Privacy Policy
Last updated: 2026-05-28
1. Who we are
LensDay is an Android mobile application providing AI-powered personal coaching. We are based in the European Union and operate under the General Data Protection Regulation (GDPR).
This Privacy Policy explains what data we collect through the LensDay app and the lensday.app marketing website, why we collect it, how we use it, and what rights you have.
Controller: LensDay (operated as a sole trader in Spain)
Location: Valencia, Spain
Privacy contact: privacy@lensday.app
LensDay does not currently appoint a Data Protection Officer under GDPR Art. 37; the privacy contact above is the single point of contact for all data-protection enquiries.
2. What data we collect
2.1 In the app — data you provide directly
- Your name, used to personalize coach responses during onboarding
- Photos and videos you submit as part of a check-in
- Voice recordings you submit as part of a check-in
- Text you write in a check-in or in a coach context field
- Profile preferences you set (preferred coach tone, voice, language, optional baseline answers)
- Email address used to create your account
2.2 In the app — data collected automatically
- Device model and operating-system version
- A unique identifier for your installation (used to associate check-ins with your account)
- Pseudonymized usage events covering navigation & engagement, coach interactions, subscription activity, and acquisition (for example: which screens you visited, how long check-ins took to complete) for the purpose of improving the app. Analytics consent is requested at first launch via a dedicated screen and can be changed anytime at Profile → Privacy & Data. When enabled, these events are forwarded server-side by our
analytics-forwardSupabase Edge Function to Google Analytics 4 via the Measurement Protocol — we never load Google’s SDK on your device. See section 4 for the full data-recipient list.
Our analytics are limited to the pseudonymized events listed above. We never collect the content of your check-ins, voice recordings, photos, or videos.
2.3 On this website — only with your consent
If you accept the analytics cookies prompted by the consent banner on this website, we collect:
- Page views and the URL path of pages you visit
- The referring URL (where you came from)
- Your browser’s language tag (e.g.,
en,pt-BR) - Clicks on links that lead to other websites (notably the Google Play Store listing)
- Whether you click an “install the app” call-to-action button on this site
We do not collect your IP address. Google Analytics 4 (the analytics tool we use, described in section 4) discards visitor IPs before recording.
If you do not accept analytics cookies, we collect none of the above from your website visit. No Google tag, no analytics script, no pixel.
2.4 What we explicitly do not collect
- Precise geolocation (GPS coordinates)
- Payment-card details or bank-account information — all payment processing is handled by Google Play
- Biometric data within the meaning of GDPR Art. 9(1). Photos and selfies you submit are processed as ordinary images for the purpose of your coaching session. LensDay does not run face detection, face recognition, face matching, or any other technique that produces a biometric template from your photos.
- Contents of your contacts list, calendar, or other apps installed on your device
We do not ask you to provide special-category data, such as health information, religion, political views, sexual orientation, or similar sensitive information.
Because LensDay is a journaling and self-reflection app, you may choose to include such information in your check-ins. If you do, we process it only to provide the LensDay service to you, including generating coach responses and related insights. We do not use this information for advertising, third-party profiling, or training general-purpose AI models.
3. How we use your data
We process your data only for the purposes listed below, and only under the legal basis indicated for each purpose under GDPR Article 6.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Delivering AI-powered coaching responses to your check-ins | Performance of a contract (Art. 6(1)(b)) |
| Personalizing the coach to your preferences (voice, tone, language, name) | Performance of a contract (Art. 6(1)(b)) |
| Sending reminder notifications about your check-in habit | Legitimate interests (Art. 6(1)(f)) |
| Improving the app (which features get used, where users drop off) | Legitimate interests (Art. 6(1)(f)) |
| Marketing-website analytics (Google Analytics 4) | Consent (Art. 6(1)(a)) — opt-in via the cookie banner |
| Meeting our legal obligations (responding to lawful requests, tax records) | Legal obligation (Art. 6(1)(c)) |
| Processing any special-category content (Art. 9 GDPR) that you voluntarily include in a check-in — for example, references to your health, mental health, religious or philosophical beliefs, political views, or sexual orientation — for the sole purpose of generating the coaching response you have asked for | Explicit consent (Art. 9(2)(a)), given when you start a check-in containing such content. You can withdraw this consent at any time by deleting your account or removing the relevant check-in. |
We do not use your data for advertising. We do not sell your data to third parties.
4. Third-party processors
We rely on the following third parties to provide parts of the LensDay service. Each has a Data Processing Agreement with us under GDPR Article 28.
In-app processors
- OpenAI / Anthropic / Google AI — LLM coaching response generation. Requests are sent without your account identifier; we have opted out of these providers using your data to train their general-purpose models.
- ElevenLabs — text-to-speech audio for coach replies.
- RevenueCat — subscription lifecycle management.
- Supabase (Frankfurt, EU —
eu-central-1) — primary database hosting. - Google Analytics 4 via Measurement Protocol — receives anonymized usage events forwarded server-side from our
analytics-forwardSupabase Edge Function (no SDK on your device). Data is sent to Google in the United States. Only fires when you’ve enabled analytics in the app’s privacy settings (Profile → Privacy & Data).
