Privacy Policy: Lights On Me
Last updated: August 19, 2026
1. Who we are
The Lights On Me application (the "App") is operated as a sole proprietorship by:
[YOUR NAME] [YOUR FULL ADDRESS] 1XXX Geneva, Switzerland
Contact email: contact@lightsonme.app
The App is currently in private beta. It provides voice-based guidance for personal wellbeing exploration. Lights On Me is not a medical, psychological, or therapeutic service. It does not replace consultation with a qualified healthcare professional under any circumstances.
2. Data we collect
2.1 Account data
- Email address
- Password (hashed, never stored in plain text)
- Anonymous unique identifier
2.2 Profile data
- Free-text answers to onboarding questions (current situation, goal, main blocker)
- Optional answers from extended profile (what you've already tried, your inner voice style)
- Programme followed and progression day
2.3 Session data
- Text transcriptions of your voice recordings
- Duration of each session, word count
- Whether you listened to your feedback, whether you chose a follow-up question
- Emotional ratings you give to received feedbacks (😞 / 😐 / 😊)
2.4 Derived data (automatically generated by AI)
- Session summaries
- Weekly summaries (a qualitative look back at your week)
- Dynamic profile (synthesis of your journey, refreshed every 5 sessions)
- Sensitive content detection (keywords signaling distress, to offer support resources)
2.5 Technical data
- Error and crash reports (via Sentry, no personal data attached)
- App language
- Usage data: app open and close times and usage duration, product journey events (sign-up, onboarding, session start) and the search text you type (capped at 60 characters). Used to understand and improve usage; kept in your space and deleted with your account.
- AI usage logs: for each AI call, the model used, the number of tokens and the cost (never the content of your exchanges). Used for internal billing and abuse limiting.
2.6 Audio recordings
The recordings of your voice sessions (sessions, daily compass, free talk) are transmitted temporarily for transcription, then immediately deleted once the text is obtained: they are never retained.
Two optional features do, however, retain an audio file, because their value lies in hearing your own voice again: the voice letter you record to yourself at the start of a programme (revealed at the end of the programme) and the "savor a moment" clips. These files are stored with our hosting provider (Zurich region), protected by the same access controls as the rest of your data, never transcribed or analyzed, playable only by you, and deleted with your account (savoring clips are kept for 14 days for replay, then automatically deleted the next time the app is opened).
3. Why we use your data
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Operate your personalized guidance | Performance of contract |
| Remember your journey and adapt sessions | Performance of contract |
| Detect distress situations to offer support resources | Legitimate interest + protection of the person (art. 6); explicit consent to the processing of health data (art. 9(2)(a)) |
| Prevent abuse (rate limiting) | Legitimate interest |
| Improve the App via anonymized statistics | Legitimate interest |
| Contact you when needed (security, major updates) | Legitimate interest |
4. Service providers and international transfers
We use the following service providers to operate the App. Most act as processors under the GDPR, meaning they process data only on our behalf; where a provider processes certain data for its own purposes, its role is specified in the table. All provide adequate GDPR safeguards (Standard Contractual Clauses or European Commission adequacy decision):
| Service provider | Role | Data location | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database and storage (account, sessions, text transcriptions, retained audio files) | Zurich, Switzerland | Swiss FADP + GDPR |
| Anthropic PBC | Conversational AI (feedback generation) | United States | EU Standard Contractual Clauses |
| Deepgram Inc. | Temporary voice transcription | United States | EU Standard Contractual Clauses |
| Resend Inc. | Account email delivery (confirmation, password reset) | Sending from the EU (Ireland); company established in the United States | EU Standard Contractual Clauses |
| Sentry (Functional Software Inc.) | Technical bug reports (sending of user identifiers disabled) | Germany (EU region) | GDPR |
| Apple Inc. | App Store + TestFlight distribution | United States | EU Standard Contractual Clauses |
| Google LLC | Google Play distribution | United States | EU Standard Contractual Clauses |
| Cloudflare, Inc. | Anti-abuse protection and captcha verification (Turnstile) at sign-up and sign-in; hosting of the lightsonme.app website. Processor for these services; independent controller for certain processing aimed at improving its own detection mechanisms, in accordance with its privacy policy | United States; processing via a global network | EU Standard Contractual Clauses |
No data is sold to third parties for advertising purposes.
