Legal

Privacy Policy

Last updated: 15 September 2026 Effective date: 15 September 2026

The short version

  • Lysning is a personal-finance app built around your goals and a “Safe to Spend” figure.
  • Your money data never leaves your device on its own. Transactions, balances, accounts, goals, income, categories — all of it lives only on your phone, in a database encrypted with a key held in your device’s secure hardware store. We have no copy and no way to see it. The app can make a backup or an export for you to keep, but only when you ask, and only to where you send it (Section 2).
  • From the app, the only data that leaves your device is opt-in analytics and crash reports, plus a check for app updates. Analytics and crash reports are off until you say yes, contain no financial data and no name or email, and are keyed by a token that is destroyed and regenerated every calendar month — so nothing links what you did in one month to the next. The update check runs each time the app opens, carries no financial data, and is described in Section 3(h). Anything you choose to email us, such as feedback, reaches us too (Section 3(i)).
  • If you join the launch waitlist on our website, we hold your email address — only because you typed it in, only to tell you when Lysning is live, and you can unsubscribe from any message we send. It is never linked to anything in the app.
  • No cloud sync today. If we launch it, this policy will change first and it will be opt-in.
  • Backups are yours to keep. Back up your data to an encrypted file, or export your transactions as a spreadsheet. Both go wherever you choose to send them — we never receive either.
  • Beta terms: using the beta is also governed by our Terms of Service.
  • You’re in control: withdraw consent any time in Settings → Privacy; collection stops immediately, at runtime.

1. Who we are

Lysning is developed and operated by Krishna Babuji, a sole trader (the “controller” for the purposes of UK data protection law). Contact: privacy@lysning.app.

This policy is written to the UK GDPR and the Data Protection Act 2018. Wherever you are, you receive the same protections described here.

2. Data stored on your device (we never receive this)

Lysning is a local-first app. The following data is created and stored only on your device, in a database encrypted at rest (SQLCipher) with a random per-installation key held in your device’s secure key store. We have no server-side copy and no ability to access it:

  • Financial transactions (amounts, dates, payee/description, notes)
  • Account names and balances; transfers between your accounts
  • Categories, categorisation rules, spending Plans (allowances)
  • Goals, goal contributions and reserves
  • Income, pay-period and “Safe to Spend” settings
  • Currency and locale preferences
  • App settings, including your consent choices

Because this data never reaches us, we cannot retrieve, back up, restore, export, or delete it for you — there is nothing at our end to act on. What the app does instead is give you the tools to do all of it yourself.

a) Backups you make

Settings → Data → Back up writes your whole database to a single .lysningbak file, encrypted with a passphrase you choose. The passphrase is never sent anywhere and is not stored — not on your device and certainly not by us — so nobody, ourselves included, can open that file without it. If you forget it, the backup cannot be recovered.

The file is handed to your device’s share sheet, which means you choose where it goes: Files, iCloud Drive, another app, a message to yourself. From that moment the file is in your hands. Where it is stored, who can reach it, and how long it is kept are governed by whichever service you sent it to and its own privacy policy, not by this one. Settings → Data → Restore reverses the process from a file you pick.

b) Exports you make

Settings → Data → Export writes your transactions to a spreadsheet file (CSV) and hands it to the same share sheet.

A CSV is not encrypted. Anyone who can open the file can read the amounts, dates, payees and notes in it. That is what an export is for — it has to be readable by a spreadsheet to be worth anything — but it does mean an export is the one form in which your financial data leaves your device in the clear. It happens only when you ask for it, and only to the destination you pick.

c) If you lose the device

If you made a backup, restore it. If you did not, the data is gone: there is no cloud copy, and we cannot recover it for you. That is the trade for there being no server.

3. Data that can reach us

On first launch you are asked whether to enable usage analytics and crash reporting. Both are off until you consent, and off in development builds — subsections (a) and (b). Subsection (f) covers the separate, optional waitlist on our website. Two things here do not run on consent. Subsection (g) is switched off in this build; it is set out in full so that nothing about it arrives unannounced. Subsection (h), the check for app updates, is active. Subsection (i) covers emails you send us, including through the app’s feedback link.

a) Product analytics (PostHog, EU-hosted)

Events describing how the app is used — e.g. an onboarding step completed, a goal created, a transaction logged, “Safe to Spend” viewed, an import started or abandoned. Each event may carry only a short allowlisted set of non-identifying properties (a step number, a source/kind enum, a millisecond timing, a yes/no flag). The app technically enforces this allowlist, so amounts, balances, account names, payees and transaction descriptions can never be included — even by mistake.