Website-only processor
- Google Analytics 4 via Google Tag Manager — loaded only if you accept analytics cookies. Data is sent to Google in the United States.
5. Cookies and browser storage
We use a small amount of browser-side storage on lensday.app. Under EU ePrivacy law, browser storage that affects user privacy is subject to the same transparency and consent rules whether it’s an HTTP cookie or localStorage; we treat both the same way.
What we set unconditionally (essential)
| Storage key | Purpose |
|---|---|
lensday.consent.v1 (localStorage) | Stores your consent decision — required so we don’t re-prompt on every page load |
lensday.locale (localStorage) | Stores your language preference so the cookie banner renders in your language on next visit |
These two are functional. They never leave your browser and they contain no personal data beyond your stated preferences.
What we set only with your consent (analytics)
| Storage | Source | Set when |
|---|---|---|
Google Tag Manager cookies (_ga, _gid, related) | You accept analytics cookies via the consent banner | |
| Google Analytics 4 cookies | Same |
We do not load any Google Tag Manager or Google Analytics script until after you accept analytics cookies. If you reject, no Google script is loaded — not even an empty stub.
How to change your consent
Click Manage cookie preferences in the footer of any page on this site. You can change your decision at any time.
How long we keep your consent decision
Your consent decision is stored in your browser indefinitely, until you clear your browser data or change it via Manage cookie preferences. We do not store consent decisions on our servers.
If we make a material change to our analytics relationships in the future, we will reset stored consent so you can re-decide. You will see the cookie banner again the next time you visit.
6. Data storage and retention
| Data category | How long we keep it |
|---|---|
| Check-in content (text, photos, voice, coach responses) | While your account is active, plus 30 days after a deletion request (soft-delete grace period — see section 8) |
| Profile data (name, preferences, voice, language) | Duration of your account |
| Pseudonymized in-app usage analytics | Up to 24 months |
| Device information | Up to 12 months |
| Marketing-website analytics (Google Analytics 4) | Per the retention period configured in our GA4 property (default 14 months) |
| Consent decision (browser storage) | Indefinitely in your browser, until you clear browser data or change your decision |
7. Data security
We protect your data through:
- TLS 1.2 or higher for all data in transit between your device and our servers
- Encryption at rest for the primary database
- Authentication and access controls limiting employee access to user data
- Regular reviews of our security posture
No method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we apply industry-standard protections.
8. Your rights under GDPR
As a data subject under GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — Ask us what data we hold about you. Export available in-app via Profile → Export Data.
- Right to rectification (Art. 16) — Correct inaccurate data. You can edit your profile, coach context, name, and preferences directly in the app.
- Right to erasure (Art. 17) — Delete your account and associated data. Two paths, both detailed at How to delete your account:
- In-app: Profile → Delete Account. Triggers a 30-day soft-delete grace period during which you can reactivate by signing back in. After 30 days your data is purged.
- By email: send a request to privacy@lensday.app from the address associated with your account.
- Right to data portability (Art. 20) — Export your data in a machine-readable format. Available in-app via Profile → Export Data — produces a JSON file you can save or share.
- Right to restriction of processing (Art. 18) — Ask us to stop processing your data while a dispute is resolved.
- Right to object (Art. 21) — Object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)) — For the analytics consent on this website, click Manage cookie preferences in the footer.
- Right to lodge a complaint with your local supervisory authority — see the European Data Protection Board’s list of national authorities.
We respond to verified requests within 30 days. For complex requests we may extend the period by a further 60 days and will inform you within the initial 30 days.
9. Children’s privacy
LensDay is not intended for users under 18 years of age. We do not knowingly collect data from children under 18. If we become aware that we have collected data from a child under 18, we will delete that data promptly.
10. International data transfers
Your primary user data is stored in the European Economic Area (Supabase, eu-central-1, Frankfurt, Germany).
Some processors operate from outside the EEA — specifically, OpenAI, Anthropic, Google AI, ElevenLabs, RevenueCat, and Google (for Google Analytics 4 — both the website’s Tag Manager integration and the app’s Measurement Protocol forwarder) may process data on infrastructure located in the United States. For these transfers we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable
- The EU-US Data Privacy Framework certification, where the processor is certified
- Other transfer mechanisms recognized under GDPR Chapter V
11. Subscription and payments
All subscription billing and payment processing is handled by Google Play. We do not see, store, or process your payment-card details or bank-account information. Refunds, chargebacks, and billing disputes are governed by Google Play’s terms.
We use RevenueCat to track your subscription state (active, expired, in trial, etc.). RevenueCat receives an anonymous app-user identifier and your subscription status from Google Play; it does not receive payment details.
12. Changes to this policy
We may update this policy from time to time. When we do:
- The Last Updated date at the top of this page changes
- Material changes are notified to active users through the app
- If a change materially affects analytics or third-party tracking on this website, we reset stored consent on the next visit so you can re-decide
Your continued use of the app or the website after a change signals acceptance of the updated policy.
For changes to our terms (as distinct from this Privacy Policy), see the Terms of Service.
13. Contact
For any privacy question, data-subject request, or complaint, write to:
We aim to respond within 5 working days for general queries and within 30 days for formal data-subject requests under GDPR.