5. Data retention
| Data type | Duration |
|---|---|
| Account and session data | As long as your account is active |
| After account deletion | Immediate and permanent deletion (all account-linked tables are erased automatically at the time of the request) |
| Anonymized technical reports (Sentry) | 30 days maximum |
| Audio recordings of voice sessions | Not retained by Lights On Me after transcription. Deepgram processes the audio for the time needed for transcription |
| Retained audio files (start-of-programme voice letter, "savor a moment" clips) | Until your account is deleted; savoring clips are kept for 14 days for replay, then automatically deleted the next time the app is opened |
| Derived data (session summaries, weekly summaries, dynamic profile) | Linked to your account, same durations |
| Proof of consent to the Terms and this Privacy Policy | 10 years from acceptance, including after account deletion |
| Crisis detection safety log | Kept for 10 years from the detection, including after account deletion (ordinary limitation period under Swiss law, Article 127 of the Code of Obligations, same duration as the acceptance log above). Since 27 July 2026, no excerpt of what was said is recorded: only the record of the event is. Entries created before that date contain an excerpt of at most 200 characters, erased after 6 months. The entry contains the category, the language, your internal user ID, the session ID, the detection method, the usage mode, the date of the detection, and the flags and timestamps for the display of the support message and the emergency resources. Legal bases: Article 9(2)(a) GDPR (your explicit consent to the processing of health data, collected in the App before any analysis and withdrawable at any time) for the analysis itself; Article 6(1)(f) and Article 9(2)(f) GDPR (establishment, exercise or defence of legal claims) for keeping the log after consent withdrawal or account deletion. Article 17(3)(e) GDPR then allows this retention to stand despite an erasure request. The log is technically tamper-proof: no early deletion is possible before the retention period ends, other than upon judicial decision. While your account is active, these entries are included in the export of your data from the App; after account deletion, you can request to view them by writing to the contact address (right of access, Article 15 GDPR). |
Exception to the right to erasure: a record of your acceptance of the Terms of Service and this Privacy Policy is preserved in a separate and tamper-proof log, including after account deletion. This log contains only: email address, internal identifier (UUID), date and time of acceptance, version of the documents accepted and a technical fingerprint of the accepted text. Legal basis: legitimate interest, Article 6(1)(f) GDPR (retention necessary for the defence of legal claims); Article 17(3)(e) GDPR then allows this retention to stand despite an erasure request. Duration: 10 years (ordinary statute of limitations under Swiss law, Article 127 of the Code of Obligations). The log is technically tamper-proof and inaccessible to users and employees alike; deletion is only possible upon judicial decision or documented manifest error.
Suspension in case of dispute: if a formal dispute is ongoing (filed complaint, court proceedings or a request from an authority), deletion of the data concerned may be suspended for the duration of the procedure, in accordance with Article 17(3)(e) GDPR.
6. Your rights
Under GDPR and Swiss FADP, you have the following rights at any time:
- Right of access: obtain a copy of all your data
- Right to rectification: correct inaccurate information
- Right to erasure ("right to be forgotten"): delete your account and all your data
- Right to portability: receive your data in a readable format (JSON; your retained audio files are provided via download links)
- Right to object: refuse certain processing based on legitimate interest
- Right to restriction: freeze the processing of your data in certain cases
- Right to withdraw consent at any time
To exercise these rights, write to contact@lightsonme.app from the email address associated with your account. We respond to your requests within the timeframes provided by applicable law, as a rule within one month. Where applicable law allows it due to the complexity or number of requests, this period may be extended by two months; we will inform you within the first month.
You may also lodge a complaint with:
- FDPIC (Federal Data Protection and Information Commissioner) in Switzerland: edoeb.admin.ch
- CNIL in France: cnil.fr
- The data protection authority of your country of residence
7. Security
We implement the following measures to protect your data:
- HTTPS/TLS encrypted communication on all requests
- Hashed passwords (never stored in plain text)
- Row Level Security (RLS) on the database: each user can only access their own data
- Regular security audits
- No personal data in bug reports
No system is infallible; we encourage you to use a strong, unique password.
8. Sensitive content detection
This analysis only takes place if you have explicitly consented to it in the App (a consent separate from these terms, withdrawable at any time from Settings). For your safety, the App then analyzes the text of what you share (transcripts of your voice sessions, text you type) to detect signs of serious distress related to suicide or self-harm, violence suffered, addiction, or eating disorders. Psychotic and dissociative states are not searched for. The safety log does not record which subject was detected: it only records whether it was a suicide-risk signal or another form of distress. When detected:
- Instead of an AI feedback, the App displays a support message and verified emergency resources (24/7 professional helplines for your country)
- A detection event is logged for safety and system improvement: category, no excerpt of what was said since 27 July 2026 (earlier entries contain one, of at most 200 characters, erased after 6 months), language, your internal user ID (which links you to that entry), session ID, detection method, usage mode, date of the detection, and the flags and timestamps for the display of the support message and the emergency resources. The entry is kept for 10 years from the detection
No external human contact is automatically triggered. You remain the sole decision-maker. In case of imminent danger, contact emergency services immediately (112 in Europe, 911 in North America, or your local emergency number).
9. Minors
The App is restricted to adults (18 years and older). Age is confirmed at account creation. If you are under 18, do not use the App. If we discover that an account has been created by a minor, we will delete it immediately.
10. Cookies and tracking
The mobile App does not use cookies. It contains no advertising pixels or third-party trackers for marketing purposes.
11. Changes to this policy
This policy may be updated to reflect legal, technical, or functional changes. The last updated date appears at the top of this document. In case of substantial changes, you will be notified within the App at least 14 days before the changes take effect.
12. Governing law and jurisdiction
This policy is governed by Swiss law. For users residing in the European Union, the mandatory provisions of GDPR and national data protection laws apply additionally.
Any dispute will fall under the jurisdiction of the courts of Geneva, Switzerland, subject to mandatory rules of jurisdiction applicable to consumers.
For any question: contact@lightsonme.app