These events are pseudonymous, not anonymous: each carries a token derived on your device from a random per-install secret and the current calendar month. The token is discarded and regenerated at each month boundary, so events can be grouped within a month but never across one. We do not build user profiles, and we never call the analytics functions that would link identities (identify(), alias()) — this is enforced by automated test. We never learn your name, email, or any account from these events.

b) Crash reporting (Sentry)

If you have consented, uncaught errors send only the exception type and code stack frames (file / function / line — not the runtime values in them), plus the operating system name and major version. Error messages are redacted before sending, diagnostic breadcrumbs are dropped, and Sentry’s per-install identifier, your IP address, device model, screen dimensions and locale are all stripped — a crash report carries no identifier at all.

c) Technical metadata

As with any networked service, connection metadata such as your IP address is visible to the server that terminates the connection — a property of how networks work, not something an app can suppress. The stored crash dataset carries no identifier; the stored analytics dataset carries only the monthly rotating token described above.

d) TestFlight (beta only)

The current beta is distributed through Apple’s TestFlight. Apple collects data from beta testers under its own terms — including your email address or invitation link, name (if provided), and usage, crash and device information which Apple may share with us in aggregate or per-build form. This collection is governed by Apple’s privacy policy and the TestFlight terms, not by this policy. This section will be removed at public release.

e) App-store analytics

Apple’s App Store provides us aggregate, anonymised metrics (installs, crashes, coarse demographics) under Apple’s own terms, subject to your device’s privacy settings.

f) Launch waitlist (website)

Our website at lysning.app offers an optional waitlist. If you choose to submit it, we receive your email address and nothing else — no name, no financial data, and nothing connected to your use of the app. There is no waitlist in the app, and submitting one is never required to use Lysning.

The form is hosted by Buttondown (Buttondown LLC, United States), who store the address on our behalf under a data processing agreement. We use it for a single purpose: to tell you when Lysning is publicly available. Every message includes a one-click unsubscribe, and we delete the list once the launch announcement has been sent (see Section 7).

g) Aggregate statistics — built, but not switched on in this build

The app contains a second, deliberately different kind of measurement, which we are describing here before it is ever used rather than after.

It carries no identifier at all — not even the monthly token in (a). Instead of sending us events, the app keeps a few counters on your device and, at most, sends a periodic summary of them as coarse bands: roughly how many days the app has been used (a band such as “8–14”, never a number), whether a first goal has been created (yes/no), how far onboarding got, the app version and the operating system name. The counting happens on your device; the individual events never leave it, and there is nothing in a summary that distinguishes one installation from another.

Because it carries no identifier and exists only to produce statistics, this would run under the statistical-purposes exception in PECR (Schedule A1 ¶5) rather than on your consent — so it would be on by default, with a right to object rather than a request to opt in.

None of it is active in the build you are using. The code is present and switched off. Before we switch it on we will publish an updated version of this policy describing exactly what is sent, and ship a control in Settings → Privacy to object and stop it. Until both of those things exist, the only data that reaches us from the app is the opt-in analytics and crash reporting in (a) and (b), the update check in (h), and any email you choose to send us under (i).

h) App updates (Expo)

Each time you open the app, it asks our update service, run for us by Expo, whether a newer version of the app’s code is available, and downloads it if so. This is how fixes, and new versions of this policy and our Terms, reach you without waiting for an App Store release. It runs whether or not you have consented to analytics, because without it the app cannot receive updates.

The request carries your IP address (see (c)), your operating system (iOS or Android), the app’s version and release channel, identifiers of the app update currently installed, and a random identifier created by the update software when the app is installed. That identifier stays the same until you uninstall the app. It contains no financial data, no name or email, and is not connected to the analytics token in (a) or to crash reports in (b).

i) Feedback and emails you send us

The Send feedback link in Settings opens your own email app with a draft addressed to support@lysning.app. Nothing is sent until you press send, and you can change or delete anything in the draft first. The draft includes the app’s version, build and installed update, your operating system and its version, the screen you were on and, if you are reporting a problem, a short error message. It never includes financial data.

When you send it — or any other email to one of our addresses — we receive the message, anything you attach, and your email address. We use it only to reply to you and to fix what you report.

