Privacy Policy
Last updated: July 9, 2026
Privacy at a glance
A short guide to the main points. The full policy below is the official, up-to-date source of truth.
It is tied to your account and may be cached locally for smoother use.
Lightli is UK-based, while Firebase/Google Cloud hosts the main app data.
Firebase uses HTTPS/TLS and encryption at rest; app content is not E2E encrypted.
As a one-person company, founder access is limited to support, maintenance, security, or legal needs.
Cycle and Journalmi can include sensitive details you choose to add.
Signed-in users can request export or delete their account and data in-app.
Analytics and diagnostics help improve reliability and investigate issues while avoiding app content.
Lightli does not sell personal data or use app-created content for advertising.
Privacy Introduction
This Privacy Policy explains how Lightli LTD ("Lightli", "we", "us", or "our") handles personal data when you use our apps, website, subscriptions, support, and related services.
Lightli apps are account-based, cloud-backed apps. App data syncs with Firebase and may be cached on your device so features work smoothly. Firebase uses HTTPS/TLS in transit and Google-managed encryption at rest, but app content is not end-to-end encrypted or zero-knowledge.
We collect data to run the apps, sync and back up your content, manage accounts and purchases, improve reliability, fix bugs, keep services secure, and respond to support requests. We do not sell personal data or use app-created content for advertising.
Who Controls Your Data
Lightli LTD is the data controller for personal data processed through Lightli services, unless this policy says otherwise. Lightli is currently an independent one-person company, so privacy and support requests are handled directly by the founder unless a trusted provider or future contractor is needed.
Lightli has not appointed a separate Data Protection Officer. You can contact us about privacy matters at hello@lightli.uk.
What Data We Collect
The data we collect depends on the app and features you use. It may include:
- Account Data
- Email address, sign-in identifier, and name or display name where provided through Google Sign-In or Apple Sign-In.
- App Content
- Entries, lists, habits, cycle records, workouts, settings, images, and other content you choose to create or sync.
- Purchase Status
- Subscription and one-time purchase entitlement information from Apple, Google, and RevenueCat. Lightli does not store full payment card details.
- Usage and Diagnostics
- Device, browser, app version, crash, performance, event, and technical data used to keep services working and improve quality while avoiding your app content.
- Support Information
- Messages and details you send when contacting Lightli.
Google, Apple, Firebase, RevenueCat, and app stores may process data under their own terms and privacy notices when you use their services.
App-Specific Data
Lightli apps collect the content and settings needed to provide the features you choose to use:
- Journalmi: journal entries, modules, timestamps, tags, moods, uploaded images, and related settings.
- Cycle: period dates, pregnancy tracking dates, symptoms, fertility data, predictions, and related health observations.
- Routino: habits, routines, schedules, completion history, icons, colours, and timer or reminder settings.
- Quitly: quit timers, start dates, habit or substance names, milestones, timer history, and preferences.
- Listly: note titles, note content, lists, tasks, list items, and organisation settings.
- Gymly: exercises, workout plans, templates, set and rep data, rest times, completion history, body weight logs, and measurements.
Health Information
Cycle processes menstrual, pregnancy, symptom, fertility, and related health data. Journalmi and Gymly may also contain health information if you choose to add it. This can be special category data under UK GDPR.
We process health-related app data to provide the features you request, such as cycle tracking, journaling, workout tracking, predictions, and personal records. Where UK GDPR requires an Article 9 condition, we rely on your explicit consent. You can delete your account and data, and you can withdraw consent, although this may limit or disable features that need health data.
Medical disclaimer: Lightli apps are not medical devices and should not be used for medical diagnosis, treatment, or emergency decisions. Please speak to a qualified healthcare professional for medical advice.
How We Use Data and Legal Bases
We use personal data only where we have a lawful basis to do so. The main purposes are:
- Provide the apps: authentication, sync, storage, backup, account features, premium access, and support. This is mainly contract performance.
- Handle purchases: subscription and one-time purchase entitlement checks through the App Store, Google Play, and RevenueCat. This is mainly contract performance and legal obligation.
- Protect and improve Lightli: analytics, diagnostics, crash reporting, fraud prevention, abuse prevention, security, and troubleshooting. This is mainly legitimate interests, with consent where required.
- Health-related features: cycle, pregnancy, symptom, journal, workout, and body measurement features you choose to use. This is contract performance and, where required, explicit consent for special category data.
- Legal and admin needs: accounting, compliance, responding to lawful requests, enforcing terms, and protecting rights and safety. This is mainly legal obligation or legitimate interests.
- Optional marketing: only where we have a lawful basis, such as consent where required. You can opt out at any time.
Storage, Security, and Access
Your main app data is stored using Firebase and Google Cloud, currently with primary storage in the United States. Uploaded images, such as Journalmi images, are stored in Firebase Storage. Some service, support, analytics, or security data may also be processed in the United Kingdom, the United States, or other countries where our providers operate.
- In transit: data sent between your device and our services is encrypted using HTTPS/TLS.
