children under 13. If you are under 13, you should use Lightli only with consent and supervision from a parent or guardian. If you are under the age of majority where you live, your parent or guardian should review this policy and our Terms with you.

If you are a parent or guardian and believe a child has provided personal data without appropriate consent, contact hello@lightli.uk so we can take appropriate action.

Lightli may link to websites or services we do not operate, such as app stores or provider pages. Their terms and privacy notices apply to their services.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Changes are effective when posted on this page unless a later date is stated. Where required, we will provide additional notice for material changes.

Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about your data, please contact us:

Supervisory Authority

If you have concerns about how we handle your data and wish to lodge a complaint, you can contact the UK Information Commissioner's Office (ICO).