Privacy Policy
Who we are
LO (hellolo.app) is a family-memory app operated from the United Kingdom. We are the data controller for the personal information described in this policy. You can reach us about anything privacy-related at hello@hellolo.app.
Our promise, in plain words.
Your family's memories belong to your family. We never sell personal information, we show no advertising, and we never use your photos, voice recordings, letters, or your child's information to train AI models — ours or anyone else's.
Everything LO knows about your child comes from you, their parent or guardian. You can edit or delete any of it — or your whole account — at any time, from inside the app.
The information we collect
About you
- Account details — your email address and, if you sign in with Apple or Google, the identity token they share with us. LO has no passwords.
- Device details — your time zone (so morning cards arrive in your morning) and, if you allow notifications, a push token for your device.
- Subscription status — whether your membership is active, managed for us by RevenueCat and Apple. We never see your payment card.
About your child — provided by you
- Their name, date of birth, and gender.
- The moments you record: written notes, voice notes, letters, milestones, and things they've said.
- Details of the photos you add (see below).
Photos
Your photo library stays on your device. When you add a photo to LO, we store its details — when and where it was taken, and quality signals such as whether faces are visible — not the picture itself. The images you see in LO are displayed from your own device.
To write captions and stories, a photo is sent over an encrypted connection to our AI provider (Google Vertex AI), processed, and not retained by LO's servers — we store only the resulting caption and description. See "How we use AI" below.
Voice recordings
When you record a voice note or letter, the audio is transcribed by our transcription provider (OpenAI) over an encrypted connection. If you save the note, the recording is kept privately with it so you can listen back; if you don't save, it is discarded. Deleting a note deletes its audio.
Face information — only with your explicit consent
Covered fully in its own section below. LO never creates face data without you agreeing first.
Collected automatically
- Crash and error reports — technical diagnostics (via Sentry, hosted in the EU) so we can fix problems. These are configured to contain no personal content, no screenshots, and no message text.
LO uses no advertising or tracking technology, no third-party analytics profiles, and does not track you across other apps or websites.
Your child's information
LO exists to hold memories of your child. Everything LO knows about them — their name, their birthday, the photos, the things they've said — comes from you, their parent or guardian, and is visible only within your account. You are in control: you can edit or delete any single memory, or delete your child's entire record, at any time.
We designed LO with children's best interests in mind. Children's information is never used for advertising, never profiled for commercial purposes, never sold, and never used to train AI.
LO accounts are for adults (18+). We do not knowingly collect information directly from children, and children cannot create accounts. If we learn a child has created an account, we will delete it.
Face information (biometric data)
If you turn on face recognition, LO analyses photos on your device and creates a numerical summary of each face — a "face print" — so we can suggest who appears in your photos ("Is this Nana?"). Face prints are biometric data under UK GDPR (special-category data, Article 9). Here is exactly how we treat them:
- We only create face prints with your explicit consent, asked for in the app before any face analysis happens. This is enforced on our servers, not just in the app's interface.
- Face analysis happens on your device. The resulting face prints (numbers, never images) are stored with your account on our UK servers.
- Face prints are used for one purpose only: suggesting and organising who appears in your family's photos. Never for identification outside your account, never shared, never used for training.
- The app also estimates the approximate age of faces on your device to tell adults from children when grouping — those estimates are momentary and are never stored anywhere.
- You can withdraw consent at any time in My Account. If you do, face recognition stops.
- Deleting a tagged person, a child, or your account deletes the associated face prints.
Face tagging can include other people in your photos — grandparents, friends. Please only tag people with their agreement.
How we use AI
LO uses AI to turn what you capture into keepsakes: photo captions, story text, slideshow narration, tidied-up transcripts of voice notes and letters, and gentle context (for example, understanding from your notes that your child is in a dinosaur phase, so captions feel true to them). To do this:
- Google Vertex AI (Gemini) processes photos and the text you write to generate captions and stories. Google processes this as our service provider and does not use it to train its models.
- OpenAI transcribes voice recordings. OpenAI processes this as our service provider and does not use it to train its models.