  • Consent (UK GDPR Art. 6(1)(a); PECR reg. 6): analytics and crash reporting run only on your consent, requested clearly before any collection begins.
  • Purpose: exclusively to understand aggregate product usage, measure reliability, and fix crashes. Never for advertising; never sold or shared with data brokers.
  • Waitlist consent (UK GDPR Art. 6(1)(a); PECR reg. 22): we email you only because you asked us to. Unsubscribe via the link in any message, or by emailing privacy@lysning.app — either removes you from the list entirely.
  • Aggregate statistics (PECR Schedule A1 ¶5, statistical purposes; UK GDPR Art. 6(1)(f), legitimate interests): the measurement described in Section 3(g) would rely on this rather than on consent, because it carries no identifier and produces only aggregate counts. It is not active in this build, and will not become active before this policy is revised and an objection control ships.
  • App updates (UK GDPR Art. 6(1)(f), legitimate interests): the update check in Section 3(h) delivers fixes and security updates to the app you installed. It does not rely on consent, and withdrawing analytics consent does not stop it.
  • Feedback and emails (UK GDPR Art. 6(1)(f), legitimate interests): we use what you send us, described in Section 3(i), to reply to you and to fix what you report.
  • Withdrawal: any time in Settings → Privacy. Withdrawal takes effect immediately at runtime — it stops all further collection, tears down the analytics and crash SDKs, and destroys the install secret the monthly token is derived from, so the token cannot be regenerated.

5. Data sharing and processors

We do not sell your data. The only third parties processing data on our behalf are:

  • PostHog (product analytics; EU-hosted — and, should Section 3(g) ever be switched on, a second, entirely separate project for it, so that an identifier-free summary can never be joined to a pseudonymous event stream)
  • Sentry (crash reporting)
  • Expo (app update delivery)
  • Apple (TestFlight distribution and aggregate store analytics)
  • Umami (website analytics; cookieless, collects no personal data and sets no cookies)
  • Buttondown (website waitlist; stores the email address you submit)

6. International transfers

Analytics data is stored by PostHog in the EU (covered by the UK adequacy decision for the EEA). Crash data may be processed by Sentry in the United States. Update checks are handled by Expo in the United States. Waitlist email addresses are stored by Buttondown in the United States; the transfer relies on Standard Contractual Clauses with the UK Addendum, as set out in Buttondown’s data processing agreement.

7. Data retention

  • On-device financial data: stays on your device until you delete it or uninstall; we hold no copy and set no retention period because we never receive it.
  • Analytics and crash data: retained by our processors per configured retention, and unlinked from you at each month boundary by the token rotation.
  • Update-check data: retained by Expo per its retention for update requests.
  • Feedback and emails: kept only as long as needed to reply and to fix what you reported, then deleted.
  • Waitlist email addresses: held until the launch announcement is sent, then deleted within 30 days — or immediately, whenever you unsubscribe or ask us to remove you.

8. Your rights (UK GDPR)

You have the right to access, rectify, erase, restrict, object to the processing of, and port your personal data, and to withdraw consent at any time without affecting prior processing.

  • Your financial data: we never hold it, so you exercise these rights directly in the app — edit or delete records, export them to a spreadsheet (which is how portability works here, since there is nothing for us to transmit), erase everything at once in Settings → Data → Delete all data, or uninstall.
  • Analytics, crash and update-check data: the datasets are pseudonymous and we hold nothing that links them to you as an individual; under UK GDPR Art. 11 we may be unable to identify your records in order to fulfil an access or erasure request, and we will tell you if so. Withdrawal of consent (Section 4) is always available and immediate.
  • Waitlist data and emails you send us: unlike the datasets above, your email address does identify you, so your access, rectification, erasure, restriction, objection and portability rights apply to it in full and without qualification. Email privacy@lysning.app and we will act on it.
  • Complaints: you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, though we’d appreciate the chance to resolve any concern first — contact us at privacy@lysning.app.

9. Children

Lysning is a financial app intended for adults. It is not directed at anyone under 18, and we do not knowingly collect data from anyone under 18.

10. Security

Your on-device data is encrypted at rest (SQLCipher) with a per-installation key stored in your device’s secure store. Analytics, crash and update-check data travel over encrypted connections. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

11. Changes to this policy

If how data is handled changes materially — in particular if we launch optional cloud sync/backup or a paid tier — we will update this policy, revise the “Last updated” date, and, where required, obtain fresh consent before any new processing begins.

If the operation of Lysning transfers to another entity — on a reorganisation, merger, acquisition, or sale of the business or its assets — that entity becomes the controller in our place. We will update this policy to name it, and revise the “Last updated” date, before or at the point the transfer takes effect. A transfer does not of itself change how your data is handled; any change to that would be notified as above. See Section 12 of the Terms of Service.

12. Future features — not active today

  • Cloud sync (planned for a paid tier): would let you sync your data between devices, or hold a copy for you. Not available today — the backups and exports in Section 2 are files you make and keep yourself, and nothing goes to a server of ours. If launched, this section will describe what is synced, where, the legal basis, retention and transfers, and it will require explicit opt-in.
  • Aggregate statistics (Section 3(g)): built and switched off. Not active until this policy is revised and an objection control ships.

13. Governing law

This policy is governed by the laws of the United Kingdom, including the UK GDPR and the Data Protection Act 2018.