Legal
Lyralog Privacy Policy
Effective date: effective date
Lyralog ("Lyralog", "the app", "we", "us") is a personal life-logging app for iOS and Android. It is provided by operator name, operator address, which is the data controller for the personal data described here.
What you log about your life is some of the most personal data there is. This policy explains exactly what we collect, what we do with it, who else touches it, and how to take it with you or delete it. If anything here is unclear, write to lyralogai@gmail.com.
Summary
- We collect what you choose to log, plus the email address you sign in with. We don't collect your location, contacts, photos or advertising identifiers.
- We never sell your data, show you ads or track you across other apps or websites.
- AI processing runs under Zero Data Retention. To extract metrics, answer your questions and build charts, your entries are sent to OpenAI under a contract that forbids storing them or using them to train models.
- Voice entry stays on your phone. When you speak an entry, your iPhone turns the speech into text itself. The audio is never recorded, stored or sent anywhere; only the text you choose to save reaches us, just like a typed entry.
- Biometrics stay on your phone. Face ID, Touch ID and fingerprint checks are done by your device's operating system. The app only learns "unlocked" or "not unlocked".
- Your data is yours. Export everything as JSON or CSV at any time, and delete your account and all your entries from inside the app.
1. What we collect
1.1 Data you give us
| Data | Examples | Why |
|---|---|---|
| Account details | Email address; password (stored only as a one-way hash by our authentication provider); optionally, a name or nickname you give us | To create your account and sign you in, by password or by a one-time email link. The name is only for the app to greet you ("Good morning, Priya"); without one, the app uses the part of your email before the @. You can change it in Settings. It's stored with your account, not your entries, and isn't sent to our AI provider. |
| Log entries | The text you write or speak, such as "Slept 7h, mood 6, spent $42 on groceries", and when it happened | To store and show your life log. This is the core of the service. |
| Questions and chart requests | "How did I sleep in March?", "Chart my spending by week", typed or spoken to Lyra, the in-app assistant | To answer them. Not stored: processed once and discarded. |
| Feedback reports (optional) | A report's title and description; if you allow it, the app version, platform and OS version; your email only if you turn on You can contact me about this | To fix bugs and plan features. Stored in our database for the team to review. Anonymous by default: without that switch, a report isn't linked to your account and we can't reply to you about it. An automated AI check compares each report's title and description with earlier reports to spot duplicates (OpenAI, under Zero Data Retention; never your email). |
Entries can contain sensitive information if you choose to write it: health, mood, sleep, fitness, finances, relationships. We treat everything you log as sensitive and use it only to provide the app to you.
1.2 Data we derive from your entries
When an entry reaches our server, we automatically derive:
- Structured metadata: a tracker type, a category, tags, metrics such as mood (1–10), hours slept or an amount spent, a short summary, and any suggested follow-up date.
- An embedding: a list of numbers representing the entry's meaning. It lets the app find entries relevant to your questions. It is stored with the entry and never shown to anyone or included in exports.
1.3 Data collected automatically
| Data | Details |
|---|---|
| Sign-in and security events | Our authentication provider records sign-ins, sign-outs and token refreshes, with IP address, device or browser type, and time. They're used to protect your account and investigate abuse. |
| Server request logs | Which API endpoint was called, the response code and how long it took. No entry text, questions, answers or tokens. |
| AI usage counts | Per account, per day: how many AI requests were made (entries processed, questions, charts) and how many tokens they used, with an estimated cost. Counts only, never what was asked or logged. Used to control costs and spot abuse. |
| Crash reports | If the app or server crashes: the error type, a stack trace, app and OS version, and device model. Your entries, questions, account ID, email, device name and IP address are removed before a report is stored. |
1.4 Data that stays on your device
This data is on your phone only. We never receive it:
| Data | Where | Details |
|---|---|---|
| Sign-in session | iOS Keychain / Android Keystore-encrypted storage | Access and refresh tokens. Bound to this device, excluded from backups, and removed when you sign out. |
| Entries not yet synced | App database on the device | Entries saved while offline. Each is deleted from the device once our server confirms it. Sign-out deletes any left over. |
| Voice audio (iPhone) | Your phone's own speech recognition, on the device | Used only to turn your speech into text while you're speaking, for entries and for questions to Lyra. The microphone is on only after you tap the mic; there's no always-listening "Hey Lyra". Lyra's spoken replies use your phone's built-in voice, so their text isn't sent to any voice service. It is never recorded or stored, and never leaves your phone: Lyralog doesn't allow Apple's server-based recognition, so voice entry isn't offered on devices that can't recognize speech on-device. |
| Biometric lock setting | Keychain / Keystore | Whether you turned on Face ID, Touch ID or fingerprint unlock |
| Preferences | App storage on the device | Theme (light/dark), whether you've seen onboarding, whether voice entries save automatically, whether Lyra reads her replies aloud |
1.5 What we don't collect
Precise or approximate location, contacts, photos, calendars, browsing history, advertising identifiers, voice recordings, or your biometric data. We also don't use cookies or third-party analytics SDKs in the app.