- Our AI features may recognise sensitive themes in what you write (for example illness or loss) solely so that generated text handles them with care. These signals stay inside your account and are never used for anything else.
We never use your content to train AI models, and we do not permit our providers to. AI-generated text is always editable by you.
Why we process your information (lawful bases)
| Information | Purpose | Lawful basis (UK GDPR) |
|---|---|---|
| Account & subscription details | Providing LO, signing you in, managing membership | Contract (Art. 6(1)(b)) |
| Your child's information, photos details, notes, letters, voice recordings | Creating and keeping your family's memories; generating captions, stories and slideshows | Contract (Art. 6(1)(b)) |
| Face prints | Suggesting who appears in your photos | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| Time zone & push token | Delivering notifications at the right time | Contract / consent (you choose whether to allow notifications) |
| Crash & error reports | Keeping LO working and secure | Legitimate interests (Art. 6(1)(f)) |
| Emails we send (sign-in codes, account notices) | Operating your account | Contract |
We do not rely on consent for anything except face recognition and notifications — and we never send third-party marketing.
Who we share information with
We share personal information only with the service providers below, only so they can provide their service to us, and never for their own purposes:
| Provider | What they do for LO | Where |
|---|---|---|
| Supabase | Database, authentication and storage hosting | London, UK (AWS eu-west-2) |
| Google Cloud (Vertex AI) | AI caption and story generation | EU data storage; processing may occur globally |
| OpenAI | Voice transcription | United States |
| Apple | Sign in with Apple, notifications, payments | Global |
| RevenueCat | Subscription management | United States |
| Resend | Sending sign-in and account emails | EU sending region |
| Sentry | Crash and error reporting | EU (Germany) |
| Cloudflare | Serving this website | Global edge |
We may also disclose information if the law requires it. We never sell personal information, and we never share it with advertisers or data brokers.
International transfers
Your family's data lives primarily in London, United Kingdom. Where a provider processes data outside the UK (for example OpenAI and RevenueCat in the United States, or Google's global AI processing), we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, alongside the providers' own safeguards.
How long we keep your information
- While your account is active: we keep your memories for as long as you keep your account — that is the point of LO.
- Account or child deletion: a 30-day grace period applies, during which everything is frozen and invisible and you can change your mind. After 30 days, deletion is permanent.
- Tagged people: deleting a person from your family tree removes them, and their face prints, immediately.
- Withdrawn face-recognition consent: stops face-print creation immediately.
- Backups: residual copies in encrypted backups clear within 30 days of deletion.
- Deletion record: after deletion we keep a record that a deletion happened (dates and counts only — it contains no names, no emails, and no content).
Deleting your data
Deletion is self-service, inside the app: My Account → Settings lets you delete a single tagged person (immediate), a child's entire record, or your whole account (both with the 30-day grace period, and reinstatable during it). Account deletion also deletes your sign-in identity and, if you used Sign in with Apple, revokes it with Apple. You can also email hello@hellolo.app and we will do it for you.
Security
All data is encrypted in transit and at rest. Access to your family's data is enforced row-by-row at the database level — every request is checked against your signed-in identity, so no other account can read your family's memories. Photo pixels never leave your device except transiently for AI captioning, as described above.
Your rights
Under UK GDPR (and EU GDPR where it applies) you have the right to access, correct, delete, restrict, or object to our processing of your personal information, the right to data portability, and the right to withdraw consent (for face recognition) at any time. Most of these you can exercise directly in the app; for anything else, email hello@hellolo.app. We respond to all legitimate requests within one month.
US privacy rights
If you live in California or another US state with a consumer-privacy law: we do not sell or share personal information as those laws define it, and we do not use sensitive personal information beyond providing LO's features. You have the right to know, correct, and delete the personal information we hold — the in-app tools and email address above are how to exercise them. We do not discriminate against anyone for exercising privacy rights.
Complaints
If you're unhappy with how we've handled your information, please contact us first at hello@hellolo.app — we'd like the chance to put it right. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
Changes to this policy
If we make material changes, we'll tell you in the app before they take effect. The date at the top is the version currently in force.
LO · hellolo.app · hello@hellolo.app