Luciyah Privacy Policy
What we collect, why we collect it, who we share it with, and your rights.
Who we are
Luciyah is provided by Anshina Ltd (“we”, “us”, “our”), a company registered in England and Wales. Anshina Ltd is the controller of the personal data described in this policy. Contact: admin@anshinaltd.com.
What this policy covers
This policy explains what personal data Luciyah collects, why we collect it, how we use it, who we share it with, how long we keep it, and your rights.
Data we collect
Depending on how you use the app, we may process:
- Account and profile data: your phone number, authentication and account identifiers, confirmation that you are 18 or over, and profile details you choose to add, such as your name, pronouns, and photos.
- Service data: pulses you create, mutuals, invitation state, preferences, hashed identifiers used for discovery, and an optional name hint for a person you select. We may receive a hashed identifier or name hint relating to you when another user selects you.
- Contacts: if you allow contacts access, the app reads names and phone numbers on your device. For discovery and to deliver pulses, Luciyah sends hashes of normalised phone numbers, not raw contact phone numbers, to our servers. We do not upload your address book. If you select someone for a pulse, we may store the name you choose as a hint. If you invite someone, their number is passed to the messaging app you choose.
- Usage analytics data: coarse, categorical information about how the app is used — which screens are reached, whether an action started, succeeded, or failed, a coarse failure category, referral-source answers, and how many recipients a bulk invitation was addressed to — together with app version, device type, operating system, approximate region, and an app-instance identifier generated by Google Analytics for Firebase. Luciyah’s analytics events do not include your name, phone number, email address, contact details, pulse text, the specific pulse category you chose, or any pulse, mutual, notification, account, or request identifier. We removed those identifiers from our analytics events; until an installation is updated, an older version of the app may still send some of them. See “Usage analytics and your choice” below.
- Security and communications data: IP addresses, push and device tokens, app-integrity information, and operational and error logs used to authenticate users, deliver notifications, prevent abuse, and keep the service reliable.
- Purchase and subscription data: product, receipt or purchase-token, purchase, renewal, refund, and entitlement information. Apple or Google processes your payment and store-account details; we do not receive your full payment-card details.
We do not request precise GPS location. We do not sell personal data or share it for third-party advertising.
How we use data
We process the data described above to:
- Create and operate your account and provide Luciyah’s pulse and mutual features.
- Analyse usage trends, understand how people find and use Luciyah, troubleshoot problems, and improve the service.
- Process purchases, maintain subscription entitlements, prevent fraud, and provide customer support.
- Send service, pulse, mutual, and account-related notifications.
- Protect the reliability and security of Luciyah.
Legal bases (UK/EEA)
We process your data based on:
- Contract — to create and operate your account, provide pulse and mutual features, and manage paid features.
- Legitimate interests — to secure, troubleshoot, understand, and improve Luciyah, after balancing those interests against your rights. This includes the aggregate usage statistics described under “Usage analytics and your choice”, which you can switch off in the app.
- Consent — where we ask for it, including for optional device permissions or storage and access technologies where consent is required.
Who receives data
We disclose personal data only as needed to operate Luciyah:
- Other Luciyah users — pulse information, mutual status, and relevant profile information where Luciyah’s pulse and mutual features require it.
- Google Firebase — processes account, profile, service, photo, notification, and security data for Authentication, Firestore, Cloud Functions, Cloud Storage, Cloud Messaging, App Check, and Hosting.
- Google Analytics for Firebase — for the coarse app-activity, app-instance, event, and device data described above, used only to produce aggregate usage statistics and service-improvement reports. Google acts as our processor for this data. We do not enable Google Signals, advertising or Google Ads links, ads personalisation, Analytics User-ID, or user-provided data, and we do not enable sharing with other Google products and services.
- RevenueCat — processes a Luciyah account identifier, store receipts or purchase tokens, product and subscription history, and entitlement status to validate purchases, provide paid access, and produce purchase reports.
- Apple App Store or Google Play — operates the relevant store and payment service under its own privacy notice. It provides purchase confirmations and receipt information, not full payment-card details, to us and RevenueCat.
We may also disclose information where the law requires us to do so. We do not sell or rent personal data or share it for third-party advertising.
International data transfers
Some providers process data outside the UK. Where UK law treats a transfer as restricted, we use an applicable adequacy regulation or approved contractual safeguards, as appropriate.
Data retention
- We keep account and service data while your account is active.
- You may delete your account at any time. This removes your account, profile, photos, pulses you sent, mutual records, device registrations, and related in-app notification records.
- Limited provider records, transaction records, security logs, and records submitted by others may remain where needed for legal or accounting obligations, fraud prevention, security, or disputes.
- Usage analytics event data is retained in Google Analytics for Firebase for two months. Technical logs are kept only for the period reasonably needed to secure the service and investigate problems. Aggregate statistics that no longer identify an individual may be kept for longer.
- We keep purchase and subscription records while needed to provide entitlements and afterwards where required for accounting, fraud prevention, or disputes.
Usage analytics and your choice
Luciyah uses Google Analytics for Firebase to produce aggregate statistics about how the app is used, so we can see where people get stuck and improve it. We do not use it for advertising, and we do not use it to build a profile of you.
We rely on the statistical-purposes exception in the UK Privacy and Electronic Communications Regulations, together with our legitimate interest in improving the service, rather than on your consent. That means usage analytics is on by default and you can object at any time.
To turn it off in current versions of the app, open Luciyah and go to your avatar → Account & Safety → Usage analytics. If you do not see that control, update to the latest version. The setting applies to the installation of Luciyah on that device and stays off across restarts and account changes until you turn it back on, clear the app’s data, or uninstall the app.
Turning it off stops Luciyah’s own analytics events and stops Google Analytics for Firebase collecting automatically from that installation, and resets the app-instance identifier held on the device. It does not delete aggregate reports Google has already received. To ask us about data already collected, see “Your rights” below.
Your rights
Depending on your location, you may have the right to:
- Access, correct, or delete your data.
- Restrict or object to certain processing, including processing based on legitimate interests.
- Request data portability.
- Withdraw consent where processing relies on consent.
To exercise your rights, email admin@anshinaltd.com. You can withdraw permissions (e.g., contacts access) in your device settings at any time.
Data protection complaints
If you have concerns about how we use your personal data, you can make a data protection complaint by emailing admin@anshinaltd.com. Using “Data protection complaint” in the subject line will help us route it, but you do not need to use those exact words. We will acknowledge your complaint within 30 days, investigate it without undue delay, keep you informed, and explain the outcome.
You can also complain to the UK Information Commissioner’s Office or your local data-protection authority at any time.
Children
Luciyah is intended for adults aged 18 and over.
We do not knowingly collect or process personal data from anyone under 18. If we become aware that we have inadvertently received data from a user under 18, we will delete it promptly.
By using the app, you confirm that you are 18 or older.
Security
We use appropriate technical and organisational measures to protect personal data. No system can be guaranteed completely secure.
Changes
We may update this policy periodically. The most recent version will always be published at the same URL, with an updated “Last updated” date.
Contact
Anshina Ltd
London, United Kingdom
Email:
admin@anshinaltd.com