2. How AI processing works (Zero Data Retention)
Lyralog uses OpenAI's API for three things:
| Feature | What is sent to OpenAI | What comes back |
|---|---|---|
| Extraction, when an entry syncs | That one entry's text, and the names of trackers you already use | Structured metadata (§1.2) and an embedding |
| Questions | Your question, plus up to 8 of your entries most relevant to it | An answer based only on those entries |
| Charts | Your chart request | A chart specification. Our server then runs the query on your data itself; your entries aren't sent. |
What protects this data:
- Zero Data Retention (ZDR). Our OpenAI account is covered by a Zero Data Retention agreement. OpenAI processes the request and doesn't store the inputs or outputs, including for abuse monitoring. It never uses them to train or improve models. We also switch off response storage (
store=false) on every request. - No identity sent. We never send your email, name, account ID, IP address or device information to OpenAI. Each request contains only the text needed for that task.
- Only your data. Answers are limited to your own retrieved entries. If they don't contain the answer, the app says "I don't have any logged entries regarding that." It does not guess or use outside knowledge.
- Automated processing only. Our staff don't read your entries to provide these features. AI output can be wrong; see the Terms of Service.
We will not send your data to any other AI provider without a similar zero-retention contract, and we will update this policy first.
3. How we protect your data
- Encryption in transit. All traffic between the app, our server, our database and our providers uses HTTPS/TLS.
- Encryption at rest. Our database provider encrypts stored data and backups.
- Isolation between users. Every request is tied to your verified sign-in. Our database enforces row-level security, so a request made for you can only ever see your rows, even if our application code had a bug. The database's public web API has no access to your entries.
- Least privilege. Neither the app nor our server uses the database provider's all-access "service role" key.
- No content in logs or crash reports. Our logs and crash reports are filtered to exclude entry text, questions, answers and tokens (§1.3).
- Limited staff access. Our internal admin tools show account details (email, sign-up and last sign-in dates), counts (how many entries, AI usage) and service health. They can't show what you wrote: entry text, extracted details and embeddings aren't available in them. Only a small number of administrators can sign in, with multiple checks, and every administrative action on an account (such as suspending it) is logged.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires. To report a vulnerability, see our Security Policy.
4. Biometric unlock and on-device security
Biometric unlock is optional (Settings → Security). When it's on, the app asks for Face ID, Touch ID or your fingerprint each time you open it or return to it.
- We never receive your biometric data. The check is done entirely by your phone's operating system and its secure hardware (Apple's Secure Enclave, Android's trusted execution environment), using the fingerprint or face you enrolled in your phone's settings. The app is told only whether the check succeeded. It never sees, stores or transmits a fingerprint, a face image or a template.
- Passcode fallback. If biometrics fail or aren't available, you can use your device passcode, so you're never locked out of your own data.
- On Android, only "strong" (Class 3) biometrics are accepted.
- What the lock does, and doesn't do. The lock hides the app's content from someone holding your unlocked phone. Your sign-in tokens are protected separately, by the iOS Keychain or Android Keystore (§1.4), whether or not the lock is on.
- Entries not yet synced are stored in the app's private storage. They're protected by your phone's built-in encryption, which requires your passcode after a restart. On Android they're excluded from device backups. On iPhone, until they sync, they may be included in your iCloud backup.
Signing out deletes your session tokens and any unsynced entries for your account from that device.
5. Why we use your data (legal bases)
We use your data only to provide and secure Lyralog. We do not use it for advertising, profiling for marketing, or selling to anyone.
If you are in the European Economic Area, the UK or Switzerland, our legal bases are:
| Purpose | Legal basis |
|---|---|
| Creating your account, storing and syncing entries, extraction, answering questions, charts, export | Performance of our contract with you (GDPR Art. 6(1)(b)) |
| Health-related information you choose to log (mood, sleep, symptoms, fitness) | Your explicit consent (Art. 9(2)(a)), which you give by choosing to log such information. You can withdraw it at any time by deleting that data or your account. |
| Security: sign-in logs, abuse prevention, crash diagnostics | Our legitimate interest in keeping the service secure and working (Art. 6(1)(f)) |
| Keeping records the law requires, and answering lawful requests | Legal obligation (Art. 6(1)(c)) |
6. Who we share data with
We do not sell or share your personal information for advertising, as defined by the California Consumer Privacy Act (CCPA/CPRA) or any similar law. We don't give it to data brokers.
