lucina

Privacy Policy

Last updated 17 August 2026

lucina is operated by Noam Eilon. This policy explains what the app collects, why, who processes it, and how to delete it. If anything here is unclear, email [email protected].

What we collect

Account

You can sign in with an email address and password, with Sign in with Apple, or with Sign in with Google. We store your email address; passwords are held by our authentication provider and are never visible to us. If you use Sign in with Apple, Apple may give us a private relay address instead of your real one; that works fine, and we never receive your Apple ID password. If you use Sign in with Google, Google tells us the email address on your Google account. Password reset emails are sent by our authentication provider.

Your name choices

Every swipe you make — keep or pass — is stored against your account. This is what the app is for: it powers your lists, and it is how a match is detected when you and your partner both keep the same name. Your passes are never shown to your partner. Names you add yourself, and any note you attach to them, are stored the same way.

Your couple link

If you pair with a partner, we store the link between your two accounts so matches can be computed and so a single subscription can cover you both.

Subscription status

We store whether your subscription is active and when it ends, together with the purchase records our subscription provider sends us. Payment is handled entirely by Apple through the App Store — we never see or store your card details.

Push notifications

If you allow notifications, we store a device push token so we can tell you about a new match or a family vote. To deliver a notification, its text passes through our push provider and then through Apple's or Google's notification service — and that text names the matched name, or the nickname of the family member who voted. Revoking the permission in your phone's settings stops the notifications; the stored token itself is removed when you delete your account.

Analytics

Product analytics are off by default. They are collected only if you switch on Product analytics from your profile in the app, and you can switch it back off at any time. When enabled, we record which features you use — for example that a swipe happened, or that a family page was created with a certain number of names. We never send the names you swipe on, your matches, the contents of a family page, your email address or your location.

These events are linked to your account, not anonymous: we send them with your account identifier so that one person's usage can be told apart from another's. Turning the setting off stops new events being sent.

Family pages

When you publish a shortlist for relatives to vote on, we store the names on that list, the passcode protecting it, and each participant's chosen nickname, votes and comments. The passcode is stored in a form we can show you again in the app, so treat it as a shared code rather than a password. The page is not listed anywhere and is excluded from search engines — anyone with the link and the passcode can view it, so share both carefully. Deleting the page deletes the votes and comments with it. Family members who vote do not need an account, and we do not ask them for an email address.

Diagnostics and server logs

If the app crashes we receive a technical error report to help fix it. These reports are about the failure, not about you: your account is identified in them only by a one-way hash, never by your email address. Our servers also write a line per request, in which client IP addresses are truncated before they are written. Those lines stay on the server that produced them and are discarded when it is replaced by a new deployment; we do not ship them anywhere else.

Who processes your data

We do not sell your data, and we do not use it for advertising.

Where your data is held

Our database is hosted in the European Union, and so is our crash reporting. Our product analytics provider stores its data in the United States, and the other processors listed above operate in the United States or globally, so your data may be transferred outside the EU.

Deleting your data

You can delete your account from your profile in the app. This removes your account, your swipes, your lists and your saved push tokens.

Two deliberate exceptions, both about not destroying someone else's work:

One technical record also survives, for a different reason. Each time your partner swipes, our server keeps its own answer to that request so that it can repeat that answer safely if the app asks again after a dropped connection. That record belongs to your partner's account, not yours, so your deletion does not reach it. If the answer announced a match, it holds the name that matched and any note written on it, frozen as it was at the time. Nothing in the app displays these records, and we can clear them, but nothing clears them on a schedule today.

We also keep a limited set of security and payment records — for example administrative audit entries and the purchase notifications sent to us by our subscription provider — which may still contain your account identifier after your account is deleted. Deletion does not cancel a subscription; that is done through Apple.

Deleting the app without deleting your account does not delete your data.

How long we keep things

Nothing attached to your account is deleted on a timer, so most of these are criteria rather than fixed periods:

Your rights

Wherever you live, and in particular if you are in the EU or UK, you can ask us to:

Email [email protected] to exercise any of these. If you think we have handled your data badly, you can also complain to the data protection supervisory authority for the country you live in.

Children

lucina is not directed at children and is not intended for use by anyone under 13.

Changes

If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you in the app.

Contact

[email protected]