- At rest: stored data is protected by Google-managed encryption at rest.
- Authentication: account access uses Firebase Authentication, Google Sign-In, Apple Sign-In, and related provider controls.
- Database rules: Firebase security rules and authentication requirements are used to protect user data.
- Admin access: as a one-person company, the founder may access data only when needed for support, security, maintenance, legal obligations, or abuse prevention.
No online service can guarantee absolute security. If Lightli works with future contractors or support providers, access will be limited to what they need for their role and subject to confidentiality and data protection obligations.
Sharing and Service Providers
We do not sell your personal data. We share personal data only where needed to operate Lightli, comply with law, or protect the service:
- Infrastructure and analytics: Google Cloud Platform, Firebase, Google Analytics, and Google Tag Manager.
- Sign-in providers: Google and Apple, when you choose those sign-in methods.
- App stores and entitlements: Apple App Store and Google Play for app distribution, billing, cancellation, and refunds; RevenueCat for subscriptions, one-time purchase entitlements, and purchase status.
- Support and future contractors: only where needed to help operate, support, secure, or improve Lightli.
- Legal, safety, and business reasons: where required by law, to respond to lawful requests, prevent abuse, protect rights and safety, enforce terms, or handle a business transfer.
- With your consent: where you ask us or agree to share data for another purpose.
International Transfers
Lightli is based in the United Kingdom, while the main Firebase-backed app infrastructure currently stores data primarily in the United States. Our providers may also process personal data in other countries.
Where UK GDPR requires safeguards for international transfers, we rely on appropriate mechanisms such as adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where applicable, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses, Standard Contractual Clauses, and technical and organisational protections.
Retention, Export, and Deletion
We keep personal data only for as long as reasonably needed for the purposes in this policy, including to provide the apps, comply with law, resolve disputes, maintain security, and enforce our terms.
- Account data and app content: kept until you delete your account or request deletion, subject to limited legal, security, and backup needs.
- Anonymous guest accounts: automatically deleted 30 days from creation.
- Analytics and diagnostics: kept according to provider settings and generally for shorter periods than account content.
- Support messages: normally kept for up to 3 years from last contact.
- Legal, tax, or compliance records: kept where required or permitted by law, often up to 6 years.
Signed-in users can request a JSON data export in-app from Settings and can delete their account and data from within the app. Export should be requested before account deletion because deletion removes active account data.
Self-service export is designed to include your account profile, app-created content, app settings, and user-readable file metadata where available. It does not include authentication secrets, payment provider secrets, internal support notes, raw diagnostics, analytics, product telemetry, security logs, raw database paths, backend bucket names, backend object paths, or records we are allowed to withhold for security, legal, or third-party privacy reasons.
When you delete your account, active account data is deleted or anonymised. Residual copies may remain in backups for a limited period until overwritten or deleted according to backup cycles, unless retention is required by law.
Your Rights Under UK GDPR
Under UK GDPR and the Data Protection Act 2018, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal data. You may also withdraw consent where we rely on consent, and you can complain to the UK Information Commissioner's Office (ICO).
Some rights are not absolute, and we may need to verify your identity before acting on a request. To exercise your rights, email hello@lightli.uk or use the in-app account settings where available. We will respond within one month unless UK GDPR allows more time for complex or multiple requests.
Analytics, Cookies, and Diagnostics
Lightli uses analytics and diagnostics to keep the apps working, improve quality, and investigate issues while avoiding your app content. This may include Google Analytics, Google Tag Manager, Firebase Analytics, crash reports, and similar technical tools.
On the website, essential cookies or similar technologies may be needed for basic operation. Optional Google Analytics and Google Tag Manager cookies or similar technologies are used only after you accept analytics. They help us understand page views, link clicks, approximate location (not GPS), device/browser details, traffic sources, site performance, and which apps are popular in different countries. They do not include your app content, and Lightli does not sell this data. You can change your choice using the Cookies button on the site, and you can also opt out of Google Analytics with the Google Analytics Opt-out Browser Add-on.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Children's Privacy
Lightli services are not directed at children under 13. If you are under 13, you should use Lightli only with consent and supervision from a parent or guardian. If you are under the age of majority where you live, your parent or guardian should review this policy and our Terms with you.
If you are a parent or guardian and believe a child has provided personal data without appropriate consent, contact hello@lightli.uk so we can take appropriate action.
Links to Other Websites
Lightli may link to websites or services we do not operate, such as app stores or provider pages. Their terms and privacy notices apply to their services.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Changes are effective when posted on this page unless a later date is stated. Where required, we will provide additional notice for material changes.
Contact Us
If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about your data, please contact us:
- Email: hello@lightli.uk
- Company: Lightli LTD
- Country: United Kingdom
Supervisory Authority
If you have concerns about how we handle your data and wish to lodge a complaint, you can contact the UK Information Commissioner's Office (ICO).
- UK Information Commissioner's Office (ICO)
- Website: https://ico.org.uk
- Helpline: 0303 123 1113