We use these service providers ("processors") to run Lyralog. They may process your data only on our instructions and under contracts that protect it:
| Provider | Role | Data | Location |
|---|---|---|---|
| Supabase | Authentication and database hosting | Account details, entries, derived metadata, sign-in logs, backups | data region |
| Render | Hosts our API server | Data passing through the API; request logs (§1.3) | United States |
| OpenAI | AI extraction, embeddings, answers, chart specs, under Zero Data Retention | The request contents described in §2 | United States |
| Sentry | Crash and error reporting | Scrubbed crash reports (§1.3) | United States |
| Discord and/or GitHub | Only if our team chooses to forward a feedback report there, to track the work | The report's title, description and device info, never your account ID or email | United States |
| Apple / Google | App distribution, and biometric checks on your device | Nothing from Lyralog. Their own policies cover the App Store and Google Play. | — |
We may also disclose data:
- if required by law, a court order or a valid government request (we will tell you unless we're legally prohibited)
- to protect someone's safety, or the security of the service
- to a successor if Lyralog is merged or acquired, under this policy's protections, with notice to you first
International transfers
Some providers process data in the United States. Where the law requires it, transfers from the EEA, UK or Switzerland rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), or on the provider's certification under the EU-U.S. Data Privacy Framework.
7. Your rights and controls
7.1 Export your data (portability)
In the app: Settings → Data & Privacy → Export My Data, then choose:
- JSON: machine-readable, with every entry and its extracted metadata
- CSV: opens in Excel, Numbers or Google Sheets
The export includes every entry you've logged, including ones not yet synced (marked not_synced), with its text, date and time, tracker type, category, tags, metrics, summary and follow-up date. Embeddings are internal and not included. The file is created on your phone, and you choose where to save or share it using your phone's share sheet.
7.2 Delete your account and data
In the app: Settings → Account → Delete Account, then confirm twice.
Without the app: email lyralogai@gmail.com from the address you signed up with, with the subject "Delete my account", or follow the instructions at https://lyralog.app/delete-account. We will confirm the request by email before deleting, so nobody else can delete your account.
Deletion:
- Immediately and permanently removes your account, every entry, and all derived metadata and embeddings from our live database. It can't be undone. Export first if you want a copy.
- Clears your session and unsynced entries on the device you delete from. Signing out, or uninstalling the app, clears other devices.
- Backups containing your data are overwritten on a rolling schedule and are gone within backup retention days days. Until then they are encrypted, access-restricted, and used only for disaster recovery. If we ever restore one, we delete your data again.
- Logs and crash reports aren't linked to your account and expire on their own schedule (§8).
- Feedback reports aren't linked to your account (unless you chose to include your email), so deleting your account doesn't find them. To have one deleted, email us the report ID the app showed you when you sent it.
7.3 Your other rights
Depending on where you live, you may have the right to:
- access a copy of your data (the export covers your entries; email us for anything else, such as sign-in history)
- correct inaccurate data: on the Log tab, delete an entry from the last 7 days and log it again (it keeps its original date). For older entries, email us.
- delete it: a single entry from the Log tab (right after saving with Undo, or from the last 7 days), or your whole account (§7.2). Deleting an entry removes its text, extracted details and embedding from our live database immediately; backups age out as described in §7.2.
- restrict or object to processing, including processing based on legitimate interests
- withdraw consent at any time, without affecting processing before withdrawal
- not be discriminated against for exercising these rights (California)
- complain to your local data protection authority. We'd appreciate the chance to fix it first.
To exercise any right, email lyralogai@gmail.com. We'll reply within one month (GDPR/UK GDPR) or 45 days (CCPA), and may ask you to confirm the request from your account's email address. You can use an authorized agent where the law allows.
We don't make decisions about you that have legal or similarly significant effects based solely on automated processing.
8. How long we keep data
| Data | Kept |
|---|---|
| Account details, entries, derived metadata, embeddings | Until you delete your account (§7.2). If you have no other way to reach us, deleting the app does not delete your account. |
| Questions and chart requests | Not stored. Discarded once answered. |
| AI usage counts | Until you delete your account |
| Database backups | Up to backup retention days days |
| Sign-in and security logs, server request logs | Up to log retention days days |
| Crash reports | Up to 90 days |
| Feedback reports | Until the issue is resolved and no longer needed |
| On-device data | Until it syncs, you sign out, or you uninstall the app (§1.4) |
9. Children
Lyralog is not intended for anyone under 16, and we don't knowingly collect data from them. If you believe a child has created an account, email lyralogai@gmail.com and we'll delete it.
10. Changes to this policy
We'll update the effective date above whenever this policy changes. For material changes, such as a new kind of data or a new provider that receives your entries, we'll tell you in the app before the change takes effect. You can then export or delete your data if you don't agree. Earlier versions are available on request.
11. Contact
operator name
operator address
Privacy and data requests: lyralogai@gmail.com
Security vulnerabilities: see SECURITY_POLICY.md