Privacy policy
Last updated · September 18, 2026
Overview
Lazely ("we", "our", "the app") helps you build healthier digital habits. Most settings and detailed Screen Time information stay on your device. Some data is processed by our service providers to run subscriptions, generate AI conversations, secure the service, and understand how the app is used. This policy explains those differences.
You do not need to create an account. We do not sell your personal data or use it for advertising or tracking across other companies' apps and websites.
Screen Time, goals and preferences
Lazely uses Apple's FamilyControls, ManagedSettings and DeviceActivity frameworks to manage the apps you select and display usage reports. App selection uses opaque tokens. We do not send those tokens, app names, bundle identifiers, detailed per-app duration reports, or browsing history to our backend, Google Gemini, or Mixpanel.
Your onboarding answers, goals, focus sessions, intervention history and preferences are stored on your device. When you use an AI guardian, the app may send your active goal's title and category, your target duration, and whether the app you are trying to unlock has crossed certain daily usage thresholds (30, 60, 90, 120, 150 or 180 minutes). These threshold signals do not identify the app or disclose its exact usage duration. Analytics also include threshold events, as explained below.
AI guardian conversations
When you send a message to a guardian, including in the onboarding demo, your message is sent through our backend hosted on Cloudflare to Google's Gemini API to generate a reply. During an ongoing conversation, previous messages and replies are included to provide context. The regular guardian chat can also include the limited goal and usage context described above; the onboarding demo does not include your actual Screen Time history.
Our backend processes conversations to return replies and check generated content for safety. We do not store conversation text in our backend databases or include it in our analytics or operational logs. Text you choose to type can nevertheless contain personal information, so please avoid sending sensitive information or information about other people.
We use the paid Gemini API. Under Google's paid-service terms, prompts and replies are not used to improve Google's products or train its models. Google may retain them for a limited period for abuse prevention, security and legal obligations. This is different from saying that no provider ever retains a message. See the Gemini API terms.
Subscriptions and service security
Apple processes payments through the App Store. RevenueCat manages purchase history, subscription status and access to paid features using a randomly generated app user ID and transaction information, such as the product, expiration and renewal status. We do not receive your payment card details or Apple ID credentials. See RevenueCat's Privacy Policy.
Our backend uses Apple App Attest to verify requests from the app, and RevenueCat to verify subscription access where required. It stores an attested public key, verification counters and the app user ID, along with rate-limit and demo-usage state, to authenticate requests and prevent abuse.
Analytics and operational records
We use Mixpanel to understand onboarding completion, feature use, subscription conversion and intervention outcomes. Events can include timestamps, guardian or intervention mode, subscription tier, number of selected apps, usage thresholds crossed, and basic app, device and language information. Network requests also expose an IP address to the receiving provider, which may derive approximate location. We configure Mixpanel to use its EU collection endpoint.
A stable, randomly generated identifier links events from the same installation. The same identifier is used by RevenueCat and our backend, allowing us to relate app usage, subscription status and AI operating costs. These records are pseudonymous, not anonymous: they do not require your name or email, but can be linked together. We do not send chat text, goal text or the identities of your selected apps to Mixpanel. See Mixpanel's Privacy Policy.
Our backend retains technical records including request timestamps, device-key identifiers, app user IDs, model names and input/output token counts for cost monitoring. Safety incident records contain categories and actions such as a blocked or regenerated reply, not the message text.
In Lazely v2, the analytics switch in Settings disables product analytics from both the main app and its Screen Time extensions. Events from the disabled period are not sent if you turn analytics back on. This does not delete previously collected records or stop subscription processing and the backend security and operational records needed when you use AI chat. Contact us to object to processing or request deletion of existing records.
Notifications and support
With your permission, reminders and summaries use local notifications generated on your device. If you contact support, we receive your email address and the information you include, and use them to answer your request.
Service providers and international processing
- Apple — App Store payments and app integrity verification.
- RevenueCat — subscription management.
- Mixpanel — product analytics using its EU endpoint.
- Cloudflare — hosting our AI backend and its security and operational records. See Cloudflare's Privacy Policy.
- Google Gemini — generating and checking guardian replies through its paid API.
These services process data for the purposes described above. Their infrastructure and support operations may involve countries outside your country or the European Economic Area. Use of an EU analytics endpoint does not mean that every Lazely service processes data exclusively in the EU. Provider terms describe their processing locations and applicable transfer safeguards.
This website is hosted by Vercel and loads fonts from Google Fonts. Visiting it sends ordinary connection information, including your IP address and browser request details, to those providers. See Vercel's Privacy Policy and Google Fonts' privacy information.
Data retention and deletion
Local settings and history remain on your device until you remove them or delete the app. Device backups are managed separately through your Apple settings. Deleting the app does not automatically delete records already held by our backend, Mixpanel or RevenueCat.
Our backend does not maintain a saved conversation history. Its authentication, usage-cost and safety records currently have no automatic time-based deletion schedule. You can contact us to request deletion of records associated with your installation. Subscription, analytics and provider-side records are also subject to the relevant providers' retention rules and any applicable legal requirements. Google's limited safety retention is described in the AI section above.
Children's privacy
Lazely is designed for adults and is not directed at children under 13. If you believe a child has provided personal information through Lazely, contact us so we can investigate and address it.
Your privacy rights
Depending on applicable law, including the GDPR, you may request access, correction, deletion, restriction or portability of your personal data, and object to certain processing. Where processing relies on consent, you may withdraw it. You can also lodge a complaint with the CNIL or your local data protection authority.
Contact lazely.app@gmail.com to exercise these rights. When possible, include the User ID available in the app's Settings before uninstalling, so we can locate pseudonymous records. We may need additional information to verify and handle your request. We normally respond within one month, subject to the extensions allowed by applicable law.
Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
Contact
If you have questions about this privacy policy, contact us at lazely.app@gmail.com.
🦥